AI agent payments have produced four competing specifications, two industry foundations and an enormous amount of coverage in about a year. What they have not yet produced, for the overwhelming majority of merchants, is revenue. The gap between the noise and the numbers is the useful part to understand, because the excited coverage and the dismissive coverage are both wrong in ways that cost money.

Something real is being built. Google, OpenAI, Stripe, Coinbase, Shopify, Visa and Mastercard have all shipped specifications or products here, and two of those specifications now sit under neutral foundations rather than a single vendor. Some of it is in production. Most of the production traffic is machines buying API calls from other machines, not a shopping assistant buying a sofa from you.

This article separates what has shipped from what is a specification with logos attached, explains what changes about your checkout and your fraud posture, and sets out a twelve month plan ordered by cost.

Should a UK merchant act on AI agent payments in 2026? Only in small ways. The protocols are genuine but early, consumer-facing volume sits on a handful of mostly US surfaces, and almost all measurable machine payment activity is agents paying for data and compute rather than goods. The work worth doing now is making your product data machine readable, checking your bot rules do not block buying agents, and publishing stock and returns terms a machine can parse.


Why Card Rails Break When the Buyer Is Software

The payments system you use every day rests on an assumption that has held since the card was invented. At the moment of purchase, a person is present and consenting. Almost everything built on top of it inherits the assumption: authentication, fraud scoring, dispute rules and the allocation of liability between you, your acquirer and the issuer.

An agent buying on someone’s behalf does not break that assumption loudly. It breaks it quietly, in four separate places, and each break lands on a different part of your business.

Cardholder present is a technical state, not a courtesy

Every card transaction carries data describing how the card details reached you and how much the issuer should trust that path. An agent pasting a stored card number into your checkout looks like ordinary card-not-present ecommerce, which is already the most expensive and most disputed category you process.

That is the default outcome if agentic traffic reaches you through an unmodified web checkout, and it is worse than the status quo rather than better. The whole point of the agent-specific token schemes the card networks have built, Visa Intelligent Commerce and Mastercard Agent Pay among them, is to give the issuer a better signal than “someone typed a card number into a form”.

Authentication has nobody to challenge

Strong customer authentication assumes the payer can respond to a challenge in the moment: a push to a banking app, a biometric, a code. An autonomous agent has no thumb and no phone. It cannot pass a step-up.

The industry answer is to move the human moment earlier. The user authenticates once, when they delegate authority and set the limits, and the resulting purchase runs against that recorded authorisation rather than against a live challenge. That is exactly what the mandate model in Google’s protocol encodes, and it is why the authorisation layer and the checkout layer are separate problems.

Disputes assume a human who can say what they meant

Chargeback rules are built around a person recalling what they intended. When the buyer was software, the interesting question is not whether the transaction happened but whether it matched the instruction, and the parties who could answer that are the user, the agent operator, the model provider and you.

None of the existing reason codes describe “the agent misread the size chart”. Until schemes publish agent-specific dispute handling, the practical risk is that ambiguous agent purchases resolve the way ambiguous card-not-present purchases resolve today, which is usually not in the merchant’s favour.

You cannot currently tell a buyer from a scraper

The fourth break is the one merchants underestimate. A buying agent and a price scraper arrive over the same protocol, from similar infrastructure, with similar headers. Your bot management sees traffic, not intent.

What the AI Agent Payments Standards Actually Do

Four specifications matter, and they solve different layers. Treating them as rivals is the most common analytical error in this space; three of the four explicitly reference each other.

AP2: the authorisation and mandate layer

Google announced the Agent Payments Protocol on 16 September 2025 with, in Google Cloud’s own announcement, more than sixty launch organisations including Adyen, American Express, Coinbase, Mastercard, PayPal and Worldpay. Its content is a set of cryptographically signed mandates: an Intent Mandate recording what the user asked for, and a Cart Mandate recording the exact items and price the user approved.

The point is an auditable chain from human instruction to charge. Version 0.2.0 landed on 28 April 2026, adding “human not present” flows, and the release history on GitHub shows only those two releases. Governance has moved to the FIDO Alliance. This is an early specification with heavyweight sponsorship, not a finished rail.

ACP: the checkout protocol

The Agentic Commerce Protocol was published by Stripe and OpenAI on 29 September 2025 under the Apache 2.0 licence. Rather than pushing an agent through your ordinary web checkout, it relays payment credentials to the merchant as a token whose use is permissioned and logged, which is a materially better signal than a pasted card number.

It is also the most concrete of the four for a merchant, because it defines endpoints you would actually build. Stripe’s documentation now lists Meta alongside Stripe and OpenAI as an author, and names the building blocks: agentic checkout, cart and feed, delegated payment, delegated authentication with OAuth 2.0, and order webhooks. The published specification directory is dated 2026-04-17, which tells you both that it is maintained and that it is young.

UCP: Google’s commerce layer

Google launched the Universal Commerce Protocol at the National Retail Federation conference on 11 January 2026. Per Google’s announcement, it was built with Shopify, Etsy, Wayfair, Target and Walmart, and endorsed by more than twenty others including Adyen, Mastercard, Stripe and Visa.

UCP covers the whole journey rather than the payment: discovery, cart, checkout and post-purchase support across Google Search, AI Mode and Gemini. It leans on Merchant Center feeds you may already maintain, and it uses AP2 underneath for the payment step. If you sell physical goods and already run Google Shopping, this is the specification most likely to reach you first.

x402: HTTP native machine payments

x402 revives the HTTP 402 Payment Required status code that has sat unused since the first HTTP specifications. A server answers 402 with a description of what payment it wants, the client attaches a signed payment payload to the retry, and the request succeeds. No accounts, no checkout page, no human.

Coinbase contributed the protocol to a foundation now hosted by the Linux Foundation, whose press release of 14 July 2026 records 40 members with premier members including AWS, American Express, Cloudflare, Fiserv, Google, Mastercard, Shopify, Stripe and Visa. It is designed for stablecoins and cards alike, and it is the only one of the four with public volume figures.

How the Four Fit Together

A useful way to hold this: x402 is a way for a machine to pay for a request, AP2 is a way to prove a human authorised a purchase, ACP is a way for an agent to complete a checkout with a merchant, and UCP is a way for a retailer to expose an entire shop to an agent.

They compose rather than compete. Google’s documentation positions AP2 as the payment layer beneath UCP’s commerce orchestration, and points at a reference implementation combining its agent protocol with x402 for crypto settlement. ACP integrates with the Model Context Protocol that agents already speak.

What that means commercially is that betting on the wrong protocol is a smaller risk than it looks. The layers are separable, and the plumbing your platform builds for one is largely reusable. The larger risk is spending money on any of it before the demand exists.

Where the Volume Actually Is

This is the section that should calibrate everything else, and it is where most coverage becomes unmoored.

Machine to machine is real and tiny in value

The x402 dashboard publishes rolling thirty day figures. Read on 2 September 2026 it reported 75.41 million transactions, 24.24 million dollars of volume, 94,060 buyers and 22,000 sellers. Those are the foundation’s own numbers, not an independent audit.

Divide them. That is an average transaction of roughly 32 US cents. Seventy five million payments is a genuinely large number of transactions and a genuinely small amount of money, and the shape tells you what it is: agents paying per call for API access, data and compute. It is not people buying furniture.

Consumer agentic checkout is concentrated and mostly American

The consumer side runs through a small number of surfaces. Shopify, in its own announcement of 24 March 2026, says merchants are live across ChatGPT, Microsoft Copilot, AI Mode in Google Search and the Gemini app, with products discoverable by default and no transaction fees beyond standard processing rates. Merchants remain the merchant of record.

Shopify is the party with the most to gain from that framing, so treat the enthusiasm accordingly. But the direction is clear, and it matters for UK sellers that the earliest checkout availability has repeatedly been scoped to US buyers even where the merchant sits elsewhere. Check availability for your market before planning around it.

What This Changes About Your Storefront

Your product data becomes the interface

An agent cannot interpret your carousel, your size guide image or your delivery promise in a footer graphic. It reads feeds and structured data. Everything that only exists visually is invisible.

This is the same discipline as making a catalogue legible to AI search, which we covered in GEO for ecommerce and in our guide to how AI search engines read schema markup. The overlap is close to total, which is why the work is cheap: you are probably part way through it already.

Stock accuracy stops being a nicety. An agent that completes a purchase against a stale feed generates a cancellation, and cancellation rates are the metric these surfaces will use to decide who they keep showing.

Payment tokens arrive with conditions attached

Under the agent token schemes, what reaches you is not a raw card number but a credential scoped to an agent, a spending limit and often a merchant category. That is better for you: the issuer has more context, and the transaction carries provenance that a typed card number does not.

The cost is integration. Supporting scoped agent credentials properly means your payment provider handling them, your fraud rules understanding them, and your order flow recording which agent acted for which customer. None of that is free, and none of it is urgent for a business seeing no agent traffic.

Your Bot Rules Are About to Block Your Best Customer

The infrastructure that keeps scrapers off your site is the same infrastructure a buying agent must pass through. Merchants who tightened bot rules during the AI scraping wave, a decision we worked through in blocking or allowing AI crawlers, may now be blocking software their customer asked to shop for them.

Signed identity is solved, intent is not

Cryptographic identity is the part that works. Cloudflare’s signed agents approach has agents sign HTTP requests with Web Bot Auth so a site can verify who is calling without maintaining IP lists. Visa’s Trusted Agent Protocol uses the same underlying HTTP message signature mechanism and adds an explicit intent field. Signatures prove identity and defeat impersonation.

They do not prove purpose. The same operator’s agent can browse for a buyer on Monday and harvest your entire catalogue on Tuesday, signed identically both times. Intent has to be inferred from behaviour, or asserted by the agent and trusted, and neither is robust yet.

The practical move is not to open the gates. It is to check that your current rules are a decision rather than an accident, and to know which categories you are blocking.

Returns and Disputes When the Buyer Was Not a Person

Consumer law does not care that a machine clicked. For a UK distance sale the buyer still gets the statutory cancellation right, and GOV.UK sets out the mechanics: fourteen days from receipt to tell you they are cancelling, another fourteen to return the goods, and fourteen for you to refund including standard delivery.

What changes is the failure rate. A human who misreads a product page usually catches it at checkout. An agent working from a thin feed will not, and the resulting returns are your cost, not the agent operator’s.

The other unsettled question is who answers for an unauthorised agent purchase. The user delegated, the platform hosted, the model reasoned and you accepted, and no scheme rule cleanly assigns that yet. Keep the mandate evidence the protocols generate. It is the only record that shows what the human actually approved.

The UK Regulatory Position

Strong customer authentication is under review, not settled

HM Treasury’s Payments Forward Plan, published 26 February 2026, puts this squarely on the roadmap. Modernising payment services regulation includes updates to the strong customer authentication regime and, in the plan’s own words, “consideration of whether change/development of regulation is needed to support agentic AI payments”.

The timetable is slow: a Treasury consultation in the second quarter of 2026, an FCA engagement paper across the second to fourth quarters, a consultation response in the fourth quarter, and FCA policy statements in 2027 and 2028. Anyone telling you the UK rules for agentic payments are settled is guessing.

The FCA is applying existing rules, not writing new ones

The FCA’s published position on artificial intelligence, last updated 13 February 2026, is explicit: “We do not plan to introduce extra regulations for AI. Instead, we’ll rely on existing frameworks, which mitigate many of the risks associated with AI.”

For a merchant that is reassuring and slightly unhelpful. Reassuring because nothing new lands on you. Unhelpful because the existing frameworks were not drafted with delegated machine purchasing in mind, and the gaps get resolved case by case rather than by rule.

The EU AI Act Angle if You Sell Into Europe

If you deploy an agent yourself, a shopping assistant or a support agent that can transact, the transparency obligations in Article 50 of the EU AI Act apply from 2 August 2026. The European Commission’s guidance on Article 50 requires that people are informed they are interacting with an AI system, from the start of the first interaction and in a clear and distinguishable manner, unless it is obvious.

That obligation sits on providers and deployers of the system, not on a merchant whose site an external agent visits. If you build the agent, it is yours. If someone else’s agent buys from you, it is theirs.

The Commission has published a code of practice on marking AI generated content alongside it. If you generate product copy at scale for machine consumption, that is worth reading before you scale the practice further.

A Twelve Month Plan, Ordered by Cost

Nearly free: fix the product data

Complete, accurate, structured product data with real stock levels, dimensions, materials, delivery times and return terms. This pays for itself in AI search visibility whether or not a single agent ever buys from you, which is what makes it the only genuinely safe investment on this list.

One day: audit your bot rules

List what you block and why. Decide deliberately whether known agent traffic should reach product and checkout pages. Write the decision down so the next person does not reverse it by accident. If your traffic is already shifting towards AI surfaces, the analysis in Google AI Mode and your website traffic is the companion piece.

One week: make your policies machine readable

Returns, delivery, warranty and eligibility rules expressed as data rather than prose on a page. This reduces the returns risk described above and is the precondition for any agentic checkout integration later.

Ongoing and free: a watching brief

Set a quarterly reminder to check the status of the four specifications and whether your ecommerce platform or payment provider has shipped support. If you are on a hosted platform, most of the work will arrive as a feature you enable, as it has done on Shopify. If you run a custom build, the choices in Shopify versus a custom ecommerce build start to matter more here.

What Not To Do Yet

Do not build a bespoke agentic checkout. Specifications that changed twice in twelve months and carry two releases will change again, and you would be integrating ahead of your platform for traffic you cannot yet measure.

Do not accept stablecoin payments because x402 supports them. That is a treasury, tax and accounting decision with real friction, and the 32 cent average transaction size says the demand is for API access, not retail.

Do not buy an agentic commerce consultancy engagement priced against a market that does not yet exist for you. Measure your own agent traffic first. If it is zero, the honest answer is to wait.

Do not build autonomous purchasing agents for your own procurement without reading the failure modes first, which we set out in AI agents for business. The same delegation problems apply when you are the buyer.

Where This Leaves a UK Merchant

The standards race is real, the sponsorship is serious, and the consumer volume is not there yet for most of you. That combination argues for cheap preparation and against expensive commitment.

Mecanik builds the underlying pieces as ordinary work: structured product data, feed accuracy, bot policy and payment integration through our website development service, and agent-facing systems through AI integration services. The judgement we would offer is that the first three items on the list above are worth doing this quarter, and the fourth is worth doing when your logs show someone asking.



Frequently Asked Questions

Do AI agents actually buy things from ordinary merchants yet? Rarely. The x402 dashboard reported 75.41 million transactions worth 24.24 million dollars over thirty days when read on 2 September 2026, an average of roughly 32 US cents, which is the signature of agents paying for API access rather than buying goods. Consumer agentic checkout exists but is concentrated on a few surfaces and has often been scoped to US buyers first.

What is the difference between AP2, ACP, UCP and x402? They sit at different layers. AP2 records cryptographic proof that a human authorised a purchase, ACP defines the checkout endpoints an agent calls to buy from a merchant, UCP exposes a whole retailer to Google’s AI surfaces, and x402 lets a machine pay for a single HTTP request. They are designed to compose, not to replace each other.

Will blocking AI bots stop agents from buying from me? It can. Buying agents and scrapers arrive over the same protocol from similar infrastructure, and bot management sees traffic rather than purpose. Cryptographic signing schemes such as Web Bot Auth prove which operator is calling, but they do not prove intent, so review what you block deliberately rather than assuming a default rule is still correct.

Does strong customer authentication apply when an AI agent pays? The position is unsettled in the UK. HM Treasury’s Payments Forward Plan of 26 February 2026 commits to updating the strong customer authentication regime and considering whether regulation needs to change to support agentic AI payments, with FCA policy statements not expected until 2027 or 2028. The industry workaround is to authenticate the human once at the point of delegation.

What should a UK merchant do about agentic commerce in the next year? Three cheap things. Make product data complete, accurate and structured, including live stock and return terms. Audit your bot rules so blocking is a decision rather than an accident. Publish delivery and returns policies as machine readable data. Then keep a quarterly watching brief on the specifications and wait for your own logs to show demand.