Back to Blog

When Your AI Employee Starts Buying: What Agentic Commerce Means for Your Business

Henri Jung, Co-founder at Superkind
Henri Jung

Co-founder at Superkind

A dark matte metal payment card with an orange chip, representing an AI employee authorised to buy

In September 2025, a shopper in the United States asked ChatGPT to buy a specific item from an Etsy seller, and ChatGPT did it - discovery to payment, inside the chat, without ever opening the merchant’s website1. Four months later, at the National Retail Federation in January 2026, Google unveiled the Universal Commerce Protocol with Shopify, Target, and Walmart on stage - a shared language that lets an AI agent query live inventory and pricing, negotiate terms, and create an order directly2,3.

This is agentic commerce, and it is not a demo. Visa and Mastercard have built tokenised payment rails that give an agent a card scoped to a single amount and merchant6,7. Gartner expects 20 percent of all digital commerce transactions to run through AI platforms by 203010. Morgan Stanley puts the US opportunity at $190 billion to $385 billion11. The rails are live, and they point in one direction: software that does not just recommend what to buy, but buys it.

For a business, this cuts two ways. Your own AI employees will start executing purchases - reordering, renewing, placing supplier orders - inside your real policies. And other companies’ buying agents will start looking for you, which means your products, prices, and terms have to be readable by a machine, not just a human clicking through a website. This guide is for the operations leader, CFO, or Geschaeftsfuehrer who needs a practical, honest view of both sides - without the hype.

TL;DR

Agentic commerce lets AI agents research, decide, and execute purchases - not just recommend them - over new rails from OpenAI, Google, Visa, and Mastercard.

Two sides affect you: your own AI employees buying within your policies, and other firms’ agents needing to find and transact with you.

Safe buying starts in the Company Brain - an agent can only buy well when it acts out of your spend policies, preferred suppliers, past decisions, and contract terms.

Three guardrails make it safe: hard spend limits, human sign-off thresholds, and full auditability of every agent action.

The honest caveat: Gartner expects over 40 percent of agentic AI projects to be cancelled by 2027. The rails work; the discipline to deploy them well is the hard part.

The Two-Sided Shift

Most coverage of agentic commerce frames it as a consumer story: people shopping through chatbots. For a business, the more important change is structural, and it hits from two directions at once.

  • Side one: your agents buy - Your AI employees move from suggesting a purchase order to actually placing it, from flagging a renewal to executing it, from drafting a supplier email to completing the transaction - all inside your budgets and approval rules.
  • Side two: their agents buy from you - Buyers at other companies increasingly send an agent to research and transact. If your catalogue, pricing, and terms are not machine-readable, their agent cannot choose you, no matter how good your product is.
  • Both sides share one dependency - A buying agent is only as good as the context it acts from. On the buy side that context is your spend policy; on the sell side it is your structured product and offer data.
  • The timeline is short - OpenAI shipped Instant Checkout in September 2025, Google shipped UCP in January 2026, and the payment networks shipped their rails in 20251,2,6. This is a 12-to-18-month shift, not a five-year one.
  • The risk is asymmetric - Getting the buy side wrong costs you money through bad or runaway purchases. Getting the sell side wrong costs you revenue silently, as agents route around you without ever telling you.

Key Data Point

Gartner predicts 20 percent of all digital commerce transactions will be executed autonomously through AI platforms by 2030, which the firm frames as a trillion-dollar opportunity. Morgan Stanley estimates agentic shoppers alone could represent $190 billion to $385 billion in US e-commerce by 2030, or 10 to 20 percent of the market10,11.

DimensionBuy Side (your agents)Sell Side (their agents)
What changesAgents execute purchases, not just suggestAgents discover and transact with you directly
What it depends onYour spend policy and supplier termsYour structured product and offer data
Main riskOverspend, wrong or off-contract buysBeing invisible to buying agents
How you winContext plus hard guardrailsMachine-readable catalogue and policies
Who owns itFinance and operationsSales, e-commerce, and product data

The rest of this guide takes both sides in turn, starting with the rails that make any of it possible.

The New Rails for Agentic Commerce

An agent cannot buy anything without three things: a way to read a merchant’s live offer, a way to prove what the user authorised, and a way to pay that a bank and a seller will trust. In the space of a year, the industry shipped all three.

The protocols that let agents transact

  • OpenAI Agentic Commerce Protocol (ACP) - Co-developed with Stripe and launched September 2025 to power Instant Checkout in ChatGPT. Users buy from Etsy sellers and over a million Shopify merchants inside the chat, with payment through encrypted tokens authorised for a specific amount and merchant1,21.
  • Google Universal Commerce Protocol (UCP) - Announced at NRF in January 2026 with Shopify, Etsy, Wayfair, Target, and Walmart, and endorsed by Stripe, Adyen, and American Express. Merchants expose live inventory, pricing, shipping, tax, and discount logic that an agent queries in real time2,3,14.
  • Google Agent Payments Protocol (AP2) - Announced September 2025 with 60-plus partners. It adds three signed mandates - Intent, Cart, and Payment - carried as W3C Verifiable Credentials, giving a cryptographic record of what was authorised, selected, and charged4,5.
  • Agent2Agent (A2A) - An open protocol for agents to discover each other and collaborate, moved to the Linux Foundation in June 2025 with AWS, Microsoft, Cisco, and Salesforce as founding members. AP2 is built as an extension of A2A and the Model Context Protocol9.

The payment rails that let agents pay

  • Visa Intelligent Commerce - Opens Visa’s network to agent developers with tokenised cards that encrypt card numbers and prove the agent is authorised to buy. Launch partners include Anthropic, OpenAI, Microsoft, Mistral, Perplexity, Stripe, and Samsung6,7.
  • Mastercard Agent Pay - Tokenised payment technology built into conversational AI platforms, so an agent can pay inside the recommendation flow rather than bouncing the user to a checkout page7,8.
  • Scoped, single-use tokens - The common thread is that the agent never holds a raw card number. It gets a token locked to one amount and one merchant, which is what makes overspend structurally hard rather than merely discouraged6.
  • Stablecoin and bank rails - AP2 treats stablecoins and bank transfers as first-class payment types alongside cards, which matters for cross-border and business-to-business settlement5.
RailWhoLaunchedWhat it does
ACPOpenAI + StripeSept 2025Checkout inside ChatGPT
UCPGoogle + retailersJan 2026Live merchant data for agents
AP2Google + 60 partnersSept 2025Verifiable authorisation mandates
Intelligent CommerceVisa2025Tokenised cards for agents
Agent PayMastercard2025Payments in conversation

“Soon people will have AI agents browse, select, purchase and manage on their behalf. These agents will need to be trusted with payments, not only by users, but by banks and sellers as well.”

- Jack Forestell, Chief Product and Strategy Officer at Visa6

That line - trusted by users, banks, and sellers - is the whole game. The protocols above are machinery for creating that trust. Which is exactly why, inside a company, the trust has to come from somewhere specific: your own rules and history. More on how AI agents differ from simple automation is covered in our guide to telling whether you can rely on an AI agent.

When Your AI Employee Starts Buying

The most immediate impact is not consumers shopping in chat. It is the routine buying work inside your own company - the reorders, renewals, and supplier orders that eat hours and leak money. These are the first jobs an AI employee should take over, because they are repetitive, rule-bound, and easy to check.

Where the money leaks today

  • Maverick spend is large - Industry analyses put purchases made outside approved contracts at roughly 23 percent of total procurement spend, with organisations losing 5 to 15 percent of annual procurement spend to off-contract buying16.
  • Off-contract buys cost a premium - When teams buy outside agreed terms, estimates put the waste at 12 to 18 percent on each affected dollar, from lost volume discounts and worse pricing16.
  • Sourcing is slow - Manual sourcing cycles routinely run 12 weeks; AI-assisted procurement has compressed them toward 6 weeks by automating supplier identification, requests, and bid evaluation15.
  • Requisitions drag - Dialog-based buying guidance has cut requisition cycle times by up to 78 percent in reported deployments, mostly by removing back-and-forth and wrong-supplier rework15,17.
  • Invoices pile up - Matching invoices to purchase orders and delivery notes is the kind of high-volume checking work that consumes finance teams and is a natural fit for automation, as covered in our piece on AI tools for accounts payable.

Nine concrete things an AI employee can buy or transact

  1. Consumables reorder - When stock of a standard item drops below a threshold, the agent places a repeat order with the approved supplier at the contracted price.
  2. Software renewals - It flags an upcoming subscription renewal, checks usage against seats, and either renews within policy or escalates if the cost or seat count changed. This is where the seat-based software trap often hides.
  3. Supplier repeat orders - For known parts or materials, it raises a purchase order against the framework agreement without a buyer re-keying anything.
  4. Spot-buy within limits - For a one-off under a small threshold, it finds an approved vendor, confirms the price, and buys, logging the reason.
  5. Invoice-to-PO matching - It reconciles incoming invoices against purchase orders and goods receipts, approving clean matches and routing exceptions to a human.
  6. Contract-term enforcement - Before any order, it checks the supplier’s agreed terms, minimum order quantities, and rebate thresholds so the company actually gets what it negotiated.
  7. Travel and events booking - Within travel policy and budget, it books and pays, then files the receipt and expense record automatically.
  8. Supplier onboarding checks - For a new vendor, it gathers the compliance documents and runs them against policy before any spend is allowed.
  9. Budget-aware approvals routing - It reads the live budget line, approves what fits the rules, and sends anything above the sign-off threshold to the right person with the context attached.

The point of the list

None of these are glamorous. That is the point. The first wins in agentic commerce come from the boring, repetitive buying that follows clear rules - exactly the work an AI employee should take off your team, and exactly the work where a mistake is cheap to catch.

Letting an Agent Buy vs Keeping It Manual

Agent buys (within rules)

  • ✓ Speed - reorders and renewals happen the moment they are due
  • ✓ Policy adherence - every buy checks contracts and preferred suppliers first
  • ✓ Less maverick spend - the easy path becomes the compliant one
  • ✓ Clean audit trail - every action is logged with its reason

Manual only

  • ✗ Slow - requisitions and sourcing stretch into weeks
  • ✗ Inconsistent - policy adherence depends on who is doing it
  • ✗ Decisions hidden in email - the trail is scattered and hard to audit
  • ✗ Expensive attention - skilled staff spend time re-keying orders

Could an AI employee handle your routine buying?

Book a 30-minute call. We will map one purchasing workflow and its guardrails together.

Book a Demo →

Why Safe Buying Starts in the Company Brain

A generic shopping agent knows the internet. It does not know that your legal team mandated a specific data-processing clause, that you have a framework agreement with one supplier at a better price, or that the last time someone bought this category off-contract it caused a three-month billing dispute. An AI employee that buys for you has to know all of that. That knowledge is the Company Brain.

What the Company Brain gives a buying agent

  • Spend policies - who can buy what, up to which amount, in which category, and what needs sign-off. The rules that normally live in a PDF nobody reads become rules the agent enforces.
  • Preferred suppliers and framework terms - the agreed price, minimum quantities, lead times, and rebate thresholds, so the agent buys on the terms you negotiated rather than list price.
  • Past decisions and their outcomes - which suppliers delivered late, which substitutions worked, which categories caused disputes. The institutional memory that usually walks out the door with a retiring buyer.
  • Contract and compliance context - data-processing requirements, certifications a supplier must hold, and clauses that must be present before an order is placed.
  • Live system state - current budget lines, open purchase orders, and stock levels, read from the ERP and CRM in real time rather than from a stale export.

The core argument

An AI employee can only buy safely when it acts out of the Company Brain. The rails handle discovery and payment; the Company Brain supplies the judgement - your policies, suppliers, history, and terms. Without it, you have a fast way to make the wrong purchase. With it, you have a colleague that buys the way your best buyer would, every time, at machine speed.

How the Company Brain gets built

  1. Connect the systems - The agent reads from the tools you already run: email, Teams, SharePoint, the CRM, and the ERP. Policy documents, contracts, and supplier records come from where they already live.
  2. Capture the unwritten rules - The knowledge that lives only in people’s heads gets surfaced through daily use, as the team corrects and confirms what the agent proposes.
  3. Learn from feedback - Every approval, rejection, and correction teaches the agent. It gets sharper on your categories and suppliers over time, which is the opposite of a generic tool that stays generic.
  4. Keep the memory current - New contracts, price changes, and lessons from disputes feed back in, so the agent’s context does not drift out of date.

We go deeper on how this memory is assembled and ramped up in our guide to building a Company Brain. The short version: the buying agent is only trustworthy because of what sits behind it.

The Guardrails That Make It Safe

Context tells the agent what a good purchase looks like. Guardrails make sure a bad one cannot slip through anyway. Three controls do most of the work, and none of them should rely on the model’s judgement alone.

The three non-negotiable controls

  • Hard spend limits - Enforced in code and at the payment token, not as a prompt instruction. A token scoped to one amount and one merchant cannot be stretched, which is the structural reason tokenised rails matter6.
  • Human sign-off thresholds - Above a defined amount, or for any new supplier or unusual category, a person approves before anything is bought. The agent prepares the decision with full context; the human makes it.
  • Full auditability - Every action is logged: what the agent searched, which policy it applied, what it ordered, what it paid, and who approved anything above threshold. Verifiable-credential protocols like AP2 add cryptographic proof of authorisation at the transaction level4,5.
GuardrailWhat it preventsWhere it is enforced
Spend limitOverspend on any single buyCode plus scoped payment token
Approval thresholdAutonomous high-stakes decisionsWorkflow sign-off step
Supplier allow-listOff-contract and unvetted vendorsCompany Brain policy check
Category rulesBuying outside the agent’s remitCompany Brain policy check
Audit logUntraceable or unexplained actionsSystem logs plus AP2 mandates

Agentic Buying Readiness Checklist

  • You can state a per-transaction spend limit for each buying category
  • You have a clear threshold above which a human must approve
  • You maintain an allow-list of approved suppliers and terms
  • Your purchase policies are written down, not just understood
  • Your ERP and purchasing tools expose APIs or data connectors
  • You can log every agent action in a way an auditor can read
  • You have an owner in finance or operations for the pilot
  • You are starting with one low-risk category, not all of them

“Most agentic AI projects right now are early-stage experiments or proofs of concept that are mostly driven by hype and are often misapplied.”

- Anushree Verma, Senior Director Analyst at Gartner12

This is the honest counterweight. Gartner expects more than 40 percent of agentic AI projects to be cancelled by the end of 2027, citing unclear value, rising costs, and weak risk controls12. The lesson is not to wait - it is to deploy with discipline: narrow use case, real guardrails, measured results. For a deeper look at what separates a reliable agent from a demo, see our analysis of agent reliability.

Autonomous vs Human-in-the-Loop Buying

Fully autonomous (narrow scope)

  • ✓ Fastest - no waiting on a person for routine reorders
  • ✓ Consistent - the same rules apply every time
  • ✗ Only safe within tight limits - low amounts, known suppliers
  • ✗ Needs strong logging - trust depends on the audit trail

Human-in-the-loop

  • ✓ Safer for high stakes - a person signs off on big or new buys
  • ✓ Builds trust gradually - expand autonomy as the record proves out
  • ✗ Slower - approvals add latency to every flow above threshold
  • ✗ Needs good context - the human must get the full picture to decide fast
A machined metal control dial with an orange ring, representing spend limits and approval thresholds

Becoming Machine-Readable: When Other Firms’ Agents Buy From You

The second side of agentic commerce is quieter and, for many companies, more dangerous. If buyers send agents to research and purchase, your business has to be legible to those agents. A beautiful website a human loves is worthless to a machine that needs structured inventory, price, and terms.

What agents need from you to transact

  • Live, structured product data - Not a PDF catalogue, but queryable inventory, pricing, variants, and availability. UCP is built precisely so merchants expose these as live commerce primitives rather than static feeds2,14.
  • Machine-readable terms - Shipping, tax, returns, and discount logic an agent can read and factor into a decision, not bury in a footer a person has to scroll to find.
  • A trusted payment path - Support for the tokenised rails buyers’ agents use, so the transaction can actually complete once the agent decides6,7.
  • Clear identity and provenance - Verifiable records of who you are and what you offer, which is where credential-based protocols like AP2 point4.
  • Accurate, current data - An agent that gets a wrong price or a false in-stock will not forgive it the way a human might; bad data means lost or disputed orders.

“Throughout this process, the retailer remains the merchant of record, allowing them to own and shape the customer relationship.”

- Sundar Pichai, CEO of Google2

The reassuring part of Pichai’s point is that you do not lose the customer relationship - you stay the merchant of record. The hard part is that you only get into the consideration set at all if your data is readable. Agents cannot choose what they cannot parse.

AssetHuman-readable onlyMachine-readable
CatalogueWeb pages and PDFsLive, queryable product data
PricingShown on the pageExposed via a commerce protocol
Availability“In stock” labelReal-time inventory an agent can check
TermsFooter and T&C pageStructured shipping, tax, returns logic
DiscoverabilitySEO for human searchReadable by buying agents

Why this is urgent

If Gartner is right that 20 percent of digital commerce runs through AI platforms by 2030, the companies whose data agents cannot read will lose that share without ever seeing a lost click. The work to become machine-readable - clean product data, structured terms, supported payment rails - is the same work that makes you discoverable in the new agentic browser era10.

How Superkind Fits

Superkind builds AI employees that take over routine work and live inside the systems a company already uses. For agentic commerce, that means an AI employee that buys out of your Company Brain, within your guardrails, connected to your real tools - not a generic shopping bot bolted on from outside.

  • Buys from the Company Brain - The agent acts out of your spend policies, preferred suppliers, past decisions, and contract terms, so a purchase reflects how your best buyer would decide.
  • Connected to your real systems - It reads and writes across email, Teams, SharePoint, CRM (Salesforce, HubSpot), and ERP (SAP Business One), plus accounting tools like DATEV and Lexware, rather than forcing a new platform.
  • Hard guardrails by design - Spend limits, approval thresholds, and supplier allow-lists are enforced as rules, with a human-in-the-loop step for anything above the line.
  • Full audit trail - Every action the agent takes is logged with its reason, so finance and auditors can see exactly what was bought, why, and on whose authority.
  • Learns from daily feedback - Your team corrects and confirms what the agent proposes, and it gets sharper on your categories and suppliers over time.
  • First use case live in weeks - A focused purchasing workflow goes into production fast, rather than through a six-month rollout.
  • No rip-and-replace - The AI employee sits on top of your stack, so you keep the ERP and purchasing tools you already trust.
  • Outcome-focused - The engagement is tied to a measurable result on a real workflow, not seats or licences, as we argue in our piece on the seat-based software trap.
ApproachGeneric shopping agentSuperkind AI employee
Knows your policiesNo - knows the internetYes - acts out of the Company Brain
Supplier termsList priceYour negotiated framework terms
GuardrailsGeneric limitsYour spend limits and sign-off thresholds
SystemsStandaloneInside your ERP, CRM, email
Audit trailLimitedEvery action logged with reason
Improves over timeStays genericLearns your categories from feedback

Superkind

Pros

  • ✓ Context-first - buys out of your real policies and history
  • ✓ Guardrails built in - limits, thresholds, allow-lists, audit log
  • ✓ Works on your stack - no rip-and-replace
  • ✓ Fast first use case - live in weeks, not quarters
  • ✓ Gets better - learns from your team’s daily feedback

Cons

  • ✗ Not a self-serve app - needs engagement with our team to set up
  • ✗ Needs clear policies - we have to encode real rules, not vague ones
  • ✗ Requires system access - the agent must connect to your real tools
  • ✗ Not for one-off buys - the value is in repeatable, rule-bound work

Decision Framework: Are You Ready for Agentic Commerce?

Not every company should let an agent buy tomorrow, and not every company can afford to be invisible to buying agents. Use these signals to decide where to act first.

SignalWhat it meansAction
You have high-volume, rule-bound buyingStrong candidate for an AI employee on the buy sidePilot one low-risk category with hard limits
You suspect significant maverick spendMoney is leaking through off-contract buyingLet the agent enforce preferred suppliers and terms
You sell products or services onlineBuying agents may already be routing around youMake your catalogue and terms machine-readable
Your policies live only in people’s headsNo agent can buy safely without written rulesEncode spend policy into the Company Brain first
Your systems have no API accessIntegration will be the hard partFix connectivity before automating purchases
You are a very small team with simple buyingAgentic buying may be overkill right nowStart with simpler automation, revisit later

Acting Now vs Waiting

Acting Now

  • ✓ Capture leaked spend - enforce contracts before more money leaks
  • ✓ Build the Company Brain early - context compounds the longer it learns
  • ✓ Stay discoverable - be readable before agents become the buyer
  • ✓ Learn safely - start narrow while stakes are low

Waiting

  • ✗ Silent revenue loss - agents route to readable competitors
  • ✗ Continued leakage - maverick spend keeps costing you
  • ✗ Steeper catch-up - rivals’ agents get sharper every month
  • ✗ Rushed, risky rollout later - pressure invites skipped guardrails

Your First 90 Days in Agentic Commerce

  • Pick one low-risk, high-volume buying category for the pilot
  • Write down the spend policy and approval thresholds for it
  • Confirm the supplier allow-list and framework terms
  • Connect the agent to your ERP, email, and purchasing tools
  • Set hard spend limits and a human sign-off step
  • Run the agent in parallel with the manual process first
  • Review the audit log weekly and expand autonomy as trust grows
  • In parallel, audit whether your own catalogue is machine-readable

Frequently Asked Questions

Agentic commerce is the practice of letting AI agents research, decide, and execute purchases or transactions on behalf of a person or a company, rather than just recommending options a human then buys manually. It runs on new protocols such as OpenAI’s Agentic Commerce Protocol, Google’s Universal Commerce Protocol, and payment rails from Visa and Mastercard that let an agent submit a secure, authorised payment. The key difference from a normal online checkout is that the agent completes the whole flow, from discovery to payment, inside a conversation or workflow.

A recommendation chatbot stops at the suggestion and hands the decision back to a human. An agentic commerce system goes further: it checks live inventory and pricing, applies your rules, and submits a payment token that is authorised for a specific amount and merchant. The transaction actually completes. That is why the guardrails matter so much more than with a chatbot that cannot spend money.

It is safe when the agent acts within hard limits and leaves a complete record. Safe agentic buying rests on three things: spend limits enforced in code, human sign-off thresholds above which a person must approve, and full auditability of every action the agent takes. Payment rails like Visa Intelligent Commerce add tokenised cards that are scoped to a single amount and merchant, so even an authorised agent cannot overspend. Without these controls, autonomous buying is a liability rather than an advantage.

The Universal Commerce Protocol (UCP) is an open standard Google announced at NRF in January 2026, co-developed with Shopify, Etsy, Wayfair, Target, and Walmart and endorsed by payment companies including Stripe, Adyen, and American Express. It lets merchants expose live commerce data - inventory, pricing, shipping, tax, and discount logic - that an AI agent can query in real time, then negotiate terms and create an order. It is one of several competing standards that make agent-led buying possible.

The Agentic Commerce Protocol (ACP) is an open standard OpenAI co-developed with Stripe, launched in September 2025 to power Instant Checkout in ChatGPT. It lets users buy directly from merchants inside a chat, starting with Etsy sellers and over a million Shopify merchants. Payment runs through encrypted tokens authorised only for a specific amount and merchant, and the user confirms each step. It is the consumer-facing cousin of the enterprise buying your own AI employees will do.

AP2, the Agent Payments Protocol, is Google’s open standard announced in September 2025 with more than 60 partners including Mastercard, PayPal, and American Express. It introduces three signed mandates - Intent, Cart, and Payment - carried as W3C Verifiable Credentials. Each is a cryptographically signed record of what the user authorised, what the agent selected, and what was charged. That matters because it gives merchants and banks proof of authorisation instead of trusting an AI’s word, which is the foundation of a clean audit trail.

No. A well-built AI employee sits on top of your existing systems and connects through APIs and data connectors. It reads purchase policies, supplier terms, and budgets from the tools you already run - ERP, CRM, email, SharePoint - and writes orders back into them. The goal is to automate the routine buying work inside your current stack, not to rip it out and start again.

Three layers. First, the agent acts out of your Company Brain, so it knows your spend policies, preferred suppliers, and contract terms before it acts. Second, hard spend limits and approval thresholds are enforced in code, not left to the model’s judgement. Third, tokenised payment credentials cap each transaction at a specific amount and merchant. If anything falls outside the rules, the agent escalates to a human instead of guessing.

It means structuring your product, price, availability, and policy data so that another company’s buying agent can find, understand, and transact with you without a human in the loop. Gartner expects 20 percent of digital commerce transactions to run through AI platforms by 2030. If your catalogue and terms are only readable by humans clicking through a website, agents will route around you to competitors whose data they can actually use.

Start with high-volume, low-risk, well-defined buying: reordering consumables and office supplies, renewing known software subscriptions, placing repeat orders with approved suppliers, and reconciling invoices against purchase orders. These are repetitive, rule-bound, and easy to audit, which makes them ideal first use cases. Leave one-off strategic purchases and anything above a meaningful spend threshold to human sign-off until trust is established.

Every action an AI employee takes should be logged: what it searched, which policy it applied, what it ordered, what it paid, and which human approved anything above the threshold. Verifiable-credential-based protocols like AP2 add cryptographic proof of authorisation at the transaction level. Combined with your own system logs, this gives auditors a clearer record than most manual procurement, where decisions often live in email threads and nobody’s memory.

Both. The rails are real: OpenAI, Google, Visa, and Mastercard all shipped working protocols between September 2025 and January 2026, and consumers can already buy inside ChatGPT and Google’s AI Mode. At the same time, Gartner predicts more than 40 percent of agentic AI projects will be cancelled by the end of 2027 due to unclear value and weak risk controls. The technology works; the discipline to deploy it safely and pick the right use cases is what separates results from wasted budget.

Sources

  1. OpenAI - Buy it in ChatGPT: Instant Checkout and the Agentic Commerce Protocol (2025)
  2. Google - Sundar Pichai’s Remarks at the 2026 National Retail Federation (Universal Commerce Protocol)
  3. Skift - Google’s New Tech Lets AI Agents Handle Checkout (January 2026)
  4. The Paypers - Google launches the Agent Payments Protocol (AP2)
  5. Analytics Vidhya - Google’s Agent Payments Protocol (AP2) Explained
  6. Visa Newsroom - Find and Buy with AI: Visa Unveils a New Era of Commerce (Intelligent Commerce)
  7. TechCrunch - Visa and Mastercard unveil AI-powered shopping (2025)
  8. Cognizant - Mastercard and Visa Agent Pay: agentic AI in payments
  9. SD Times - Google’s Agent2Agent protocol finds new home at the Linux Foundation
  10. Technology Magazine - Agentic AI Will Transform E-Commerce Strategies by 2030 (Gartner)
  11. Morgan Stanley - Here Come the Shopping Bots: Agentic Commerce Market Outlook
  12. Outlook Business - Over 40% of Agentic AI Projects Will Be Scrapped by 2027, Says Gartner (Anushree Verma)
  13. eMarketer - Google brings checkout to AI Mode as it races rivals in agentic commerce
  14. ChannelEngine - Google’s Universal Commerce Protocol and Merchant Center
  15. Delos - AI-Powered Procurement: How Enterprises Cut Sourcing Cycles
  16. Hyperbots - How to Prevent Maverick Spending in Procurement
  17. SAP - Augment procurement with AI Agents
  18. Wikipedia - Agentic commerce
  19. BigCommerce - Google Agentic Checkout: Enable Buying in AI Mode and Gemini
  20. Retail TouchPoints - Visa, Mastercard, PayPal Dive into the Agentic Era
  21. PPC Land - OpenAI launches Instant Checkout for ChatGPT with Stripe partnership
  22. Modo25 - Google launches the Universal Commerce Protocol (UCP) for agent-led shopping
Henri Jung, Co-founder at Superkind
Henri Jung

Co-founder of Superkind, where he helps SMEs and enterprises deploy custom AI employees that actually fit how their teams work. Henri is passionate about closing the gap between what AI can do and the value it creates in real companies. He believes the Mittelstand has everything it needs to lead in AI - it just needs the right approach, with the guardrails and company knowledge that make autonomy safe.

Ready to let an AI employee handle your routine buying?

Book a 30-minute call with Henri. We will map one purchasing workflow, its guardrails, and the Company Brain behind it - no commitment, no sales pitch.

Book a Demo →