A purchasing agent that never sleeps, never asks twice, and never second-guesses a reorder is not a thought experiment anymore. It is a live payment rail. In 2026, Visa, Mastercard, Google, and OpenAI all shipped protocols that let an AI agent complete a transaction on a person's or a business's behalf, without a human clicking "confirm." That shift is called agentic commerce, and it is moving faster than most procurement and finance teams have policies for.

What agentic commerce actually is

Agentic commerce is any purchase where an AI agent, not a person, initiates and completes the transaction: choosing a vendor, confirming a price, and authorizing payment inside a single automated flow. It differs from the "AI shopping assistant" era of the early 2020s, where a chatbot could recommend a product but a human still had to check out. In the current model, the agent holds delegated spend authority, subject to caps and revocation rules set in advance.

Juniper Research forecasts global agentic commerce transaction value will grow from $8 billion in 2026 to $3.5 trillion by 2031, with the number of active users rising from under 300 million to 1.3 billion over the same period. Card-based rails lead today because tokenization already exists to secure them; broader support for digital wallets and account-to-account payments is still catching up.

The new payment rails behind it

Four infrastructure moves account for most of this year's momentum:

  • Visa Trusted Agent Protocol, announced in Visa's October 2025 newsroom release and extended through Visa Intelligent Commerce Connect in April 2026, gives merchants a way to tell a legitimate purchasing agent apart from a malicious bot, and issues cryptographic agent tokens with user-set spend caps.
  • Mastercard Agent Pay, paired with a "verifiable intent" layer, focuses on authenticating the agent itself and confirming the transaction matches what the user actually authorized, with early live deployments in Asia-Pacific.
  • Google's Agent Payments Protocol (AP2) is an open, cross-network standard so an agent can discover a merchant and complete checkout regardless of which payment network sits behind it.
  • OpenAI's Instant Checkout, built on Stripe, launched direct in-chat purchases and has since shifted toward agent-assisted discovery routed through merchant APIs.

Here is how the headline numbers compare, using the Juniper Research figures above:

Bar chart comparing agentic commerce transaction value in 2026 versus the 2031 forecast, in billions of dollars

YearAgentic commerce transaction value
2026$8 billion
2031 (forecast)$3,500 billion

Source: Juniper Research, Agentic Commerce Market 2026-2031.

Why this matters for SME procurement, not just consumer shopping

The consumer story (an agent reordering groceries) gets the headlines, but the business case is procurement: an AI agent inside your ERP or purchasing workflow that reorders raw materials, renews a SaaS subscription, or books a vendor service when a threshold is hit. That is a natural extension of the automation SMEs already run through their ERP, but it moves a live payment decision outside a human approval step. If your team has ever tightened a vendor-approval workflow after an ERP implementation, agentic commerce is the same governance problem, applied to real-time card transactions instead of purchase orders.

The risks nobody has fully solved yet

None of the 2026 protocols come with a mature answer to these questions:

  • Liability. If an agent buys the wrong quantity, the wrong SKU, or from the wrong vendor, who absorbs the cost? Spend caps and revocation exist, but dispute and refund processes for agent-initiated transactions are still being built out protocol by protocol.
  • Identity and fraud. An agent acting under a compromised or spoofed identity is a new fraud surface entirely. This is the same class of failure covered in our piece on AI agent security and prompt injection: an agent that can be manipulated into an unintended action is far more costly when that action is a payment.
  • Shadow procurement. A team that adopts an agent-driven purchasing tool without IT or finance sign-off creates the same blind spot documented in our shadow AI governance piece, except the unmonitored activity now touches a company card.
  • Vendor lock-in. Committing to one network's agent-identity and dispute model early can be costly to unwind once a competing standard consolidates the market.

What to do before you give an agent a card number

  1. Set spend caps and approval tiers before deployment, not after the first overspend. Every protocol above supports caps; use them as the default, not the exception.
  2. Route agent purchases through the same approval chain as human purchases, logged in your ERP or procurement system, so an agent transaction is auditable the same way a purchase order is.
  3. Name an owner. Treat agentic purchasing the same way you would treat a new payment method: one accountable person signs off on which vendors and categories an agent is allowed to touch.
  4. Pilot on a low-risk category first, such as recurring low-value consumables, before extending an agent's spend authority to anything contract-sized.

Agentic commerce is not a reason to slow down automation. It is a reason to make sure the governance around your digital transformation approach covers payment authority as carefully as it covers data access. If your business is weighing where AI agents belong in procurement and finance workflows without losing control of the purchase order, talk to ThinqHub about building that in from the start.