An AI PM reads the specs behind agentic commerce: what ACP, AP2, x402, MPP, and UCP each do, ZeroClick's unpublished pricing, and how to sell to AI agents.
The challenge with with AI shopping agents is that the attack surface increases exponentially.
Cash - you can be robbed
Card - your card number can be stolen
AI shopping agents - Now we have an entirely new and much broader ground for bad actors to make money by influencing these agents, and they don't even have to steal your credit card number!
Great article. And I believe agentic payment technology is advancing faster than the trust layer. In other words, agentic payments may work, but consumers don't trust AI with their credit cards, and they also don't trust AI to provide accurate and unbiased product recommendations. My company recently surveyed 1,463 consumers, and 86% of those using AI to shop double-check AI product recommendations (and for good reason).
This suggests we're missing a verification engine for shopping agents that validates product claims, pricing information, availability, discount codes, etc. Where do you think that might fit into agentic shopping workflows?
None of the five protocols really cover that gap. ACP, AP2, x402, MPP and UCP deal with payment, authorization, or the transaction itself, but none verify whether the underlying product claims are actually true.
So I’d put the verification layer before payment, at the point where the agent reads the listing and decides whether to act. By the time ACP or x402 fires, the agent has already made the decision.
That makes your 86% figure especially interesting. The problem starts before the money moves. It starts with whether the agent can trust the information it used to make the decision.
The checkout-layer protocols are moving fast, but the harder unsolved problem sits one layer down: most product feeds still aren't structured cleanly enough for an agent to compare listings like-for-like across merchants. Do any of these specs define a required attribute schema for the agent to trust a listing, or is that still left entirely to GTIN/GS1 and each retailer's own Merchant Center data quality? That gap is where long-tail SKUs will keep getting excluded from agentic shopping long after hero products are agent-ready.
Useful split, and the layer chart matches what building on it actually feels like. I run pay-per-call endpoints that settle in USDC on Base, and the protocol was never the hard part. Deciding what exactly one call buys, and what happens when it fails halfway, took far longer than the integration. Refund semantics are the gap none of the five specs closes. Volumes are small and it shows up anyway.
The challenge with with AI shopping agents is that the attack surface increases exponentially.
Cash - you can be robbed
Card - your card number can be stolen
AI shopping agents - Now we have an entirely new and much broader ground for bad actors to make money by influencing these agents, and they don't even have to steal your credit card number!
Spot on Anita, agent are not mature for deployment yet, and not recommended for non-savvy users who knows just the basic deployment
Great article. And I believe agentic payment technology is advancing faster than the trust layer. In other words, agentic payments may work, but consumers don't trust AI with their credit cards, and they also don't trust AI to provide accurate and unbiased product recommendations. My company recently surveyed 1,463 consumers, and 86% of those using AI to shop double-check AI product recommendations (and for good reason).
This suggests we're missing a verification engine for shopping agents that validates product claims, pricing information, availability, discount codes, etc. Where do you think that might fit into agentic shopping workflows?
None of the five protocols really cover that gap. ACP, AP2, x402, MPP and UCP deal with payment, authorization, or the transaction itself, but none verify whether the underlying product claims are actually true.
So I’d put the verification layer before payment, at the point where the agent reads the listing and decides whether to act. By the time ACP or x402 fires, the agent has already made the decision.
That makes your 86% figure especially interesting. The problem starts before the money moves. It starts with whether the agent can trust the information it used to make the decision.
Very helpful! Thank you
Thank you for reading, Paul! 🤗
The checkout-layer protocols are moving fast, but the harder unsolved problem sits one layer down: most product feeds still aren't structured cleanly enough for an agent to compare listings like-for-like across merchants. Do any of these specs define a required attribute schema for the agent to trust a listing, or is that still left entirely to GTIN/GS1 and each retailer's own Merchant Center data quality? That gap is where long-tail SKUs will keep getting excluded from agentic shopping long after hero products are agent-ready.
Useful split, and the layer chart matches what building on it actually feels like. I run pay-per-call endpoints that settle in USDC on Base, and the protocol was never the hard part. Deciding what exactly one call buys, and what happens when it fails halfway, took far longer than the integration. Refund semantics are the gap none of the five specs closes. Volumes are small and it shows up anyway.
Your layer-cake breakdown is the most useful mental model for the Agentic Finance section I published, with the same tension about x402 headline metrics vs. real commerce: https://thiagopedicosaragiotto.substack.com/p/the-vibrant-and-daring-interconnection