In July 2026, three months after OpenAI scaled back checkout directly inside ChatGPT, it partnered with Visa to let agents make purchases after users gave permission. The company stepped back from the checkout screen just as its software gained the ability to cross it.

Key takeaways

  • Agentic commerce depends less on embedding checkout in a chatbot than on making delegated authority legible to merchants, processors, and networks.
  • Every agentic receipt should identify the customer, the software the customer authorized, and the actor or credential the merchant observed, with a separate field assigning liability for losses.
  • A usable mandate must bound the agent by merchant, amount, time period, purchase conditions, and any threshold requiring renewed human approval.
  • Fraud detection becomes commercially useful only when providers can reconstruct an agent’s action and apply a predetermined rule for who absorbs an unauthorized charge or mistake.
  • Stablecoins can make agent settlement programmable and immediate, but settlement alone does not prove that a transaction fell within the user’s mandate.

A shopper sees checkout as a button. Merchants and processors use it to decide whether to accept a credential and which rules apply if the payment is disputed. When software presses the button for a shopper, the merchant must evaluate a chain of authority rather than one apparent actor.

Agents turn one click into several obligations

A typical web checkout presents the shopper’s action and payment credential in one flow. The merchant approves or declines the transaction without reconstructing every decision that preceded it.

An agent can continue acting through external systems after making a recommendation. Cloudflare says agents can create accounts, start paid subscriptions, register domains, and deploy applications for users. After those actions, the user has an identity to maintain, a recurring bill to control, an asset to renew, or an application to secure.

OpenAI’s broader managed-execution turn includes shared context, onboarding, and permission boundaries. These products treat payment as one state change inside an automated workflow that may continue after the initial consent.

Users must turn permission into a mandate

Useful permission specifies what an agent may buy, from whom, for how much, over what period, and under which conditions it must return for approval. A spending limit that requires human confirmation above a threshold changes the commercial meaning of the transaction.

A merchant needs to distinguish three identities in a delegated purchase. The first is the customer whose funds or credit are at risk. The second is the software that received the mandate. The third is the actor or credential the merchant actually observes. That third identity may match the authorized software; recording both makes the match testable rather than assumed. A separate liability field must name the party responsible for resolving a loss.

World’s AgentKit lets sites verify that a real human stands behind an AI shopping agent’s purchase decisions. That proof clarifies one link in the chain while exposing the commercial trade-off. Verification that destroys conversion is weak; conversion that cannot establish authority leaves merchants and processors unable to assign responsibility.

By July 2026, World and Visa had described different parts of the chain: one links an agent to a human principal, while the other enables user-authorized purchases. Neither cited announcement describes a shared receipt schema that preserves all three identities and the liability field.

A workable merchant design would record the mandate identifier, spending and time limits, confirmation threshold, authorized software, and presented actor. A recurring-billing control would retain the renewal scope and revocation status. If the customer disputes the charge, the processor could place the same fields in the dispute file alongside the party assigned to bear the loss. That is deployment accountability reduced to an inspectable transaction record.

Processors earn trust by taking a side on losses

Stripe made the distinction between prediction and responsibility visible before agents entered checkout. Its 2019 Chargeback Protection product, built on Radar, automatically reimbursed businesses for covered disputed-charge costs. Fraud detection supplied the estimate; explicit loss allocation made the estimate commercially useful.

Processors can also change what merchants permit. Kickstarter said Stripe requirements had driven stricter mature-content rules, then retracted those rules after creator backlash. Stripe’s requirements had reached beyond payment acceptance into what Kickstarter initially allowed creators to sell.

When an agent exceeds its mandate, the merchant cannot seek reimbursement from the software itself. A customer, operator, merchant, processor, or network must absorb the charge or refund under an agreed rule. Providers that can reconstruct the action and apply that rule offer merchants more than a fraud score.

Stablecoins can settle before merchants verify intent

On May 7, 2026, AWS introduced Bedrock AgentCore Payments with Coinbase and Stripe so AI agents could execute stablecoin transactions. The service makes agent-initiated settlement programmable, but the merchant still has to decide whether the instruction falls within the user’s mandate.

Visa intends its Stablecoin Platform to help a network of roughly 15,000 financial institutions and more than 200 million merchants use stablecoins.

financial institutions in Visa’s network
merchants addressed by the platform

A stablecoin transfer can execute an instruction without proving who authorized it. Visa, AWS, Coinbase, and Stripe can broaden the routes through which agents move value; merchants still need evidence before delivering goods, activating services, or resolving a disputed purchase.

Stripe’s July sequence reached from settlement to models

Three July reports placed Stripe next to a stablecoin standard, greater financial capacity, and the model-routing layer developers use:

Open USD places Stripe inside an emerging settlement standard. The revenue report indicates resources to pursue acquisitions, while an OpenRouter deal would put payment infrastructure and model routing under the same corporate roof. The reports do not describe a finished product for recording agent mandates or assigning liability.

Cloudflare’s subscription example supplies a concrete test. If a user authorizes one month of service and an agent selects an annual plan, the merchant should be able to see the customer, authorized software, presented actor, one-month scope, annual action, and liability bearer in one dispute record. The processor could then apply the agreed remedy without asking a support team to reconstruct the entire chat.

At the old checkout, the card number was enough to open the gate. OpenAI’s three-month sequence shows what changes when software walks through it. The agentic receipt needs three names—the customer, the software the customer authorized, and the actor the merchant actually saw—plus a separate liability field naming the party that must resolve a loss. Otherwise, the purchase can complete before anyone has agreed who owns the mistake.

Stripe’s July 2026 expansion across settlement, finance, and model routing

  • July 1, 2026 — Visa, Mastercard, Stripe, BlackRock, Coinbase, and 140+ companies joined Open Standard as launch members.
  • July 22, 2026 — A source reported that Stripe’s 2025 revenue rose by one-third to $6.8 billion and free cash flow increased 52% to $3.2 billion.
  • July 23, 2026 — Stripe was reportedly in talks to acquire model-routing platform OpenRouter in a deal potentially worth around $10 billion.

Frequently asked questions

What information should an agentic payment record contain?

It should record the mandate identifier, spending and time limits, confirmation threshold, authorized software, presented actor, and liability bearer. Recurring purchases also require renewal scope and current revocation status.

Who is responsible if an AI agent exceeds its purchasing authority?

The software itself cannot reimburse the merchant. The customer, agent operator, merchant, processor, or payment network must bear the loss under a rule agreed before the dispute.

Why is proof that a human stands behind an agent not enough?

Human verification establishes the principal but not the full scope of permission, whether the observed actor matches the authorized software, or who bears a loss. Merchants need those facts without adding enough friction to destroy conversion.

Do stablecoin payments solve authorization and dispute problems for AI agents?

No. Stablecoins can execute and settle an instruction, but merchants still need evidence that the user authorized the specific purchase before delivering goods or activating services.

What would happen if an agent bought an annual plan after receiving permission for one month?

The dispute record should show the one-month mandate, the annual action, all three identities, and the assigned liability bearer. The processor could then apply the agreed remedy without reconstructing the underlying chat.