Your competitor's AI agent just completed a transaction with a potential customer. It compared product specifications across multiple products and vendors, verified negotiated price and terms, and executed the purchase before you finished your morning coffee.
This is on the cusp of happening. But for most businesses, this future remains blocked by a structural problem: the internet's trust infrastructure was never designed for agents.
The payment systems, checkout processes, and verification mechanisms that powered twenty years of e-commerce all assume one thing: a human will press "buy now". When that human is replaced by an AI agent, the entire trust model collapses.
This is why Google, along with a coalition of over sixty partners including Mastercard and PayPal, is rebuilding the foundation of digital commerce around what they call "the Three A's": Authentication, Authorisation, and Accountability.
Understanding the Three A's isn't just important for technology strategy. It's the difference between participating in agentic commerce and being invisible to it.
Why Traditional Commerce Breaks With Agents
For two decades, e-commerce operated on implied trust. You entered payment details, clicked buy, and the system assumed you were present, genuine, and authorised this exact purchase. Every fraud system, every compliance mechanism, every security protocol was calibrated around that moment of human action.
Agents delete that moment entirely.
When an AI agent transacts on your behalf, there's no human clicking. The agent might be executing an instruction you gave weeks ago. It might be interpreting vague intent. It might be negotiating across multiple vendors simultaneously. The traditional trust markers don't exist.
This creates three distinct gaps that existing infrastructure cannot solve. The Three A's represent the technical and philosophical shift required to enable trusted agent transactions.
Authorisation is the critical divergence point between traditional commerce and agentic commerce. The challenge isn't technical. It's philosophical. How do you encode human intent in a way machines can verify and execute?
Consider this scenario: You tell your assistant, "Check prices on those green running shoes I was looking at". The agent finds them, sees they're on sale, and buys them. Was that authorised? You said "check prices", not "buy them". But the agent interpreted urgency from the sale price and your browsing history.
This ambiguity is why most agentic commerce remains theoretical. Traditional e-commerce never had to solve this because the human was always present for the final action. You browsed, you clicked, you bought. Each step was an explicit signal of intent. The payment processor could trust that the person completing the transaction wanted exactly what they were purchasing.
Agents compress discovery, consideration, and transaction into a single delegated action. The system must now answer: What did the human actually permit?
This is where Google's Agent Payments Protocol (AP2) introduces the concept of "Mandates". Think of Mandates as cryptographically signed, tamper-proof permission structures that translate vague human instructions into verifiable machine actions.
Here are the three types that solve authorisation:
Intent Mandates define broad, ongoing instructions. "Keep my office supplies stocked when inventory drops below these thresholds, prioritising suppliers I've used before, with this monthly budget cap." This captures standing permission for recurring actions within defined parameters.
Cart Mandates capture explicit approval of specific purchases at specific prices. The agent must present this Mandate before executing the transaction. It's the digital equivalent of signing a contract, but happening in milliseconds with cryptographic verification.
Payment Mandates pass the authorised transaction details to payment networks and issuers, ensuring every party in the chain can verify the instruction is genuine.
The critical innovation here is verifiability. Mandates aren't just metadata or log files. They're mathematical proof. Any party in the transaction chain can cryptographically verify the Mandate is genuine, hasn't been tampered with, and accurately represents what the user authorised.
This means the agent can't just claim permission. It must present cryptographic proof. And the merchant, payment processor, and bank can all independently verify that proof without trusting the agent itself.
Over time, this architecture will become the standard for all delegated digital transactions. The businesses that adopt Mandate-compatible systems first will be able to accept agent transactions. Those that don't will be invisible to an expanding channel.
Authenticity: Verifying Agents and the Information They Use
Authorisation solves "what was permitted". Authenticity solves "who's actually asking" and "is the information trustworthy".
This is where things get messy, because authenticity operates on two levels: agent identity and information quality.
Agent Identity: The Good Bot Problem
Merchants face a critical challenge: when traffic arrives claiming to be ChatGPT or another AI agent, how do you verify it's genuine and not spoofed by bad actors? Security teams already report significant efforts to spoof generative AI traffic. Attackers impersonate legitimate agents to bypass security systems, scrape pricing data, or probe for vulnerabilities. The instinct for most retailers is to block all bot traffic indiscriminately.
That's a strategic mistake. Agents are becoming your biggest customers. Blocking them means disappearing from agent-driven commerce entirely.
The solution requires industry standards for agent verification. Legitimate agents often self-declare their identity (ChatGPT traffic identifies itself in headers) and can present verifiable credentials. What's missing is the infrastructure for merchants to whitelist revenue-generating agents while blocking malicious traffic.
This isn't just security infrastructure. It's just as important as commercial infrastructure. The merchants who build verification and whitelisting systems will capture agent-driven transactions. Those who don't will see agent traffic hit their firewall and disappear.
Information Quality: The Polluted Web Problem
The second authenticity challenge is harder: AI agents can only recommend what they find on the web. But the web has been polluted by 25 years of SEO gaming and affiliate marketing content designed to manipulate search rankings, not inform decisions.
Here's the issue: agents trained on this data inherit its biases. Products that don't pay affiliate commissions get filtered out. Brands that invested in authentic content get buried under SEO-optimised junk. "Authentic" recommendations become structurally impossible when the source data is compromised.
Consumers already fear AI will have an agenda or bias in its recommendations. If they feel they're being "sold something" due to paid placements, they'll change behaviour. The entire value proposition of agent commerce (trusted delegation) collapses when the information ecosystem isn't trustworthy.
This is why content strategy matters more in the agent era than it did in the search era. Agents need rich, genuine product information: detailed specifications, authentic reviews, comprehensive context. Brands that provide this will be surfaced by agents. Those relying on thin content or SEO manipulation will be invisible.
The authenticity layer isn't just about preventing fraud. It's about ensuring the entire data ecosystem agents rely on is trustworthy enough to delegate purchasing decisions to them.
Accountability: Making Mistakes Traceable When Agents Act
Even with authorisation and authenticity solved, a third challenge remains: Who's responsible when things go wrong?
When an agent makes a mistake (wrong item, misinterpreted specifications, unintended transaction), liability becomes complex. Is it the user who gave vague instructions? The AI company that built the agent? The merchant who fulfilled an ambiguous order? The payment processor who enabled it?
This isn't theoretical. Returns in fashion e-commerce already run at fifty percent. When agents make autonomous decisions, potentially without users seeing products beforehand, error rates could increase significantly.
The accountability layer addresses this through immutable audit trails. When an agent transacts, it must create a cryptographic record of:
What instruction the user gave (the original Mandate)
How the agent interpreted that instruction (its reasoning process)
What actions the agent took (every API call and decision point)
What verification steps occurred at each stage (Mandate validation, payment authorisation)
Google's AP2 creates what it describes as "audit trails that are not subject to repudiation". This language matters. It means if something goes wrong, there's cryptographic proof of exactly what happened and who authorised what. No one can later claim "that's not what I asked for" when the Mandate clearly shows otherwise.
The accountability framework also defines how agents handle edge cases through three mechanisms:
Time-bound Mandates expire automatically. A standing instruction to "buy when price drops below $50" doesn't remain valid indefinitely. It expires after 30 days unless renewed, preventing stale authorisations from executing.
Context-bound Mandates apply to specific scenarios. An instruction to "keep my pantry stocked" doesn't give the agent permission to purchase furniture just because it's also household items. The Mandate constrains agent action to defined parameters.
Revocable Mandates let users cancel standing authorisations instantly. If you change your mind or realise an instruction was too broad, you can revoke it before the agent acts.
This creates clear lines of responsibility. If the user's Mandate was vague, that's user error. If the agent misinterpreted a clear Mandate, that's agent error. If the merchant fulfilled something outside the Mandate's scope, that's merchant error. If the payment processor approved a transaction without valid Mandate verification, that's processor error.
The accountability layer doesn't eliminate mistakes. It makes mistakes traceable and attributable, which is what enables trust at scale.
What This Means for Your Business
The Three A's aren't abstract technical problems. They're the infrastructure that determines whether your business can participate in agentic commerce.
Retailers report agent-driven traffic already surging 4,700%. Customers arriving through agents show 2-6x higher purchase intent. McKinsey projects agentic commerce will reach $1 trillion in the US alone by 2030.
The businesses that solve the Three A's first will become default providers for agent transactions. Here's what you need to do:
On Authorisation: Engage with your payment service providers now. Ask about their timeline for supporting agent authorisation frameworks like AP2. Ask how their platform will handle Mandate verification and audit trails. Ask what technical changes you'll need to make. The answers determine your readiness timeline.
On Authenticity: Prepare your systems to verify and whitelist legitimate agent traffic. Work with security teams to develop mechanisms that distinguish revenue-generating agents from malicious bots. Simultaneously, audit your product content. Agents need rich, authentic information to recommend your products. Thin content and SEO manipulation will filter you out entirely.
On Accountability: Ensure your order management systems can receive and store Mandate data alongside transactions. When an agent places an order, you need the original authorisation context, not just the payment confirmation. This is what enables you to resolve disputes and maintain customer trust.
The era of implied trust (where clicking "buy now" was sufficient proof of intent) is ending. The new era requires explicit, verifiable, cryptographic proof of authorisation, authenticated agent identity, and traceable accountability.
Your competitors are already working on this. The agents are already transacting. The only question is who will be ready when they arrive.

Passionate about all things AI, emerging tech and start-ups, Mike is the Founder of The AI Corner.
Subscribe to The AI Corner
