The Agentic Commerce Trust Gap: Who Governs When Machines Spend?
CryptoVault
On August 4, 2026, the 9th Circuit Court of Appeals handed down its ruling in Amazon v. Perplexity AI. Hours later, the Secure Technology Alliance launched the Agentic Trust and Commerce Forum. The timing was not a coincidence. Washington was still parsing the GENIUS Act, a stablecoin framework that leaves machine-initiated transactions essentially unregulated. The court, meanwhile, classified AI agents as browsers rather than intruders, holding users liable under the Computer Fraud and Abuse Act. The protocol held, but the consensus fractured. By evening, every payments strategist in the ecosystem was asking the same question: who verifies the handshake when the hand is a subroutine?
On its face, the browser ruling sounds benign. A browser is a tool; a user is responsible for what they do with it. But an AI agent is not a static window into the web. It is an autonomous system that negotiates, consents, pays, and is expected to do so in milliseconds. The court did not provide a framework for verifying a machine's intent or authorization. It simply assigned liability to the human on the other end. That creates a world where the user is accountable for every micro-decision the agent makes, but has no standardized way to audit those decisions. This is the liability vacuum the new Forum is designed to fill. The Forum, spun out of the U.S. Payments Forum, sees itself as the natural successor to the EMV migration a decade ago. That effort received broad praise for reducing card-present fraud through industry coordination. But the EMV analogy only goes so far: a chip is a static object, while an agent is a moving target. The distinction matters because the Computer Fraud and Abuse Act hinges on authorization: if an agent is a browser, then the user authorized its access to any site the browser visits. That logic collapses the moment an agent signs a contract or moves funds.
The Forum has mapped its mandate onto four questions: agent identity, data standards for intent, valid consumer authorization, and dispute handling when no human is at the point of transaction. These are not academic. They are the operating system for a projected $300 billion U.S. market by 2030. As Itai Sela, chair of the Secure Technology Alliance Board, put it: "We need a clearer understanding of how intent is established, how consent is conveyed and who is accountable when an AI-initiated transaction goes off course. Identity and authentication will be cornerstones in that trust equation." That is a diplomatic way of admitting that the private sector is about to write the law by default.
The industry is not waiting for the Forum's first meeting in November. Visa has already spent $2.4 billion acquiring BioCatch, a behavioral biometrics firm that claims to use 3,000 data points per session to verify whether an agent is acting normally. Mastercard has spent $1.8 billion on BVNK, adding stablecoin settlement rails to its empire, and earlier launched Verifiable Intent, a cryptographic trust layer co-developed with Google. At the protocol layer, the x402 Foundation, now under the Linux Foundation, is pushing protocol-fee-free stablecoin settlement. It has processed 200 million transactions, though that volume still looks like a puddle next to the projected $300 billion market. In the deep end, liquidity is the only oxygen. The EPAA is the Asia-Pacific version of the same race, with its own AI and agentic payments working group. Visa and Mastercard are not alone; PayPal, Apple, and a dozen fintech startups will likely join the Forum, each with their own definition of consent. The result is a layered stack: biometrics to authenticate, cryptography to sign, stablecoins to settle, and no shared standard for the moment of intent.
I have seen this pattern before. In the DeFi summer of 2020, I was a risk manager auditing liquidity pools where the rewards were mathematically seductive and structurally unsound. I watched capital rotate into impermanent loss because the trust layer was a spreadsheet. Agentic commerce is different in mechanics but identical in shape: the transaction rail is being built before the governance layer. Alpha is not found; it is harvested from chaos. The core problem is what I have come to call the intent oracle. DeFi learned the hard way that a blockchain cannot verify off-chain reality by itself and that trusting centralized feeds creates systemic fragility. Agentic commerce has the same problem, except the off-chain reality is not a price; it is a human's momentary willingness to authorize a purchase. How do you verify what a machine was asked to do, with whom it was permitted to interact, and under what limits? Biometrics and cryptographic signatures tell you that a machine is acting in a way that looks like the user, not that the user actually intended that specific action at that specific moment.
The fourth question—dispute resolution—is the most painful. In traditional payments, a chargeback is a human saying "I did not authorize this." What happens when an agent executes a trade, signs an agreement, and the user later claims the instruction was ambiguous? Without a standardized log of intent, every dispute is a war between opaque models. Consumer sentiment reflects this uncertainty: only 14% of consumers trust AI to execute purchases without human verification. That 14% is small, but it is enough to seed a $300 billion market if the infrastructure is concentrated in a few hands. The Forum's explicit goal is to prevent fragmented approaches from creating fraud, but fragmentation is exactly what happens when every incumbent builds its own intent format. The Forum says it wants to prevent that outcome, but it is starting late. The first real-world agentic payment failure will not announce itself with a warning; it will simply manifest as a chargeback war, or a drained account, and the industry will react the way it always does—by layering on another authentication step.
Here is the uncomfortable truth: this industry-led governance is not neutral infrastructure. It is a power grab wrapped in interoperability language. The court created the liability vacuum; the private sector is filling it with its own arbiters. BioCatch's behavioral biometrics become the gatekeepers of whether a transaction is "normal." Verifiable Intent becomes a miniature courtroom. The browser classification is not a loophole for consumers; it is the foundation of a surveillance economy. If users are liable for the actions of their agents, the only way to protect themselves is to hand more data to the platforms that are validating those actions. Pattern recognition is the only true hedge, but machine pattern recognition is optimized for the network, not the user. And the stablecoin layer is heading in the same direction. Mastercard's acquisition of BVNK means the settlement rails of machine commerce will live inside the same institutions that spent a decade treating Bitcoin as a threat. After the ETF approval, Bitcoin became a Wall Street toy. Now stablecoins are becoming fee-generation engines for card networks. Yet there is no alternative. A fully decentralized agentic commerce layer would need to solve the same identity problem without a trusted anchor, and that technology does not exist yet.
The Forum will hold its first in-person meeting on November 17-18 at Best Buy's corporate campus in Minneapolis. Membership is open to everyone from LLM providers to fraud prevention firms. That is a broad tent, but broad tents in this industry usually mean the incumbents set the agenda. The regulatory gap will not stay open forever. The question is whether this self-regulation arrives in time to provide a stable foundation, or whether the first catastrophic agent payment failure forces a reactive and far more restrictive response. I have watched technical robustness fall to bad governance before. Agentic commerce can still choose a different path, but the window is measured in months, not years.