We use cookies to improve your browsing experience. To learn more, visit our privacy policy.

Agentic Commerce Has the Traffic. Does It Have the Trust?

New numbers from Shopify show agentic shopping is scaling fast, but the rules for trusting an agent with real money are still being written.

Agentic commerce was pitched as inevitable for long enough that the pitch stopped being interesting. What's interesting now is that someone finally has the numbers to back it up, and that the platform providing those numbers is the same one saying, plainly, that the technology isn't finished maturing.

In a conversation with Retailgentic, Shopify's VP of Product, Mani Fazeli, recently put real figures behind the shift: AI-driven traffic to Shopify merchants is up 8X year-over-year, orders placed through those channels are up 13X, and roughly 70% of AI-attributed orders last year landed outside the platform's top 100 product categories, meaning agents are already surfacing small and mid-sized merchants that traditional search never would. Fazeli frames the industry's progress using a four-stage model—crawl, walk, run, fly—running from AI-assisted discovery through to fully autonomous, budget-based buying. And according to Fazeli, right now things stand "somewhere between walk and run."

But while the traffic curve says adoption is no longer hypothetical, the maturity curve says autonomy isn't finished arriving. Read together, that flags a different concern than the one most agentic commerce coverage asks. It's not "will agents shop," it's "who governs the transaction once a person isn't the one making it."

Traffic Isn't Trust

More agent-driven volume means more transactions happening with less human oversight per transaction. That's the actual risk surface. Not whether agents show up, but what happens once they're negotiating, paying, and representing someone else's interests without a person double-checking each step. Two efforts, from two different directions, are already trying to answer that.

Governing From the Outside In

Retail AI Council has created a working group for the Shopper Context Protocol (SCP), chaired by Matt Howland, with Andy Laudato—COO of The Vitamin Shoppe and Retail AI Council co-founder—backing it publicly. As agents handle more of the discovery and checkout journey, merchants risk losing the direct customer relationship they've spent years building. SCP is designed to carry that relationship context (things like loyalty, preference, and purchase history) into the moment an agent is transacting, so a returning customer doesn't get treated like a stranger just because an AI made the introduction.

That gap exists because of what SCP is explicitly built on top of: the Agentic Commerce Protocol (ACP), OpenAI and Stripe's standard for agent-led discovery and checkout. ACP handles the transaction. It doesn't carry any sense of who the customer is or what they've bought before. SCP's entire reason for existing is to fill that gap. It's still a working group, not a finished standard, but it's a clear signal that the industry sees the relationship risk clearly enough to organize around it before it becomes a crisis.

Building Trust From the Inside Out

Retail AI Council's approach governs the relationship. A separate, harder problem is governing the agent itself and making sure it can be trusted with money at all. Orium recently published a piece on exactly that, in the B2B procurement context: a working prototype where a buyer's agent negotiates a restock order against three supplier agents, using a shared discovery layer (AGNTCY, with suppliers publishing offerings in the OASF schema) and a common negotiation protocol (A2A, with A2CN handling the rulebook and proof of what was agreed to). Once both sides settle on a price, Stripe moves real money in USDC.

Three findings from that build are worth pulling forward, because they apply to any agent handling money on someone else's behalf, not just this one prototype.

First, an agent needs genuine optionality to negotiate at all. An early version of the prototype settled on the exact same price in every run, because its only real move was to concede or walk away. Adding a third option—holding firm—was what finally produced a realistic spread of outcomes.

Second, the guardrails that actually held were enforced outside the AI, not requested of it: a hard filter stripped anything from outbound messages that could reveal the agent's spending limit, and a price cap the agent couldn't see or reason around, even when the researchers ran a negotiation where the counterparty tried, on every turn, to manipulate the agent into revealing it.

Third, and most instructive: the worst bug wasn't in the AI's instructions at all. A separate trust-scoring system, written correctly on its own terms, quietly penalized an honest supplier for holding its price, and the buyer started walking away from the best deals in the batch, for reasons that had nothing to do with the deal itself. It only surfaced because the team ran the negotiation dozens of times and looked at the range of outcomes, not just whether one run worked.

That last point generalizes further than the other two. An agent's behavior is spread across its instructions, the code around it, and scoring systems like this one, and nothing automatically checks that all of them agree. The bug that mattered most wasn't a prompt-engineering problem, but rather a systems problem that a single test run would have missed entirely.

Three Protocols, No Consolidation

Here's what makes this bigger than two isolated efforts: there are now at least four separate protocol initiatives trying to solve adjacent pieces of the same problem, and none of them have consolidated. OpenAI and Stripe's ACP (Agentic Commerce Protocol) handles agent-led discovery and checkout. Google and Shopify's UCP (Universal Commerce Protocol) governs how agents discover and transact with merchant catalogs across the full shopping journey. Retail AI Council's SCP layers customer relationship context on top of a protocol like ACP, so agents don't flatten every shopper into a stranger. And AGNTCY, OASF, A2A, and A2CN—the stack behind Orium's negotiation prototype—govern how agents discover counterparties and negotiate B2B deals with verifiable settlement.

Whether that's healthy plurality or the early stage of fragmentation remains unresolved, and will only be determined over time. Composable architecture has always bet that open standards beat any single vendor owning the whole stack, but that bet only pays off if the standards eventually talk to each other. Right now, they're being built in parallel, by different organizations, for different corners of the same shift, with at least one (SCP) already defined as sitting on top of another (ACP) rather than replacing it.

What This Means for Commerce Leaders

Adoption readiness and governance readiness are two different questions, and most agentic commerce planning right now only asks the first one. Shopify's numbers answer "is this real” but they don't answer "who's accountable when the agent gets it wrong, or who owns the relationship when the agent is the one shopping." Before committing to agentic commerce infrastructure, it's worth asking which governance layer, if any, you're building toward (or betting on someone else to finish).

Author Image

Leigh Bryant

Editorial Director, Composable.com

Leigh Bryant is a seasoned content and brand strategist with over a decade of experience in digital storytelling. Starting in retail before shifting to the technology space, she has spent the past ten years crafting compelling narratives as a writer, editor, and strategist.