AI systems engineer monitoring secure agentic commerce and AI agent payment workflows in a modern office

Visa, Mastercard, and Google Just Built Three Different Ways for AI Agents to Pay for Things

Sat, Aug 22, 2026

In late 2025 and early 2026, the payments industry saw an avalanche of new agentic commerce protocols, each solving the AI-shopping problem in its own way. Google (with its Agent Payments Protocol, AP2), Visa (with the Trusted Agent Protocol, TAP), Mastercard (with Agent Pay), and even a joint OpenAI/Stripe effort (the Agentic Commerce Protocol, ACP) launched competing standards almost simultaneously. As an AI engineer who’s fielded the question “which protocol do we build against so our agent can actually buy the thing?”, I know the reality is messy. The protocols promise autonomous checkout, but real deployments have been modest so far. This article will explain what AP2, Visa TAP, Mastercard Agent Pay, and OpenAI/Stripe ACP actually do, how they differ, and which ones are live or still experimental, without glossing over the hype-versus-adoption gap. (See also Refonte Learning’s Agentic AI Engineer Program for training on the underlying agent tech.)

Four Companies, Four Different Ideas of How an AI Agent Should Pay

Today’s “agentic commerce” landscape features four distinct approaches, summarized below, plus a host of related standards and infrastructure layers. Each protocol comes from a different perspective:

  • Google’s Agent Payments Protocol (AP2): A Google Cloud-led standard (later donated to the FIDO Alliance) that uses cryptographic Intents, Cart Mandates, and Payment Mandates. In effect, the user signs digital contracts letting an agent shop within defined boundaries. AP2 is payment-agnostic (supporting cards, bank transfers, even crypto via extensions) and focuses on end-to-end auditability.

  • Visa’s Trusted Agent Protocol (TAP): Visa and Cloudflare’s standard, launched Oct 2025. It’s an identity/trust layer: every AI agent gets a crypto-signed identity and intent token checked against a Visa-operated directory. TAP doesn’t specify how money moves, but it tells merchants “this request really came from Alice’s verified agent,” distinguishing legitimate AI shoppers from bots.

  • Mastercard Agent Pay: A Mastercard network feature (with Microsoft, IBM, etc.) that issues agentic tokens and enforces spending rules. Launched 2025 and expanded in 2026 with “Agent Pay for Machines,” it lets agents pay with credit/debit cards, bank links, or even stablecoins, but under tight credentialing and spend limits. Mastercard’s pilots (e.g. Australia’s 2026 trials) have actually completed agent-led transactions using real cards.

  • OpenAI/Stripe Agentic Commerce Protocol (ACP): An open spec from OpenAI and Stripe, announced Sept 2025 (Apache 2.0). It introduces Shared Payment Tokens, single-use merchant-scoped tokens that carry buyer intent, ensuring the business stays the merchant-of-record. ACP powered ChatGPT’s “Instant Checkout” (Etsy/Shopify in chat), although that feature was retired in Mar 2026 after minimal uptake.

Each approach sits at a different layer of the stack (AP2/TAP/Agent Pay/ACP handle payment authorization; other protocols like A2A and MCP handle agent-to-agent communication, and memory or API layers handle context, which Refonte covers elsewhere). The table below compares the four protocols side by side:

Protocol

Developed By

Key Mechanism

Supported Payments

Merchant of Record

Deployment Status

Google AP2

Google (donated to FIDO)

Signed Intent, Cart, and Payment Mandates that cryptographically bind a user’s authorization to specific items and amounts

Credit/debit cards, bank transfers, stablecoins (via the x402 extension)

User’s payment method (merchant receives funds)

Open standard (AP2 v0.2 in April 2026 added “Human Not Present”); initial rollout, with deeper Google ecosystem integration planned.

Visa TAP

Visa (with Cloudflare)

Agent-specific HTTP signatures carrying fields like Agent Intent and Consumer Recognition (established via Visa’s directory)

Credit/debit cards (Visa network), others

Merchant (uses Visa auth network)

Launched Oct 2025; working group formed. Visa says pilots in Europe/APAC are slated for early 2026.

Mastercard Agent Pay

Mastercard

Agent registration and tokenization. Agents get unique tokens and enforced spending limits in each transaction

Cards, bank account transfers, stablecoins

Merchant (via Mastercard rails)

Launched 2025; expanded 2026 as “Agent Pay for Machines”. Piloted live transactions (e.g. Jan 2026 Australia).

OpenAI/Stripe ACP

OpenAI & Stripe

Agent obtains a secure, single-use payment token tied to a specific merchant and amount, which the payment provider uses to charge the buyer

Card payments (via Stripe; can extend to others)

Merchant (business remains merchant-of-record)

Released Sept 2025; limited real usage. ChatGPT’s Instant Checkout (Etsy/Shopify) was shut down in Mar 2026 after only about a dozen merchants had integrated.

Each protocol builds trust and controls in different ways. Google’s AP2 creates an auditable chain from user intent to cart to payment, giving consumers digital “mandates” and a transparent payment log. Visa’s TAP simply vouches for the agent’s identity and approval (think of it as a “cryptographic handshake” before checkout). Mastercard’s solution puts agents on its token network and lets issuers set hard spending rules. And Stripe/OpenAI’s ACP uses a one-time token approach so agents can’t “steal” a user’s card details, keeping the merchant in control.

Why This Suddenly Matters: Agents That Can Actually Buy Things

The hype around agentic commerce comes from a simple idea: don’t make people click “Add to Cart”; let AI do it. In 2023-25, we saw huge progress in enabling agents to find and compare products via LLM APIs (LLM-driven search, RAG for product catalogs, etc.). But passing the final “buy” step was the missing piece. In late 2025, big companies announced solutions. The pitches emphasized convenience (e.g. an agent snagging limited-edition items the instant they drop) and security (tamper-proof mandates, federated identity, spending limits).

Why is this now such a focus? Three factors combined:

  • AI adoption at scale. Surveys show roughly half of consumers now use AI tools for shopping tasks. Team Jet, Klarna, and others already let chatbots initiate parts of shopping. The next logical step is enabling payment. But unsecured, that would open huge fraud risks (imagine rogue bots buying thousands of gift cards). So there’s a race to “secure it right” before it can go mainstream.

  • Vendor competition and lock-in. Each tech giant and network provider wants control of the next commerce wave. Google wants to own the shopping journey (hence Universal Cart and AP2). Visa and Mastercard want to protect their card rails. Stripe wants to insert itself into this new channel. Everyone is pushing a standard, but none can outright dominate yet. (This fragmentation is why a client recently asked us, seriously, “which protocol should our agent build for?” We had to say, “it’s complicated.”)

  • Agent readiness. Underneath the checkout, agents have gotten powerful. LangChain/LangGraph/AutoGen (the backbone of production agents) can now orchestrate multi-step tasks reliably. Claude, Gemini, GPT-4o, etc. can understand product data and payment APIs. Refonte’s AI Agent Memory Systems already shows how agents manage state and long-term context. Here, the next frontier is giving them secure “hands” to complete transactions.

That said, actual usage is still low. Despite all the press announcements, very few consumer-facing agent payments have shipped. A Forrester research blog notes that most companies are still piloting agentic AI, and it’s not widely in production. Merchants are curious but cautious. As PayPal put it, merchants want AI-driven sales only if “they can retain control of customer relationships and data”. Many solutions are still in closed betas or planned rollouts. In short, the tech is emerging, but the hype outstrips reality so far. This article drills into exactly what is live today versus still being tested.

Google's AP2: Intent, Cart, and Payment Mandates

Google’s Agent Payments Protocol (AP2) debuted Sept 16, 2025. It’s an open protocol (now donated to FIDO Alliance) that introduces the concept of digital mandates. The user and agent go through these steps:

1.  Intent Mandate: The human gives the agent a signed “Intent,” for example, “Find me a green winter jacket under $200”. This cryptographically binds the user’s request as an authorized action.

2.  Cart Mandate: When ready to checkout, the agent presents a proposed cart of items. The user signs a Cart Mandate approving those exact items and prices. This creates an unchangeable record: “what you see is what you pay for”.

3.  Payment Mandate: Finally, the user’s payment method (card, bank, etc.) is cryptographically linked to the approved cart. The payment processor pays out to the merchant, but only according to the signed mandate. The entire chain is verifiable end-to-end.

This intent-to-cart-to-payment chain ensures a transparent audit trail that answers “Did the user authorize this purchase?”. In practice, AP2 integrates with Google’s ecosystem: at Google I/O 2026, Google announced a “Universal Cart” across Search, Gemini, YouTube, and Gmail, all secured by AP2 mandates. Google promises features like spending criteria and brand rules (for example, “only buy Nike shoes under $150” or “only use Visa cards”) embedded in AP2’s guardrails.

Importantly, AP2 is payment-agnostic. By default it works with traditional payment rails, but Google quickly extended it to crypto: in April 2026 Google released an “x402” extension on GitHub to allow agent payments in stablecoins or crypto (built with Coinbase and Ethereum Foundation). Through these extensions, AP2 can tap Visa/Mastercard rails or Web3 rails as needed. However, despite Google’s announcements and broad partner support, AP2-powered shopping is only beginning to be rolled out (initially in Google’s own products like Gemini Spark) and is not yet ubiquitous.

"Human Not Present" Payments, Added in April 2026

A key AP2 enhancement arrived in April 2026: “Human Not Present” mode. Google announced AP2 v0.2 at the FIDO Alliance blog, which added support for fully autonomous purchases. In this mode, the user pre-signs a detailed Intent Mandate specifying exactly what can be bought (e.g. “Buy two concert tickets this Friday at up to $100 each”). Then the agent watches the market and, when conditions match, it auto-generates a Cart Mandate and completes the payment without a real-time human click. Google explicitly cited examples like scoring limited-release tickets the instant they go on sale, all while maintaining user-defined boundaries.

This “delegated tasks” workflow is baked into AP2 from the start, but v0.2 formalized it: an Intent Mandate signed upfront includes spend limits, time constraints, and other rules. Only after those criteria are met does the agent create a Cart Mandate and link to the user’s payment. Google’s blog promises this is “based on pre-authorized user instructions”, providing a way for agents to act entirely on their own (albeit constrained by the signed mandate).

In short, AP2’s combination of cryptographic mandates and eventual human-not-present checkout is a powerful approach. Google has also donated AP2 to the FIDO Alliance (an open-standards consortium) to encourage industry adoption. In theory any merchant or wallet could implement AP2 once standardized. In practice, AP2 is still very new: no major retailer has a live AP2 checkout yet. But it’s the most mature “agent pays autonomously” system so far, and Google plans to bake it into products like Gemini Spark in the coming months.

Visa's Trusted Agent Protocol: Proving an Agent Is Legitimate

Visa took a different angle. In mid-Oct 2025, Visa (with Cloudflare) rolled out the Trusted Agent Protocol (TAP). Unlike AP2, TAP isn’t about shopping cart data; it’s about identity and trust. The idea: merchants should know for sure that an AI checkout request really comes from a legitimate, user-authorized agent, not a malicious bot.

TAP works by giving each agent a cryptographic signature embedded in its HTTPS requests. When the agent tries to pay, it attaches a signed token containing metadata fields such as Agent Intent, Consumer Recognition, and optional payment data. Visa operates a directory service: when the merchant sees a TAP signature, it can contact Visa to verify it. This tells the merchant "Yes, this request was signed by Alice’s agent, with the right credentials." In effect, TAP is an “identity secret handshake” for agents. The merchant doesn’t know the user’s private keys, but Visa has vouched for that agent’s link to a real consumer account.

For example, Visa’s announcement says TAP includes:

  • Agent Intent: what purchase is being attempted

  • Consumer Recognition: a token confirming the customer’s identity (e.g. their card or account)

  • Payment Information: optional data for continuity across the payment journey.

The scheme runs over standard web technologies (TAP is built on HTTPS message signing and aligned with WebAuthn). Its advantage is that it works with existing payment flows: after verifying the agent, the payment itself can proceed normally through Visa’s network. Visa’s release notes say “TAP establishes a framework… to enable secure communication between AI agents and merchants”, helping the merchant distinguish “legitimate AI agents acting on behalf of consumers” from random bots.

Visa was quick to involve many partners. The TAP working group (publicized in late 2025) included processors like Adyen, Stripe, Worldpay, and platforms like Shopify (via Stripe), Coinbase, and even cloud builders (Akamai is adopting TAP). Visa has been bullish: it published a December 2025 press release predicting “millions of consumers will use AI agents to complete purchases by the 2026 holiday season”, and said pilot programs are planned in APAC and Europe in early 2026.

In short, Visa TAP is about AI agent identity verification for payments. It doesn’t specify how the payment is paid (that’s still Visa/MC/etc routing), but it gives strong confidence that “this AI checkout is properly authorized.” For anyone worried that a rogue agent might fraudulently buy things, TAP is an attempt to ensure agent identity is authenticated before checkout.

Mastercard Agent Pay: Spending Limits for Machines

Mastercard’s approach is a third take. It launched its Agent Pay program in 2025, aiming to put AI agents into its payments network with guardrails. Unlike AP2 or TAP, Agent Pay focuses on credibility and control of agents rather than a specific messaging format. Essentially, Mastercard does two things: it issues each agent a cryptographic credential, and it tokenizes the agent’s purchases with spend limits and transaction policies.

In practice, Mastercard agents operate with “Agentic Tokens” (building on the network’s existing tokenization tech). Every agent must first register and be verified. Once credentialed, the agent can use card, bank, or even crypto rails to pay, but every transaction is controlled by dynamic rules. Mastercard’s 2025 announcement highlights:

  • Credentialing: Agents must be trusted and authenticated before transacting. (Merchants can then trust purchases knowing the agent is known to Mastercard.)

  • Permissioning: Issuers or users set spend limits and rules for the agent. For example, “agent can spend up to $50 on groceries per week” or “max $100 total on travel.”

  • Transacting & Settling: With credentials in place, the agent can transact across various rails; behind the scenes, Mastercard ensures it all settles (even between different systems).

In 2026 Mastercard extended Agent Pay to a new “Agent Pay for Machines” service targeting high-volume, automated transactions. The press release on June 10, 2026 explains this scales Agent Pay across multiple payment networks (cards, accounts, stablecoins) with interoperability and governance controls. For example, one bullet lists:

Agent Pay for Machines supports credentialing every agent with verifiable intent, permissioning rules (like spend caps), continuous multi-party transacting, and guaranteed settlement across cards/banks/crypto.

Notably, Mastercard has emphasized cross-network collaboration: it worked with Google/AP2 and Stripe/ACP teams on aligning how intent and identity should be represented. And Mastercard has already run real agentic transactions: in Jan 2026 it announced Australia’s “first authenticated agentic payments” pilot. In that trial, an AI agent named Matilda (built by Maincode) used a CBA debit card to buy movie tickets and a Westpac credit card to book a hotel, all fully authorized with cardholder consent and visible to issuer, acquirer, and merchant. Mastercard touted this as proof that agents can be “visible, governed participants” in payment flows.

So Agent Pay is live in the sense that banks and providers are integrating it into their systems. It provides the framework for agents to exist on card networks with spend constraints. But like AP2 and TAP, it remains mostly in pilots and sandboxes. The general consumer doesn’t yet see “Pay with Agent” buttons, at least not publicly. Instead, Mastercard is equipping banks, fintechs, and enterprise systems to eventually enable this.

OpenAI and Stripe's Agentic Commerce Protocol

OpenAI and Stripe went open-source. In late Sept 2025 they co-published the Agentic Commerce Protocol (ACP) specification (Apache 2.0), aiming to become a universal agentic checkout standard. ACP’s design philosophy differs from AP2/TAP/AgentPay: it focuses on keeping the merchant in control of the sale. In ACP, agents and platforms can initiate a checkout, but the merchant of record and order flow remain with the business.

Technically, ACP introduces “Shared Payment Tokens” (SPTs). In a purchase flow, once an AI agent has confirmed what the user wants, it requests an SPT from the payment provider. This token is a one-time credential scoped to that specific merchant and transaction amount. The agent then passes the SPT to the merchant’s checkout API, which uses it to collect payment from the user’s method (via Stripe). The merchant never sees the user’s raw card details, just the SPT, and the purchase is tied to exactly the intended amount. Stripe describes SPTs as “single-use token[s] tied to a specific merchant and transaction amount”.

Key points of ACP:

  • Merchant of Record stays the merchant. The agent may facilitate the purchase, but the business still owns the customer relationship and the sale. Stripe explicitly notes the business remains the "merchant of record".

  • Amount-bound, one-off tokens. Agents can't reuse a token or adjust amounts beyond what was approved. This prevents an agent from charging more than agreed.

  • Integration-oriented design. ACP includes product feed standards and APIs so merchants can list products to agents. It’s explicitly built to let any agent interact with any store.

In September 2025, ChatGPT’s interface debuted a version of ACP via its “Instant Checkout” feature (using Stripe under the hood). In that demo, ChatGPT could let U.S. shoppers buy single items from partnered Etsy/Shopify stores directly in chat. However, this feature was scaled way back in March 2026. OpenAI reportedly “pulled back” Instant Checkout, and only about a dozen Shopify merchants ever integrated it. The reasons seem to be low merchant interest and possibly technical immaturity of ACP (it initially lacked even basic features like merchant tax calculation).

Even so, ACP continues to evolve. Stripe has released more of the spec and tools (the “agentic commerce suite” with x402 stablecoin support, etc.). But for now, ACP’s traction is minimal outside of private tests. Unlike the more closed AP2 or TAP pilots, ACP is open-source and not tied to any single platform, so in theory it could see wider adoption if agents and merchants choose it. It’s too early to tell which checkout model users will prefer.

Why Instant Checkout Got Retired in March 2026

It’s worth emphasizing that ChatGPT’s “Instant Checkout” retirement was a reality check. The feature was meant to show ACP in action, but merchants barely adopted it. Forbes and industry reports noted that at most a few dozen Shopify stores enabled it. In practice, most shoppers discovering products in chat still navigate to the merchant site to pay. Stripe’s own blog alluded to the complexity: enterprise procurement is a different funnel than consumer retail.

The takeaway for builders: “agentic commerce” doesn’t magically collapse into existing e-commerce. For consumer retail it still looks like regular checkout under the hood; for enterprise SaaS, it often has to interact with marketplace billing or large contract processes that agents can’t bypass. As a result, ACP remains an evolving standard, not a turnkey drop-in solution.

Six Standards, One Confusing Landscape

By mid-2026, at least six overlapping “agentic commerce” standards were on the table:

  • OpenAI/Stripe ACP (Agentic Commerce Protocol): for agent-initiated checkouts.

  • Google’s Universal Commerce Protocol (UCP/Universal Cart): Google’s broader standard for agentic shopping across platforms.

  • Google AP2: for payment mandates and authorization (covered above).

  • Model Context Protocol (MCP): an open spec (by Anthropic, co-led by Google) for agent-to-agent state/context.

  • Google A2A: Google’s Agent-to-Agent protocol for service discovery and communication (underlying infrastructure).

  • Visa TAP: for agent identity verification.

All these names can blur together. A key point: MCP and A2A are a different layer entirely. They don’t touch money at all; they are “operating system” protocols that let agents discover each other and share context (APIs, data, etc.). For example, Refonte’s API Design for AI Agents: MCP vs. A2A vs. OpenAPI covers how MCP/A2A are about agent-to-agent communication. In contrast, AP2/TAP/AgentPay/ACP sit on top of that as a commerce/settlement layer.

In practice, you’d implement one protocol for payments and maybe use MCP/A2A under the hood for orchestration. But many headlines lump them together as “agentic standards.” The PayPal blog even categorizes them into tiers: commerce (ACP, UCP), payment/trust (AP2, TAP, Agent Pay), and infrastructure (A2A, MCP). Understanding these categories helps: don’t confuse an inter-agent messaging spec with an actual agent checkout protocol.

MCP and A2A Are a Different Layer Entirely

Just to be explicit: Google’s A2A and Anthropic’s MCP protocols do not handle payments or trust at the checkout. They are lower-level tools that let agents talk to each other and access shared data. For example, Google A2A lets agents call web services with security, and MCP standardizes how agents store and retrieve context between sessions. These are absolutely necessary for building complex multi-agent workflows, but an agent can use A2A/MCP without any of the above commerce protocols. (See Refonte’s MCP vs A2A article for details on that network layer.)

How These Protocols Actually Compare

The table above gives a side-by-side view. In summary:

· Integration complexity: ACP and AP2 require fairly deep integrations (APIs, mandates flow, etc.), whereas TAP is mostly an added signature check in existing flows. Agent Pay is largely handled behind the scenes by banks/token services once agents are credentialed.

  • Who pays: All keep the merchant as the one being paid. ACP explicitly preserves the merchant-of-record; AP2/TAP/AgentPay also assume the user’s regular payment route (card or stablecoin) pays the merchant.

  • Agent identity: TAP is designed explicitly for agent identity. AP2 includes user identity implicitly via the signed mandates, and Mastercard Agent Pay includes agent credentials. ACP relies on Stripe’s authentication for agents, which is still evolving.

  • Payment scope: All support credit cards; AP2 and Agent Pay explicitly mention bank transfers and crypto options. ACP via Stripe primarily targets cards and possibly UPI/banking rails in future.

Each standard also differs in maturity: TAP and AgentPay are network-driven (Visa/Mastercard) and only as open as Visa/Mastercard allow. AP2 started as Google Cloud but now is open and going standard. ACP is open by nature, but still purely voluntary adoption. Right now, there is no single winner. Engineers must often design agents to be protocol-agnostic or easily switchable between these methods.

The Hype-vs-Reality Gap: What's Live vs. What's Still a Pilot

Despite big announcements, actual “agent buys stuff” rollouts are rare. Here’s where things stand:

  • Google AP2: Live status: Only demo and limited beta usage so far. Google said AP2 v0.2 is coming to Gemini Spark and other products, but as of mid-2026 the average user cannot yet click “Buy” via AP2 on Google Search or Gemini. AP2’s partners (e.g. Samsung, Intuit, Salesforce, etc.) are developing support, but we haven’t seen a public AP2 checkout button on a merchant site yet.

  • Visa TAP: Live status: The spec is finalized and on Visa Developer, and Visa is testing it with partners. Visa’s press says “hundreds” of agent-initiated transactions have occurred in pilot settings. Consumers won’t consciously “use TAP”; it’s a background validation. Visa’s roadmap indicates more pilots globally in 2026 (APAC/Europe). So TAP is live in the sense that issuers and merchants can validate agents now, but it’s still largely in trial mode.

  • Mastercard Agent Pay: Live status: Agent Pay tokens work within Mastercard’s network, and several banks (CBA, ANZ, Westpac, Wages) are ready for it. The Jan 2026 Australian trials were real, authorized payments on Mastercard rails. Mastercard says it’s collaborating on future standards too (e.g. with Google AP2 and Stripe ACP) to ensure compatibility. So Agent Pay is farther along: agents can get credentials and real transactions have been done. But again, a consumer doesn’t see a “Pay with Agent” option on any consumer app yet.

  • OpenAI/Stripe ACP: Live status: Largely experimental. Stripe and OpenAI showed ChatGPT Instant Checkout, but that feature is now off. Stripe has released dev docs and a test suite for ACP, but adoption by merchants has been minimal. No major retailer or platform publicly offers native agent checkout under ACP yet. It remains a spec that companies can choose to implement.

In practice, most “AI agents placing orders” today happen behind closed doors: tech demos, pilot programs, and controlled environments. Savvy enterprises might enable agentic purchasing in B2B scenarios (see below), but the average shopper isn’t clicking “Agent Pay” on Amazon yet. The protocols exist, but broad consumer rollout is likely still a couple of years away.

What Security Analysts Are Actually Worried About

Industry analysts are watching agentic payments with mixed feelings. On one hand, secure standards like AP2/TAP/AgentPay are exactly the guardrails experts asked for. On the other hand, they warn of new risks:

  • AI identity sprawl. As Forrester’s 2026 security survey reports, 49% of security leaders now list agentic AI as a top concern. In particular, they worry about many machine identities multiplying uncontrollably: “Agents can impersonate each other and escalate privileges because nonhuman identity is still a mess”. In other words, without proper IAM controls, an agent might fraudulently assume another agent’s identity or act outside its scope.

  • IAM for agents. Gartner’s 2026 trends explicitly calls out “Identity and Access Management adapts to AI agents” as a key theme. Traditional IAM was built for human logins and service accounts, not thousands of autonomous agents. Analysts urge companies to give each agent unique credentials, least privilege rights, and robust logging. Essentially, treat every agent as a long-lived identity that needs lifecycle management.

  • Governance challenges. (Broader than just payments.) Gartner estimated 40%+ of agentic AI projects may fail by 2027, not because of fraud, but because legacy IT environments and governance aren’t ready. It’s important to note: that warning is about general AI projects, not specifically payment protocols. However, it reflects the truth that integrating agents (and their payments) into existing systems is nontrivial.

  • Fraud at agent speed. This is a popular phrase: agents could enable “fraud at machine speed” if a malicious agent unleashed rapid small purchases or tests stolen credentials. While there aren’t hard stats yet, experts caution that conventional fraud detection may need to evolve. As PayPal notes, when “an AI agent, not a consumer, clicks ‘Buy,’ familiar fraud and trust concerns take on new urgency”. We don’t yet know how often agents will be tricked or corrupted, but it’s a top concern in risk models.

  • False alarms vs. bot-blocking. Ironically, some systems designed to block bots could misinterpret valid agent requests. Analysts advise differentiating “good” AI agents (authorized shoppers) from “bad” bots. That’s exactly Visa TAP’s aim. But until all merchants adopt TAP or similar, some agents may be mistakenly blocked or challenged by CAPTCHAs.

In summary, security pros agree on the categories of risk (identity theft, rogue agents, rapid transactions), but they lack quantifiable data. For now it’s “threat modeling, not incident stats.” As Refonte’s curriculum emphasizes, any agentic system must have robust logging, vetting, and manual override paths, ideally powered by a trusted protocol underneath.

The Identity-Sprawl Problem

A special emphasis of the Forrester report is the so-called “identity-sprawl” issue. Every new agent you launch could count as a separate user identity (with keys or certificates) in your systems. Without a solid trust protocol, you could end up with millions of unknown digital identities. The Forrester blog bluntly warns that agents “grow faster than anyone can keep track of” and that traditional security teams are totally unprepared for this flood of non-human actors.

The payment protocols aim to mitigate this: TAP and AgentPay give each agent a credential, AP2’s mandates attest to legitimate user agency, and ACP’s tokens ensure only pre-approved actions occur. But engineering must still ensure agents are named, owned, and revocable. For now, “AI agent identity verification for payments” is not solved by one magic switch; it requires adopting these new standards and integrating them into the company’s IAM/PKI infrastructure.

Fraud at Agent Speed: A Real but Still-Unquantified Risk

Analysts often highlight “fraud at agent speed,” meaning an AI agent could attempt a huge number of transactions in parallel or very quickly, potentially outpacing human monitoring. It’s a logical concern: an agent with stolen credentials or malicious code might rapidly probe merchants. But to date, we lack public cases or data quantifying this.

Industry commentary tends to be qualitative. For instance, one security analyst noted that most KYC/fraud tools aren’t built for “agent speed” scenarios. PayPal’s own assessment puts it well: merchant leaders see “familiar concerns about trust, payments and fraud take on new urgency when an AI agent, not a consumer, clicks ‘Buy’”. In practice, fraud risk will depend on the adoption method: if TAP/AgentPay protocols are used, there are extra checks against agent spoofing. If agents are simply given account logins, risk is much higher.

In short, fraud risk is widely acknowledged but still an evolving story. No study has yet “measured fraud losses due to agents.” It remains a point of vigilance rather than a demonstrated crisis.

What This Means for How You Build Agentic Systems Today

Given the fragmented state of agentic payment protocols, how should you design your agents? A few best practices emerge:

  • Keep payment logic modular. Don’t hard-code one protocol deeply into your agent’s core. Instead, architect your agent such that the checkout step is a plugin or adapter. For example, your agent’s final action might be “Call payment_integration.process(order)”. Then you can swap out that module to AP2, TAP, ACP, or even a human-in-the-loop fallback as the situation demands.

  • Use established agent frameworks. Focus first on building robust agents with clear intent boundaries, tools, and context. Refonte’s recommended stack (LangChain, LangGraph, AutoGen, Claude/OpenAI APIs, Pinecone or Chroma for retrieval, LangSmith for orchestrating) provides that foundation. An agent built this way can accept orders and produce a structured “cart.” Once you have a working agent, you can then integrate whichever payment protocol is required.

  • Design for uncertainty. Any one protocol might not “win.” For instance, you could start with Stripe ACP (since its documentation is open), but if your customers mainly use Google devices, you might pivot to AP2. Design your system to cleanly handle failure modes: if a protocol is unsupported or flagged as insecure, the agent should escalate to a human or retry with a different method.

  • Plan fallbacks. While standards mature, you might let agents prepare orders and then send the transaction to a user for final human checkout. For example, in a limited-release ticket use case, the agent could notify the user in real-time to approve payment via their own browser. This mimics “Human Present” mode in AP2. It’s less convenient but avoids reliance on incomplete protocols.

  • Build observability and controls. No matter what protocol you use, log every agent action. Tie logs to the signed mandates or tokens if available. Also, implement rate limits and watch for unusual patterns (e.g. an agent suddenly spending near its limit). Google’s AP2 and Mastercard’s frameworks assume you will do this; make sure your system enforces any spending caps or merchant allow-lists attached to the protocols.

In practical terms, the skills you need are the core agentic engineering skills: handling LLM tool use, orchestration, state management, and API integration (including payment APIs). The Refonte Learning Agentic AI Engineer Program covers exactly these foundations. It teaches LangChain, LangGraph, AutoGen, and function calling so you can plug in new APIs (like a payment gateway) at will. It also emphasizes deployment and safety guardrails, which are crucial when automating purchases. Once a protocol becomes standard, the program’s “API integration and external tool use” modules will directly apply to implementing it.

Designing for a Standard That Might Not Win

Given how many contenders there are, it’s wise to stay protocol-agnostic as long as possible. For example, if you design your ordering logic to output a JSON cart, you can later map that to AP2 mandates, TAP signatures, or ACP tokens without rewriting everything. In other words, abstract the payment layer. This is similar to how no-code agent platforms let you choose Shopify vs Stripe vs PayPal out of the box; here you want an abstraction for “agentic checkout” that can plug into multiple standards.

We also recommend keeping the user in control as a fallback. Right now, customers are not accustomed to giving an AI complete payment authority. Refonte’s program emphasizes human-in-the-loop design whenever stakes are high. Until agentic payments are proven secure, let the user have final approval (even if just a second tap) on big-ticket buys.

Agentic AI Engineer Salaries and Where This Skill Fits in 2026

You might be wondering: what kind of career and compensation comes with these skills? Refonte Learning’s Agentic AI Engineer Program page notes a “$130K+ starting salary” and “70,000+ annual job openings” for agentic AI engineers. However, it’s crucial to interpret those figures properly. The program itself candidly says these are course positioning numbers, not guaranteed outcomes. They reflect aggressive marketing rather than labor-market research.

For context, the U.S. Bureau of Labor Statistics reports that Computer and Information Research Scientists (a broad category encompassing AI roles) had a median salary around $140,910 in 2024. Technology staffing firms (Robert Half) list mid-career AI/ML engineers at roughly $170K national mid-point. So a “$130K+” entry salary is plausible for a well-prepared graduate, but not automatic. The landscape is competitive, location- and skill-dependent. (Refonte’s figures are a good signal of industry demand but not a promise of any one person’s salary.)

As for job opportunities, specialists who can actually build reliable, production-grade agents (including payment integrations) are still relatively rare. Positions with titles like Agentic AI Engineer, AI Systems Engineer, LLM Engineer, or even Prompt & Agent Architect are emerging. Companies are searching for the exact skill set this article emphasizes: architecture design, multi-agent orchestration, RAG pipelines, memory management, and API integrations.

Refonte’s page lists career paths such as Agentic AI Engineer, AI Systems Engineer, LLM Engineer, AI Developer, and Prompt & Agent Architect. In practice, you might end up with broader titles (AI Engineer, Software Engineer (AI focus), etc.) but the key is the skill set. As Gartner and others have noted, demand for these engineers is outpacing supply in 2026, so it’s a strong field for well-qualified candidates.

Building This Skill Set: The Refonte Learning Agentic AI Engineer Program

If you’re interested in mastering these capabilities, the Refonte Learning Agentic AI Engineer Program is designed for exactly this. It’s a 3-month training + internship program (12-14 hours/week) combining live sessions, self-paced modules, and a hands-on project. Its confirmed curriculum includes three key modules: “Introduction to Agentic AI”, “Tool Use & Function Calling”, and “Building Your First Agent with LangChain and LangGraph”.

Throughout the program, you’ll work with the industry-standard frameworks: LangChain, LangGraph, AutoGen, the Claude API, OpenAI’s APIs, vector databases (Pinecone, Chroma), and the LangSmith orchestration platform. These are precisely the tools you’d use to integrate any payment protocol. The courses cover core agentic competencies: LLM architecture patterns, multi-agent orchestration, RAG/memory systems, API integration, deployment, observability, and safety/guardrails.

The program is taught by expert mentors (e.g. Dr. John Anderson, a senior AI engineer with 17 years’ experience) and culminates in an internship project that you can add to your portfolio. Upon completion, Refonte offers certification and even potential placement support.

Logistics: The program requires you to be working toward a bachelor’s (or higher) degree, and recommends familiarity with Python and basic LLM usage (no deep ML background needed). The fee is very affordable: $300 upfront (a 30% discount off the $387 list price) or two installments ($204 + $98).

By joining, you’ll gain exactly the practical skills needed to build production-ready agents, the kind of agents that can eventually tie into AP2, TAP, ACP or whatever new protocol arises. In other words, while no program can yet promise a seamless agentic checkout integration module, Refonte’s curriculum gives you the building blocks for that step. After all, protocols change fast, but fundamentals endure: designing LLM-based agents, connecting APIs, managing memory, and enforcing safety are all core to this role.

As an AI systems engineer with 10+ years of experience, I can attest: knowing how to build multi-agent systems and integrate with external APIs is far more valuable than betting on one payment standard. The Refonte Learning Agentic AI Engineer Program equips you for that reality, whether your future job involves implementing Google’s AP2 or Stripe’s ACP or something entirely new.

Ready to become an Agentic AI Engineer? Learn more on the Refonte Learning Agentic AI Engineer Program page and take the first step toward building the autonomous commerce systems of tomorrow.