A shared vocabulary arrives for agentic checkout
On July 22, 2026, the U.S. Payments Forum published 'Agentic Commerce: A Primer for the Payments Industry,' developed by its Emerging Payments and Payments Fraud Working Committees under the Secure Technology Alliance. When a body that convenes issuers, networks, processors and wallets puts a stake in the ground, it signals that a topic has moved from conference panels into infrastructure planning. The primer gives the industry a common language for something that has been described in incompatible terms across every vendor pitch. That alignment is the quiet precondition for interoperability, because parties that cannot agree on what a transaction is cannot agree on how to authorize, price or settle it.
That standardization matters more than any single technical detail in the paper. Agentic commerce has suffered from a definitional fog where every participant means something slightly different by 'AI agent checkout,' which stalls procurement and slows integration. A shared primer from a neutral convener lets merchants, banks and processors negotiate from the same definitions and scope their work against a common reference. For retail CTOs, the arrival of common terminology is the practical cue to move agentic commerce off the research backlog and into an active workstream with named owners, a budget line and a defined set of decisions to make this year.
AIT joins the transaction taxonomy that runs your payments
The paper's core contribution is introducing agent-initiated transactions, or AIT, alongside the two categories that already govern card payments: customer-initiated transactions (CIT) and merchant-initiated transactions (MIT). Those existing categories carry heavy operational weight, driving authorization rules, liability assignment, dispute handling and network processing logic. Adding a third category is a structural change to how transactions get classified, routed and reconciled across the entire payment stack. It touches systems that most retailers consider settled infrastructure, which means the work of accommodating AIT will reach into fraud engines, ledgers and chargeback workflows rather than staying contained in a checkout module.
Devon Rohrer, Managing Director of the U.S. Payments Forum, stated the premise plainly: 'AI agents are becoming autonomous participants in the payment process, capable of initiating transactions on behalf of shoppers.' If an agent initiating a purchase is a distinct transaction type, then your payment stack eventually needs to recognize, authorize and reconcile it distinctly, with its own risk rules and liability model. The primer also introduces consent and delegated-authority frameworks, which formalize how a shopper hands an agent the right to spend and within what limits. Those frameworks are where the practical engineering work will concentrate, because they define the boundary between an authorized purchase and an abuse of delegated power.
Know Your Agent is the fraud problem you cannot ignore
The primer flags security concerns that existing controls were never built to handle, chief among them prompt injection and a challenge it labels Know Your Agent, or KYA. Prompt injection means an attacker manipulates the instructions an agent follows, potentially steering a purchase, altering quantities or leaking payment context to a third party. This is a fraud vector with no analog in card-present or standard card-not-present commerce, which means your current fraud tooling has a blind spot precisely where autonomous agents will operate. Detection models trained on human behavioral signals will struggle to flag a compromised agent that transacts within normal-looking parameters while acting on manipulated instructions.
Know Your Agent extends the familiar Know Your Customer discipline into a world where the entity at checkout may be software acting for a person. Establishing that an agent is legitimate, authorized and operating within its delegated limits becomes a new authentication layer that sits on top of verifying the underlying shopper. We read KYA as the defining fraud problem of agentic commerce, and the retailers who wait for it to fully materialize before building detection will find themselves reacting to losses after they land. Standing up agent identity, credentialing and behavioral baselines now gives you a foundation to tune before agent volume becomes material and the losses become real.
Guidance keeps your options open
The Forum deliberately offers guidance to merchants, issuers, networks, PSPs and digital wallets while stopping short of prescribing a single standard. That choice reflects how early the market is, and it has direct consequences for how you plan. With no mandated standard in place, multiple approaches will compete for adoption, and the retailers who engage now help shape which conventions win. Early participants also gain the practical benefit of designing their systems around patterns they helped define, which lowers the odds of an expensive retrofit when the market eventually converges on dominant practices.
This is a moment of genuine leverage for retail payment leaders. Standards bodies tend to codify the practices that early adopters prove out in the field, so contributing findings buys real influence over your own future compliance burden. We would treat the primer as an invitation to pilot and to feed results back into the working committees while the frameworks remain malleable. The cost of engagement today is modest against the cost of retrofitting your checkout, fraud and settlement systems to someone else's standard later. Sitting out the formative phase cedes that influence to competitors who will happily shape the rules around their own architectures.
What belongs on your payments roadmap now
The concrete action this primer forces is an audit. Walk your checkout and fraud stack and ask where an agent-initiated transaction would enter, how it would be authorized, and whether anything you run today could verify the agent's authority and its delegated limits. Most retailers will find no clear answer at any of those points, which is precisely the gap to start closing. The consent and delegated-authority frameworks in the paper give you a concrete model to design against before agents arrive in volume, and mapping your systems against that model surfaces the integration work early, while it is still cheap.
We see this publication as the moment agentic commerce crossed from speculation into payments infrastructure planning. A named transaction category and a named fraud discipline are the artifacts of a topic becoming operational and fundable. For CTOs and CIOs in retail, the roadmap implication is direct: assign an owner to AIT readiness, prototype KYA detection against real agent traffic where you can find it, and engage with the emerging frameworks while they are still being shaped. The window to influence the standard is open now, and it will close as the largest players harden their implementations and the conventions calcify around them.



