No single company sees enough of an agent's behavior to judge it alone, which is why the fix is shared infrastructure, not a sharper private model.
4 minutes

Agentic commerce needs a trust layer no one owns

No single company sees enough of an agent's behavior to judge it alone, which is why the fix is shared infrastructure, not a sharper private model.

Harsh Mehta
Harsh Mehta
Head of Partnerships, AI and Agentic Commerce
Harsh Mehta works at the intersection of AI, commerce and strategic partnerships, helping shape the ecosystems behind agentic transactions. His experience spans AI, global tech, fintech, payments, open banking and digital commerce.

Key points

  • An agent's trustworthiness isn't a property of any one storefront. It's a property of how the agent behaves across every merchant it touches, and that evidence is scattered across parties that share nothing today.
  • Rival verification schemes from Visa, Mastercard and Cloudflare each work within their own rails, but none of them carry across rails, leaving merchants to reconcile a growing stack of private allowlists by hand.
  • Worldpay, now Global Payments, scores agent behavior across the merchants it serves rather than a single storefront, and backs open standards work with EMVCo and the Agentic AI Foundation on the premise that a shared trust layer is what makes any single score worth trusting.

The instinct in payments is to treat fraud defense as a moat: the better your models, the bigger your edge. Agentic commerce is the first problem where that instinct fails.

Picture an agent that has placed legitimate orders across 500 merchants. On the 501st, a line buried in a product review tells it to buy something the shopper never asked for, and it complies. The cart looks ordinary. The token is valid. The authorization is clean. Nothing at the point of sale is out of place, and the only thing that would give it away is that this agent just behaved unlike itself – a judgment that requires seeing the other 500 merchants, which no single party does.
That’s the whole problem, in a nutshell. An agent's trustworthiness is not a property of your storefront. It’s a property of how the agent behaves across all of them, and the evidence is scattered across parties that share nothing today.

A signature proves provenance, not intent

Each party in an agent’s payment can verify one thing and no more. The acquirer confirms the token is valid, but never sees the prompt behind the order. The registry confirms the request was signed by a registered key, but not that the agent wasn't manipulated into signing it. The platform sees the model's reasoning, but never the payment. Each holds one link and is blind to the rest.
A signed request tells you an order came from a registered agent. It does not tell you the agent bought what the shopper wanted, and that gap is where disputes live. A mandate authorizing “a running shoe under $120” is satisfied by a $118 shoe – including the wrong shoe, in the wrong size, that the shopper never meant. The cryptography holds and the purchase is still wrong. No amount of verification at the moment of payment closes that gap, because the failure happened upstream, before the transaction existed.

When everyone issues their own passport

The answer taking shape is for each party to mint its own proof. Visa's Trusted Agent Protocol verifies agents at the network edge. Cloudflare's Web Bot Auth does it with signed HTTP requests checked against a public key directory. Visa Intelligent Commerce and Mastercard Agent Pay each issue their own agent tokens on their own rails. Each works, in isolation.
"Trust that stops at a company's boundary is a local allowlist, not a trust signal, and it resets every time the agent crosses a line on the map."
An agent verified under one network's protocol arrives at a merchant who integrated a different one, and the verification doesn't carry. The merchant re-checks it, waves it through or blocks it, and whichever it chooses, the reputation the agent earned everywhere else counts for nothing. Trust that stops at a company's boundary is a local allowlist, not a trust signal, and it resets every time the agent crosses a line on the map. The more frameworks launch, the more allowlists a merchant reconciles by hand, and the more seams an attacker can slip between.

The internet already ran this experiment

We know how this ends, because the open internet settled the same question years ago.
Every time the padlock appears in your browser, you are handing a card number to a stranger's website, and it works the same way on a global bank and a corner-shop storefront. No company built a private trust system for its own site. They all speak one open standard, HTTPS, that belongs to no one, that anyone can implement, and, crucially, that anyone can inspect. Its security comes from being picked apart in public by everyone with a reason to break it, not from a vendor's promise that it is safe. The closed alternative, “trust my method and don't ask how,” is the one no serious system runs on.
Agent trust needs the same architecture. How an agent proves who it is, how a shopper's mandate is recorded and checked, how a compromised agent is revoked so every party honors it – that layer has to be shared or it does nothing. Google's AP2 and Mastercard's Verifiable Intent sketch what a verifiable mandate could be. Whether it becomes one common record or a dozen private ones is the decision being made now.

Open isn't the same as unowned

Fraud defense is supposed to stay secret, so publishing any of it sounds like handing attackers a map. That applies to tactics, not to the substrate underneath them. Your scoring, thresholds and models stay yours, the same way a bank's fraud logic stays private while it still speaks the same TLS as everyone else. What has to be shared is the layer that lets an agent be identified and its intent verified, because a verification only one party recognizes protects only that party.
"The winner will not be whoever built the tallest wall around agent identity. It will be whoever turns the shared layer into results a merchant can see on a dashboard."
The winner will not be whoever built the tallest wall around agent identity. It will be whoever turns the shared layer into results a merchant can see on a dashboard – more approvals, fewer false declines on real agents, stronger evidence when a mandate is challenged. Certificate authorities compete hard on price and service. The moat moves from owning trust to delivering it.

What we're backing

This is where we spend our efforts. We contribute to EMVCo's Agentic Payments Task Force, to identity and intent work with the networks and platforms, and to the Agentic AI Foundation, on one position throughout: The layer holds only if it is open. Our own agent detection scores behavior across the merchants we serve rather than a single storefront, because that is the only vantage point where an agent's actual pattern shows. Identity, intent, revocation – we gain nothing by hoarding them. That is a strange thing for a payments company to say about fraud, and agentic commerce is what makes it right.

A closed stack can lead, but not hold

Someone will build the closed version regardless – a large network or platform assembling an end-to-end agent-trust stack on its own rails. Done well, it can lead for a while. But an agent's trust is only worth something if it travels with the agent, and a stack that works on one set of rails is worth less the instant the agent shops off them. A closed trust layer privatizes the one thing whose value depends on being shared. Claiming it shrinks it.
The standards are still soft enough to shape. That’s the only reason this is a choice. Contribute to the open layer now, or rebuild it in the open later, after the closed one has failed at the seams where it meets everyone else.

Agentic trust layer FAQ