The moment of payment authorization, the person is no longer present.
Written by: Will Awang
On August 27, the 15th China Payment and Clearing Forum took place. Lu Lei, a member of the Party Committee and Deputy Governor of the People's Bank of China, talked about the hottest topic at the moment: intelligent agent payment.
The president’s three statements almost encompassed all the battles that the intelligent agent payment industry will fight in the next two years.
The first statement concerns the essence of payment. The essence of payment is the transfer of fund ownership, which objectively requires that the results of transactions are predictable, responsibilities can be defined, and trails can be traced; however, large models and autonomous agents have characteristics such as random output and insufficient logical transparency, if blindly or excessively granting autonomous agents decision-making powers in transactions, it will affect the trust foundation of fund transactions.
The second statement concerns business rules. The current governance rules and dispute resolution mechanisms of the payment industry are built around "people as the final decision-makers in transactions"; the new model of transactions initiated and assisted by agents can easily blur the boundary of responsibility among consumers, operating institutions, and algorithm systems.
The third statement concerns multi-party competition. The essence of the dispute over agreements is the struggle for business rules and technical standards, as well as the struggle for dominance in the era of artificial intelligence.
When reading these three statements together, one finds they talk about the same thing.
The payment business has been operating for sixty years, and what it has always sold is certainty. You can walk out of the store with your items immediately after checking out because there is a guarantee behind it: you can enter your card number on a website you've never heard of because if something goes wrong, someone has your back. The entire system—authorization, clearing, chargeback, responsibility transfer—each link is predicated on:
The person making the decision is present, and they are responsible for their decision.
And now, the entity initiating the transaction is uncertain in itself. It can misunderstand, be influenced, or buy the wrong item within budget, yet every step it takes is impeccable at the level of cryptography. When the final decision-maker of the transaction is no longer a human, how can this system, built on certainty, still operate?
Under this premise, internet giants, AI titans, card organizations, and payment companies have provided their answers in every dimension, and the answers differ from one another. Some are modifying the existing framework, some are building new tracks, and some are buying time.
This research report is based on our ongoing tracking of this field over recent years and some practical experiences, hoping to clarify the not-so-simple logic behind the simple phrase "Agentic Payment Intelligent Agent.”
1. The Unchanged Premise After Fifty Years

1.1 Six Generations of Authorization, All Means Changed
The payment industry has upgraded its authorization technology over fifty years through six generations, yet has never changed one premise: At the moment of authorization, the person is present.
From signature imprinting to magnetic stripes with real-time authorization networks, to EMV chip encryption, to NFC, and now to Tokenization, up to today's Agentic Token—the six generations have only traded in validation means, always verifying the same thing: Is the person at the transaction site the cardholder? Signature, PIN, fingerprint, Face ID—each means becomes more sophisticated, yet the premise remains unchanged.
Similarly, the framework of disputes among card organizations over decades is established on a binary question—either the cardholder has authorized, or they have not.
However, Agent has dismantled the three pillars of this premise at once:
- Authorization and transaction are temporally separated; a statement made three days ago may be executed by the agent at two o'clock in the morning;
- Intent expressed in natural language, whereas "help me book a cheaper flight" cannot fit into any risk control engine's parameters;
- Finally, the one initiating the transaction, for the first time, is not the cardholder themselves.
In the world of Agent, a third scenario can emerge: the card has not been stolen, the merchant has made no mistake, the Agent has done what it was asked to do, yet the consumer still says "I don't want this."
1.2 Three "Capabilities," Correspondingly Listed
Returning to the three terms of Governor Lu, if we align them with the traditional payment methods, the points of failure become clear.
- Predictability relies on a person pressing the confirmation button. That button fixes a vague intention into a transaction with a certain amount and a specific target. However, Agent lacks this button.
- Definability depended on merchant of record and card organization rules in the past. Who the seller in the contract is, is who to turn to when issues arise; this set of rules has been in place for decades and is based on the premise that the roles in the transaction chain are fixed, limited, and recognized by the rules. When it comes to the Agent link, there is no part in the entire chain that has been recognized by existing rules.
- Traceability relied on account systems and transaction flows. In this respect, Agent performs even better—the signature chain is complete, the audit trail is intact, and every step can be nailed down to the level of cryptography.
Among the three, the only thing AI big models can offer is the last one, and that one is precisely the least difficult.
1.3 Four Questions Raised by a Plane Ticket
On Wednesday morning at seven, you wake up in Hong Kong, and there’s a deduction notification on your phone: HKD 2600, Cathay Pacific, Hong Kong to Singapore, Thursday.
But you wanted Wednesday. Last night before sleep, you had the agent book an economy class ticket for Wednesday, with a budget under 3000; after falling asleep, flights direct to Wednesday soared to 3800, and the agent only found a ticket for Thursday morning at 2600 by three in the morning—within budget, correct destination, but the date is off by a day. You booked this ticket to catch a meeting at nine in the morning in Singapore on Thursday—by the time the Thursday morning flight lands, the meeting will have already ended.
Did you authorize this transaction? By the letter of authorization, yes; by your actual intention, no. Both answers are correct, and therein lies the trouble.
If you want to recover this 2600 dollars, should you find the agent’s developer, contact Cathay Pacific, or seek assistance from the issuing bank? This investigation breaks down into the four legal questions that cannot be avoided in delegated payments:
- Was the authorization valid?
- Where is the boundary?
- If breached, who is responsible?
- Ultimately, who bears the loss?
The framework of agency law for the past two thousand years is precisely these four questions. And it naturally divides into two halves: the first two are in the territory of "verification," which can be answered by cryptography; the latter two are in the territory of "deciding," which can only be answered by rules. Today, nearly all players are stuck on the first two questions.

These four questions are precisely the expansion of Lu Lei’s second statement.
The reason current governance rules are "built around people as the final decision-makers in transactions" is specifically about the answers to these four questions pertaining to individuals: people authorize themselves, the boundaries are defined by them, unauthorized actions can only be attributed to impersonation, and losses have a ready method for allocation.
The four answers share the same premise. Once the premise disappears, all four answers are rendered void.
None of the four questions has an answer today. But the industry is not waiting.
2. Ecological Map of Agentic Commerce
In the past year, domestic and foreign bank card organizations, payment institutions, and technology companies have intensively released more than a dozen protocols related to agent payment; giants are acquiring companies, building new tracks, and vying for standards. The rules are not yet finished, and the industry has already populated the positions.
At the same forum, Han Xinyi, CEO of Ant Group and chairman of Alipay, provided four exploratory paths for global AI payment: The first category is represented by Stripe, which focuses on payment technology and infrastructure platforms; the second category, represented by cryptocurrency companies like Circle and Coinbase, relies on stablecoins and their wallet systems to support automated payment scenarios between machines; the third category is traditional payment networks represented by Visa and Mastercard; the fourth category consists of AI platform companies like Google and OpenAI.
This list is very informative; when viewed together, it shows four types of entities but can be broken down into five links.
By cutting by entity, we can see who is present, but we cannot determine their positions. To understand the latter, we must change the axis—cutting according to the value capture chain of an intelligent transaction.
2.1 Five Links in the Value Capture Chain
An intelligent transaction goes through five links from intent generation to fund settlement. Each link holds different assets, has varying methods of collecting payment, and the level of value attribution is also entirely different.

There are three points in this chart that require expansion.
First, the low-value box is precisely the one that is fully open-source. MCP, A2A, AP2, UCP, and x402 have all been donated to foundations, and their positions are marked as low value attribution on nearly all public maps. This is not a coincidence. Protocols being donated are precisely to prevent anyone from collecting rent at that layer; open-source here is a means of value non-attribution, not a cause.
Second, card organizations occupy two boxes simultaneously. They charge for rules in box three and own their own clearing network in box five. The only entity that spans both links is them, and these two links happen to be the most difficult to replace.
Thirdly, and most importantly, two of the five links cannot bear responsibility.
The ingress layer holds the most expensive assets but is not in the cash flow; the protocol layer has no legal subject, cannot be served, cannot be sued, and cannot compensate. Boxes three, four, and five can. The executive power of the trust layer does not come from the court but from "I can refuse this transaction"; the PSP in the orchestration layer is itself a licensed acquirer, and it has to cover the merchant's chargebacks; the settlement layer relies on balance sheets and reserves.
This results in a dislocation: among the three links with the highest value attribution, two can manage responsibility, while the third—the ingress—is the only one that handles the highest value but bears no responsibility.
2.2 Humans Let AI Choose, but Dare Not Let AI Pay
The positions are filled, yet the temperature on the demand side is distinctly divided into two halves.
The first half has already flipped over.
Data from Adobe based on over a trillion visits to US retail sites show that by May 2026, the conversion rate of retail visitors from AI is 54% higher than that of non-AI channels, while a year prior, this group's conversion rate was less than half that of non-AI. In March 2025, it was still lagging by 38%, and by March 2026, it had improved by 42%—in 12 months, it shifted by 80 percentage points.
Shopify's platform data explains the reason: more than half of AI-recommended sessions land directly on product detail pages, whereas natural search only accounts for about 20%; the conversion rate for AI-referred visitors is nearly 50% higher than for natural search, and the average order value is 14% higher.
It's not that more people are coming, but that different people are arriving. They know exactly what they want, heading straight for specific products, often purchasing long-tail items that wouldn't rank high on search engines. The inversion of conversion rates isn't due to consumers becoming bolder but is based on the fact that those coming are people who are already ready to buy.
The latter half, however, has barely moved at all.
Research released by Checkout.com in June of this year indicates that today, only 3% of transactions involve AI agents. More illustrative of the issue than this figure is the nature of “daring”—24% of consumers say they would never delegate purchases to AI, while 27% do not trust any organization to operate AI shopping agents. This reflects not hesitation but outright rejection.
Why the reluctance? A situation in the crypto world from February clarifies it best. An AI agent named Lobstar Wilde saw a help request on a social platform, assessed it on its own, and autonomously transferred out $450,000. The post was fabricated, and the user had only intended to send 4 SOL.
The budget cap contained the scale of loss but could not contain deviations from intent within the budget.
People have passed the "trust AI's recommendations" barrier but have not passed the barrier of "daring to let it pay for me."
2.3 Yet This Channel Itself Has Not Fully Developed
Beyond the temperature lies the basis, and this industry currently lacks even a unified standard.
Contentsquare's benchmarks based on nearly 100 billion conversations show that AI-driven traffic only accounts for 0.2% of all conversations.
This is data from Q4 2025, with the report published in January 2026—taking it to compare with Adobe's May findings has a two-quarter gap, yet this curve has grown sixfold in a year. In the same benchmark, the absolute conversion rate of AI-driven traffic is at 1.3%, still lower than the email channel’s 1.9%; and Adobe reported relative premiums, making the two non-comparable.
The growth rate aspect provides even more insights. On May 11, Shopify stated on its corporate blog that AI-recommended orders grew nearly thirteen times year-on-year in Q1; in a conference call on August 5, it stated that AI-driven traffic and orders had each grown threefold year-on-year.
These two figures cannot be subtracted. The former only measures referred orders, while the latter combines traffic and orders, forming a broader bucket; and the threefold figure does not exist in Q2's press release and in the 10-Q form.
This "inability to subtract" is itself indicative of the problem. The same company, on the same topic, gave two numbers twelve weeks apart that don't even match overall—this is already one of the most transparent figures in the industry.
A similar pitfall exists on the responsibility side as well: the often-cited controversy growth forecast covers all chargebacks online, with not a single transaction attributed to an Agent.
2.4 And the Merchant Side Is Not Connected
Moving down the chain one link, we arrive at the merchants expected to catch all of this.
Ballerine, a compliance risk management company, offers a straightforward judgment: 73% of merchants are not yet ready for agents, and most payment service providers have not adopted these protocols, while no party in the payment chain has reached consensus on responsibility attribution. The numbers from Checkout.com seem conflicting but are actually asking a different question: 89% of merchants say they are actively preparing.
Both 73% unprepared and 89% in preparation can coexist—one questions systemic readiness, the other asks if there’s active engagement.
Everyone is working, and after one year, only that 3% is still connected.
2.5 While On the Machine A2A Side, There Are Already Hundreds of Millions of Transactions
Shifting the focus from people to machines presents an entirely different picture.
The original data from x402 shows a cumulative transaction flow of $135.7 million and 178.3 million transactions. After filtering out fraudulent and test transactions, there still remains $15 million in adjusted flow, 109.6 million valid transactions, and about 5,300 valid merchants. The real market is an order of magnitude smaller than the on-chain surface data, yet even after this level of cleansing, the number of transactions is still in the hundreds of millions.
None of these transactions involved hesitating consumers, no merchants needed to transform their cash registers, and no one was waiting for anyone to authorize.
What are they actually purchasing? Based on the current categories on-chain, it is roughly five types:
- By commercially callable payment interfaces: search, maps, weather, corporate registration queries—any measurement endpoint, the agent can discover and utilize on-the-fly without needing to pre-apply for keys;
- Data and market information: financial reports, on-chain data, regulatory information, social signals; billed by query or data volume;
- Reasoning and computing power: billed by model invocation, GPU, and sandbox environment rental as requested, exiting upon task completion;
- Content and assets: images, music, fonts, papers, datasets, used on-demand rather than pre-purchased amounts;
- Agent-to-agent procurement: one agent outsources sub-tasks to another agent, buying its output and settling in USDC.
Counted by transaction numbers, this is the current largest category.
These five categories share a common feature: delivery is consumption, with no room for reversal. There is nothing to return, no disputes arise, and no instance requires a person to later say, "I don’t want this."
But hundreds of millions of transactions do not equal a mature market. Disassembling the structure reveals a very young shape: the top 1% of buyers contribute about 90% of the flow, while only 0.02% of buyers account for about 48%—far from being a mass market, it better resembles an automated backend running for a few dozen institutions; the chain distribution is similarly concentrated, with one chain (Base) carrying about 90% of effective transactions, while the supply side has yet to develop.
The shape of the curve is even more worthy of contemplation. Transaction volumes peaked in November 2025 at about 38 million per month; by March 2026, it dropped to around 2.1 million transactions, yet the flow was still at $1.64 million with the average transaction price reaching a new high since it went live.
Transaction counts declined by 77%, yet prices increased. This curve is not dead; it is merely transitioning in categories.
The industry has filled positions, consumers trust recommendations but refuse to let payment rights go, and merchants are preparing but still not connected—on the human side of this chain, all three parties are hesitant to move first; whereas on the machines’ side, hundreds of millions of transactions have already been completed.
Agentic payment, the same term, cannot encompass both these matters.
3. Two Denominators Under One Term
The reason the two scenes described in the previous chapter do not align is that they are fundamentally measuring different things.
The term Agentic Commerce conceals a fundamental split—it actually refers to two completely different transactions sharing a single name.
- AI Agent Shopping: Humans delegate the agent to purchase items, "help me buy a pair of size 42 running shoes”; the agent searches, compares prices, checks out, but the purchasing decision is made by humans, using human money.
- AI Autonomous Transactions: Machines autonomously purchase digital services to complete their tasks, invoking an LLM API, paying $0.003, obtaining results, and continuing work without any human clicking a "confirm purchase" button.
The former represents a substitution relationship, capturing shares from existing human shopping behaviors; the latter signifies a generation relationship, creating transaction volume out of thin air.
The ceiling for the two is determined by entirely different factors, and almost all forecasts circulating in the market are about the first half.

(Everyone is talking about Agentic Commerce, but no one clarifies that it actually refers to two different matters: two paths, three layers of structure)
3.1 AI Agent Shopping: The Ceiling Is the Money People Were Already Going to Spend
First, let’s look at the half that has been measured the most.
According to estimates from Morgan Stanley, by 2030, the figure ranges from $190 billion to $385 billion, with the clear basis stating: 10% to 20% of US e-commerce. eMarketer estimates that AI platform retail e-commerce in the US this year will be approximately $20.6 billion. McKinsey predicts that by 2030, global agentic commerce will range between $3 trillion and $5 trillion.
The gap between two hundred billion and five trillion is more than two hundred times. This disparity, rather than reflecting differences in growth rates, speaks more to differences in "what exactly are we counting"—some only count checkouts completed within the AI interface, others count all orders influenced by AI, and still others include machine-to-machine calls as well.
However, regardless of deviations in definitions, there is a common ceiling for substituting this half: its denominator is the money humans would have spent anyway.
Michael Miebach, CEO of Mastercard, illustrates this concept with a scenario. You decide to go camping and ask AI what to bring; it generates a list of fifteen items and, knowing you already have a tent, does not recommend buying one. Once you have the list, you still have to check each website one by one, spending a considerable amount of time; if you could directly check out at that moment, everything would be smoother.
Then he added a judgment: essentially, people will not buy five extra tents just because there’s an agent—it’s more a replacement of existing traffic.
What agents change is how that money is spent, on what, and who profits from it, not how much is spent.
This is a dispute over channels, entry points, and attribution—essentially about resource migration; and on the other side of resource migration, every stakeholder in each link has reason to delay—merchants are hesitant to relinquish checkout, platforms are unwilling to give up entry points, and card organizations stand to lose nothing on this path.
3.2 AI Autonomous Transactions: The Other Half That Has Not Appeared in Forecasts
The other half has not appeared in any forecasts.
Joe wakes up in the morning and receives a message from his personal agent. Last night, it closed out his position in Walmart—satellite images show a decline in foot traffic in front of the store, compounded by bearish sentiment in the prediction market; it sent calendar invites to three potential clients' agents, each with a background briefing attached; it also scanned prices from six cloud service providers and found a comparable option with features low by 65% in annual fees.
Total expenditure: $0.67.
This $0.67 was not saved but created. Previously, these transactions did not exist, not because there was no demand, but because the human decision-making cost exceeded the transaction value—no one would spend a cent to check if it was worth selling a position based on satellite parking data. Simply deciding "is it worth checking" is itself worth several cents.
Such micro-payments have never been feasible in the human economy; mathematically, it just does not hold. Change the payee, and the equation flips.
When this equation flips, the consumption pattern of the Agent diverges significantly from that of humans. AMP PBC analyzed one hundred trillion tokens flowing through OpenRouter and concluded, contrary to most imaginations, that the median request was not a human asking a large model a question, but a machine running in a loop. An agent can run overnight, repeating the same type of invocation thousands of times autonomously.
This has become not just a single purchasing behavior but a continuous flow of consumption.
Another remarkable figure emerges at this division. The on-chain AI agents have cumulatively completed approximately 176 million transactions in the past year, with an average per-transaction amount of only $0.31 to $0.48, of which about 76% is below Visa’s fee threshold of $0.30.
Card networks are not insufficient here; it’s that humans inherently do not conduct these transactions.

(Agentic Economy: Why the agent economy thrives on-chain)
So what is the denominator of this generative half?
Circle CEO Jeremy Allaire provided a coordinate: companies are essentially "organized cognition with logos attached," where labor costs account for one-fourth to one-half of revenue, nearly the whole in knowledge-based firms. When each function is refined into well-defined skills, skills clean enough to be orchestrated internally in companies become clean enough to be discovered and hired externally; an open agent labor market does not need to be created by anyone—it overflows from self-optimizing efforts of thousands of companies.
The denominator for substituting that half is human shopping expenditure; for generating that half, the denominator is labor costs.
What generative measures fundamentally assess are not purchases, but token settlements and the hiring of machine labor. The two denominators being different is the strongest evidence of "two types of transactions."
3.3 The Two Pictures Have Aligned
Now looking back at the misalignment in the previous chapter.
Whether it's 3% or 73%, both measure substitution—and substitution precisely requires complete consumer protection: returns, chargebacks, dispute handling, KYC, and nothing can be missed; it also requires every entrenched interest to agree to relinquish a bit of their position.
{@...}
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。