AI agents are beginning to shop, compare prices, and even initiate payments on behalf of millions of consumers — and the financial system is scrambling to decide how those payments should work, who approves them, and who is liable when an autonomous assistant gets it wrong.

On Oct. 1, Nike released the Caitlin 1, Caitlin Clark’s first signature shoe, in a royal blue colorway called “Caitlin Blue.” I am always on the hunt for cool royal blue kicks, so I wanted a pair. So did a lot of other people. According to Yahoo Sports , the shoe nearly sold out within the first two hours.

Normally, chasing a hyped release means refreshing Nike’s app, opening a dozen browser tabs, and losing to someone faster. This time I handed the job to an AI agent.

It went to Nike first and reported back that the blue Caitlin 1 was sold out at $140. It told me resale sites like StockX, GOAT, and eBay probably had pairs, though likely well above retail, and asked whether I wanted to pay up or keep hunting at retail. It also flagged something I hadn’t thought about. The shoe comes in unisex sizing, so it asked whether my 10.5 was men’s or women’s.

I said retail, men’s. A few minutes later, it found a pair at Dick’s Sporting Goods for $139.99, men’s 10.5, free shipping, estimated delivery that Saturday. The cart showed “Only 1 left!” and a banner saying 2,731 shoppers had bought the shoe that day. The agent put the pair in my cart.

“You aren’t signed in to Dick’s, and I can’t sign in or enter card details for you,” it told me. It walked me through the last three steps, warned me that a pair sitting in a cart is not a pair on hold, and said that even if I were signed in with a saved card, it would still show me the total and wait for my yes before placing the order.

I signed in, checked out, and the last pair of men’s 10.5s was mine.

Welcome to the world of agentic commerce.

Agentic commerce is software that finds, decides, and pays on your behalf, inside limits you set. A chatbot can recommend a pair of shoes. An agent can go get them. The difference is the moment money moves, and as my Caitlin 1 hunt showed, that moment is exactly where today’s agents still hand control back to the human.

The money at stake is enormous. McKinsey projects that up to $1 trillion in US retail revenue could flow through AI agents by 2030. Adoption today is early. A Checkout.com survey in June found agents involved in roughly 3% of transactions, and Forrester found that only 24% of U.S. online adults trust AI to handle routine purchases, according to reporting on both studies . The technology is moving faster than consumer comfort, and how that gap closes will shape how all of us shop.

Why Agents Still Stop At Checkout

My agent did everything a fast, patient human would do. It searched, compared, checked sizing, and filled a cart. It stopped at the one step the internet was never built for, a machine paying a store that has never met it, on behalf of a person the store can’t see.

The walled-garden version of this already works. Amazon folded its Rufus assistant into Alexa for shopping in May, and because Amazon already has your card, your address, and the inventory, its assistant can watch a price, buy when it drops, and check out with your saved payment method. The open web is harder. A new set of plumbing is being built to close that gap, and it works in three steps.

First, the agent writes down what you asked for. Google’s Agent Payments Protocol turns an instruction like “blue Caitlin 1, men’s 10.5, retail price only” into a digitally signed “mandate,” essentially a permission slip with your name on it. When the agent picks a specific pair, it creates a second signed record of the exact shoe, price, and store. If an agent ever buys something outside your instructions, those two records show exactly where it went off course.

Second, it shops. Retailers are starting to plug into shared standards, like the Agentic Commerce Protocol from Stripe and OpenAI and Google’s Universal Commerce Protocol that let an agent check sizes, stock, and delivery dates directly with a store’s systems, skipping the website built for human eyes. Retailers that plug in show up in the agent’s results. Retailers that wait risk becoming invisible to a growing share of shoppers.

Third, it pays, which is the step my agent couldn’t take. Visa and Mastercard now issue what they call agentic tokens, stand-in card numbers tied to a single agent with their own spending limits. Think of a valet key. It drives the car, and the trunk stays locked. If the agent misbehaves or gets hacked, you cancel that one token and your real card keeps working. The card networks also send the store a signal confirming that this is a registered agent acting for a real customer. On a release day like October 1, that signal is what lets a retailer tell my agent apart from the sneaker bots that have been scooping up limited drops for years.

The road has bumps. OpenAI launched Instant Checkout inside ChatGPT in September 2025 and scaled it back in March , now sending shoppers to retailer apps to finish the purchase. A checkout button turns out to be the easy part. Fraud controls, returns, and customer service at scale are the hard part.

My Caitlin 1s ran on a card. The more surprising activity happens one layer down, where agents pay other machines for the things they need to do their jobs, like a price feed, an inventory check, or a few seconds of computing power. Those payments can be a fraction of a cent, and card fees alone are larger than the purchase.

That is where stablecoins come in. They are digital dollars, backed by cash and short-term Treasuries, that move on a blockchain in seconds, around the clock, for almost nothing. The stablecoin market stood at about $307 billion at the end of September, according to market data .

Circle, which issues USDC, the second-largest stablecoin at roughly $75 billion, is building directly for this machine economy. In May it released a developer framework for Nanopayments , which lets agents send USDC payments as small as a millionth of a dollar. Circle verifies each payment in under a second and then bundles thousands of them into a single blockchain transaction, so the cost of each one approaches zero.

Many of these payments use x402 , an open standard originally built by Coinbase. It revives an old web code, HTTP 402, which literally means “Payment Required.” An agent asks for something, the server names a price, the agent pays in USDC, and the server delivers, all in seconds. In July, the Linux Foundation launched the x402 Foundation with Circle, Visa, Mastercard, American Express, Stripe, Google, and Amazon Web Services among its members. In a recent 30-day stretch, x402 handled about 75 million payments averaging roughly 32 cents.

The likely split is simple. People will keep buying sneakers with cards. Machines paying machines will increasingly use stablecoins.

I spent years as a federal prosecutor, and every new payment rail I have seen attracts criminals early. This one will too.

Start with security. Agents read everything, including text a person would skim right past. A scammer can hide instructions in a product listing or on a webpage telling the agent to buy from a fake store or send money somewhere new. Security researchers call this prompt injection, and it turns your own assistant into the inside man. Hyped releases are the perfect bait. Imagine an agent, told to find a sold-out Caitlin 1 at any price, landing on a slick knockoff site offering a “last pair” at $95, with hidden text nudging it to pay. The shoes stay imaginary, and the credentials the agent used end up in criminal hands.

Then there is illicit finance. Fraudsters will build storefronts designed to fool agents, the same way phishing sites are designed to fool people. Criminal networks could run thousands of agents making small payments to services they control, which looks a lot like ordinary machine commerce and a lot like money laundering. And if an agent pays a sanctioned party, even a few cents for a data request, that payment is still a sanctions violation, and someone owns the exposure.

Stablecoins bring a real advantage here. Every payment sits on a public ledger, which means it can be traced. Under the GENIUS Act , signed in July 2025, US stablecoin issuers carry anti-money laundering obligations and must be able to freeze tokens when the law requires it. Blockchain intelligence can screen a wallet in real time, before an agent sends a single dollar, and flag links to scams, hacks, or sanctioned actors. Banking has run on “know your customer” for decades. Agentic commerce will need “know your agent.”

Then there is consumer protection. Our rules for disputing a charge hinge on whether a payment was “unauthorized.” If I give my agent my credentials, a bank may argue that everything it buys is authorized, including the wrong size or a $400 resale pair it decided was “close enough” to retail. Stablecoin payments raise the stakes, because they settle in seconds and generally stay settled. Those signed mandates may end up being a consumer’s best evidence. A permission slip that says “retail price only” is proof that a $400 purchase broke the rules.

That leads to the biggest open question. Who is responsible when an agent gets it wrong? I gave the instruction. An AI company built the model that interpreted it. A card network or wallet provider issued the credentials. A merchant accepted the order. Courts are just starting to sort this out. In August, the Ninth Circuit ruled in Amazon’s fight with Perplexity that an agent acting on a user’s instructions is effectively the user. That logic cuts both ways. If my agent is me when it logs into a website, it may also be me when it buys the wrong shoes.

We already delegate money decisions through autopay, recurring transfers, and corporate cards for assistants. Agentic commerce extends that habit to software that can reason about what we want.

My Caitlin 1 hunt showed both halves of where we are. The agent was faster and more thorough than I would have been, and it knew exactly where to stop. Getting to the next stage means spending limits that hold, permissions you can revoke instantly, clear records of what you approved, and real-time screening that keeps agent payments away from fraudsters and sanctioned actors. It also means policymakers updating dispute rules for agent-initiated payments, working with industry on standards for verifying agents, and giving law enforcement the tools to follow illicit funds through agent networks at machine speed.

The robots are already shopping. For now, they still hand us the pen at checkout. Our job is to build a system where, when they stop asking, it can still tell the difference between my agent and a criminal’s.