Agentic commerce has a press-release problem. Every participant has a reason to announce early and describe a pilot as a launch, and the coverage mostly repeats the framing it was handed. So this piece does one thing. It takes every significant announcement from the last 18 months, puts a date and a source on it, and gives it one of four labels. Live means real transactions or a shipped product that people use. Pilot means controlled or "first" transactions. Spec means a published protocol with no confirmed live use I could find. Withdrawn means it shipped and was pulled.
No ranking, no scores. The labels are the analysis. The card networks and the platforms appear in the record as what they announced, in their own words. Where I have a view, it is in the sections at the end, and it is about the merchants and the shopper, because that is where the record turns.
After 18 months it is proven that an agent can pay. It is not proven that a consumer wants to let it, that a merchant will let it in, or that anyone knows what happens when it gets the order wrong. The announcements outran all three.
Spring 2025: the networks name it
The chronology starts in the last two days of April 2025. On April 29, Mastercard unveiled Agent Pay and Agentic Tokens, extending the tokenization used for contactless and card-on-file payments to purchases made by agents. Label: spec at announcement. On April 30, Visa announced Visa Intelligent Commerce, naming Anthropic, IBM, Microsoft, Mistral AI, OpenAI, Perplexity, Samsung and Stripe as partners. Label: spec at announcement.
Both are recorded here as dated facts. What they established was the vocabulary: a token bound to an agent, a merchant scope, and a consent. Everything that followed either adopted that shape or argued with it.
Autumn 2025: the platforms build the rails
Four announcements in six weeks defined the protocol layer.
On September 16, Google published the Agent Payments Protocol, AP2, with more than 60 organizations. Its unit is the mandate: a cryptographically signed record of what the user asked for. Label: spec. Version 0.2 arrived in April 2026 and standardization moved into the FIDO Alliance.
On September 29, OpenAI launched Instant Checkout in ChatGPT, with Etsy live and a million Shopify merchants to follow, on an Agentic Commerce Protocol co-developed with Stripe. Stripe's shared payment tokens were "scoped to specific merchants and cart totals." Label at launch: live. The label did not hold, and that is the next section.
On October 14, Visa released its Trusted Agent Protocol, co-developed with Cloudflare, so a merchant can verify an agent's identity cryptographically. Label: spec. On October 28, PayPal announced its wallet inside ChatGPT. Label: announced.
Then the first transactions, and here the labels matter most. Mastercard's chief executive told investors on October 30, 2025 that "our first agentic transaction took place on our network this quarter." Visa reported "hundreds" of controlled agent-initiated transactions in December. Label for both: pilot. Real money, real rails, and counts in the hundreds.
Spring 2026: the first withdrawal
On March 24, 2026, OpenAI discontinued the initial version of Instant Checkout. Its own words: it "did not offer the level of flexibility that we aspire to provide." ChatGPT would focus on product discovery and hand the shopper to a checkout the merchant runs. Label: withdrawn. The protocol specification stayed published; the product that made it live did not.
Two months earlier, in January, Google had launched the Universal Commerce Protocol with Shopify, Etsy, Wayfair, Target and Walmart, and UCP made a different choice from the start: the retailer stays merchant of record and the agent stays outside the checkout. Label: spec, then live as handlers shipped through the year.
The two decisions describe the same finding from opposite directions. Simon Taylor put the finding in one line in Fintech Brainfood in May: "The merchant does," meaning owns the checkout. His evidence was Walmart's own test, which kept checkout on Walmart.com behind its assistant and converted at roughly 70 percent of direct rates, against Instant Checkout's roughly one third of click-out. "AI by the merchant can work. AI by the aggregator doesn't yet." I think that is the single most important sentence of the 18 months, and every protocol launched since has behaved as if it agrees.
The pilots continued in the meantime. In January, Mastercard reported Australia's first authenticated agentic transactions. In March, Santander and Mastercard reported what they called Europe's first live end-to-end payment executed by an AI agent. Label: pilot, each one.
Summer 2026: from "can it pay" to "who governs it"
By the middle of 2026 the announcements changed subject. Nobody was still asking whether an agent could complete a payment. The questions were who is responsible, who checks the agent's identity, and how many protocols a merchant has to support.
In April, American Express released a developer kit with Agent Purchase Protection, covering "charges related to AI agent error" for registered agents. Label: live for registered agents. Visa launched Intelligent Commerce Connect, supporting four protocols at once, and a tokenized-credential arrangement with OpenAI with user-set spending limits. Mastercard launched Agent Pay for Machines in June. Adyen shipped a stack supporting UCP, AP2 and ACP together. In July, Visa said more than 30 European issuers had enabled agents to buy at merchants including lastminute.com and Frasers. Label: live, at the issuer end, with volumes not disclosed.
On July 14 the x402 Foundation launched under the Linux Foundation with 40 named members and a steering committee of Coinbase, Cloudflare and Stripe, which gave the HTTP 402 approach to machine payments a governing body. On September 9 Mastercard announced Agent Connect, one integration point for agents, merchants and payment providers, and the same day Ant International, Mastercard and Visa announced a Know-Your-Agent interoperability framework. Label: announced.
The pattern across the summer: every layer of the stack repositioned around the agent, and every protocol converged on two objects, a signed mandate and a verifiable identity. None of them settled liability. That is still true in September.
September 2026: the merchants answer
The record's most instructive month is the most recent one, because for the first time the merchants spoke back.
On September 8, Meta launched Muse, a personal agent that shops and pays through Link by Stripe, and it went to the top of Apple's free app chart. The same day, Shopify added Meta to its Agentic Storefronts program with merchant catalogs shared by default. Twelve days later, Amazon cut Muse off, telling shoppers that "continued access by an unauthorized AI agent violates Amazon's Conditions of Use," and telling the press that purchasing agents "should operate openly and respect service provider decisions about whether or not to participate." Two of the largest retail platforms in the world, opposite answers, 12 days apart.
My own scan of 92 of the NRF Top 100 storefronts the week of the block found the rest of the industry closer to Amazon than to Shopify, and quieter than either: a third would not show a self-identified agent their robots.txt, only 16 of 63 readable files named any AI agent, and only 50 of 92 served a non-browser agent a readable homepage. Three publish a UCP profile. The door policy exists; it is mostly unwritten.
The same month, OpenAI put a paid door inside the ChatGPT conversation with Sponsored Agents, and Google gave merchants a share-of-voice measure for AI answers. A federal appeals court decided that when an agent logs in for you, legally you did it. AIUC raised $40 million to insure the companies that deploy agents, with exclusions that leave the counterparty the agent damaged outside the policy. And Amazon folded Rufus, which it says assisted more than 300 million customers in 2025, into Alexa for Shopping, where its newest feature is telling customers whether a text message is a scam.
Read together: discovery is now a paid, measured channel; the agent is legally the user; the merchant cannot see the user; the insurer covers the deployer and not the victim; and the largest marketplace has decided that an agent it did not authorize is a terms-of-service violation. That is the state of the art.
The last week of September: the button moves, the merchant's way
On September 28, eight days after the block, Shopify extended WebMCP to checkout. An agent running in the buyer's browser on a Shopify storefront can now inspect the checkout, change details such as the delivery address, and submit the order once the buyer has authorized it, with Shop Pay included, through three named tools: getcheckout, updatecheckout and complete_checkout. It is rolling out to all eligible merchants. Label: live.
It is the first time in this record that a platform has moved the buy button, and the way it moved it is the finding. The agent works inside the merchant's own checkout. The payment runs through the platform's own wallet. The final authorization stays with the buyer. Shopify's product manager for agentic commerce, Gil Greenberg, said that "shopping with an agent shouldn't feel like watching paint dry," and the tools were "purposely designed" to give agents accurate commerce facts. Shopify decides which merchants are eligible, the buyer decides whether the order goes, and the agent does the typing. That is Simon Taylor's sentence, built as a product.
The tally

Counting the record above, entry by entry, on the label each one carries today.
Live: Amex's purchase protection for registered agents, Visa's European issuer enablement, Adyen's multi-protocol stack, UCP handlers such as Worldline's, Shopify's Agentic Storefronts, Muse itself, Sponsored Agents in test, the x402 Foundation as an operating body, and Shopify's WebMCP checkout. Nine, and the volumes behind most of them are not disclosed.
Pilot: the network transaction firsts of October 2025 through March 2026. Four, with counts in the hundreds where counts were given at all.
Spec: AP2, Trusted Agent Protocol, the Agentic Commerce Protocol as a published standard, Agent Pay's original framing, Agent Connect, the KYA framework. Six.
Withdrawn: one. It was the one that had the most merchants attached.
Now the demand side, in four numbers from the guide. PYMNTS Intelligence found in September that 56 percent of US consumers would let an AI search and compare, and 37 percent would authorize a payment through it. Visa's polling found 23 percent trust generative AI to handle a payment on their behalf, and 60 percent would not allow an agent to spend without approval. Shopify reported AI-driven traffic and orders each tripling year on year. Adobe measured a 693 percent rise in AI-referred retail traffic across the 2025 holidays.
Shopping with AI is mainstream. Paying with it is not. After 18 months the industry has built an elaborate set of rails to a button that, until the last week of September, nobody had moved, and the one platform that moved it left the buyer's hand on it.
What the first year settled, and what it did not
Settled. An agent can pay, on existing rails, with a token bound to a merchant and an amount; the pilots proved that by December 2025 and nothing since has contradicted it. The merchant stays merchant of record; the one product that tried the other way was withdrawn in six months, every protocol since has kept the checkout with the store, and when the button finally moved it moved inside the store. Discovery is a channel with a price on it; the shelf moved inside the conversation and got a sponsored tier.
Not settled. Identity at the door: a merchant still cannot tell a customer's agent from a scraper, which is why Amazon blocks, why my scan finds locked doors, and why the standards bodies are carrying drafts nobody has shipped. Liability when it is wrong: the court says the agent is you, the insurer says it covers the deployer, the dispute layer says nothing, and no protocol in the record has a field for who pays. And demand: the numbers say people want the search and not the spend, and no announcement in 18 months has moved that.
In the MM Trust Layer Model the first year filled the settlement layer and most of discovery, and left authorization, the layer in the middle, where it was. The Destination Economy Thesis predicted the merchants would not give up the checkout, and the record is the thesis with dates on it.
The second year starts with the merchants having spoken. What they said, in Amazon's words and in the scan's numbers, is that the door stays shut until they can see who is at it. That is the layer to watch, and it is the one nobody has announced.
Sources
- Major Matters: Software That Acts, the guide, Part 3 (the chronological record and its 30 primary sources)
- Major Matters: The Agent Payment Protocols Tracker
- Major Matters: The x402 Adoption Tracker
- Fintech Brainfood: AI Checkout and Mercury's OCC approval
- OpenAI: Powering product discovery in ChatGPT
- Payments Dive: Amazon blocks Meta's AI shopper
- Practical Ecommerce: Shopify opens to Meta Muse; Amazon balks
- Major Matters: The Merchant Agent-Readiness Index
- PYMNTS Intelligence: AI picks the shortlist before retailers get the click
- TechCrunch: Shopify opens checkout to browser-based AI agents
If the rails are built and the merchants have locked the door, is the second year of agentic commerce about payments at all?
Charlie Major is a Product Development Manager at Mastercard. The views and opinions expressed in Major Matters are his own and do not represent those of Mastercard.
