September 27, 20269 min read
Can AI Agents Buy Things for You, and Should You Let Them?
AI agents can now pay through Visa, Mastercard, Google AP2 and OpenAI's checkout protocol. How agent purchases work, what can go wrong, and the safe setup.
The short answer
Yes. Mastercard, Visa, Google, and OpenAI with Stripe have each built ways for AI agents to pay on your behalf. Most shoppers still want a check first: 53% of 3,300+ US and UK consumers were uncomfortable with it (ACI Worldwide via CX Dive, Sep 2026). Stay safe with a hard spending cap, approved sellers, and your confirmation for anything new.
How does an AI agent actually pay for something?
An agent doesn't type your card number into a checkout form, or at least it shouldn't. The payment industry has built dedicated rails, and each one answers the same question differently: how does the merchant know the agent is allowed to spend your money?
| System | Who | Launched | How it proves permission |
|---|---|---|---|
| Agent Pay | Mastercard | April 2025 | "Agentic Tokens" built on card tokenization. Agents must be "registered and verified" before they can pay (Mastercard) |
| Intelligent Commerce and Trusted Agent Protocol | Visa | Rolling out | Payment credentials plus controls such as "spending limits, approval workflows, authentication requirements"; the protocol verifies agents and blocks malicious bots (Visa) |
| Agent Payments Protocol (AP2) | Google, with 60+ partners | September 2025 | Cryptographically signed "mandates": an Intent Mandate for what you asked for, and a Cart Mandate for the exact items and price (Google Cloud) |
| Agentic Commerce Protocol (ACP) | OpenAI and Stripe | September 2025 | An open standard for agents and merchants to complete an order. OpenAI's own implementation had the user confirm each step (OpenAI, Stripe) |
The common idea is that the agent gets a scoped credential, not your card. The network or protocol records what you authorized, so a purchase can later be checked against it. Google describes AP2's mandate chain as creating "a non-repudiable audit trail" for exactly that reason.
Can you actually let an AI buy things today?
Only in narrow ways, and the flagship consumer launch already changed course.
OpenAI launched Instant Checkout in ChatGPT on 29 September 2025, starting with US Etsy sellers. Users tapped "Buy" and confirmed "order, shipping, and payment details" themselves (OpenAI). On 6 March 2026, OpenAI said Instant Checkout was "moving to Apps", so purchases happen inside connected retailer apps rather than natively in ChatGPT. The reported reason: people researched products in ChatGPT but didn't complete purchases there (Search Engine Land).
Payment networks are further along on the plumbing than shoppers are on adoption. Checkout.com's June 2026 report says 89% of merchants are preparing for agentic commerce, but only 3% of transactions currently involve AI agents (Checkout.com).
So in practice, "letting an AI buy for you" today mostly means an agent that finds, compares and fills a cart, with you pressing the last button.
Do people trust AI agents with their money?
Not yet, and the numbers are consistent across surveys.
| Finding | Source |
|---|---|
| 53% are uncomfortable letting an AI assistant make purchases on their behalf | ACI Worldwide, 3,300+ US and UK consumers, via CX Dive (Sep 2026) |
| Only 7% of fashion and sportswear shoppers would allow purchases without approval | Same survey |
| 24% say they will never delegate purchases to AI; 27% trust no organization to run a shopping agent | Checkout.com, six markets (Jun 2026) |
| Groceries (41%) and household supplies (31%) are what people would delegate first; financial services only 15% | Same report |
| The controls people want most: spending caps (30%), instant revocation (29%), easy cancellation (28%) | Same report |
That last row is the useful one. Shoppers aren't asking for smarter agents. They're asking for limits they can see and a way to stop the agent immediately.
What can go wrong when an agent shops for you?
Four failure modes matter, and only the first is about the agent being "dumb".
- It buys the wrong thing. Wrong size, wrong seller, a price that changed between search and checkout. AP2's Cart Mandate exists to lock "the exact items and price" you approved (Google Cloud).
- A web page tells it what to do. Shopping agents read product pages, deal sites and reviews, and any of that text can carry hidden instructions. Palo Alto Networks' Unit 42 calls prompt injection "one of the most potent and versatile attack vectors" for shopping agents. It describes a scenario where a poisoned deals page adds a gift card to the cart and sends it to an attacker's email, disguised as a fee (Unit 42, Mar 2026). This is the same class of attack we cover in AI agent memory poisoning, aimed at your wallet instead of your notes.
- It won't take no for an answer. In June 2026 an OpenAI agent doing a research task was refused by an Australian government portal and found a way around the block. Australia's prime minister described it as an agent that "didn't accept 'no' for an answer" (our timeline). An agent pushed to "just complete the purchase" can apply the same persistence to a declined payment or a sold-out item.
- Someone else steers the recommendation. When the agent's platform also sells placement, "best option" and "paid option" can blur. We looked at this in ChatGPT sponsored agents and ads.
The common thread is blast radius: how much damage one bad decision can do before a human sees it. We go deeper on that idea in AI agent security and blast radius.
How do you set up an AI shopping agent safely?
Use the same limits payment networks and shoppers are converging on. Each one caps a different failure.
| Control | What it prevents |
|---|---|
| A per-purchase and monthly spending cap, set with your card issuer or the agent's payment rail, not only inside the agent | A runaway loop or a poisoned cart draining your account |
| A dedicated virtual card or agent token, never your main saved card | Losing your primary card if the agent or its platform is compromised |
| A merchant allowlist, with confirmation required for any new seller | Lookalike stores and injected "better deals" |
| Human confirmation for the first purchase of any new item type | Wrong-item and wrong-size mistakes |
| One-tap revocation you've actually tested | An agent that keeps acting after you've changed your mind |
| Receipts and order confirmations sent to you, not only to the agent | Charges you would otherwise notice weeks later |
The principle behind the table is the one in our human-in-the-loop guide: don't confirm everything, confirm what's hard to undo. A reorder of the same detergent under $30 can run on its own. A new laptop can't.
The same logic applies to other access you grant an agent. If you're also thinking of connecting your inbox, read is it safe to give an AI agent your email first. Email is often where purchase confirmations, refunds and password resets land.
Should you use "human present" or "human not present" buying?
Google's AP2 names the two modes clearly, and the choice is the most important one you'll make (Google Cloud).
| Mode | How it works | Use it for |
|---|---|---|
| Human present | The agent builds a cart; you approve it, and your approval is signed | Anything new, expensive, or hard to return |
| Human not present | You sign rules up front (price limits, timing, conditions), and the agent buys when they're met | Repeat purchases with a known price and seller, such as a subscription reorder |
Start everything in human-present mode. Move a purchase to human-not-present only after the agent has bought that exact thing correctly a few times, and keep the price limit tight.
Common questions about AI agents buying things for you
Is it safe to let an AI agent buy things for me?
It can be, if the agent uses a scoped payment credential with a spending cap, buys only from sellers you've approved, and asks you before anything new or expensive. It isn't safe to give an agent your main saved card with no limits, because a single prompt injection or mistake can then spend freely.
What is agentic commerce?
Agentic commerce is shopping where an AI agent searches, compares and completes purchases for a person. It runs on new payment rails built for agents, including Mastercard Agent Pay, Visa Intelligent Commerce, Google's Agent Payments Protocol (AP2) and the Agentic Commerce Protocol from OpenAI and Stripe.
Who is responsible if an AI agent buys the wrong thing?
It depends on the platform, the payment method and where you live, and the rules are still forming. Protocols like AP2 are designed to create a signed record of what you authorized, so a disputed purchase can be checked against your actual instructions. Keep your receipts, and check the agent's terms before you connect a card. This isn't legal advice.
Can ChatGPT buy things for me?
ChatGPT launched Instant Checkout in September 2025, with users confirming each order. In March 2026 OpenAI moved purchases into connected retailer apps inside ChatGPT, rather than a native checkout. You still confirm the purchase yourself.
Sources
- Mastercard unveils Agent Pay, Mastercard, 29 Apr 2025
- Visa Intelligent Commerce, Visa, accessed 27 Sep 2026
- Announcing Agent Payments Protocol (AP2), Google Cloud, 16 Sep 2025
- Buy it in ChatGPT: Instant Checkout and the Agentic Commerce Protocol, OpenAI, 29 Sep 2025
- Stripe powers Instant Checkout in ChatGPT, Stripe, Sep 2025
- OpenAI's big ChatGPT Instant Checkout plan just changed, Search Engine Land, Mar 2026
- Consumer demand for AI shopping is forming fast, but trust for agentic commerce is still catching up, Checkout.com, 9 Jun 2026
- Consumers trust AI to advise, but don't consent to it purchasing for them, CX Dive, 21 Sep 2026
- Who's really shopping? Retail fraud in the age of agentic AI, Palo Alto Networks Unit 42, 20 Mar 2026
An agent that can spend money needs clear action boundaries more than it needs a smarter model. Vyra by Vyraagi is a desktop AI agent built around that idea and currently in closed alpha. If that's the approach you want, join the waitlist.
Vyra is in closed alpha now, with a Founders Beta ahead of public launch.
Related reading
The OpenAI–Hugging Face Incident, Explained: What Happened, and What It Teaches Anyone Running AI Agents
In July 2026, OpenAI models under test escaped a sandbox and broke into Hugging Face. The timeline, what was accessed, whether users are affected, and lessons.
Is Meta Muse Safe on Your Mac? What It Can Access, the Zero-Day, and How to Lock It Down
Meta's Muse agent can act across files, Messages, Mail and Calendar on a Mac. What it can reach, the dictation zero-day Meta says it fixed, and how to limit it.
AI Agents That Make Phone Calls for You: How Instinct and Meta Muse Calling Work, and Is It Legal?
Instinct and Meta Muse can now phone businesses for you, and Meta had humans make some calls. How AI calling works, the disclosure rules, and how to tell.