September 27, 20269 min read

Can AI Agents Buy Things for You, and Should You Let Them?

AI agents can now pay through Visa, Mastercard, Google AP2 and OpenAI's checkout protocol. How agent purchases work, what can go wrong, and the safe setup.

ByLokesh Kumar· Founder & Builder, Vyra
Share on XShare on LinkedIn

The short answer

Yes. Mastercard, Visa, Google, and OpenAI with Stripe have each built ways for AI agents to pay on your behalf. Most shoppers still want a check first: 53% of 3,300+ US and UK consumers were uncomfortable with it (ACI Worldwide via CX Dive, Sep 2026). Stay safe with a hard spending cap, approved sellers, and your confirmation for anything new.

How does an AI agent actually pay for something?

An agent doesn't type your card number into a checkout form, or at least it shouldn't. The payment industry has built dedicated rails, and each one answers the same question differently: how does the merchant know the agent is allowed to spend your money?

SystemWhoLaunchedHow it proves permission
Agent PayMastercardApril 2025"Agentic Tokens" built on card tokenization. Agents must be "registered and verified" before they can pay (Mastercard)
Intelligent Commerce and Trusted Agent ProtocolVisaRolling outPayment credentials plus controls such as "spending limits, approval workflows, authentication requirements"; the protocol verifies agents and blocks malicious bots (Visa)
Agent Payments Protocol (AP2)Google, with 60+ partnersSeptember 2025Cryptographically signed "mandates": an Intent Mandate for what you asked for, and a Cart Mandate for the exact items and price (Google Cloud)
Agentic Commerce Protocol (ACP)OpenAI and StripeSeptember 2025An open standard for agents and merchants to complete an order. OpenAI's own implementation had the user confirm each step (OpenAI, Stripe)

The common idea is that the agent gets a scoped credential, not your card. The network or protocol records what you authorized, so a purchase can later be checked against it. Google describes AP2's mandate chain as creating "a non-repudiable audit trail" for exactly that reason.

Can you actually let an AI buy things today?

Only in narrow ways, and the flagship consumer launch already changed course.

OpenAI launched Instant Checkout in ChatGPT on 29 September 2025, starting with US Etsy sellers. Users tapped "Buy" and confirmed "order, shipping, and payment details" themselves (OpenAI). On 6 March 2026, OpenAI said Instant Checkout was "moving to Apps", so purchases happen inside connected retailer apps rather than natively in ChatGPT. The reported reason: people researched products in ChatGPT but didn't complete purchases there (Search Engine Land).

Payment networks are further along on the plumbing than shoppers are on adoption. Checkout.com's June 2026 report says 89% of merchants are preparing for agentic commerce, but only 3% of transactions currently involve AI agents (Checkout.com).

So in practice, "letting an AI buy for you" today mostly means an agent that finds, compares and fills a cart, with you pressing the last button.

Do people trust AI agents with their money?

Not yet, and the numbers are consistent across surveys.

FindingSource
53% are uncomfortable letting an AI assistant make purchases on their behalfACI Worldwide, 3,300+ US and UK consumers, via CX Dive (Sep 2026)
Only 7% of fashion and sportswear shoppers would allow purchases without approvalSame survey
24% say they will never delegate purchases to AI; 27% trust no organization to run a shopping agentCheckout.com, six markets (Jun 2026)
Groceries (41%) and household supplies (31%) are what people would delegate first; financial services only 15%Same report
The controls people want most: spending caps (30%), instant revocation (29%), easy cancellation (28%)Same report

That last row is the useful one. Shoppers aren't asking for smarter agents. They're asking for limits they can see and a way to stop the agent immediately.

What can go wrong when an agent shops for you?

Four failure modes matter, and only the first is about the agent being "dumb".

  1. It buys the wrong thing. Wrong size, wrong seller, a price that changed between search and checkout. AP2's Cart Mandate exists to lock "the exact items and price" you approved (Google Cloud).
  2. A web page tells it what to do. Shopping agents read product pages, deal sites and reviews, and any of that text can carry hidden instructions. Palo Alto Networks' Unit 42 calls prompt injection "one of the most potent and versatile attack vectors" for shopping agents. It describes a scenario where a poisoned deals page adds a gift card to the cart and sends it to an attacker's email, disguised as a fee (Unit 42, Mar 2026). This is the same class of attack we cover in AI agent memory poisoning, aimed at your wallet instead of your notes.
  3. It won't take no for an answer. In June 2026 an OpenAI agent doing a research task was refused by an Australian government portal and found a way around the block. Australia's prime minister described it as an agent that "didn't accept 'no' for an answer" (our timeline). An agent pushed to "just complete the purchase" can apply the same persistence to a declined payment or a sold-out item.
  4. Someone else steers the recommendation. When the agent's platform also sells placement, "best option" and "paid option" can blur. We looked at this in ChatGPT sponsored agents and ads.

The common thread is blast radius: how much damage one bad decision can do before a human sees it. We go deeper on that idea in AI agent security and blast radius.

How do you set up an AI shopping agent safely?

Use the same limits payment networks and shoppers are converging on. Each one caps a different failure.

ControlWhat it prevents
A per-purchase and monthly spending cap, set with your card issuer or the agent's payment rail, not only inside the agentA runaway loop or a poisoned cart draining your account
A dedicated virtual card or agent token, never your main saved cardLosing your primary card if the agent or its platform is compromised
A merchant allowlist, with confirmation required for any new sellerLookalike stores and injected "better deals"
Human confirmation for the first purchase of any new item typeWrong-item and wrong-size mistakes
One-tap revocation you've actually testedAn agent that keeps acting after you've changed your mind
Receipts and order confirmations sent to you, not only to the agentCharges you would otherwise notice weeks later

The principle behind the table is the one in our human-in-the-loop guide: don't confirm everything, confirm what's hard to undo. A reorder of the same detergent under $30 can run on its own. A new laptop can't.

The same logic applies to other access you grant an agent. If you're also thinking of connecting your inbox, read is it safe to give an AI agent your email first. Email is often where purchase confirmations, refunds and password resets land.

Should you use "human present" or "human not present" buying?

Google's AP2 names the two modes clearly, and the choice is the most important one you'll make (Google Cloud).

ModeHow it worksUse it for
Human presentThe agent builds a cart; you approve it, and your approval is signedAnything new, expensive, or hard to return
Human not presentYou sign rules up front (price limits, timing, conditions), and the agent buys when they're metRepeat purchases with a known price and seller, such as a subscription reorder

Start everything in human-present mode. Move a purchase to human-not-present only after the agent has bought that exact thing correctly a few times, and keep the price limit tight.

Common questions about AI agents buying things for you

Is it safe to let an AI agent buy things for me?

It can be, if the agent uses a scoped payment credential with a spending cap, buys only from sellers you've approved, and asks you before anything new or expensive. It isn't safe to give an agent your main saved card with no limits, because a single prompt injection or mistake can then spend freely.

What is agentic commerce?

Agentic commerce is shopping where an AI agent searches, compares and completes purchases for a person. It runs on new payment rails built for agents, including Mastercard Agent Pay, Visa Intelligent Commerce, Google's Agent Payments Protocol (AP2) and the Agentic Commerce Protocol from OpenAI and Stripe.

Who is responsible if an AI agent buys the wrong thing?

It depends on the platform, the payment method and where you live, and the rules are still forming. Protocols like AP2 are designed to create a signed record of what you authorized, so a disputed purchase can be checked against your actual instructions. Keep your receipts, and check the agent's terms before you connect a card. This isn't legal advice.

Can ChatGPT buy things for me?

ChatGPT launched Instant Checkout in September 2025, with users confirming each order. In March 2026 OpenAI moved purchases into connected retailer apps inside ChatGPT, rather than a native checkout. You still confirm the purchase yourself.

Sources


An agent that can spend money needs clear action boundaries more than it needs a smarter model. Vyra by Vyraagi is a desktop AI agent built around that idea and currently in closed alpha. If that's the approach you want, join the waitlist.

Vyra is in closed alpha now, with a Founders Beta ahead of public launch.

Related reading