Hook
OpenAI Instant Checkout launched in September 2025 with Etsy as its flagship merchant, then expanded into Shopify's catalog through the Agentic Commerce Protocol. By March 2026 it was gone β a six-month experiment that never scaled past roughly thirty Shopify stores, paired with a Walmart integration inside ChatGPT that converted at one-third the rate of Walmart's own checkout page. Here is the number every post-mortem skipped: 61 million US consumers β 23% of shoppers β were still asking AI what to buy while Instant Checkout was dying. The rails failed. The intent did not. That disconnect is the entire story, and the coverage buried it under a single word: trust.
I read the reverts before the headlines. When a protocol dies at six months with demand intact on both sides of the market, the failure is never demand. It is the architecture underneath. And the architecture underneath agentic commerce has a name the reports keep declining to state: it is a trust layer, it does not exist yet, and three-quarters of the merchants who need it cannot even see the traffic that requires it.

Context
Let me set the baseline, because the numbers are load-bearing.
Agentic commerce β AI agents that research, select, and purchase goods on a consumer's behalf β crossed a real threshold in 2025. By mid-2026, the PYMNTS/Visa Global Digital Shopping Index, Merchant Edition, reported that 23% of consumers had used an AI assistant to research a purchase, and average order values on AI-assisted transactions had risen 17% in two months. Sixty percent of those AI-assisted purchases terminated on Amazon. Not Shopify. Not brand.com. Amazon.
That structure matters because it is not what anyone building agent checkout predicted. The revenue model for agentic commerce assumes the agent captures the transaction β takes a commission, captures the customer relationship, owns the data and the repeat purchase. What actually happened is the agent captured the intent and Amazon captured the sale. Sixty percent is not a distribution channel. It is a transfer of value from the AI stack to Amazon's order book, financed by inference compute the AI companies pay for and Amazon does not.
The counter-evidence sits in the same report. A controlled test β where consumers were told they were comparing identical products at identical prices with identical shipping and identical return policies β showed that 40% would still choose a platform channel, 22% a department store, 16% a brand directly. Even under perfect information symmetry, the maximum migratable share was twenty percentage points. And of that twenty, the slice AI could plausibly own was already fragmented: digital wallets with stored credentials converted at 24%, while end-to-end AI checkout converted at 12%. The wallets re-used a trust relationship that already existed. The AI checkout tried to manufacture a new one, and got half the conversion for the effort.
Two events on the same day tell you more than any survey. Shopify opened its full catalog to AI shopping agents β an offensive bet that openness brings incremental traffic. Amazon, the same day, blocked that agent's access to its listings β a defensive bet that closure protects transaction share. Neither move was a technology decision. Both were strategic posture. Amazon could afford to close because twenty years of default-shopping behavior gave it the cushion to defend. Shopify could not afford to close because it needs the demand. The mirror image is not a coincidence. It is a statement about who holds leverage.

The logic held until the liquidity dried up. Only here it was not liquidity. It was conversion.
Core
Here is where the crypto lens earns its keep, because the agentic commerce trust problem is structurally identical to the oracle problem that has defined DeFi since 2020.
In DeFi, the smart contract is deterministic. The state is verifiable. The failure is always at the boundary β where the contract asks an external feed for a price and the feed lies, or lags, or gets manipulated. Chainlink solved decentralization by running a federated set of node operators that are, in practice, a permissioned consortium wearing a decentralized costume. Everyone in audit knows this. Everyone in audit also knows the alternative β a purely on-chain oracle for real-world assets β does not exist, because you cannot read the physical world from inside consensus. When I reconstructed the Anchor Protocol oracle feedback loop after TerraUSD collapsed in May 2022, running local nodes to simulate the peg's death spiral, the lesson was not that the model was wrong. The lesson was that the model's correctness depended entirely on a boundary condition β the price feed β that degraded precisely when it was needed most. The failure was at the edge, not the core.
Agentic commerce has the same edge, and the edge is naked.
The agent's model is the contract. The merchant's product data, inventory, pricing, and return policy are the oracle feed. And the feed is lying β not maliciously, just by being 85% absent. Only 15% of merchants have structured product data an agent can actually parse. Only 11% of small and mid-size businesses are agent-ready at all. Only 23% of merchants can distinguish agent traffic from human traffic in their logs. That last figure should terrify anyone who has ever traced a hack. It means 77% of merchants are running blind on the exact traffic class growing fastest. They cannot attribute it, rate-limit it, dispute it, or audit it. You cannot secure a perimeter you cannot see.
I spent part of 2026 auditing smart contract interfaces for three AI-agent platforms, and I found a reentrancy vulnerability in a payment routing module that let an agent drain funds whenever the external AI model returned a delayed response. The external call β the model inference itself β was the reentrancy vector. Everyone building agent infrastructure is relearning what Solidity developers learned in 2016: any boundary you do not control is an attack surface, and the more you abstract it, the less you can see it. The AI-agent stack has abstracted the boundary further than anything in DeFi history, and called the abstraction a feature.
Consider the parallel failure modes side by side, because they are the same failures with new nouns.
Prompt injection is to agentic commerce what oracle manipulation is to DeFi. A DeFi protocol trusts a price feed to be honest data. An AI shopping agent trusts a product page, a review, or a seller description to be information rather than instruction. Both trust boundaries can be crossed by an adversary who controls the input stream. A malicious product listing can embed instructions that redirect the agent to buy the wrong item, at the wrong price, from the wrong seller. The consumer believes their assistant is acting on their behalf. The assistant has been hijacked by a product page. This is not hypothetical β it is the direct commerce analogue of the AI-agent reentrancy class I documented, and traditional audits miss it entirely because they audit code, not semantics. A prompt is not a parameter. It has no schema, no validation, no type system. It is unstructured input trusted to govern structured behavior, and that is a category error no amount of model quality fixes.
Payment credential delegation is the tokenization problem. Every serious agentic checkout proposal β the card networks' agentic network tokens, Stripe's delegated payment credentials, the whole ACP stack β is a reimplementation of what payment tokenization already does: replace a sensitive credential with a scoped, revocable substitute. The technical novelty is zero. The commercial stakes are enormous, because whoever defines the delegated-credential standard controls both the fee and the liability allocation. This is the real competition, and it happens below the checkout button where no consumer and few analysts are watching. When I traced the movement of over $4 billion from Alameda Research addresses in early 2023, mapping the laundering path through Tornado Cash and centralized exchange deposits before any court document existed, the operational lesson was that money flow is the ground truth. Press releases describe intentions. Ledgers describe behavior. The same holds for agent credentials: the company that issues the delegated token defines who eats the loss.
The trust the reports cite is not trust. It is unbundled risk transfer, and it is not free. The data shows 64% of consumers will verify a seller's identity but still trust the platform to resolve disputes. Read that as an engineer. Consumers are not trusting the seller. They are buying Amazon's return policy and Amazon's fraud desk. Amazon's moat is not product data, not logistics, not even price. It is that when the transaction goes wrong β wrong item, damaged item, never-arriving item β someone with a call center and a chargeback workflow absorbs the loss. An AI agent offers none of that. An AI agent offers information. Information and insurance are different products, sold to different buyers, priced on different models, and the report treats them as the same word.
There is a third constraint the report folds into trust and should not. Capability. AI checkout does not solve logistics, and reverse logistics β returns β is the most expensive and most trust-sensitive part of e-commerce. The Walmart conversion number, one-third of its own site rate inside ChatGPT, is not a trust problem. It is a checkout-flow and fulfillment problem the agent cannot abstract away. When I audited agent payment routing, the failure mode was never the model's reasoning quality. It was the external call's latency and the downstream service's response contract. Agentic commerce inherits every latency and every broken return path the merchant already had, and adds new ones. The report calls this trust because trust is the word that sells. The engineer calls it integration surface, and integration surface is where the reverts live.
Code does not lie, but incentives do. The narrative says the bottleneck is consumer trust. The data says the bottleneck is that AI checkout sells information while consumers buy insurance. Those are not the same market, and no trust-building campaign collapses them into one.
Run the unit economics and Instant Checkout's death stops being a mystery. Take a commission-model checkout. Multiply the merchant base β call it thirty Shopify stores at shutdown β by average order value, by an agentic attach rate itself in the low single digits, by a take rate in the single-digit percent range. The product is the delta: a commission stream on a small slice of GMV. Against that, load ChatGPT's inference cost per shopping session, the compliance cost of operating a payment intermediary, and the support cost of returns and disputes. The numbers do not converge. The product did not fail because it was unloved. It failed because the arithmetic was negative.
There is a second layer the report never opens. Attribution. If 77% of merchants cannot distinguish agent traffic, then the entire commercial model of agentic commerce is unverifiable at the supply end. A merchant cannot pay a commission on a sale it cannot attribute to an agent. A merchant cannot dispute a fraudulent click it cannot identify. A merchant cannot optimize a product page for an agent it cannot detect. The 23% detection figure is not a data point. It is a gate. Until it clears β I would set the threshold near 70% β agentic commerce cannot be settled, only hypothesized.
And underneath all of it sits the question nobody asks out loud. If the majority of AI-assisted purchases land on Amazon, then OpenAI β and every AI company building shopping features β is financing Amazon's demand funnel with its own inference bill. The intent layer pays. The transaction layer collects. The narrative calls this agentic commerce. The ledger calls it a subsidy.

Contrarian
Now the part the teardown has to concede, because a real audit does not stop at the finding.
The anchoring report is sponsored, directly and structurally, by the party that benefits from its conclusion. The data comes from PYMNTS Intelligence and the PYMNTS/Visa Global Digital Shopping Index. The framing β the Febreze moment, the top of wallet becomes top of agent thesis β comes from Karen Webster, the CEO of PYMNTS. The conclusion is that payment networks should make their zero-liability guarantee explicit across the agent layer and thereby capture the gap. That conclusion is Visa's commercial strategy. This is not a conspiracy. It is a data-to-conclusion closed loop, and it should be read as a policy proposal from an interested party, not a neutral finding. I flag it the same way I flag a protocol publishing its own audit summary.
But here is what the report gets right that the crypto-native skeptics get wrong. The decentralize-everything reflex β the instinct that says the trust layer should be a permissionless protocol with on-chain attestations and no intermediaries β is precisely the instinct that produced Chainlink's centralized-node decentralization theater. The agentic trust layer will not be permissionless, because the thing being trusted is not a number. It is a legal promise to absorb a loss, and you cannot make a legal promise permissionless. You can make the credential portable, revocable, and auditable β a genuine and achievable target. It is also exactly what the card networks already have the regulatory plumbing to sell. Stripe's 288-item release cadence is impressive and unverified; 288 features is not 288 adoptions, and I have seen no merchant attach rates or GMV contribution for the agent stack. The networks own the one asset Stripe is still renting: an existing liability regime that consumers already trust.
One final constraint the report omits is motive, not capability. The 11% agent-ready figure is read as a readiness gap β merchants cannot keep up. But readiness is partly willingness in disguise. A merchant that hands its customer to an agent surrenders price comparison, surrenders cross-sell, and accepts that the agent may recommend a competitor. No brand with twenty years of customer equity wants to become a fungible data feed routed through a third party's interface. The 11% may be a supply constraint. It is at least as plausibly a channel-conflict decision dressed as an infrastructure lag, because that is the polite way to decline.
And there is the blind spot the report never names. Google is absent from the entire analysis, and its absence is the loudest signal in the document. Commercial queries β best laptop for video editing, cheapest running shoes β are the most monetizable class in search advertising. If AI assistants capture the what-should-I-buy question at the top of the funnel, they are not merely skipping Amazon's checkout; they are extracting revenue from Google's most valuable query pool. A report on how AI changes where people buy, that never mentions Google, is not neutral. It has a blind spot the size of Alphabet's search line β and the likely reason is that naming it converts a tidy agentic-commerce story into a story about search advertising collapsing, which is much larger and much less comfortable.
So the bull case is right that payment networks win. It is wrong that the win is fast, and wrong that it is the AI companies' to lose. The strategic opportunity is real. It is also a 2029 opportunity being marketed as a 2026 one.
Takeaway
The exploit was in the trust, not the contract. That has been true of every protocol I have audited since the 0x integer overflow I traced through the preliminary testnet contracts in 2017, and it is true of agentic commerce in 2026. The transaction passed validation. The trust boundary did not.
Track one number above all others: the share of agent-influenced GMV that settles inside an agent-native checkout, not the penetration of AI-assisted research. The 23% tells you how people learn. It does not tell you where value lands. The 6% tells you where value lands, and value is landing on Amazon. Until the detection figure clears 70% and a verifiable agent identity standard exists, the entire sector is a hypothesis dressed as a market.
The forward question is not whether agents will mediate commerce. They will. The question is who owns the liability when they get it wrong, and whether that liability is priced or hidden. Today it is hidden β buried inside the 60% that lands on Amazon, where the platform absorbs the cost as the price of default dominance. The moment an agent-native checkout claims that liability at scale, it will have to price it, and the price will look like insurance, not software.
Entropy always wins if you stop watching. Watch the settlement layer, not the search box.