AI agents are moving closer to making purchases on consumers’ behalf. Mastercard has partnered with Alchemy to connect its agentic payment technology with tools developers can use to build shopping agents, according to The Wall Street Journal. Users can delegate purchases to an agent while setting restrictions such as spending limits or approved merchants.
What changes when an AI agent enters the transaction?
The development is part of a broader effort to build infrastructure for agentic commerce. Payment networks are currently developing a framework for card-based agentic payments. One of the questions it addresses is how to establish a consumer’s intent and determine that they actually delegated authority to an AI agent.
An agentic transaction introduces several parties into what used to be a relatively direct interaction between a customer and a merchant.
That makes traceability particularly important. If an agent is authorized to spend up to $500 on flights, for example, the eventual transaction needs to be attributable to the authority originally granted by a particular user, including the conditions attached to it.
For identity and payment systems, that creates an essential question:
How do you connect that authorization to the person who gave it?
Identity verification can provide an anchor for the chain of trust by establishing who is delegating authority in the first place.
The rest of the transaction may then rely on other forms of evidence: authentication, proof of authorization, agent credentials, transaction data, and records showing whether the agent remained within its permitted scope. Different controls answer different questions, but they need to remain connected.
“Identity verification will not tell you whether every action an AI agent takes is legitimate. Its role is to give the chain a trusted starting point by letting you know who is behind the agent. From there, businesses need to be able to connect the verified person to the authority given to the agent and then to the action the agent performs. If something goes wrong, that chain also gives you a way to trace the transaction back and understand where trust failed.”
— Henry Patishman, Executive Vice President of Identity Verification Solutions
This distinction becomes more important as agents gain greater autonomy. Authorization may cover a single purchase, a spending limit, a particular merchant, a product category, or a time period. The identity behind the authorization can remain the same while the scope of what the agent is allowed to do changes.
How can businesses keep the trust chain verifiable?
In agentic transactions, it is useful to treat identity, authorization, and the eventual action as connected evidence rather than independent checks.
The appropriate controls will depend on the risk of the transaction. A low-value repeat purchase may require little additional assurance, while a new agent, changed payment details, an unusually large transaction, or a request outside the agent’s normal scope may justify stronger authentication or a fresh identity check.
Identity orchestration can help adapt verification to different levels of risk. Regula IDV Platform is designed to manage identity across the lifecycle rather than as a single onboarding event. It can combine document, biometric, and data-based checks in configurable workflows, keep identity information and verification results connected in one place, and trigger different verification steps depending on the scenario.
For example, the same identity profile can be reused across different sessions and workflows, while additional checks can be introduced when the context changes. Regula IDV Platform also keeps a history of identity-related interactions and workflow results, giving organizations an audit trail they can use to understand how a decision was reached and what evidence was available at each stage.
In agentic commerce, the identity check is only the beginning. The value comes from being able to preserve the connection between the verified person, later verification events, and the other signals or systems involved in deciding whether a particular action should be trusted.
We’ll deliver hand-picked content from Regula’s experts into your inbox
