Guide

Agentic commerce risks and how to mitigate them

AI assistants can now find vendors, compare options and request prices on their own. That saves people a lot of time. The hard part comes when money is about to move. These are the main risks, and the controls that contain them.

01

Runaway or unauthorized spend

The risk

An agent holding a card, wallet or spending limit can buy the wrong thing, buy it twice, or be talked into buying something its owner never wanted. Spending limits cap the damage; they don't prevent it.

The control

Separate scoping from paying. Let the agent gather requirements and request a price, but require a person to confirm payment in a browser. If no machine credential can complete a payment, there is nothing for an agent to misuse.

02

Price drift between quote and payment

The risk

If a price can change after the agent agrees to it, the buyer may pay something different from what was discussed — through error, a race condition, or tampering.

The control

Lock the price in a signed quote. Sign the line items, total and expiry with a server-held key, and verify the signature when the payment page loads and again at checkout. A changed quote fails verification and cannot be paid.

03

Stale offers

The risk

A quote that stays valid forever lets old prices be paid long after conditions changed, or lets a leaked link be used much later.

The control

Give quotes a short life (AI2AI uses 30 minutes). An expired quote never silently refreshes; it produces a re-quote link, and the new quote records the one it replaced.

04

Prompt injection and manipulated agents

The risk

Web pages, emails and tool outputs can contain hidden instructions that steer an agent toward a purchase or a different vendor.

The control

Assume the agent can be fooled and make that harmless. When the final step shows a person exactly what was scoped, by which assistant, for how much, a manipulated request is caught before money moves.

05

No audit trail

The risk

When something goes wrong, neither buyer nor seller can show who asked for what, which price was offered, or who approved the payment.

The control

Keep quotes insert-only and log every step: scope, quote, re-quote, the moment a human confirmed, and settlement. Changes create new records rather than overwriting old ones.

06

Controls that live only in the interface

The risk

A rule enforced only by a button or a prompt can be bypassed by calling the API directly.

The control

Enforce the critical rules where data is stored. In AI2AI, the database refuses to mark a payment as paid without a human confirmation timestamp, whatever the caller.

A worked example: the human payment gate

The AI2AI handoff protocol puts these controls into four steps. The assistant opens a scope session, locks a signed 30-minute quote, and hands its human a payment link. The person reviews and pays by card. The assistant then checks the receipt, which records when the human confirmed. No payment tool exists for the assistant, over the web or over MCP.