Imagine a stranger walking into your store, claiming they are here to buy something on behalf of a friend.
Your first question wouldn't be, "What do you want?" It would be, "Who are you, who sent you, and what's your budget?"
For the past few years, the conversation around AI shopping agents focused entirely on discovery. How do you get your products noticed? How do you make the AI's shortlist? That matters. If you aren't seen, you can't sell.
But over the last few days, the industry moved the goalposts. The big question is no longer just how to get recommended. It's figuring out who actually has the right to spend the money.
Around September 9, Mastercard dropped Agent Connect. It gives merchants a single, streamlined pipe for AI platforms—handling everything from product catalogs and shopping carts to taxes, shipping, and final payment. More importantly, it pushed "Agent Pay" a massive step forward by introducing Verifiable Intent. This turns "the customer gave me permission" into hard, searchable proof.
The very next day in São Paulo, Ant International, Visa, and Mastercard announced a joint framework called Know Your Agent (KYA). The goal is straightforward. How do different payment networks agree on what a software agent is, who is running it, and how to keep an eye on it?
In medieval Europe, kings and lords didn't just blindly trust a messenger; they trusted the wax seal of the signet ring pressed into the letter. Today's AI agents are shopping for those exact digital signet rings.
When we swipe a card today, the system assumes a human is standing there. Passwords, text codes, and Face ID all exist to prove human presence. But what happens when the buyer is just a piece of code? It can search, compare, load up a cart, and walk right up to the checkout line.
Merchants need to know: did a real human actually authorize this specific purchase? That is the Permission Gap.
Technologically, agents can already run the marathon of shopping. But trust-wise, the industry is stuck at the finish line, asking, "Who actually approved this charge?"
Right now, everyone has their own fix. Visa has the Trusted Agent Protocol, which bakes identity into the request header. Mastercard has Verifiable Intent, locking the ID and the outcome into an unchangeable record. Ant has its Agentic Mobile Protocol. KYA isn't trying to merge them all overnight. It's just trying to get them to recognize each other.
This might sound like backend payment plumbing, but for merchants, it hits right at home.
First, the traffic is shifting. Reports show AI-driven visits on retail sites are surging. If a store can't tell the difference between a helpful shopping agent and a malicious scraping bot, it will either block real buyers or roll out the red carpet for fraudsters.
Second, the rulebook is broken. Current dispute rules assume a human clicked "buy." If an agent goes rogue and buys the wrong thing, who handles the chargeback? Without a verifiable audit trail, it's just a shouting match.
Third, merchants fear losing control. As the payment giant Adyen recently pointed out, whoever holds the proof of intent holds the customer relationship. If merchants outsource this entire layer, they hand over the keys to their business.
Right now, KYA is just a framework. The technical specs and timelines are fuzzy. That's normal. You need a handshake before you write the code. But the signal is loud and clear: the next big commerce battle isn't just about the digital shelf. It's about identity.
Discovery figures out what to sell. Transactions figure out how to pay. Identity figures out if the sale is even allowed. Skip one, and the whole system falls apart. Without a verified ID, merchants won't open their doors. Without clear recommendations, buyers won't trust bots with their wallets.
The statistician W. Edwards Deming famously said, "In God we trust; all others must bring data." In the world of AI commerce, we can tweak that: Without verifiable data, there is no deal.
AI agents are great talkers. They compare specs instantly and save people hours of scrolling. But before they touch a dime, the industry needs to hand them an ID card. Who sent them? What is their spending limit? Has the authorization expired? What happens if they mess up?
For merchants, the homework is now very clear. Your catalogs must be flawless, because bots make decisions based on hard facts. Your authorization boundaries must be strict, because "buy this for me" doesn't mean "buy anything." And your records must be auditable, because verbal excuses lose to unchangeable data every single time.
At Hasmord, we view this simply. Outwardly, we are a Merchant OS for AI product discovery. We help stores get understood, compared fairly, and recommended by AI. But underneath, we provide what the industry actually lacks: the control layer between the store and the bot. We help merchants know exactly what is happening, and exactly what is allowed to happen.
Agent Connect and KYA don't decide what gets recommended. They do the dirty work. They check the ID before the wallet opens. The digital shelves are fully stocked, but the bouncers are finally at the door.
ID first, pay later. It isn't playing it safe. It's how you scale.
