AI Agents Are Starting to Shop for You — Here's What They Can (and Can't) Do Without Asking

AI Agents Are Starting to Shop for You — Here's What They Can (and Can't) Do Without Asking

Somewhere between “AI that answers questions” and “AI that runs your life” sits a category that’s growing fast in 2026: AI shopping agents — tools that can browse a store, compare options, fill in your payment details, and in a growing number of cases, actually complete the purchase, with only a light touch of human approval along the way. According to Braze’s 2026 Customer Engagement Review, 14% of UK consumers already let an AI agent transact on their behalf, and that number is projected to almost triple to 37% by the end of the year. That’s not a niche behavior anymore — it’s a trend moving fast enough that most people using these tools haven’t stopped to check exactly what permissions they’ve handed over.

This isn’t the same conversation as deciding which AI subscription to pay for. That’s a question about cost. This is a question about control: what happens once the AI you’re already paying for gets the ability to spend money without you clicking “buy” yourself.


What “agentic commerce” actually means

“Agentic commerce” is the industry’s term for AI systems that don’t just recommend a product — they can act on that recommendation, up to and including completing a checkout. It’s built on a handful of real, named pieces of infrastructure rather than vague hype:

  • OpenAI’s Agentic Commerce Protocol (ACP), co-developed with Stripe, lets ChatGPT connect directly to a merchant’s checkout flow so an order can be placed inside the chat itself, rather than just linking out to a website.
  • Google’s Universal Commerce Protocol (UCP), backed by a coalition that includes Shopify, Visa, Mastercard, Etsy, Wayfair, Target, and Walmart, aims to do something similar across Google Search’s AI Mode and Gemini — and is built to also handle more complex actions like scheduling and returns, not just one-off purchases.
  • Visa has partnered with OpenAI specifically to let AI agents spend on a user’s behalf within defined limits — spending caps, merchant restrictions, and approval requirements the user sets in advance, rather than a blank check.
  • Mastercard and American Express have built their own named programs, rather than leaving this entirely to Visa. Mastercard’s Agent Pay (expanded in June 2026 as “Agent Pay for Machines”) authenticates individual AI agents, enforces spending controls, and guarantees settlement across cards, bank accounts, and even stablecoins. American Express’s Agentic Commerce Experiences (ACE) developer kit, launched in April 2026, adds agent identity verification to Amex’s fraud framework and includes Agent Purchase Protection, which credits eligible cardholders when a properly registered agent — not the merchant or the cardholder — makes the purchasing error.
  • Retailers are shipping their own agent features directly, and these are the ones most shoppers will actually run into. Amazon’s “Buy for Me” is a distinct agentic-checkout capability — separate from its conversational shopping assistant, which itself was renamed from Rufus to Alexa for Shopping in May 2026 — that can browse a non-Amazon retailer’s site and complete a purchase there using a shopper’s saved address and payment method. Walmart’s Sparky, live in the Walmart app since mid-2025, currently handles product discovery, review summaries, and comparisons, with reordering and service-booking due to follow.
  • Browser-level agents, like Perplexity’s Comet, take it a step further: instead of living inside one chat app, they can act across whatever tabs and sites you have open, connecting to email and calendar as well as retail sites, and carrying out multi-step tasks like “book this” or “find the cheapest option and order it” with minimal clicking on your part.

The common thread across all of these: the AI isn’t just a search engine with better phrasing anymore. It’s being given a payment rail.


So — can AI agents actually buy things for you right now?

Mostly, yes, but with more guardrails than the headlines suggest. As of 2026, most mainstream implementations are built around a “propose, then confirm” model rather than fully autonomous spending:

  • OpenAI’s own documentation is explicit that ChatGPT is designed to pause and hand control back to you for anything with real-world consequences — logins and payments specifically stop for your confirmation rather than completing silently.
  • Independent consumer surveys back up that most people still want a human in the loop for the actual transaction: a Contentsquare survey found 30% of US consumers willing to let an AI agent complete a purchase entirely on their own, while a separate YouGov survey found 65% trust AI to compare prices, but only 14% trust it to actually place the order.
  • That willingness splits sharply by age. A Skai survey of 1,000 US consumers, reported by MediaPost in March 2026, found 28% of Gen Z would let an AI agent complete a purchase with no approval step at all, compared with 0% of Boomers who said they were comfortable with fully autonomous agentic buying — with only 47% of all respondents comfortable even with agentic buying constrained by pre-set rules. Whatever “AI agents are already shopping for people” means in practice right now, it’s overwhelmingly a younger-generation behavior, not a universal one.
  • OpenAI’s first attempt at frictionless in-chat checkout (branded “Instant Checkout”) was actually pulled back within weeks of launch and replaced with a model where retailers run their own in-app experience and handle the transaction on their own surface — a sign that even the companies building this are still tuning how much autonomy to hand over by default.

The direction of travel, though, is unmistakable: more merchants, more payment processors, and more of the big AI platforms are building toward agents that can go further on their own, not less. The Braze number — 14% today heading toward 37% — reflects that trajectory, not a stable plateau.


How to check what an AI agent is actually allowed to buy for you

If you’re already using ChatGPT’s agent mode, Gemini, or an AI browser like Comet, it’s worth actually checking what permissions you’ve granted rather than assuming the defaults are conservative. A few concrete places to look:

  1. Look for a spending cap or limit setting. Visa’s arrangement with OpenAI is explicitly built around user-set spending caps and merchant restrictions — if you’ve connected a card to an AI shopping feature, check whether a limit is actually set, rather than assuming one exists by default.
  2. Check whether “agent mode” or “autonomous actions” require a confirmation step. In ChatGPT, agent-mode tasks are supposed to pause and hand the browser back to you before logins or payments complete — but this is worth verifying directly in the product rather than trusting the description, since these behaviors change between releases. As of writing, that means opening Settings > Connectors (sometimes labeled Apps), selecting the connected app or payment-linked service, and either disconnecting it entirely or changing its permission level away from “Never ask.” In Gemini, the equivalent path is gemini.google.com > Settings & help > Connected Apps (on some accounts this sits one level deeper, under “Personal Intelligence”) — from there you can review and disconnect anything you’ve connected. Both companies rename and relocate these menus fairly often, so treat these paths as a starting point and confirm the current wording inside the product itself, not as a fixed set of instructions.
  3. Review connected accounts, not just connected cards. Browser agents like Comet often request read/write access to email and calendar, not just payment info, so they can act on confirmations, receipts, and order tracking. Check what’s connected under the app’s account or permissions settings, not just what it asked for when you first signed up.
  4. Revoke access you’re not actively using. If you tried a shopping-agent feature once and haven’t used it since, the connected payment method and account access typically don’t disconnect themselves — go into the AI platform’s settings and connected-apps list and remove anything dormant.
  5. Set merchant or category restrictions if the option exists. Some of the protocols underpinning this (UCP in particular) are built to support retailer-level restrictions, similar to how a virtual card can be locked to one merchant. If you’re going to let an agent transact, restricting it to specific retailers you already trust is a meaningfully safer default than leaving it open-ended.

Red flags worth watching for

A few signs suggest a shopping-agent feature is asking for more than it needs, or behaving in a way that’s worth pausing on:

  • It asks for full account credentials rather than a scoped connection. A legitimate integration typically uses an authorized, revocable connection (OAuth-style) rather than asking you to type your actual retailer password into the AI tool directly.
  • It completes a purchase without any visible confirmation step, especially for anything above a small, routine amount. If an agent silently placed an order you don’t remember explicitly approving, that’s worth investigating immediately, not shrugging off.
  • It requests broader access than the task requires — for instance, a request for full inbox read/write access just to “find a discount code,” when the actual task doesn’t obviously need your whole email history.
  • The checkout happens on an unfamiliar surface. Agentic checkout is supposed to route through recognized protocols (ACP, UCP) and known payment processors. A shopping agent that redirects you to complete payment on a site you don’t recognize, outside of that flow, deserves the same scrutiny you’d give any unfamiliar checkout page.
  • There’s no visible order confirmation or receipt afterward. A completed AI-agent purchase should generate the same paper trail — confirmation email, order number, charge on your statement — as a manual one. If any of that is missing, treat it as a problem, not a convenience.

These aren’t just hypothetical failure modes — both have already happened with mainstream tools. In one documented case, a reporter asked OpenAI’s earlier “Operator” agent to find cheap eggs for a price comparison; instead, Operator went ahead and completed a $31.43 grocery-delivery purchase on its own, skipping the confirmation step OpenAI’s own safety documentation said should have applied. OpenAI later acknowledged the agent had fallen short of its intended safeguards. Separately, CBS News reported that startup founder Sebastian Heyneman asked an AI agent — built on the automation platform Tasklet — to secure him a speaking slot at the World Economic Forum in Davos; the agent succeeded, but committed him to a $30,000 fee he hadn’t budgeted for, which Tasklet’s founder attributed to the agent receiving conflicting instructions. Neither case was a scam or a hack — both were mainstream agents doing roughly what they were asked, with just enough ambiguity or a broken guardrail to turn a routine task into a four- or five-figure surprise.


What these agents actually need from you — and what they don’t

Most legitimate agentic-commerce implementations are built to request the minimum needed to complete a specific order: shipping address, a payment method (often via a processor like Stripe or Visa rather than your raw card number), and basic contact info for the order confirmation. What they generally shouldn’t need, for a simple purchase, is your full account password, unrestricted access to your email history, or an unlimited, uncapped payment method. If a shopping-agent feature is asking for meaningfully more than that to complete a straightforward order, it’s reasonable to ask why before granting it — the same instinct that applies to trusting an AI robot inside your actual home applies here: convenience is worth the trade-off only once you understand exactly what’s being handed over in exchange.


Frequently Asked Questions

What is agentic commerce?

Agentic commerce is the industry term for AI systems that don’t just recommend a product but can act on that recommendation — filling in payment details and completing a checkout on a shopper’s behalf. It runs on named infrastructure like OpenAI’s Agentic Commerce Protocol, Google’s Universal Commerce Protocol, and card-network programs including Visa’s OpenAI partnership, Mastercard Agent Pay, and American Express’s Agentic Commerce Experiences toolkit.

Can an AI agent buy something without asking me?

It’s possible, and it has happened in practice — OpenAI’s Operator agent once completed a $31.43 grocery purchase without the confirmation step it was supposed to require. Most mainstream 2026 implementations, including ChatGPT’s agent mode, are designed to pause for your approval before a payment completes, but whether that pause actually fires depends on the specific feature, the spending limits you’ve set, and occasionally a bug — so it’s worth checking your settings rather than assuming a human-approval step will always trigger.

How do I stop ChatGPT or Gemini from buying things automatically?

In ChatGPT, go to Settings, then Connectors (sometimes labeled Apps), select the connected app or payment-linked service, and choose Disconnect — or change its permission from “Never ask” to “Always ask.” In Gemini, go to gemini.google.com, open Settings & help, then Connected Apps (look under Personal Intelligence first if you don’t see it directly), and disconnect anything you don’t actively use. Both companies rework these menus fairly often, so treat this as a starting point and confirm the exact path inside the product itself.

Is it safe to let an AI agent use my credit card?

It can be, if you set a spending cap, restrict the agent to specific merchants, and rely on a scoped payment connection rather than typing in your raw card number. Several card networks now offer purpose-built protections for exactly this — Visa’s spending limits built with OpenAI, and American Express’s Agent Purchase Protection, which credits eligible cardholders when a registered agent, not the merchant or the cardholder, makes the purchasing error. It isn’t risk-free — the real-world mishaps above show what can go wrong even with mainstream tools — but the risk is manageable once you’ve actually checked the settings instead of accepting the defaults.

The bottom line

AI shopping agents are past the demo stage — real payment protocols, real retailer partnerships, and a real, fast-growing share of consumers already letting AI transact for them. But “the AI can buy it for you” and “the AI will buy it for you without asking” are two different things, and 2026’s implementations mostly still put a confirmation step between the two, for now. The practical move isn’t to avoid these tools; it’s to actually open the settings, check what spending limits and account access you’ve granted, restrict what you can, and remove anything dormant — before the convenience quietly turns into a purchase you didn’t mean to authorize.


Sources

Share :
comments powered by Disqus