Two stories are going around about agentic payments, and both feel true. The first: a full stack of primitives, settlement, authorisation, checkout and identity, has shipped faster than most people noticed. The second: the volume figures look large until you strip out the wash activity. Hanging over both is a question nobody has answered: when an agent pays the wrong merchant, or a redirected prompt spends money it should not, who owns the loss?
This is the sceptic’s piece in this series, so we work through it with numbers from TRM Labs, Bernstein, Chainalysis, Visa/Artemis and Morgan Stanley. By the end you should be able to weigh the adoption evidence and make a build-or-skip call on signal quality, not a vendor’s headline. For context, start with AI agent wallets and the agentic commerce landscape.
What payment and identity primitives for AI agents are live right now?
More than you probably think, and the useful split is shipped versus still forming.
x402 revives the dormant HTTP 402 “Payment Required” status code: an agent requests a resource, the server returns a price and asset, and the agent pays in stablecoin in the same request cycle. It settles on Base, Solana and Polygon, is stewarded by the Linux Foundation’s x402 Foundation, and most measured flows settle in USDC.
Stripe’s Machine Payments Protocol (MPP) launched March 2026 with Tempo and introduced the session, a pre-authorised limit that streams micropayments without an on-chain transaction each time. Google’s AP2 launched September 2025 with 60-plus partners and represents each purchase as three signed mandates: Intent, Cart and Payment. The Agentic Commerce Protocol (ACP), open-sourced by OpenAI and Stripe, standardises consumer checkout on fiat rails. Fireblocks’ comparison of the four protocols is the clearest single read on what each solves.
Those four are in production. Know Your Agent (KYA) identity and ERC-8004 on-chain agent identity are real but not yet standardised, and Cloudflare’s cloudflare.pay (pay-per-crawl) is still a private beta. Treat the layers as complementary rather than rivals: settlement (x402, MPP), authorisation (AP2), checkout (ACP), identity and compliance (KYA). Production systems touch more than one, AP2 can route through x402, and Visa has extended MPP onto card rails. The clearest signal that identity is consolidating: Ant International has Visa and Mastercard signed to a shared KYA interoperability effort. We cover how x402 and MPP work and which fits which use case.
That leaves one question to answer: which of these layers does your product actually have to support, and is it ready for that?
How should you assess whether agentic payments are ready for your product?
Readiness is a judgement you make on three signals, and raw transaction volume is the weakest of the three.
The first is adoption quality. Tester-to-payer conversion, the share of wallets that go on to pay a real counterparty, and wallet retention separate curious testers from real payers. Chainalysis found tester-to-payer conversion improved fourfold in six months and wallet retention is trending upward, a sign agentic payments are becoming infrastructure, not novelty.
The second is integration cost. Supporting x402, MPP or AP2 carries real engineering and compliance work, but a 50 to 500 person SaaS or FinTech does not need bank-scale governance. A proportionate frame is clear spending limits and a revocable mandate. For the build-versus-buy side of that call, there is a separate piece on building versus buying on this evidence.
The third, and the one most teams skip, is liability posture. The authorisation and liability vacuum means the readiness decision carries a risk the market has not priced yet, so it belongs inside the assessment, not after it. We go deeper on the liability gap.
Before the risk question can be priced, the demand question has to be settled, which means checking whether the volume is real.
How can you tell whether agent payment volume is real adoption or hype?
TRM Labs published a study on 9 September 2026 finding that about half of the US$52.7 million in measured x402 settlement volume disappears once you remove self-payments, bulk flows from one or two payers, and sellers with fewer than ten buyers. What remains is about US$25.6 million in likely genuine commerce. Bernstein puts agentic commerce below 1% of e-commerce and pegs x402 at roughly US$0.5 to US$1 million in monthly volume, at an average ticket around US$0.20.
Chainalysis traced much of x402’s growth on Base to memecoin farming. PING, a pay-to-mint experiment charging 1 USDC per mint, saw its transaction count spike by over 10,000% in a week and processed more than 150,000 transactions in its first month. Farmers stuck around for a week, pushed retention to 87%, then went dormant and cratered it to 5%. On Base, that traffic is wash.
So watch conversion and retention, not headline volume. You can verify it yourself in the Visa and Artemis report and in Chainalysis’s on-chain adoption analytics, which track settlement across Base, Solana and Polygon. Be honest about the gap: the adjusted figures disagree, Bernstein’s monthly number versus Visa and Artemis’s higher cumulative figure, so triangulate rather than trust any single number. For what the on-chain rail data actually shows, read our piece on x402 and MPP. Strip the wash out and where agentic payments are heading becomes readable, even if the numbers stay unflattering.
Is the real constraint on agentic commerce trust or demand?
Trust. The evidence is short and hard to argue with.
Visa’s research found only 23% of consumers trust AI agents to conduct payment transactions on their behalf. Hold that against the liability vacuum: no jurisdiction owns the loss, and chargeback rules were written for human-speed commerce with one clear order to point to. Demand exists, but it cannot convert while authorisation and recourse are unresolved, so trust binds first.
The demand ceiling is real, but it is a projection, not a fact. Ant International cites US$3 to US$5 trillion of agent-orchestrated consumer commerce by 2030, and Morgan Stanley estimates US$190 to US$385 billion in US e-commerce alone. Morgan Stanley’s more cautious timing view is the counterweight. The lever that unlocks all of it is identity and delegated authority, Know Your Agent and AI assurance, which is the liability gap behind low consumer trust. For the bigger picture, see the agentic commerce landscape.
So where does that leave you?
You stop reading headline volume as adoption and start reading adoption quality and liability posture instead. The teams that treat identity and delegated authority as the actual product are the ones who will be ready when demand unlocks. Zoom out to the wider agentic commerce picture and the same conclusion holds: readiness is a judgement about quality and accountability, not headline volume.
Frequently Asked Questions
What does HTTP 402 actually mean, and why did x402 bring it back?
HTTP 402 is the “Payment Required” status code that has sat unused in the HTTP specification since the 1990s, reserved for a payment layer that never arrived. x402 revives it by embedding stablecoin micropayments directly into ordinary web requests, so a client can pay for a resource in the same round trip it requests it. It settles on Base, Solana and Polygon, and is stewarded by the Linux Foundation’s x402 Foundation.
Do I need to support every protocol, or can I start with just one?
Start with the one layer your product actually touches, because the protocols are complementary rather than interchangeable. A checkout flow might only need the Agentic Commerce Protocol, while a machine-to-machine settlement use case points to x402 or Stripe’s Machine Payments Protocol. Production systems often span more than one (AP2 can route through x402), but you rarely need the full stack on day one. Match integration to the job, not the market map.
What is a signed mandate in AP2, and why should a CTO care?
A mandate is a cryptographically signed record of what an agent is authorised to do, and AP2 uses three of them: Intent, Cart and Payment. Each creates a verifiable trail from the user’s original instruction to the final payment, which is what makes an agent-initiated transaction auditable after the fact. That matters because it is the closest thing today to delegated authority you can defend in a dispute.
Why do most measured x402 payments settle in USDC rather than a traditional currency?
Most x402 flows settle in USDC because it is a stablecoin: it holds a dollar peg, moves on-chain in seconds, and needs no card network or acquirer to clear a small payment. That makes it practical for micropayments where a card fee would exceed the transaction itself. Plenty of measured volume still runs through card rails via Visa and Mastercard, so USDC is the dominant settlement asset, not the only one.
Is agentic commerce only for crypto-native businesses, or can mainstream companies use it?
Agentic commerce is no longer crypto-native. The card rails have entered the space: Mastercard Agent Pay and Visa’s Trusted Agent Protocol bring agents onto existing card infrastructure, and the Agentic Commerce Protocol runs consumer checkout on fiat. A mainstream retailer or SaaS product can adopt agent payments without touching a stablecoin or running an on-chain wallet. The crypto lens is one entry point, and increasingly a minority one.
What happens if an AI agent pays the wrong amount or the wrong merchant?
Right now, that is the open wound. No jurisdiction or standard clearly assigns who owns the loss when an agent-initiated payment goes wrong, a gap the market calls the liability vacuum. The practical answer is to constrain the agent before the fact: clear spending limits, a revocable mandate and signed authorisation, so a mistaken payment stays bounded and traceable. Until liability rules settle, treat recourse as something you engineer.
What is Know Your Agent, and will my business be required to adopt it?
Know Your Agent (KYA) is an emerging identity and compliance layer that verifies an AI agent the way Know Your Customer verifies a person, so a merchant can trust who is transacting. It is not standardised yet, though Ant International has Visa and Mastercard signed to a shared interoperability effort, which points toward consolidation. Adoption is not mandatory today, but it is the layer most likely to carry liability and trust once it matures.
How do I actually measure tester-to-payer conversion and wallet retention?
Tester-to-payer conversion tracks how many wallets that try your agent payment go on to pay again, and wallet retention tracks how many keep transacting over time. Together they separate curious testers from real payers, which raw transaction volume cannot do. Measure both against your own baseline rather than the headline market figure, because that number includes wash activity. Rising conversion and retention are the signals that your demand is genuine.
What is the cheapest way to test agentic payments without bank-scale governance?
Start with a bounded pilot: clear spending limits and a revocable mandate, rather than the governance overhead a bank would carry. A 50 to 500-person SaaS or FinTech does not need enterprise-scale controls to test one protocol on one use case. Pick the single layer that fits your product, cap the exposure, and measure conversion and retention before expanding. Proportionate governance, not heavy compliance, is the sensible first step.
When is agentic commerce likely to reach mainstream adoption?
No one knows, and the honest answer is that it depends on trust mechanics, not technology. Ant International projects US$3 to US$5 trillion by 2030, but that is a projection, not a fact, and Morgan Stanley offers a more cautious timing view. The rails have shipped quickly, yet adoption stays gated behind authorisation and recourse. Expect steady adoption as KYA and delegated authority mature, not a single switch.
How is agentic commerce different from giving an API a stored credit card?
A stored credit card is a fixed credential an application can reuse, while agentic commerce is about an agent holding delegated authority to decide and pay within limits. The difference is authorisation and auditability: agent protocols sign mandates, scope permissions and create a verifiable trail, so you can see what an agent was allowed to do and what it did. That control is what a stored card never gave you, and it is also where the current gaps lie.
What new security risks do AI agent wallets introduce?
Agent wallets concentrate risk in a new place: software, not a person, holds spending authority, so a compromised or misconfigured agent can make valid-looking payments at machine speed. The mitigations mirror the readiness signals, namely scoped credentials, spending limits and revocable mandates, so a single failure stays bounded. Identity layers such as KYA and on-chain credentials like ERC-8004 add a layer of verification. Treat the agent as an untrusted actor that must prove authority every time.