Blog · Agentic commerce

Agentic Commerce News — July 2026 Roundup

What happened in agentic commerce and agent payments through late July 2026: the UK Treasury consultation on agentic payment liability, the EU AI Act disclosure rules, the x402 Foundation launch, the first verified volume figures, and the guardrails card networks and PSPs actually shipped.

Updated July 28, 2026 · 16 min read

Every two weeks, this roundup collects what actually happened in agentic commerce — payment protocols, card networks, infrastructure and regulation — filtered for the people responsible when an AI agent spends money. Same URL every edition: bookmark it.

New to the space? Start with our pillar guide: What is Agentic Commerce? The Complete 2026 Guide.

Edition 2 — covering July 9 – 28, 2026. The previous edition is kept below.

Regulators got there first

The surprise of this window: the most consequential news wasn't a product launch. Three governments and a prudential regulator moved on agent payments inside two weeks, and one of them starts biting in days.

HM Treasury puts agentic payments — and liability — out for consultation

On July 14 HM Treasury published Modernising Payment Services Regulation, with a dedicated section titled "Leading the world in agentic payments" (paragraphs 3.30–3.35). It states plainly that "the PSRs were designed before the development of AI and may not fully facilitate the use of agentic AI", and describes agentic AI being used to "autonomously analyse, initiate, approve, and execute payments on behalf of consumers or firms". Then it asks the question the industry has been avoiding:

Question 15: How does existing payment services regulation need to adapt to support agentic payments? For example, do provisions relating to authentication and consent of payments transactions, and liability for unauthorised payment transactions, need updating?

The consultation closes at 11:59pm on October 6, 2026 (HM Treasury).

Why it matters: a national treasury is formally asking who pays when an agent makes a payment nobody authorised. Until that answer exists, the default answer is you.

The same day: "Know Your Agent" becomes a high-priority recommendation

Also on July 14, HM Treasury published its Financial Services AI Adoption Plan. Recommendation 10 — marked Priority: High — calls for a trust framework for agentic payments built on three pillars: legal and liability frameworks that "unambiguously assign accountability when autonomous agents transact", standardised "Know Your Agent" (KYA) identity and verification protocols built specifically for autonomous software agents, and interoperable technical standards for machine-to-machine authentication. The plan records that firms report "significant uncertainty around legal and regulatory accountability, including liability and consent" (HM Treasury).

Brussels: your agent must say it's an agent, and who it works for

On July 20 the European Commission approved guidelines on the Article 50 transparency obligations of the AI Act (C(2026) 5054 final). Paragraph 31 of the annex brings agents squarely into scope when they execute tasks like "making bookings, managing correspondence, negotiating or concluding contracts, executing purchases", and requires that they be built so that:

AI agents must be designed and developed in such a way that they disclose both their artificial nature and the person on whose behalf they are acting, considering the need for transparency of the origin and the delegation of authority and accountability for the consequences of their actions.

It goes further on timing: agents "should also disclose themselves, to the persons instructing them at key steps (e.g. at the point of authorisation, reporting, validation etc.)". Article 50 applies from August 2, 2026 (Commission press release, guidelines annex).

Why it matters: this is the only binding obligation in the window, it lands in days, and it attaches to the exact moment your agent's spend gets authorised. "Disclose on whose behalf you act" is an identity and delegation requirement wearing a transparency label.

Canada publishes the control list

Canada's prudential regulator OSFI issued a Technology Risk Bulletin on generative and agentic AI (dated July 2026). Its section on controlling agent autonomy asks institutions to "assign unique non-human identities, enforce least privilege, apply scoped permissions, and use just-in-time access with short-lived credentials", to "restrict tool usage via allow-lists and API gateways and apply approval checkpoints for high-impact actions", and to log and review agent activity (OSFI). Worth the scope caveat: the bulletin is framed as sound practices, and the words payment, transact and spend do not appear in it — it governs agents inside financial institutions, not agent commerce.

Why it matters: it's the most actionable checklist published in the window, and it maps almost line for line onto what governing agent spend requires: identity per agent, least privilege, short-lived credentials, allow-lists and approval checkpoints on high-impact actions.

x402 gets a neutral owner — and a card-acceptance working group

On July 14 the Linux Foundation announced the operational launch of the x402 Foundation, with Coinbase's contribution of the protocol complete. Forty organisations joined across three tiers; the 17 Premier members include Visa, Mastercard, American Express, Stripe, Adyen, Fiserv, Shopify, Circle, Cloudflare, Google, AWS, Ripple and the Solana, Stellar and Monad foundations (Linux Foundation).

The governance detail is more informative than the member list. The Foundation's Technical Steering Committee repo went up on July 10 with biweekly open meetings and four working groups: Domain Discovery, Identity, Tax and Card Acceptance (x402-foundation/tsc). The canonical protocol repo now lives at x402-foundation/x402, with coinbase/x402 marked as the fork.

Meanwhile the spec itself kept moving without a version bump: July merges added an exact scheme proposal for Starknet, an upto scheme for SVM, a signer authorisation clarification in the offer-receipt extension, and hardening of SIWX domain binding, plus reference implementations and facilitators for XRPL and NEAR (commit history). The specs/ directory still contains only v1 and v2 — there is no v3.

Why it matters: x402 stops being one vendor's project, which changes the lock-in calculus when you pick a facilitator. And a Card Acceptance working group signals x402 is preparing to settle on card rails, not only stablecoins, while a Tax working group is the first hint that machine-to-machine payments will carry tax obligations someone has to compute. New chains and facilitators also mean more places your agent could end up paying — decide explicitly which ones you enable. Background: our x402 protocol guide.

The first hard numbers — and the ones that don't add up

On July 14 Visa published "Agentic payments from the ground up" with Artemis. The figures: x402 has done roughly $15.0 million in adjusted volume across 109.6 million transactions since its May 2025 launch, and the Machine Payments Protocol settled about $25,000 across roughly 115,000 transactions in its first weeks after launching in mid-March 2026. The totals exclude identified wash and test activity, and the on-chain data cutoff is April 21, 2026 (Visa).

Treat other volume figures carefully. CoinDesk reported on July 15 that x402 moved some 75 million transactions worth $24 million in the previous 30 days (CoinDesk), which doesn't reconcile with a cumulative 109.6 million at an April cutoff. The third-party dashboard agenteconomy.to shows a different series again, and warns its own counts include tests and infrastructure traffic. Visa/Artemis is the only series published with a stated methodology and cutoff.

Why it matters: do the division. x402's average ticket is a fraction of a cent — today this is machine micropayments, not consumer carts. Size your per-transaction limits for extreme frequency and tiny amounts, and distrust any volume number that won't state its methodology.

The controls ship as "a human has to click"

Every guardrail that shipped this window put a person in the loop.

  • Airwallex released AgentOS in early access (July 13–14), letting agents operate an Airwallex account through a CLI or MCP servers, with five packaged skills. The control is explicit: "every money-out action stays behind a ledger-level check that requires a human to confirm it first". Note the scope — this is an agent operating your own account, not agent-initiated checkout, and Airwallex's Agentic Commerce Suite is still waitlist-only (Airwallex, developer guide).
  • HSBC UK and Visa completed what HSBC calls an industry-first end-to-end agentic transaction with one of its cards on a live merchant site (July 14), on Visa's agentic infrastructure with biometric authentication. No merchant is named, no pilot or GA status is declared, and the only timing given is "soon" (HSBC).
  • Thredd joined Visa's Agentic Ready Programme (July 15) to let European issuers support agent-initiated payments, describing "specialised tokens scoped to agents, with the permissions and controls an agent transaction requires", fraud rules tuned for "execution drift and abnormal velocity", and Zilch as among the first issuers. No timeline, no named merchants (Business Wire, PYMNTS).
  • Corpay introduced Agent Card (July 28) — virtual card creation for AI-driven commerce workflows, with "authentication, spend intent authorization, and open standards for AI connectivity". The release names no partners and no card network, and does not say the capability is available today (press release).

Why it matters: the pattern is consistent and it's the honest state of the art — the industry's answer to "how do we keep agents from overspending" is still a human approval, one provider at a time, in one provider's dashboard. That works until you have twenty agents across four providers, and then the approvals themselves become the bottleneck and the audit gap.

Nobody has agreed who is liable

  • The Emerging Payments Association Asia launched an AI & Agentic Payments Working Group with HSBC as founding member (July 20), stating that "there is currently no agreed standard across APAC for who is liable when an AI agent exceeds its mandate… or how disputes are resolved when software, not a person, initiated the transaction". Formal policy recommendations are scheduled for November 2027 (EPAA, PDF).
  • The U.S. Payments Forum published Agentic Commerce: A Primer for the Payments Industry (July 22), introducing AIT (agent-initiated transaction) alongside the familiar CIT and MIT models, and covering delegated authority, consent and prompt injection. It explicitly declines to prescribe a single approach (US Payments Forum).
  • France's Autorité de la concurrence devoted part of Avis 26-A-05 (July 17) to commerce agentique, inventorying the competing payment protocols — UCP, ACP, A2A, AP2, x402, Mastercard Agent Pay, Visa's Trusted Agent Protocol — and recommending against ad hoc regulation for now: apply existing law, prefer soft law, and handle any normative change at EU scale (Avis 26-A-05, PDF).
  • A-Comm Technologies opened public comment (July 20, window closing August 14) on a draft Evidence Protocol that turns eight stages of an agentic transaction into artifacts in a tamper-evident hash chain, sealed at authorisation and exportable for disputes. Worth knowing what it is: a private company founded by former Visa executives, not a standards body, with a repo created in July (PR Newswire, repo).

Why it matters: an industry body has now put in writing that nobody knows who eats the cost when an agent exceeds its mandate, and the formal answer is scheduled for 2027. Notice also what's missing from every major protocol: none of them defines the evidence record you'd need to dispute a charge your agent made. Whatever the standard turns out to be, the log has to exist first — and that's on you.

Money and platforms

  • Ramp shipped AI token spend controls to GA (July 16) covering Anthropic, OpenAI, Gemini and Cursor: soft and hard limits per user or API key, anomaly alerts, and breakdowns by provider, model, user, key, project and team. It's API spend, not agent-initiated card payments — but it's the same instinct arriving one layer down (Ramp).
  • Coinbase Business can now accept agent payments over x402, settling in USDC, alongside an acceptance SDK for APIs and MCP servers (reported July 23). We could not reach a primary Coinbase post — coinbase.com returned 403 — so this rests on secondary reporting (CoinDesk). If you route agent spend there, note what a chargeback-free rail means when you're the payer.
  • ESW launched agentic commerce inside Microsoft Copilot for US brands (July 21), with Copilot as the first integration and no Microsoft statement in the release (PR Newswire).
  • A shopping agent lost its affiliate access. Following a Bloomberg investigation, the shopping app Phia was accused of overwriting third-party affiliate codes during checkout, and affiliate platform Impact.com suspended it (July 10). Phia said it made the necessary changes (TechCrunch). The door that closes on an agent isn't only technical or legal — it can be commercial, and it closes fast.
  • Anthropic shipped Claude Opus 5 (July 24) at $5/$25 per million input and output tokens, leading on the OSWorld 2.0 computer-use benchmark — with no mention of payments, checkout or commerce (Anthropic). Model providers keep making agents better at operating retail sites without shipping any layer that governs what those agents spend.

What's circulating that isn't true

Roundup season produces confident errors. Four we checked and can rule out:

  • "Anthropic is a member of the x402 Foundation." It appears in none of the three membership tiers in the Linux Foundation announcement.
  • "ACP shipped a release candidate on July 28." That's a conflation with the MCP spec. ACP's latest dated spec remains 2026-04-17, and its repo saw exactly one merge in this window — an optional product-URL field on checkout items (PR #281).
  • "The x402 Foundation launched in April." April was the intent to launch; the operational launch with the contribution completed is July 14.
  • "x402 did 75 million transactions in a month." See above: it doesn't reconcile with the only figures published with a methodology.

What did not happen

Verified negatives, because a roundup that only lists announcements distorts the picture:

  • No card network issued an agentic tokenisation mandate, dispute or chargeback scheme for agents, or an agent certification programme in this window. The only tokenisation detail is descriptive, inside a processor's announcement.
  • Mastercard made no agentic announcement of its own, appearing here only as an x402 member.
  • AP2 shipped nothing, and ACP has been effectively dormant since April.
  • MCP still has no payment primitives. The 2026-07-28 revision — a release candidate at the time of writing — makes the protocol stateless by removing the session handshake and Mcp-Session-Id, with no HTTP 402, monetisation or billing anywhere in it (MCP blog). If you meter or charge for tool calls, that state is yours to keep — and losing the session id means moving your counters somewhere else.

The thread this edition

Last edition, the rails arrived. This edition, the rulebooks started being written — and every one of them asks the same two questions: who authorised this, and who pays when it goes wrong. HM Treasury asks it as consultation Question 15. Brussels answers half of it by requiring agents to declare on whose behalf they act, from August 2. OSFI answers it as a control list. APAC's answer is scheduled for 2027.

What nobody is shipping is the part that makes any of those answers operational: one place where every agent's spend attempt is checked against a budget before it's signed, and recorded afterwards in a log you could hand to an auditor — or to a disputes process that doesn't exist yet. Today that lives in as many dashboards as you have providers.

Start here: What is Agentic Commerce? · x402 Protocol · AI Agent Wallets


Edition 1 — covering June 1 – July 9, 2026.

Card networks put agents on the rails

Visa plugs its network into ChatGPT — and ships an agent trust stack

At its Payments Forum on June 10, Visa announced a collaboration with OpenAI to embed the Visa network inside ChatGPT, letting agents search, recommend and buy across roughly 175 million Visa-accepting merchant locations (Digital Commerce 360). Users link a card; transactions run on tokenized Visa credentials with real-time authorization, spending limits, approved merchant categories and human-approval checkpoints. The same day, Visa unveiled three supporting tools: Agent Score (rates how agent-ready a merchant site is), an Agentic Directory of Visa-verified agents and merchants, and a Large Transaction Model for fraud detection. No launch timeline or participating merchants were disclosed.

Why it matters: the largest card network is putting agent-initiated spend on existing rails with native guardrails. If your agents buy things, Visa's registry and scoring stack could become a de facto gate on whether their transactions get authorized.

Mastercard launches Agent Pay for Machines

On the same June 10, Mastercard extended its Agent Pay program with Agent Pay for Machines (AP4M) — a multi-rail service for autonomous, high-frequency, low-value payments between AI agents and machines, down to microtransactions worth fractions of a cent (Finextra, Mastercard IR). Four capabilities: agent credentialing via "Verifiable Intent", permissioning (authorization rules and spend limits), transacting, and guaranteed settlement across cards, accounts and stablecoins. The 30+ initial participants include Adyen, Ant International, BVNK, Checkout.com, Cloudflare, Coinbase, Stripe and Tempo.

Why it matters: continuous background machine-to-machine spend is exactly the gap card rails have had for agents — and agent identity plus permissioning at the network level is infrastructure you'd otherwise build yourself.

The edge starts charging your agents

AWS ships x402 payments in CloudFront and WAF

Live since June 15: AWS integrated Coinbase's x402 protocol into CloudFront and AWS WAF (BanklessTimes, InfoQ). Publishers configure payment actions in WAF Bot Control rules, so AI agents hitting their sites or APIs get an HTTP 402 response and can pay per request — settling in USDC on Base and Solana within a few hundred milliseconds via Coinbase's x402 Facilitator, at no extra charge beyond standard WAF pricing.

Cloudflare opens a waitlist for its Monetization Gateway

On July 1, Cloudflare announced a Monetization Gateway that lets customers charge for any protected asset — web pages, datasets, APIs or MCP tools — using x402, with payment rules written like WAF expressions and enforced across its network in 330+ cities (Cloudflare blog). Pricing and launch date are not yet disclosed. For scale context, Coinbase's x402 year-one report (per InfoQ) claims 169M+ payments across 590K buyers and 100K sellers.

Why it matters: the two biggest edge networks just made 402 Payment Required a normal response your agents must handle. Budget logic, wallets and receipts are becoming table stakes in agent HTTP clients — and notably, neither AWS nor Cloudflare has yet addressed seller-side tax or invoicing for paid agent traffic.

Stablecoins consolidate behind "Open USD"

On June 30, Open Standard — an independent company led by Bridge co-founder Zach Abrams — unveiled Open USD (OUSD), a dollar-backed stablecoin governed by a consortium of 140+ banks, networks and tech firms, including Visa, Mastercard, Stripe, Coinbase, BlackRock, BNY, Google, Shopify, Ripple and Solana (PYMNTS, Yahoo Finance). Partners share reserve earnings, minting and redemption are zero-fee, and native issuance starts on Solana with go-live planned for later in 2026. Circle's stock reportedly fell about 16% on the news.

Why it matters: stablecoins are the leading settlement asset for agent-to-agent and pay-per-call payments. The incumbents consolidating behind a shared coin makes "which stablecoin does your agent stack settle in" a strategic choice this year.

PSPs pitch themselves as the universal translator

Adyen launches "Adyen Agentic"

June 16: Adyen announced a modular API suite for selling through AI platforms (Adyen press release) — Agentic Feed (real-time catalog, pricing and availability data for AI surfaces), Agentic Cart (connects existing checkout, tax and fulfillment to conversational platforms) and Agentic Payments (authentication, token portability and risk for agent-led transactions across protocols). Early ecosystem partners include Amex, Mastercard, Salesforce and Visa; launch is limited availability for US enterprise merchants.

PayPal powers the UK's first agentic commerce launch

June 2: Hey Savi, an AI fashion-search app, launched what PayPal calls the UK's first agentic commerce experience with native in-app checkout, powered by PayPal's agentic commerce services (PayPal newsroom). Debenhams Group (Debenhams, Karen Millen, Boohoo, PrettyLittleThing) is the first retail adopter, exposing product data to AI platforms through PayPal's merchant-to-AI connectivity.

Why it matters: the PSP-as-middleware model is going live — merchants plug into one payments provider and become shoppable across AI agents instead of integrating each agent platform directly.

Courts and regulators enter the chat

Perplexity v. Amazon: appeals court sounds skeptical

On June 11, Perplexity asked the US Ninth Circuit to lift the March 2026 preliminary injunction that blocks its Comet shopping agent from logging into Amazon and buying for users (Bloomberg Law, Courthouse News). Perplexity argued its agents act with user authorization, like a browser; the panel reportedly pushed back on the analogy.

Why it matters: this is the leading US test case on whether a user's authorization lets an agent access a merchant that says no — the outcome will shape terms-of-service risk for any agent that shops on third-party platforms without a formal integration.

The FCA sketches how it will supervise transacting agents

On June 24, FCA chief executive Nikhil Rathi addressed agentic systems — "systems that don't just support financial decisions, but coordinate and transact" — in a speech on rethinking regulation for the age of AI (FCA). He stressed clear accountability for regulated activities with human oversight, supported by the FCA's Supercharged Sandbox and AI Lab.

Why it matters: the clearest signal yet from a major financial regulator. Accountability and human-override expectations are on track to become compliance requirements for agent deployments anywhere near financial services.

The money keeps flowing

  • Ramp raised a $750M Series F at a $44B valuation (June 4), pitched on managing corporate AI token spend and a deepened Visa partnership that lets AI agents execute corporate payments with real-time controls (PR Newswire, TechCrunch).
  • Airwallex raised a $320M Series H at $11B (June 25) to fund autonomous finance and agentic commerce products — per CNBC, including a consumer wallet that lets AI agents make purchases within agreed limits (Business Wire, CNBC).

Why it matters: CFO-grade guardrails for agent spending is now a funded, mainstream category — spend management is becoming the natural control plane for agent budgets.

Protocol chess: the backdrop

Three moves from just before this window that the June news responds to:

  • Google expanded UCP (Universal Commerce Protocol) at I/O and Marketing Live in late May: Universal Cart across retailers via Google Pay in AI Mode and Gemini, BNPL via Affirm and Klarna, and — notably — Amazon, Meta, Microsoft, Salesforce and Stripe joining the UCP Tech Council (Google, Search Engine Land).
  • Google donated AP2 to the FIDO Alliance (April 29) to keep the Agent Payments Protocol platform-agnostic; v0.2 adds pre-authorized "human not present" transactions (FIDO Alliance).
  • OpenAI sunset its original Instant Checkout on March 5 and shifted toward app and storefront-based commerce, with Shopify's "agentic storefronts" handling purchases inside ChatGPT (Modern Retail).

Quick hits

  • x402 reportedly landed on Injective, letting agents pay chain fees and services natively (KuCoin).
  • Amazon began offering its Agentic Shopping Assistant tech to outside retailers (~May 27; early customer: Kate Spade), with Accenture citing a $3.1T agent-commerce projection by 2030 (GeekWire).
  • April, for the record: Agentic.market launched an "app store" of pay-per-use x402 services for bots (The Block); Stockholm's SolvaPay raised €2.4M for AI-agent transaction guardrails (FinTech Global).

If your agents spend money, here's the thread

Every layer of the stack — card networks, edge infrastructure, PSPs, stablecoins — shipped agent-payment rails this quarter. And every one of these announcements carries the same fine print: spending limits, permissioning, human approval, audit. The rails are arriving faster than the controls that are supposed to sit on top of them, and those controls are fragmenting across a dozen providers. Whoever runs agents in production ends up owning that reconciliation problem.

Next edition: mid-August 2026. This page is updated in place — same URL, fresh news.