Advisory | Agentic Commerce

Agentic Commerce Governance

A purchase your software placed still has to bind somebody. Governance is the work of deciding, in advance and in writing, who that is.

The market splits, and the gap is in the middle

Two kinds of firm are selling into agentic commerce and they do not overlap. Implementation agencies cover architecture, protocols, product data and checkout automation, and say nothing about who is bound by a declaration a machine made. Law firms cover attribution, liability and the incoming regulation, and say nothing about distribution architecture or what to build on Monday.

The questions that decide whether an agentic channel is safe to operate sit between them. Who inside the company owns configuration, monitoring and release. How liability distributes along a contract chain that now includes a party with no legal personality. Within what limits an agent may bind the business at all. Where a human approval is not optional. Those are consulting questions and neither camp is positioned to take them.

That gap is what this page is about, and it is why governance is a category rather than a compliance checkbox.

An agent is not an agent in the legal sense

The word invites the wrong model. Agency law assumes a representative who has capacity, who can be instructed, and who can be held to what they did. Software has none of those. Reasoning about an AI agent as though it were a legal representative produces a construction that collapses the first time anyone tests it.

The construction that holds runs the other way. The declaration is not made by the agent at the moment of purchase. It is made by the person who configured the agent, and it is completed when the agent acts inside the frame that configuration set. Attribution therefore runs backwards, from the transaction to the prior configuration, and the decisive moment moves with it.

Everything operational follows from that single move. If the binding decision happened at configuration, then configuration is the thing that has to be scoped, versioned, approved and reconstructible. Not the checkout. This is the six level framework read from the liability end rather than the market end.

The control layer

Agentic commerce is not decided at checkout. It is decided in the layer that governs what an agent may consider, what it may be trusted with, and what it may commit. Execution is being commoditised by open protocols, which strands anyone whose revenue is a percentage of transactions passing through it. What does not commoditise is the layer that sets and evidences the rules.

Four things live there. What the agent is permitted to see at all. Whether a counterparty can be verified. What machine readable context the selection depends on. And who governs and evidences the whole arrangement. Most organisations are exposed across all four and have measured none of them. The detail is in the control layer.

The delegation chain

Between a person buying something themselves and an agent buying autonomously there are not two states but several, and each moves the binding decision one step further from the transaction. A person authenticates and buys. A person instructs and still confirms. A person configures and the agent confirms. A person configures once and the agent transacts repeatedly without returning.

European payment law was written for the first of those. Dynamic linking requires authentication tied to a specific amount and a specific payee, and an agent committed transaction has neither. That is not a gap to be engineered around quietly. It is the point at which a business decides how far along the chain it is willing to operate, and what it will hold as evidence at that position. See the delegation chain.

Auditability

A mandate that cannot be reproduced is not a mandate, it is an assertion. The practical test is whether, six months after a transaction, somebody can produce the scope that authorised it, the version of that scope in force at the time, the person who approved it, and the record of the agent staying inside it. In a form a regulator or a court will accept, rather than in application logs that rotate on a thirty day cycle.

Most organisations discover the answer during a dispute, which is the most expensive moment to discover it. Building the evidence trail is cheap while volumes are low and no revenue depends on it. It is not cheap afterwards. Who audits the agent works through what that trail has to contain.

What regulation adds, and what it does not settle

Regulation governs how a system may be operated. It does not answer who a declaration binds. Those are two different questions and they are routinely treated as one, usually by assuming that a compliance programme covers the contractual exposure. It does not.

The protocols now forming, being the Agentic Commerce Protocol for checkout and merchant integration, the Agent Payments Protocol for authorisation and consent, and x402 for machine to machine settlement, converge on a signed mandate presented at authorisation and logged. That is real progress and it is an interoperability answer rather than a governance one. None of them decides how narrowly your mandates are drawn, what happens to a transaction arriving outside one, or who inside your organisation is accountable for either. Those remain yours.

What follows operationally

Governance stops being abstract at the point where it produces four artefacts. A mandate scope per transaction class, saying what may proceed on a standing authorisation and what requires a fresh one. An exception policy, written before the exception, covering a price above the ceiling, a payee outside the permitted set, an expired mandate, and a good that does not match the intent. An evidence trail that survives the retention period of your logging. And a named accountable person for configuration, monitoring and release.

Three answers exist at the exception and each costs something. Fail the transaction and lose the sale. Escalate to the human and lose the automation. Or allow it inside a wider tolerance and carry the liability. Only one of those can be chosen calmly, and only in advance.

What a mandate produces

An engagement on this ends with documents your own people can defend without us in the room. The autonomy level your market is actually at, established rather than assumed. The mandate scopes and the exception policy, agreed by the functions that will operate them. The evidence architecture, sized to the retention a dispute requires rather than to the retention your logging happens to have. And the accountability, written down with a name against it.

Capability transfer is scoped from the start and the exit is designed before the entry. We will also tell you when the answer is to do nothing yet, which costs us the engagement and is the reason the first step is small.

The way in

Start with the assessment rather than the architecture. Two to three weeks establishes your autonomy level, what a machine can currently see of your catalogue, and where a purchase made by an agent would attach to nobody. Most organisations should stop there until that has been read and argued with internally.

Our positions on all of this are published and checkable before you speak to us. The service page is agentic commerce consulting, and the direct answers to the questions buyers actually ask are in the FAQ.

Start the conversation

We advise companies on agentic commerce, from first assessment through to a defensible implementation decision.

Contact contraco