Reference

Agentic Commerce and AI Transformation: Questions Answered

Direct answers on agentic commerce, autonomous buying, the Resonance Method and AI transformation, from a consultancy that has worked on both sides of the problem since 1998.

How autonomous buying changes who decides, who is visible, and who is liable.

What is agentic commerce?

Agentic commerce is purchasing where software makes the selection and completes the transaction, and the human sets the conditions in advance rather than clicking the final screen. It is not a chatbot that recommends products and hands you to checkout. The distinguishing test is whether a person confirms the specific purchase or only configured the frame it happened inside. That distinction matters commercially, because everything a business earns from the moment of comparison is exposed once the comparison moves off its interface. It matters legally, because the decisive moment moves backwards from the transaction to the configuration.

Is agentic commerce actually happening or is it a forecast?

It is happening, at small volume. European agentic purchasing left pilot status during 2026, travel first. What is missing is not the technology but the distribution. That is precisely what makes the current period useful: while volumes are low, restructuring costs little and no revenue is lost during the work. Once volumes rise, the same restructuring happens under pressure, with live business and visible margin loss. The difference between those two situations is not technical. It is the date on which the decision was taken.

Will AI agents still visit our website?

Not where an interface exists that serves them better. An agent evaluating a purchase requests availability, price and conditions through APIs and compares them mechanically. Your page is a detour with worse data access. This does not threaten your site as a brand asset. It threatens your site as where the decision happens. If your margin depends on a person comparing options on your screen and buying there, you lose that step. If your margin comes from inventory, buying power or product quality, you do not. The question is not whether your site survives, but whether your revenue lives in the interface or in the product.

Why does our analytics not show any of this?

Because agentic traffic does not arrive labelled. It resolves into the same channel buckets you already report, direct, referral and organic, so a shift in who is deciding appears as ordinary variation. There is no rejection notice and no lost-deal report. What declines is your share of recommendations, and no standard reporting surface measures that. The practical consequence is that the first reliable signal most businesses receive is a structural gap that has already opened, at which point competitors have built their data and context advantage and it is showing up in recommendations.

Who is liable when an agent buys the wrong thing?

The purchase is attributed to the person who configured the agent, but only as far as it stayed inside the frame they set. The mandate is not formed at the moment of the transaction. It begins when the user establishes budget, scope, conditions and counterparties, and completes when the agent acts within that corridor. Action outside the corridor is not attributed on the same basis. For merchants the operational consequence is blunt: the configuration must be reconstructible after the fact. A business that cannot show which frame applied at the time of purchase loses the dispute for documentary reasons rather than legal ones.

Who audits the agent itself?

Nobody, currently. Payment infrastructure verifies that a transaction occurred and that a mandate existed. It does not verify whether the agent acted well for the person who deployed it. Those are different questions with different answers, and only the first has been built. An agent that selects the more expensive option, fails to recognise a supplier conflict of interest, or optimises against the wrong objective produces a clean audit trail and a bad outcome. This gap will become visible first in regulated industries, where the obligation to explain a decision already exists independently of how the decision was made.

How does an agent actually execute a payment?

Not through the rails you already run. Card and account infrastructure was designed around human friction, a person present, a device recognised, a moment of confirmation, and an agent has none of those to offer. What replaces them is a separation between negotiating a purchase and executing it, with authorisation issued in advance as a programmable instruction rather than granted live. That instruction has to be verifiable by the receiving party, which is why this turns into a certificate problem rather than a payments problem. Knowing your customer becomes knowing your agent, and nobody has finished building that.

Is a spending limit enough to authorise an agent?

No, and this is where most current wallet designs are weakest. A cap constrains how much can be spent. It does not identify what was bought, from whom, or on what terms, and European payment rules require authorisation to be bound to a specific amount and a specific payee. A ceiling plus a list of permitted destinations satisfies neither condition. The gap is not theoretical: it determines whether a disputed transaction can be attributed at all. Designs that ship a limit and an allowlist and call it consent have built a budgeting feature, not an authorisation.

Who captures the value when the payment pipe becomes free?

Whoever owns intent, verification, context or governance, because the pipe itself is being commoditised. Open protocols push execution toward zero margin, which strands anyone whose revenue is a percentage of transactions moving through it. Value concentrates instead in four places: the layer that decides what the agent considers at all, the layer that underwrites whether a counterparty can be trusted, the layer that supplies the machine-readable context on which selection depends, and the layer that governs and evidences the whole thing. Most enterprises are exposed across all four and have measured none of them.

Why is Asia further ahead of Europe on agentic payments?

Architecture, not technology. A market where identity, payment, messaging and merchant relationships already sit inside one platform can deploy an agent that acts end to end, because the trust relationships it needs are internal. Europe has none of that. Identity sits with one party, payment with another, the merchant relationship with a third, and the agent has to establish trust across all of them for every transaction. That fragmentation is not a defect to be engineered away, it is the market structure, and the European route runs through a protocol that makes fragmented parties mutually verifiable rather than through building a super-app that will not exist.

Method, engagement, and what we will tell you not to do.

What is the Resonance Method?

The Resonance Method is contraco's framework for transformation that holds after the consultants leave. It treats strategy, technology and organisational psychology as one problem rather than three sequential ones, on the basis that most transformation failures are not analytical failures. The strategy is usually sound. What breaks is the organisation's capacity to carry it, and that capacity is psychological and structural before it is technical. The method has been in use since 1998, which predates the current AI cycle by a quarter of a century, and it was not retrofitted to it.

What size of organisation do you work with?

Mid-sized and large organisations facing a transformation they cannot staff internally, typically in retail, travel, financial services and industrial sectors, across Germany, South Korea and the United States. The useful filter is not headcount. It is whether the problem is genuinely cross-functional. If a question can be answered inside one department, you do not need an outside firm and we will say so. If the answer requires strategy, systems and organisational behaviour to move together, that is the work.

What will you refuse to do?

Build dependency. The consulting model that produces recurring revenue by keeping the client incapable is the failure mode we write about most, and we structure engagements against it: capability transfer is scoped from the start and the exit is designed before the entry. We also decline work where the stated problem is not the actual problem and the client is not willing to look at the difference. That refusal costs revenue and it is the reason the method holds.

How do you approach entering the European market?

By treating Germany as the hardest gate rather than the largest opportunity, because the failure modes there are structural rather than commercial. Foreign entrants routinely underestimate works council involvement, procurement timelines, data protection expectations and the degree to which trust precedes transactions. A market entry plan that has budgeted only for localisation and sales headcount is already wrong. The sequencing question, which market first and on what evidence, is worth more than the go-to-market document that follows it.

The questions that decide whether an AI programme survives contact with the organisation.

How do we measure the return on an AI transformation?

Against the decision it replaced, not against the technology it introduced. Most AI return calculations measure system output, tokens processed, tickets deflected, hours notionally saved, and then fail to show up in any financial statement. The measurement that survives scrutiny compares the cost and quality of a specific decision before and after, including the cost of the decisions the organisation no longer makes for itself. That last figure is usually missing, and it is usually the one that turns a positive business case negative in year three.

Why do AI initiatives stall after the pilot?

Because the pilot proved the technology and the rollout requires the organisation, and nobody scoped the second thing. A pilot runs with volunteers, executive attention and tolerance for failure. A rollout runs with people who did not ask for it, in processes that already work well enough, under managers measured on something else. The gap between those two conditions is organisational, not technical, and no amount of model improvement closes it. Programmes that survive the transition budget for it explicitly and treat adoption as the deliverable rather than deployment.

Does AI change how we should structure the organisation?

Yes, and mostly by making the existing structure legible. AI concentrates work that was distributed across roles, which exposes where accountability was already ambiguous. Teams built around information gathering shrink. Teams built around judgement and accountability do not. The design question is therefore which decisions must remain with a named human and why, answered before any tool selection rather than after it. Organisations that reorganise around the technology and then look for the decisions end up with structures nobody can explain to a regulator or a customer.

How do we know whether our own analysis is still sound?

By checking whether anyone can still reconstruct why a conclusion was reached. The risk AI introduces is not wrong answers, which organisations catch. It is fluent answers that nobody interrogates, accumulating into positions the organisation holds without knowing why it holds them. The practical discipline is unglamorous: require that any material conclusion carry its reasoning, its source and its author, and periodically test whether a decision made six months ago can still be explained by the people living with it.

Ask us the fifteenth question.

For questions about selecting and evaluating a consultancy, see How to Choose the Best AI Consulting Firm.

The questions above have general answers. Your situation does not. A first conversation with contraco is a working session, not a pitch.

Start the conversation