AI Answer Summary
AI agents are completing purchases on behalf of consumers without explicit per-transaction consent — and the legal frameworks governing those transactions have not caught up. CERRE estimates 10–20% of e-commerce transactions will be handled by AI agents by 2030. Morgan Stanley forecasts $190B–$385B.
AI agents are completing purchases on behalf of consumers without explicit per-transaction consent — and the legal frameworks governing those transactions have not caught up. CERRE estimates 10–20% of e-commerce transactions will be handled by AI agents by 2030. Morgan Stanley forecasts $190B–$385B in US consumer spend via agentic shoppers. The consent gap between what agents do and what the law requires is the defining compliance challenge of the next three years.
[Image blocked: 3D isometric illustration showing an AI robotic arm completing a purchase on a holographic checkout screen, surrounded by legal documents, a shield with a question mark, and scales of justice]
What Is Agentic Commerce?
Agentic commerce is the category of e-commerce transactions where an AI agent — acting on standing instructions from a consumer or enterprise buyer — researches, selects, and completes purchases without requiring the buyer to initiate or confirm each transaction individually. The agent operates within parameters set by the user (budget limits, preferred vendors, product categories) but exercises autonomous judgment about when and what to buy.
This is not a theoretical future state. Mastercard launched its Agent Suite in Q2 2026, providing infrastructure for AI agents to complete card-present and card-not-present transactions. Visa launched Intelligent Commerce in the same quarter, enabling AI agents to transact using tokenised payment credentials. Both programmes are live with selected merchants and platform partners.
The commercial case is clear: agentic purchasing reduces friction, eliminates repeat decision fatigue, and enables real-time price optimisation across multiple vendors. For enterprise procurement, it automates routine supply chain transactions that currently consume significant human time. For consumers, it promises a world where replenishment purchases, subscription management, and comparison shopping happen without active effort.
The Consent Gap: Where Law and Technology Diverge
The legal frameworks governing consumer transactions were designed for a world where a human buyer makes a deliberate decision to purchase. The UK Consumer Rights Act 2015, the EU Consumer Rights Directive, and equivalent frameworks in the US require that consumers receive clear information about what they are buying, from whom, and at what price — and that they affirmatively consent to the transaction.
Agentic commerce breaks this model in five distinct ways:
[Image blocked: Infographic: The Agentic Commerce Consent Gap — 5 Legal Risks including authorisation ambiguity, return and refund rights, data minimisation, liability chain, and consent revocation, with key stats from CERRE, Morgan Stanley and Gartner]
1. Authorisation Ambiguity
When a consumer grants an AI agent permission to purchase within defined parameters, does that constitute informed consent to each individual transaction? The legal answer is unclear. A one-time authorisation to "buy office supplies under £500" may satisfy the agent's operating parameters but may not meet the standard of specific, informed consent required for each transaction under consumer protection law. Courts have not yet ruled on this question, and regulators have not issued definitive guidance.
2. Return and Refund Rights
The UK Consumer Rights Act and EU Consumer Rights Directive grant consumers a 14-day right to cancel distance contracts without giving a reason. When an AI agent completes a purchase, it is unclear whether the 14-day clock starts from the agent's transaction date or from when the consumer becomes aware of the purchase. If a consumer does not review their agent's activity for several days, they may unknowingly lose cancellation rights on purchases they did not consciously make.
3. Data Minimisation
GDPR Article 5(1)(c) requires that personal data be "adequate, relevant and limited to what is necessary" for the purpose of processing. AI purchasing agents, by their nature, collect and process more data than a human buyer would — browsing patterns, price sensitivity signals, purchase timing preferences, and behavioural data that informs future purchasing decisions. This creates a structural tension with the data minimisation principle that organisations deploying agentic commerce tools must address explicitly.
4. The Liability Chain
When an AI agent completes a transaction that the consumer disputes — wrong product, wrong price, fraudulent vendor — who bears liability? The merchant fulfilled the order in good faith. The platform provided the agent infrastructure. The agent developer wrote the purchasing logic. The consumer authorised the agent to act. Current consumer protection frameworks do not map cleanly onto this four-party liability chain. The result is a gap that benefits no one: consumers face uncertainty about redress, merchants face uncertainty about chargebacks, and platforms face uncertainty about regulatory exposure.
5. Consent Revocation
How does a consumer revoke an AI agent's purchasing authority? If the agent has standing authorisation stored across multiple platforms — a payment credential with Mastercard, a purchasing profile with Amazon, a subscription management account with a SaaS vendor — revoking that authority requires action across multiple systems. There is currently no standardised mechanism for consumers to revoke agentic purchasing authority across all platforms simultaneously.
The Legal Context Protocol: An Emerging Standard
In June 2026, the American Arbitration Association launched the Legal Context Protocol (LCP), an open standard designed to make legal requirements machine-readable for AI agents. The LCP provides a structured format for embedding consent requirements, liability frameworks, and terms of service directly into the data layer that AI agents process when completing transactions.
The intent is to close the consent gap at the technical level: rather than requiring consumers to read and understand legal terms, the LCP enables the agent itself to parse those terms and apply them to each transaction. If a merchant's terms require explicit human confirmation for purchases above a certain value, the LCP-compliant agent would surface that requirement to the consumer before completing the transaction.
The LCP is early-stage and adoption is not yet widespread. But its launch signals that the industry recognises the consent gap as a structural problem requiring a technical solution, not just a regulatory one. Organisations building agentic commerce capabilities should monitor LCP adoption as a leading indicator of where compliance requirements will land.
What the Forecasts Mean for B2B Strategy
The CERRE, Morgan Stanley, and Gartner forecasts point to agentic commerce becoming a mainstream channel within this decade. For B2B brands, this creates both an opportunity and a compliance obligation:
-
Opportunity: Brands that optimise their product data, pricing APIs, and checkout flows for agent-mediated transactions will capture a disproportionate share of agentic commerce volume. Agents select vendors based on structured data quality, API reliability, and clear pricing — not brand advertising or emotional appeal.
- Compliance obligation: Brands that accept agent-mediated transactions without auditing their consent flows, return policies, and data processing practices will face regulatory exposure as frameworks catch up with the technology.
The brands that navigate this transition successfully will be those that treat agentic commerce compliance as a product requirement, not a legal afterthought. Building consent mechanisms, liability clarity, and data minimisation into the agent transaction flow from the outset is significantly cheaper than retrofitting them after a regulatory intervention.
Practical Steps for B2B Brands
Three actions that directly reduce agentic commerce legal risk:
-
Audit your purchasing workflows for agent-mediation risk. Map every transaction type your customers or employees might delegate to an AI agent. For each, identify the consent requirement, the return right, and the data processing basis. This audit will surface the gaps before a regulator does.
-
Review your terms of service for agent-mediated transactions. Most terms of service were written for human buyers. Add explicit provisions for AI agent transactions: what authorisation is required, what data the agent may access, and what the liability position is for disputed transactions.
-
Monitor the Mastercard Agent Suite and Visa Intelligent Commerce compliance requirements. As these programmes scale, they will impose contractual compliance requirements on merchants. Early adoption of their frameworks will reduce the cost of compliance when requirements become mandatory.
-
For a deeper look at how agentic AI governance frameworks are developing in financial services, see the Bank of England's circuit-breaker model for agentic systems [blocked]. For the broader regulatory context, the EU DMA order on Google search data sharing [blocked] illustrates how quickly regulatory frameworks are moving to address AI-driven market dynamics.
If you are building agentic AI capabilities for your B2B marketing or sales workflows, our Agentic AI service [blocked] covers both the commercial design and the governance framework required to deploy agents that are effective and legally defensible.
Frequently Asked Questions
What is the agentic commerce consent gap?
The agentic commerce consent gap refers to the mismatch between what AI purchasing agents do — completing transactions autonomously on a consumer's behalf — and what existing consumer protection law requires in terms of explicit, informed, per-transaction consent. Current frameworks such as the UK Consumer Rights Act 2015 and EU Consumer Rights Directive were written for human buyers, not AI agents acting as intermediaries. The gap creates legal uncertainty for merchants, platforms, and consumers alike.
How much e-commerce will AI agents handle by 2030?
CERRE estimates that 10–20% of all e-commerce transactions will be handled by AI agents by 2030. Morgan Stanley forecasts $190B–$385B in US consumer spending will flow through agentic shoppers by the same date. Gartner projects 20% of digital commerce transactions will occur via AI platforms by 2030. These forecasts reflect a range of adoption scenarios, but all point to agentic commerce becoming a mainstream channel within this decade.
Who is legally liable when an AI agent makes a wrong purchase?
Liability in agentic commerce is currently unresolved across most jurisdictions. The merchant, the AI platform provider, and the agent developer each have a plausible claim to partial liability depending on where the failure occurred — in the authorisation flow, the transaction execution, or the data handling. The Legal Context Protocol (LCP), launched in June 2026, is an attempt to create an open standard for machine-readable legal context that could clarify liability chains, but adoption is early-stage.
Does GDPR apply to purchases made by AI agents?
GDPR applies to the personal data processed during an AI-agent-mediated transaction, including purchase history, payment data, and behavioural signals used to inform the agent's decisions. The data minimisation principle (Article 5(1)(c)) is particularly relevant: AI agents often collect and process more data than strictly necessary to complete a transaction. Organisations deploying agentic commerce tools should conduct a data protection impact assessment (DPIA) before launch.
What is the Legal Context Protocol (LCP) and how does it address agentic commerce?
The Legal Context Protocol (LCP) is an open standard launched by the American Arbitration Association in June 2026. It provides a machine-readable format for embedding legal context — terms of service, consent requirements, liability frameworks — directly into AI agent workflows. The intent is to allow AI agents to parse and apply legal constraints at the point of transaction, reducing the consent gap by making legal requirements legible to the agent rather than only to the human consumer.
How should B2B brands prepare for agentic commerce compliance?
B2B brands should take three immediate steps: first, audit which purchasing workflows could be executed by an AI agent on behalf of a client or employee, and map the consent requirements for each; second, review return and refund policies for agent-mediated transactions, since the Consumer Rights Act and equivalent frameworks may require explicit human confirmation for certain transaction types; third, monitor the LCP standard and Mastercard Agent Suite / Visa Intelligent Commerce rollouts for compliance requirements that will become contractual obligations for merchants.
About the Author
Modi Elnadi is the founder of Integrated.Social [blocked], a B2B AI marketing agency in London specialising in agentic AI strategy, AEO, and performance marketing. He advises enterprise and scale-up B2B brands on AI governance frameworks, agentic commerce readiness, and pipeline attribution. Read Modi's full profile → [blocked]







