Artificial Intelligence

Why trust in AI agents requires open global standards

Abstract digital profile of a human head formed by glowing blue glowing lines, interconnected nodes, and flowing data streams against a dark background.

Analysts estimate agentic commerce could orchestrate $3 trillion to $5 trillion in transactions globally by 2030. Image: Getty Images/iStockphoto

Andrew Shikiar
Executive Director & Chief Executive Officer, FIDO Alliance
  • Autonomous AI agents could manage trillions in commerce by 2030 but face a critical trust gap.
  • Unlocking agentic commerce requires cryptographically verifiable human authorization and limits.
  • Industry stakeholders must establish open standards to ensure delegated transactions stay secure.

AI agents are already booking travel, comparing prices, negotiating terms and completing purchases on behalf of real people. And this is only the beginning. Analysts including McKinsey estimate agentic commerce could orchestrate $3 trillion to $5 trillion in transactions globally by 2030. That kind of growth would reshape how the world buys and sells online on a timeline measured in just a few short years, not decades.

Yet one question remains unresolved, and it’s the one that determines whether that opportunity is actually realized: when an agent initiates a transaction, who or what is really on the other end, and how would anyone confirm it? Until that question has a reliable answer, agentic commerce will keep hitting the same ceiling: real deployments, real pilot volume, but hesitation every time the stakes get high enough to matter.

The gap isn’t technical capability, as agents can already negotiate, compare and transact faster than a human could supervise them in real time. The gap is trust – and specifically, trust rooted in verified human approval, cryptographically traceable back to the person who granted it. Without that anchor, no merchant, bank or regulator can reliably tell a legitimate agent-initiated purchase from a compromised or malicious one, which will prevent the realization of agentic commerce at scale.

Have you read?

Digital commerce has hit trust ceilings like this before. Online shopping itself didn’t scale until we had SSL/TLS encryption, and the browser padlock gave people a reason to trust that a stranger’s website could safely take their card number – a problem no single retailer could solve alone, and one the industry only cleared by converging on an open, shared standard. Agentic commerce is tracking a similar arc, except the underlying risk compounds faster this time, since agents can now initiate, negotiate and complete transactions with far less human involvement in the moment than any prior wave of e-commerce required.

What agentic transactions look like today

This isn’t speculative. Mastercard’s Agent Pay platform already supports AI-driven purchasing across travel, retail and financial planning use cases, and the company projects AI will manage most business travel and expense decisions within five years. Visa’s data shows agent-initiated transactions moving from pilot to real deployment within a single year. These are documented, current deployments, and each one depends on the same unresolved question: how does any party in the transaction confirm the agent is authorized to act, and for whom?

Trust rooted in human approval

Closing that gap comes down to three non-negotiable requirements. First, every agent needs verifiable identity – a durable, cryptographically anchored proof of what it is and who deployed it, far beyond a simple session token. Second, each transaction demands a defined scope of authorization, establishing clear limits set by the human on whose behalf the agent acts. Finally, the system requires accountability and revocability, ensuring every action traces directly back to a real person who can withdraw authority at any time. Weaken any one of these three pillars, and the entire chain of trust collapses the moment a transaction goes wrong.

Building on proven infrastructure

Securing delegated authority is not an unprecedented challenge. The global tech ecosystem recently solved a parallel problem in human authentication by transitioning away from passwords toward passkeys – an open, phishing-resistant standard now deployed across billions of accounts worldwide. Agentic authentication simply extends this established foundation one step further.

Rather than just verifying who a person is, the next architecture must cryptographically prove that a specific AI agent was explicitly authorized by that person to act – and precisely within what financial boundaries. By anchoring agent permissions to the same cryptographically verified identity standards already proven at internet scale, the industry can create a seamless, secure bridge between human intent and autonomous action.

Why the industry needs a standard framework

No single company can underpin who is on the other end of every agentic transaction, and no single company should try to. The industry is converging around open, interoperable standards for agentic authentication and payments, rather than a patchwork of proprietary fixes that leave gaps at the seams. This is the same approach that made passkeys work: shared technical standards adopted across an entire ecosystem, not owned by any one vendor. Real contributions are already in the market, including Google’s Agent Payments Protocol and Mastercard’s Verifiable Intent framework, alongside Mastercard’s collaboration with Microsoft to extend agentic commerce across additional platforms.

The work ahead is specific and achievable. It means giving users phishing-resistant mechanisms to authorize what an agent can do. It means allowing merchants and financial institutions to cryptographically verify that an agent is acting legitimately on behalf of an authenticated person. And it means defining clear, auditable boundaries so agent-initiated transactions execute within limits the user actually set, with the ability to revoke that authority at any time. None of this is unprecedented – OAuth already proved that delegated, scoped, revocable authorization can work at internet scale; agentic commerce needs the equivalent for financial transactions.

What will it take to get this right

Solving this will not fall to any one sector. It requires governments, standards bodies, and the organizations building and deploying these agents to work together – just as these stakeholders collaborated on earlier trust infrastructure such as payment card standards or Strong Customer Authentication requirements adopted across Europe.

The alternative is familiar and avoidable. The payment industry lived this once already. Magnetic-stripe cards carried no transaction-level security, and by 2014 US card fraud losses had topped $16 billion. Only then did the industry force a fix, adopting EMV chip technology – years after the rest of the world had already made the switch, and only after a decade of mounting losses made it unavoidable. Once adopted, EMV cut in-person fraud by roughly 70%.

The decisions made across industry, government and standards bodies in the coming months will determine whether agentic commerce scales on a genuine foundation of trust, or whether it inherits the same reactive, costly fixes that slowed earlier waves of digital commerce. The opportunity to choose the first path is still open – but we must collectively move with haste as it will not stay open indefinitely.

Loading...
Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Artificial Intelligence

Share:
The Big Picture
Explore and monitor how Artificial Intelligence is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Artificial Intelligence
See all

How we rebalance the health data economy for shared value

Michael Byczkowski and Andy Moose

September 18, 2026

What skills do employers want from young people entering the workforce in the age of AI?

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum