Analysis · August 2026 · Agentic Commerce
Analysis — no new primary measurement
The One-Way Handshake
Agentic commerce is being built with its trust vector pointing in a single direction. Every live standard credentials the agent to the business. Almost nothing credentials the business to the agent — and the mention rate the AI-visibility field has measured for two years turns out to be the selection funnel neither literature named.

By Shayne Beavan
Founder, Deep AI Solutions · Inventor of record, 6 USPTO filings
A customer tells an assistant their water heater is leaking and to get someone out today. The assistant does not open ten tabs. It returns one name, maybe three — and increasingly it can complete the booking itself.
Ask what that assistant actually knew about the company it chose. Not what it could look up if pressed: what it verified before recommending. In August 2026 the honest answer is that it verified the agent thoroughly and the business barely at all.
- 7
- Live standards charted
- 3
- Protocols handed to
- 1.2%
- Local locations recommended
- 10–30×
- First-proposal advantage
none vouch for the business
neutral standards bodies in 1 year
ChatGPT · SOCi, ~350k locations
Microsoft Research simulation
What this report is, and is not
This is an argument, not a new measurement. It connects two bodies of work that have been running in parallel for two years without citing each other. Where others reached part of it first, they are named here rather than quietly absorbed.
The observation that agent payments matured faster than agent discovery is not ours. Forbes Business Council (Christian Pickett, Orthogonal) published it in June 2026; arXiv (Shi & Joo, Operator Labs) formalized it in October 2025 and proposed reputation-weighted ranking as a fix; KPMG India (Akhilesh Tuteja) named the consequence "silent bias" in July 2026. What none of them addressed is the local and professional-services economy — the plumbers, clinics, and practices a household actually dispatches an agent to find. That is where this report goes, and it is where the gap is widest.
Finding 1 — The handshake only goes one way
Agent trust infrastructure is not missing. It is abundant, well-funded, and already shipping. It is also pointed in one direction.
Visa's Trusted Agent Protocol, built with Cloudflare, signs agent identity and user consent so a merchant can verify who is knocking (Visa). ERC-8004 puts agent identity, reputation, and validation into on-chain registries, authored by people from MetaMask, the Ethereum Foundation, Google, and Coinbase. MIT's AgentFacts anchors agent capability and behavioral history to decentralized identifiers. The W3C has multiple community groups on agent identity and trust; FIDO has a working group on agent authentication.
And this is not early-stage jockeying. The core protocols have already been handed to neutral standards bodies — the milestone that marks infrastructure as settled rather than contested. Google donated the Agent Payments Protocol to the FIDO Alliance in April 2026 (Google). Anthropic donated the Model Context Protocol to a Linux Foundation directed fund co-founded with Block and OpenAI (Anthropic). Coinbase's x402 became a Linux Foundation project with forty member organizations, Visa and Mastercard among them (Linux Foundation).
Three protocols, three neutral homes, one year. That is what a solved problem looks like.
Every one of them answers a version of the same question: may this agent act? None answers: does this business deserve the order?
| Standard | What it attests | Vouches for |
|---|---|---|
| Trusted Agent Protocol Visa | Agent identity + user consent, verified against a card-network registry | The agent |
| ERC-8004 Trustless Agents Ethereum (MetaMask, EF, Google, Coinbase) | On-chain agent identity, reputation and validation registries | The agent |
| AgentFacts / NANDA MIT Media Lab | Agent capabilities, credentials and behavioral history, anchored to DIDs | The agent |
| Agent Readiness Score Cloudflare | Whether a site is machine-consumable across 13 standards | The site |
| Universal Commerce Protocol Google + Shopify | Merchant capabilities and negotiation terms, via /.well-known/ucp | The site |
| Agent Payments Protocol Google → FIDO Alliance | That a user authorized this specific purchase — Intent, Cart and Payment mandates | The agent |
| Agent Score + Agentic Directory Visa | Whether agents can complete tasks on a merchant's site, and that a participant is legitimate — explicitly not merchant quality | The site |
| One individual IETF draft no working-group adoption · scoring method deferred | That a specific business is qualified, covered, and available — checkable by an agent at selection time | The business |
Every entry is a shipping standard or program, characterized from its own published specification. The last column is the finding: the trust vector runs toward the agent. The final row is the exception that proves it — the only merchant-side identity proposal we located is an individual Internet-Draft with no working-group adoption, and it defers the scoring method to future work.
The asymmetry is not a conspiracy, and it is worth being fair about why it exists. The parties funding this work are payment networks and infrastructure providers whose financial exposure is an unauthorized transaction — not a badly chosen contractor. They built for their own risk, competently.
But the net effect stands: the party being credentialed is the one spending money, and the party being selected is credentialed by nothing.
Finding 2 — Be precise about what is actually open
Three claims circulate in this space that are false, and repeating them is the fastest way to get a serious argument dismissed.
"There is no standard for agents finding merchants." False. The Universal Commerce Protocol shipped in January 2026 from Google and Shopify under Apache 2.0, with merchants exposing a /.well-known/ucp endpoint (Shopify Engineering (Ilya Grigorik)). It standardizes capability discovery and negotiation. What it deliberately does not define is ranking or selection among merchants.
"Nobody knows how assistants choose." False. OpenAI has published the inputs it uses when ranking merchants for the same product — availability, price, quality, and whether the merchant is the maker or primary seller of the item — and states that results are organic and unsponsored (OpenAI). The problem is not secrecy. It is that no standard requires that disclosure, no two providers disclose comparably, and none of it is independently auditable.
"No agent trust infrastructure exists." False, as Finding 1 lays out at length.
The narrow, defensible claim is this: payment authorization and capability discovery are standardized; merchant ranking is published at best and unaudited everywhere; and membership in the consideration set is governed by nothing at all.
May this agent transact on a user's behalf?
StandardizedSigned identity and consent, verifiable against a registry, with live card-network and IETF-track implementations. (Visa)
What can this merchant do, and on what terms?
StandardizedCapability discovery and negotiation via a well-known endpoint, Apache-2.0 and adopted by 20+ retailers. (Shopify Engineering (Ilya Grigorik))
How does an assistant rank merchants it already knows?
Published · unauditedAt least one provider publishes its inputs — availability, price, quality, and maker-or-primary-seller status — but no standard requires disclosure, and none is independently auditable. (OpenAI)
Which merchants enter the consideration set at all?
OpenNo standard governs it. In its absence the set is drawn from what the model retrieves — which is what the AI-visibility literature has spent two years measuring.
Can a business prove it is licensed, bonded, insured, available?
OpenVerifiable-credential formats exist and regulated credentials exist, but no live standard binds them into an agent-consumable claim a model can check at selection time.
Read top to bottom: the closer a question sits to the money, the more thoroughly it has been standardized. The question of which businesses are considered at all is the least governed and the furthest upstream.
Finding 3 — The mention rate is the selection funnel
Here is the bridge neither literature has written.
The AI-visibility field has spent two years measuring how often assistants name a business. Semrush ran an index across 126 million prompts. Profound built one on billions of citations. SOCi measured roughly 350,000 local locations and found ChatGPT recommended 1.2% of them, against 35.9% for Google's local 3-pack.
Then Search Engine Journal / Victorious measured the thing that matters most and, as far as we can tell, nobody followed the implication: 96% of brands are described accurately when an assistant is asked about them directly, while 89% never surface in the category-research answers where buyers actually begin.
The model knows the brand.
The model does not retrieve it unprompted.
Brand-level measurement across 175 brands and 8 platforms (Search Engine Journal / Victorious, 2026-07-01). The same split appears in local data: SOCi measured ChatGPT recommending 1.2% of ~350,000 local locations against 35.9% for Google's local 3-pack.
That pair is the whole argument. Being known and being chosen have come apart. The assistant is not ignorant of these businesses — it can describe them fluently on request. It simply does not retrieve them when no one names them first.
Meanwhile the agentic-commerce field has been standardizing everything that happens after a merchant is in hand: identity, consent, capability, settlement. It treats the consideration set as an input it receives, not as a thing it produces.
Put the two together and the conclusion is uncomfortable. If an agent transacts with whoever it names, then every mention-rate study ever published has been measuring the top of a transaction funnel without calling it one. A 1.2% recommendation rate stops being a marketing statistic. It becomes a market-access rate.
Our own measurement sits inside that reframing. The Houston AI Visibility Index found a median score of 31 out of 100 across 150 local cohorts — which we published as a visibility problem. Read against the agentic stack, it describes something narrower and harsher: the share of local businesses positioned to be transacted with by an agent that never asks a human for a second opinion.
Finding 4 — The mechanism is speed and position, not merit
We are not left guessing how selection behaves once it is agent-mediated, because it has been simulated at scale. Microsoft Research's Magentic Marketplace ran 100 customer agents against 300 business agents and measured what happened (Microsoft Research).
The results should unsettle anyone assuming better businesses win. First-proposal bias conferred a 10–30× advantage — responding first mattered far more than being better. Position bias persisted. Agents proved manipulable by how a proposal was framed. And welfare fell as the option set grew from 3 to 100: more choice produced worse outcomes, because the agent's ability to discriminate did not scale with the length of the list.
The load-bearing caveat, which we state rather than bury: those 300 businesses were synthetic. No published study has tested whether agents select real local service businesses, or on what basis. That is the open empirical question in this field. We would rather name it than fill it with an assumption.
Finding 5 — Local and professional services are not in the room
The commerce protocols are product-retail-first, extending into large aggregated verticals like hotels and food delivery. The trades, clinics, and professional practices are addressed by no commerce protocol at all.
And the credentials that actually decide those transactions in the physical world have no machine-readable form. Whether a contractor is licensed, bonded, insured, and has capacity Tuesday is verifiable today only by a human doing human things: a state licensing board lookup, a certificate of insurance from the carrier, a surety registry. Verifiable-credential formats exist. Regulated credentials exist. Nobody has bound them together into something an agent can check at the moment of selection.
We are not the first to notice. An individual Internet-Draft filed in May 2026 names it precisely — the merchant identity gap — observing that the receiving side of a purchase has no protocol-level identity or verification mechanism (IETF (Chris Hood, Nomotic — individual Internet-Draft)). It proposes a merchant reliability score and then defers the scoring method itself to future work. It has no working-group adoption and no standing on any standards track.
That is the state of the art: one person, correctly diagnosing the problem, in a document nobody is obligated to read.
So the agent falls back on what it can read — which returns us to retrievability, and to the funnel in Finding 3.
Where this report is contested
An index that cites only the evidence agreeing with it is marketing. Two findings cut against our own prior work, and they belong in the record.
Schema's role in local selection is contested. Our Houston Index found schema.org completeness the strongest available predictor of being named within its frame. A 104,855-citation study across six platforms found that semantic relevance outranked domain authority and that schema markup showed minimal influence on local LLM ranking (Search Atlas (Manick Bhan)). Both can be true of their respective frames; they cannot both be true as a general law. Our honest position: machine-legible identity is eligibility hygiene, not a ranking lever — and anyone selling schema markup as a ranking trick is well ahead of the evidence.
Single-run visibility measurement is unreliable — ours included. Visibility is a distribution, not a value, and measuring once produces numbers that do not reproduce (arXiv (Schulte, Bleeker, Kaufmann)). Every index in this category inherits that limitation, this organization's included. It is an argument for repeated measurement and published variance, not for ignoring the signal.
What follows for an operator
Nothing here supports a new checklist, and the honest guidance is short.
The consideration set is the asset. Rank within a list you are not on is worth nothing, and the evidence says most businesses are not on the list. Everything deciding membership today runs through retrievability: being described consistently, verifiably, and in the places a model actually reads.
Treat published ranking inputs as the best available map, not as a promise. They are unaudited, provider-specific, and revisable without notice.
And watch the credential gap. The first credible way for a regulated business to prove — machine-readably, to an agent, at selection time — that it is licensed, insured, and available will matter more than any content strategy currently being sold. That infrastructure does not exist yet. It is the most valuable unbuilt thing in this stack.
The agent will not ask whether you were the better business. It will ask what it can verify.
Method and limits
What this is. A structured reading of public primary sources — protocol specifications, provider documentation, published vendor research, and peer-reviewed and preprint literature — current as of August 10, 2026. Every external figure is attributed inline and listed below.
What this is not. New primary measurement. No original data is reported here. Deep AI Solutions' own measurements live in the Houston AI Visibility Index and are cited as ours wherever referenced.
Limits. This is a fast-moving standards landscape; several cited programs are only months old, specifications change, and some will be obsolete within a year. Characterizations of what a standard does are drawn from its own published specification, not from our testing of implementations. Where we assert a gap we mean the absence of a published, live standard — not the absence of private or unreleased work, which we cannot observe. The claim that mention rate functions as a selection funnel is an argument from converging evidence, not a measured causal finding, and is labeled as such throughout.
Sources
- Forbes Business Council (Christian Pickett, Orthogonal), "Why AI Agents Can't Find Or Pay For Anything Yet" (2026-06-29) — https://www.forbes.com/councils/forbesbusinesscouncil/2026/06/29/why-ai-agents-cant-find-or-pay-for-anything-yet/
- arXiv (Shi & Joo, Operator Labs), "Sybil-Resistant Service Discovery for Agent Economies" (2025-10-31) — https://arxiv.org/abs/2510.27554
- KPMG India (Akhilesh Tuteja), "The hidden mechanism of agentic commerce: incentives, bias and the future of choice" (2026-07-17) — https://kpmg.com/in/en/blogs/2026/07/the-hidden-mechanism-of-agentic-commerce-incentives-bias-and-the-future-of-choice.html
- Microsoft Research, "Magentic Marketplace: an open-source simulation of agentic markets" (2025-10-30) — https://arxiv.org/abs/2510.25779
- Shopify Engineering (Ilya Grigorik), "Universal Commerce Protocol" (2026-01-11) — https://shopify.engineering/UCP
- OpenAI, "Buy it in ChatGPT" (2025-09-29) — https://openai.com/index/buy-it-in-chatgpt/
- Visa, "Visa Introduces Trusted Agent Protocol — an ecosystem-led framework for AI commerce" (2025-10-14) — https://investor.visa.com/news/news-details/2025/Visa-Introduces-Trusted-Agent-Protocol-An-Ecosystem-Led-Framework-for-AI-Commerce/default.aspx
- Google, "Donating the Agent Payments Protocol to the FIDO Alliance" (2026-04-28) — https://blog.google/products-and-platforms/platforms/google-pay/agent-payments-protocol-fido-alliance/
- Anthropic, "Donating the Model Context Protocol and establishing the Agentic AI Foundation" (2025-12-09) — https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation
- Linux Foundation, "Operational launch of the x402 Foundation" (2026-07-14) — https://www.linuxfoundation.org/press/linux-foundation-announces-operational-launch-of-x402-foundation-to-standardize-internet-native-payments-for-ai-agents-and-applications
- IETF (Chris Hood, Nomotic — individual Internet-Draft), "draft-hood-agtp-merchant-identity-02" (2026-05-26) — https://datatracker.ietf.org/doc/draft-hood-agtp-merchant-identity/
- Visa, "Visa announces new AI, stablecoin and token innovations at Visa Payments Forum" (2026-06-10) — https://investor.visa.com/news/news-details/2026/Visa-Announces-New-AI-Stablecoin-and-Token-Innovations-to-Power-Intelligent-Programmable-Commerce-at-Visa-Payments-Forum/default.aspx
- Cloudflare, "Agent Readiness Score" (2026-04-17) — https://blog.cloudflare.com/agent-readiness/
- Ethereum Improvement Proposals, "ERC-8004: Trustless Agents" (2025-10-01) — https://eips.ethereum.org/EIPS/eip-8004
- MIT Media Lab (Project NANDA), "AgentFacts: a verifiable metadata standard for agents" (2025-07-18) — https://arxiv.org/abs/2507.14263
- Search Engine Journal / Victorious, "AI brand mention study — Q2 2026 Quarterly Search Report" (2026-07-01) — https://www.searchenginejournal.com/ai-brand-mention-study-victorious-spa/582765/
- SOCi, "2026 Local Visibility Index" (2026-03-06) — https://www.soci.ai/blog/the-challenge-of-ai-visibility-for-brands-part-1/
- Search Atlas (Manick Bhan), "How LLMs rank local businesses" (2026-01-17) — https://searchatlas.com/blog/how-llms-rank-local-business/
- Semrush, "Expanded 2026 AI Visibility Index" (2026-06-26) — https://www.semrush.com/news/463141-semrush-releases-expanded-2026-ai-visibility-index-analyzing-126-million-ai-search-prompts/
- Profound, "Introducing the Profound Index" (2025-11-05) — https://www.tryprofound.com/blog/introducing-profound-index
- Ahrefs, "AI brand visibility correlations" (2025-12-12) — https://ahrefs.com/blog/ai-brand-visibility-correlations/
- arXiv (Schulte, Bleeker, Kaufmann), "Don't Measure Once: Measuring Visibility in AI Search" (2026-04-08) — https://arxiv.org/abs/2604.07585