The Chai
How AI is changing what gets bought and sold
Nobody asked you whether you wanted to sell to agents.
Published 1 October 2026Covering September 2026Last updated 1 October 2026
Key
takeaways
Eight things September settled - 01
Meta launched Muse on September 8, 2026, a personal AI agent that opens a browser, fills out forms and completes purchases, with checkout running through Link by Stripe.
- 02
Apptopia estimated Muse at 1.8 million iOS downloads across the United States and Canada in its first twelve days and 642,000 US mobile daily active users, against 231,000 for ChatGPT at the same point after its own mobile debut.
- 03
Shopify and Meta agreed on September 21, 2026 to let Muse complete purchases through Shop Pay agentic checkout, with Shopify merchants discoverable and purchasable inside Muse by default and checkout settling over the Universal Commerce Protocol.
- 04
Amazon began blocking Muse from Amazon.com on September 20, 2026, telling GeekWire the agent did not identify itself and was never authorized.
- 05
Where an agent meets a merchant that does not accept Link, Link issues a single-use virtual card scoped to the approved purchase, so a merchant who has integrated nothing can still be paid by an agent.
- 06
The Universal Commerce Protocol release of August 25, 2026 carries breaking changes to the fulfillment schema, to buyer consent and to profile signing keys, so anyone already running a UCP integration has migration work before the holiday season.
- 07
McKinsey’s 2026 State of AI survey found 32 percent of organizations deciding against buying a software product or feature because they could build it in house with agentic coding tools.
- 08
Anthropic and OpenAI both cut model prices on September 22, 2026 and both framed cost per task as the axis they are now competing on.
The month the choice got made for you
For two years the question in front of a merchant was whether to build for AI agents. September answered it by removing the question. Nobody sent a notice, nobody asked for a decision and by the end of the month most stores in this market had an agent policy they did not write.
Meta shipped Muse on September 8, a consumer agent that opens a browser, reads a page, fills out a form and pays. Twelve days later it was the number one app in the United States. Shopify then agreed to let it buy through Shop Pay across every store Shopify runs, on by default. Amazon blocked the same agent on a Sunday night and told a reporter it had never been asked.
The third decision is the one with no announcement attached. Where Muse meets a merchant that does not accept Link, Stripe issues a single-use virtual card for the purchase. That card arrives at a store that built nothing, integrated nothing and agreed to nothing, carrying no signal that a person did not type it in.
We put the open door on the cover because the door is the honest picture. Two landlords set opposite defaults, a payment rail made the question moot for everyone else and the only variable still in a merchant’s hands is whether the catalog data is good enough for the agent to choose the product. That is a ten-week problem and Cyber Week is the deadline.

Agentic commerce news, September 2026
September’s material commerce moves, by beat. A consumer shopping agent shipped and reached the top of the app charts, two platforms set opposite policies on it, the card networks started building an identity layer and the research arrived on what shoppers will actually let an agent do.

Surfaces
10 itemsMeta shipped a shopping agent that checks out. Muse launched September 8 running on a dedicated cloud virtual machine with its own browser, able to open a page, fill out a form, negotiate and keep working after the app closes, checking back for approval before it sends an email or buys anything. Checkout runs through Link by Stripe and Shop Pay. The security claims and the feature list are Meta’s own and none of it has been independently tested. Meta
It reached number one in the United States inside two weeks. Market intelligence firm Apptopia estimates 1.8 million iOS downloads across the US and Canada in the first twelve days against 1.3 million for ChatGPT over the same stretch after its mobile debut, with 642,000 US mobile daily active users against 231,000 for ChatGPT at the equivalent point. These are third-party estimates and Meta has published nothing on Muse adoption. TechCrunch
Amazon cut it off. Amazon started blocking Muse from Amazon.com on the night of September 20 after asking Meta to remove Amazon from the experience, showing Muse users a popup saying continued access by an unauthorized AI agent violates Amazon’s Conditions of Use. Amazon objected that Meta never told it Muse would access the store, that the agent does not identify itself while browsing and that it appears to capture and store customer credentials. Meta did not respond to GeekWire’s request for comment and Amazon declined to say whether it would take legal action. GeekWire
OpenAI turned a ChatGPT ad into a conversation and wired Shopify into Ads Manager. Sponsored Agents let a user who clicks an ad start a labeled conversation with a business-sponsored agent before following a link out, now testing with selected US advertisers. The same release ships a ChatGPT Ads app for US Shopify merchants that reads products already synced through Shopify Catalog, with other markets following from September 23. OpenAI
Amazon Ads began selling ChatGPT inventory. Advertisers can buy ChatGPT placements through Amazon DSP as a managed service, including product feed ads that generate creative automatically from the advertiser’s catalog, with labeled text and image ads appearing beneath answers on the Free and Go tiers. The pilot is limited to selected US advertisers. Amazon Ads
Cloudflare’s new defaults took effect on September 15. Cloudflare now sorts AI crawler traffic into categories it calls Search, Agent and Training, with Agent and Training blocked by default on pages that display ads for new domains onboarding and with a verified bot label no longer meaning default allowed. Trade coverage extends the change further than the Cloudflare post itself does and the taxonomy is Cloudflare’s own rather than an industry standard. Cloudflare
Amazon put its scarce holiday toys behind an invitation. The 2026 toy list carries a Request Invitation button on high-demand limited-availability items and closes by directing shoppers to Alexa for Shopping to discover toys and find gifts. Prices and availability are Amazon’s own and stated as subject to change. Amazon
Shipt turned a photograph of dinner into a cart. Ask Shipt is live in the app and on the web, identifying ingredients from a photo of a finished dish or an uploaded recipe and planning against a stated budget. Shipt says the feature reaches about 80 percent of the US population, which is the company’s own figure. Shipt
A survey put a number on how far shoppers will go. A Vogue Business consumer survey reported 31 percent of respondents willing to outsource shopping to an AI agent that knew their taste and purchase history and 72 percent unwilling to share card details with one. The sample and method are not stated in the coverage. Fortune
The counterweight came from the man who built the Apple Store. Ron Johnson told TechCrunch that AI will improve online shopping without changing which way people shop and that nobody is going to let an agent choose and buy a 2,000 dollar laptop. This is one retail veteran’s opinion in a book-tour interview with no data attached. TechCrunch
Platforms
10 itemsShopify opened Shop Pay to Meta’s agent across every store it runs. Announced September 21 through posts by Shopify CEO Tobi Lütke and Meta CEO Mark Zuckerberg rather than a press release, the arrangement lets Muse complete purchases through Shop Pay agentic checkout, with Shopify merchants discoverable and purchasable inside Muse by default, product data flowing through Shopify Catalog and checkout running over the Universal Commerce Protocol. Shopify VP of product Rohit Mishra told American Banker the buyer’s credential is vetted, stored on file and limited to a single purchase. No company press release exists. American Banker
Shopify told investors AI traffic behaves differently. At the Goldman Sachs Communacopia conference on September 10, management said searches initiated in a large language model land on product pages at roughly 2.5 times the rate of traditional search traffic and that merchants reached through AI-driven discovery see roughly an 80 percent conversion uplift. Both are the company’s own figures, spoken at an investor conference rather than filed or published and they appear in no Shopify newsroom post we could reach. Transcript via Investing.com
Anthropic published working reference builds for a storefront agent. The commerce blueprint carries a shopping agent and a merchant agent for retail, travel, telecom and ticketing, published on GitHub with a plugin and live demos, leaving payment to the merchant’s existing checkout. Shopify says it is building a reference storefront connecting the blueprint to a merchant’s store through Catalog, UCP and Shop Sign-in. The claim of carts up to 35 percent larger is Anthropic’s own with no methodology, sample or named retailer given. Anthropic
WooCommerce adapted it and published what is broken. The new Agentic Tools repo ships a shopper assistant that searches the catalog, builds a cart and hands the shopper to the store’s own WooCommerce checkout, plus a merchant assistant that stages every write behind a human approval. The post names its own limits: experimental and unsupported, no undo, no durable audit record naming the assistant, no authentication on either service, keyword retrieval rather than semantic and a scan capped at 400 recent orders and 250 products. WooCommerce
Salesforce shipped a shopper agent with checkout inside the chat. Carter is generally available now as part of a portfolio of Agentforce agents connected to Customer 360, alongside agents for service, supply chain and outbound sales. Every customer result in the release is Salesforce’s own figure with no methodology and the release carries a disclaimer that some referenced features are unreleased. Salesforce
Salesforce also built its own CRM model. Koa is post-trained on NVIDIA Nemotron 3 Super using a proprietary synthetic dataset, with Salesforce stating no customer data went into training, in pilot now and generally available in US regions this winter. The claim of three times fewer errors rests on Salesforce’s own benchmark. Salesforce
Instacart put its grocery agent inside other grocers’ apps. Clementine is live across North America on Instacart Marketplace, turning a message, a photographed handwritten list or a recipe into a ready-to-buy cart. Cart Assistant is the white-label version a grocer runs on its own site against its own catalog and customer data, live with Food Bazaar, Heritage Grocers Group and Woodman’s. No adoption or conversion figures are given. Instacart
Google put a score on first-party data plumbing. Data Manager is now integrated into Google Analytics and Display and Video 360, with enhanced conversions in both and a new Data Strength Uplift Metric in Google Ads that calculates the additional conversions recovered by a first-party data setup. The uplift figures cited are Google internal data with footnotes spanning 2024 through June 2026. Google
MCP turned up on the media buying side. Microsoft Advertising made its case for curation to publishers and retail media networks, with Copilot in Curate using Model Context Protocol capabilities so curators can query reporting, deal detail and troubleshooting context in natural language. The private marketplace and performance figures are third-party research cited by Microsoft. Microsoft Advertising
Anthropic pointed its small business product at commerce tools. The Claude for Small Business update reaches 43 workflows and 27 integrations naming Shopify, Square, Stripe, TikTok and Zapier, extending past bookkeeping into lead qualification, after-hours inbound response and recurring reporting, with owner approval required before anything sends, posts or pays. The install figure is Anthropic’s own. Anthropic
Payments
8 itemsStripe gave agents a card for every merchant that does not take Link. Meta integrated Link’s wallet for agents with Muse, so a US consumer can connect a Link account and let the agent buy across the internet, checking out instantly at the businesses that accept Link. Everywhere else Link issues a single-use virtual card scoped to the approved purchase, with the consumer approving the total in the chat and Muse never seeing the underlying payment details. The user counts and conversion claims are Stripe’s own. Stripe
Mastercard pitched one integration for every agent. Agent Connect is intended to let merchants, agents, platforms and payment providers connect through a single integration covering catalog discovery, then final pricing with taxes shipping and fulfillment, then completion using secure payment credentials from any network, with pricing and business rules staying with the merchant. Availability is hedged as subject to market needs and product availability. Mastercard
Visa, Mastercard and Ant International agreed to recognize each other’s agents. The Know-Your-Agent interoperability work is meant to let an agent verified on one network carry recognized trust signals across cards and wallets, built on the protocols each has already shipped and run through BuildFin.ai, the industry platform convened by the Monetary Authority of Singapore. The collaboration is described as exploring common principles rather than a shipped standard. Business Wire
Trade reporting says the networks mean to charge for it. American Banker added detail on cross-network operator traceability, assessment of each agent against security and behavioral requirements and continuous monitoring to support ongoing certification. No Visa or Mastercard release covering that detail was reached, so it rests on the outlet’s reporting and a Bank of America research note quoted in the piece is the source for the value-added-service framing. American Banker
Alchemy gave agents one-time-use Mastercard credentials. The AgentCard platform now supports Mastercard payment credentials through Mastercard Agent Pay, provisioning an agent with a dedicated email, phone number, stablecoin wallet and one-time-use tokenized credentials linked to a user’s existing card in under a minute, with purchase limits, merchant categories and allowed transaction locations set by the user and the issuer. This is a joint company release rather than independent verification and no transaction volume is given. PR Newswire
A regulated European bank ran an agent payment. Danske Bank and Mastercard completed what they call Denmark’s first payment made by an AI agent, with a consumer instructing an agent to book a coffee tasting and the agent completing the booking and the payment on a Danske Bank issued Mastercard, orchestrated through Mastercard Agent Pay. This is a pilot rather than a general release. Finextra
Agent identity got its first dedicated money. Baselayer raised 35 million dollars led by M13 and launched an Agentic Identity Suite aimed at the question a bank or merchant has to answer before it lets an agent transact, with named work alongside FIS, Prove, Socure and others plus standards participation in the FIDO Alliance Authentication Working Group, the Legal Context Protocol and the x402 Identity Working Group. The fraud prevention figures are the company’s own claims. PR Newswire
Shop Pay Installments reached Australia. Affirm and Shopify launched with Affirm as exclusive provider, letting eligible shoppers split a purchase into fortnightly or monthly payments with the full schedule shown before checkout and no late fees, switched on by Australian merchants through the Shopify admin. This is Affirm’s return to a market it wound down in 2023. Business Wire
Research
4 itemsA third of organizations are skipping the software purchase. McKinsey’s 2026 State of AI survey found 32 percent of organizations deciding against buying a software product or feature because they could build it in house with agentic coding tools, most often in technology and healthcare. Forty percent of large organizations now report scaling AI agents in at least one function against 27 percent a year earlier, while 37 percent report any EBIT impact from AI at all, unchanged. Independent analyst research, fielded May 4 to June 8, 2026 across 97 countries. McKinsey
Visa put the trust gap in numbers. The Visa Trust Index reports 72 percent of US consumers having used an AI assistant while 23 percent trust generative AI to handle payment transactions on their behalf, with 61 percent saying they would trust Visa to handle agentic transactions. Fielded for Visa by the Harris Poll from May 26 to 28, 2026. The research is Visa-commissioned and the brand question asks about Visa’s own brand. Visa
Shoppers now expect agents to buy a seventh of what they buy. The Global Payments Agentic Commerce Report finds consumers expecting AI agents to make 15 percent of their purchases within five years, up from 9 percent a year earlier, with comfort letting an agent spend up to 50 dollars more than doubling in cinema tickets, meal delivery and subscriptions. The research was commissioned by Global Payments, which sells merchant acquiring into the behavior it is measuring, so read it as direction rather than measurement. Business Wire
Salesforce put a fifth of holiday traffic on AI chat agents. The 2026 holiday predictions forecast 20 percent of holiday ecommerce traffic originating from AI chat agents and one in three ecommerce sites running its own shopper agent by Cyber Week, with the operational point that agents do not browse a storefront the way a person does and instead read product feeds. Every figure is Salesforce’s own research and the recommendations point at Salesforce products. Salesforce
Nobody asked you whether you wanted to sell to agents
Three companies decided in September whether your store sells to AI agents. Shopify turned agent checkout on by default across every store it runs. Amazon blocked the same agent under its terms of use. Stripe made the question moot for everyone else by issuing agents a card that works anywhere. None of those decisions was a merchant’s.

Start with what actually happened, in order.
On September 8, Meta launched Muse, a personal AI agent that runs on a dedicated cloud virtual machine with its own browser, opens a page, fills out a form, negotiates on a person’s behalf and checks back for approval before it buys anything (Meta). Checkout runs through Link by Stripe, with Shop Pay and 1Password support described as coming.
Adoption moved faster than the industry’s usual launches. Market intelligence firm Apptopia estimates 1.8 million iOS downloads across the United States and Canada in the first twelve days against 1.3 million for ChatGPT over the same stretch after its mobile debut and puts Muse at 642,000 US mobile daily active users against 231,000 for ChatGPT at the equivalent point (TechCrunch). Those are third-party estimates from a firm with no access to Meta’s internal numbers and Meta has published nothing on adoption. Treat the shape as reliable and the decimal places as not.
Then the platforms answered, in opposite directions, inside two days.
Shopify and Meta agreed on September 21 to let Muse complete purchases through Shop Pay agentic checkout. Shopify merchants are discoverable and purchasable inside Muse by default. Product data flows through Shopify Catalog. Checkout settles over the Universal Commerce Protocol that Google and Shopify co-developed. Shopify VP of product Rohit Mishra told American Banker the human buyer’s credential is vetted, stored on file and limited to a single purchase, so the underlying card data is never exposed (American Banker). No press release exists. The announcement reached the public through two executives posting about it.
Amazon went the other way. It began blocking Muse from Amazon.com on the night of September 20 after asking Meta to remove Amazon from the experience and showed Muse users a popup saying continued access by an unauthorized AI agent violates Amazon’s Conditions of Use (GeekWire). An Amazon spokesperson said third-party applications making purchases on behalf of customers should operate openly and respect service provider decisions about whether to participate. Amazon’s specific objections were that Meta never told it Muse would access the store, that the agent does not identify itself while browsing and that it appears to capture and store customer credentials. Meta did not respond to a request for comment and Amazon declined to say whether it would take legal action.
The reason Amazon reached for its terms of use rather than the courts matters. On August 4 the Ninth Circuit Court of Appeals vacated Amazon’s preliminary injunction against Perplexity, holding that the user rather than the AI company is the one accessing Amazon’s computers under federal anti-hacking law and it denied rehearing on September 10. Ten days later the block appeared. The technical argument was settled against Amazon and the contract is what is left.
The technical argument was settled against Amazon and the contract is what is left.
The decision nobody announced
The third company never made a statement about merchant policy at all and it had the widest effect.
Stripe said on September 8 that Meta had integrated Link’s wallet for agents with Muse, so a US consumer can connect a Link account and let their agent buy from businesses across the internet. At the businesses that accept Link, checkout runs instantly on the consumer’s saved payment method. Everywhere else, Link issues a single-use virtual card scoped to the approved purchase, with the consumer approving the total in the chat interface and Muse never seeing the underlying payment details (Stripe).
Read that from the merchant’s side of the counter. A store that has built nothing, integrated nothing and agreed to nothing receives a valid card number scoped to one purchase. It carries no signal that a person did not type it in. There is no opt-in and no opt-out, because from the payment rail’s perspective nothing unusual happened.
The same pattern has more than one supplier. Alchemy’s AgentCard provisions an agent with one-time-use tokenized Mastercard credentials linked to a user’s existing card in under a minute, with purchase limits and merchant categories set by the user and the issuer (PR Newswire). Danske Bank and Mastercard ran a live agent-initiated payment on an issued card in Denmark (Finextra). The agent-shaped buyer is arriving through the ordinary card rails, sometimes with a regulated issuer’s approval behind it.
What is left to decide
Strip out the decisions already made and one variable remains in the merchant’s hands. Whether the agent picks the product.
Every surface that shipped this month reads structured product data rather than the page a human sees. Salesforce says so directly, forecasting 20 percent of holiday ecommerce traffic originating from AI chat agents and pointing out that agents do not browse a storefront the way a person or a crawler does, instead reading product feeds, so catalog syndication plus live inventory and pricing accuracy decide whether a merchant is in the consideration set at all (Salesforce). Those are the company’s own forecasts and the recommendations point at its products, so read them as direction rather than measurement. The mechanism underneath is not in dispute and the rest of the month confirms it. Shopify Catalog is what flows into Muse. The same Catalog sync is what OpenAI’s new ChatGPT Ads app reads when a Shopify merchant installs it (OpenAI). Amazon Ads generates ChatGPT ad creative straight from the advertiser’s product feed (Amazon Ads).
There is also a practical question about whether agents can reach the pages at all. Cloudflare’s defaults, effective September 15, sort AI crawler traffic into Search, Agent and Training and block Agent and Training by default on pages that display ads for new domains onboarding, with a verified bot label no longer meaning default allowed (Cloudflare). A merchant running an ad-monetized content arm behind Cloudflare may already be refusing the assistants its own customers use, without anyone having chosen that either.
Consumers, for their part, have not finished deciding. Visa’s Trust Index, fielded by the Harris Poll in late May, found 72 percent of US consumers having used an AI assistant while 23 percent trust generative AI to handle a payment on their behalf (Visa). Global Payments finds consumers expecting agents to make 15 percent of their purchases within five years, up from 9 percent a year earlier, with the brake being trust rather than interest (Business Wire). Both are vendor-commissioned by companies selling into the answer, so hold them loosely. The direction they agree on is that discovery is running ahead of payment, which is the gap a merchant plans for.
Ron Johnson, who built Apple’s retail business, offers the useful dissent. He told TechCrunch that agents will produce better-informed shoppers arriving at stores rather than fewer of them and that nobody is going to let an agent choose and buy a 2,000 dollar laptop (TechCrunch). That is an opinion with no data attached and for a high-ticket or tactile catalog it is a reasonable frame: the agent narrows the set and a person still closes.
So the work is the same either way. If the agent is narrowing the set, the catalog decides whether you are in it. If the agent is closing, the catalog decides whether it can. The deadline is Cyber Week and Merchant’s-Eye View below has the list.
For the three ways an agent pays, see this issue’s Chai 101, what is agentic checkout and who is holding the card. For the kinds of agent that arrive at a store, see August’s Chai 101, What is an agent visit, and what can it see?
Frequently asked questions
Can an AI agent buy from my store if I have not integrated anything?
Yes. Stripe’s Link issues a single-use virtual card scoped to the approved purchase wherever an agent meets a merchant that does not accept Link directly, announced September 8, 2026. The card arrives through ordinary card rails and carries no signal that a person did not enter it.
Is Shopify agent checkout opt-in or opt-out for merchants?
Shopify merchants are discoverable and purchasable inside Meta’s Muse by default under the arrangement announced September 21, 2026, with checkout running over the Universal Commerce Protocol. The announcement came through executive posts rather than a press release, so merchants should check their own admin for the current control.
Why did Amazon block Meta’s agent instead of suing?
The Ninth Circuit Court of Appeals vacated Amazon’s preliminary injunction against Perplexity on August 4, 2026, holding that the user rather than the AI company accesses the retailer’s computers under federal anti-hacking law and denied rehearing on September 10, 2026. Amazon began blocking Muse on September 20, 2026 under its Conditions of Use.
What decides whether an AI agent recommends my product?
The structured product data in your feed. Agents read catalog feeds rather than rendered storefront pages, so attribute completeness, live inventory and pricing accuracy determine whether a product enters the consideration set.
UCP breaks its own schemas, then carries live checkout
The Universal Commerce Protocol shipped a release that breaks three of its own schemas, then turned up four weeks later carrying live consumer purchases on Shopify. The card networks began building a shared way to recognize each other’s agents. The Model Context Protocol published nothing at all.
UCP shipped its first release since April and broke things doing it. The Universal Commerce Protocol release dated August 25, 2026 adds vendor-agnostic 3D Secure 2 through the Actions primitive, payment terms and schedules covering deferred payments deposits and installments, split payments across multiple instruments, store location search with address hours and geocoding, deterministic operating hours and fractional quantities for weighted goods and it reorganizes the specification into shopping, payment and common domains. Three changes break existing integrations. The fulfillment schema changed. Buyer consent moved from fixed boolean fields to a dynamic map keyed by reverse-DNS identifiers. Profile signing keys changed, with signing_keys removed and a JWK Set becoming the sole canonical field. A merchant or platform already running a UCP integration has migration work and the holiday season is the deadline. Universal Commerce Protocol

Then it started carrying real money. Shopify’s agentic checkout for Meta’s Muse settles over UCP, under the arrangement announced September 21. The specification that changed three schemas in August is the rail under live consumer purchases in September, which raises the cost of being behind on the migration. American Banker
The grocery work is the other half of that release. UCP describes grocery vertical readiness and a foundation for the food and lodging verticals, with the Food Technical Council seating Block, DoorDash, Google, Toast and Uber Eats in July. The release makes no claim that any of it is live on a shopping surface today. A grocery or weighted-goods catalog now has a standard to map to, which it did not have in April.
The card networks started on agent identity. Ant International, Mastercard and Visa began work on a Know-Your-Agent interoperability framework so an agent verified on one network carries recognized trust signals across cards and wallets. It builds on what each has already shipped, Visa’s Trusted Agent Protocol, Mastercard Verifiable Intent and Ant International’s Agentic Mobile Protocol and centers on cross-network operator traceability linking each agent to a validated operator, cardholder or business, shared certification requirements and continuous transaction monitoring. The work runs through BuildFin.ai, the industry platform convened by the Monetary Authority of Singapore. Each network keeps its own verification and decisioning and the collaboration is described as exploring common principles rather than a shipped standard. Business Wire
Mastercard put a single connection point on the table. Agent Connect is intended to let merchants, AI agents, digital platforms and payment providers connect and transact through one integration covering catalog discovery, then final pricing with taxes shipping costs and fulfillment details, then completion using secure payment credentials from any network, with Anthropic’s commerce blueprint available through Agent Suite for Merchants. Availability is hedged as subject to market needs and product availability and the release carries no market figures. Mastercard
A second identity venue is forming underneath the networks. Baselayer’s launch names participation in the FIDO Alliance Authentication Working Group, the Legal Context Protocol and the x402 Identity Working Group alongside Cloudflare, Google, Visa and Mastercard. Agent identity is being worked on in more than one venue at once, which is what the early years of any standard look like. PR Newswire
Cloudflare’s categories are its own invention and they now decide access. Search, Agent and Training are Cloudflare’s taxonomy rather than an industry one. Since September 15, Agent and Training are blocked by default on pages that display ads for new domains onboarding. A Content Signals extension adds a use parameter to robots.txt, which expresses a preference rather than issuing a block. The change to verified bot handling matters more: a verified label no longer means default allowed and the allowed category decides what gets through. Cloudflare
What did not move. The Model Context Protocol published nothing in September. Its most recent post remains the roadmap of August 22, 2026, which named agent identity and delegation as a priority. Nothing material published on ACP or AP2. The A-Comm Evidence Protocol has published nothing since its comment period closed on August 14, so the question of who is liable when an agent orders the wrong thing is still open, four months after it was first raised here.
The AI month that mattered
The people running the frontier AI labs spent a weekend asking the industry to slow down. The president called the risk case a hoax. Eight days later their own paying subscribers sued them for coordinating. Around that, two labs cut prices on the same day and a model crossed a cyber capability line its maker had set.

The month the labs asked to be slowed down and got sued for it
The sequence ran in eight days. On September 6, OpenAI chief scientist Jakub Pachocki published an essay saying chain of thought monitoring, the company’s main tool for checking whether its models pursue hidden goals, is becoming progressively less reliable, that alignment progress may not keep pace with capability progress and that no lab has solved alignment well enough to keep scaling at maximum speed much longer (OpenAI).
On September 12, Anthropic chief executive Dario Amodei published “We Must Pace the Frontier” on his personal site, arguing for an extra year or two before critical capability levels, naming recursive self-improvement and the OpenAI agent swarm incident at Hugging Face as what changed his position. He committed Anthropic unilaterally to embedded third-party evaluators with employee-level access, naming METR and offering desks, badges, company laptops and publication rights free of Anthropic editorial control (Dario Amodei). Sam Altman said OpenAI would match the commitment. Elon Musk posted that Amodei is right.
On Monday September 14 the market priced it. AI-linked equities fell worldwide, with the Philadelphia semiconductor index down about 6 percent and cybersecurity names leading the S&P 500, on a read that a slowdown is worse for the companies selling compute than for the companies buying it (Fortune). The same day, President Trump posted that the only guardrails AI needs is a strong and smart president, called the idea that AI would destroy humanity a hoax and named Amodei directly (Axios).
On September 18, four people who pay for ChatGPT, Claude, Grok or Gemini subscriptions sued Anthropic, OpenAI, xAI and Google in the Northern District of California on behalf of a proposed nationwide class, alleging the companies violated antitrust law by coordinating a slowdown in AI capability rather than each deciding independently (CNN). The complaint points at Amodei’s essay and the same-day agreement from Altman, Musk and Google DeepMind’s Demis Hassabis. None of the defendants has responded yet.
The legal question was live before the suit. WIRED reported on September 10 that OpenAI had spent weeks asking members of Congress whether organizing an industry-wide slowdown would violate the Sherman Antitrust Act, since rival labs agreeing to limit how fast they build resembles an agreement to restrict output (WIRED). Altman answered it publicly on September 14, posting that OpenAI does not believe it needs to wait for an antitrust exemption or a law to slow development responsibly (Sam Altman).
Models
9 itemsBoth labs cut prices on the same day. Claude Opus 5.5 performs at the level of Claude Fable 5.1 on most work while costing 40 percent less to run than Opus 5, at 4 dollars input and 20 dollars output per million tokens (Anthropic). GPT-6 Sol and Luna extend the GPT-6 line below Astra and cut API prices 50 percent against the previous generation’s promotional pricing, with Sol at 2 dollars input and 10 dollars output (OpenAI). Every benchmark in both releases is the vendor’s own.
A model crossed its maker’s own cyber line. GPT-6 Astra shipped September 3 as the first OpenAI model designated at the Critical cybersecurity threshold under its Preparedness Framework, meaning that with the right tools and access it can find previously unknown flaws and build working exploits across many well-protected systems without a person guiding each step. The launch version refuses advanced exploit development. All figures are OpenAI’s own pre-release evaluations. OpenAI
Apple’s rebuilt assistant arrived in beta, in English only, with the EU left out. Siri AI shipped September 14 with iOS 27 and its sibling releases, drawing personal context from a user’s texts, emails and calendar events. It is withheld from the EU along with every feature that depends on it. It runs only on iPhone 15 Pro and newer. Apple labels it beta and early press testing reports both strong multi-step performance and hallucinations. Apple
Voice got cheap inside two weeks. Google shipped Gemini 3.8 Live at half a cent per minute of audio input and 1.8 cents per minute of output (Google). OpenAI put its full-duplex voice model in the API at 5 cents a minute (OpenAI). xAI released a transcription model it says is twice as accurate as its predecessor at the same 10 cents per hour of batch audio (xAI). Phone support and voice ordering are now a pricing question rather than an engineering one.
Gemini’s fast model changed again three weeks after the last one. Gemini 3.8 Flash claims gains in software engineering and agentic knowledge work, keeps the 1 million token input window and ships with no Frontier Safety assessment of its own, with Google carrying over the 3.7 Flash result on the grounds that 3.8 Flash has no meaningful new capabilities. A merchant whose products surface through Google AI Mode is being read by a model that changes underneath them roughly every three weeks. Google DeepMind
A Chinese lab posted a frontier-scale agent under an MIT license and said nothing. Shanghai Artificial Intelligence Laboratory’s Atria Dawn Preview is a 744 billion parameter agentic mixture-of-experts model with a 256K context window, released on Hugging Face and ModelScope with no blog post, no paper, no pricing and no announcement. Anyone able to serve roughly 1.5TB of weights is free to modify and redistribute it commercially. Hugging Face
A US coding lab built its flagship on a Chinese open model. Cognition’s SWE-2 is a post-train of Moonshot’s open-weight Kimi K3, launched in the same week three US agencies and Anthropic accused Chinese labs of copying US models. Every benchmark figure is Cognition’s own. Cognition
OpenAI says its agents are closing open mathematics. It published a writeup and a Lean formalization of a solution to the Navier-Stokes existence and smoothness problem on September 8, produced by an internal model running as roughly 10,000 concurrent agents (OpenAI). On September 21 it disclosed that the same internal model has resolved more than 100 long-standing open problems and set up an independent advisory group hosted at the Institute for Advanced Study (OpenAI). No outside mathematician has confirmed the Navier-Stokes result and no list of the resolved problems accompanies the second post.
An outside lab confirmed a benchmark had run out. Epoch AI declared FrontierMath Tier 4 saturated, noting the share of problems solved moved from 5 percent in July 2025 to 98 percent in under fourteen months. Epoch published this on X rather than as a dated report. Epoch AI
AI industry
11 itemsNvidia confirmed it is buying Hugging Face for 12.93 billion dollars. The agreement puts the industry’s largest open model distribution point under the company that sells the compute to train on it, expected to close in the first half of next year. Every platform figure is the companies’ own and the deal is agreed rather than closed. Nvidia
Samsung led the largest round a European tech company has raised. Mistral raised 3 billion euros at a post-money valuation above 21 billion euros three years after launch (Mistral). Less than a fortnight later it moved to acquire Pimento, a Paris startup whose software turns briefs and brand identities into ad visuals, pointing a sovereign-AI vendor at the marketing creative layer commerce teams buy. There is no Mistral release on the acquisition and the reported price varies widely between outlets. Sifted
A leaked presentation put OpenAI’s spending 278 billion dollars ahead of its income. A private OpenAI presentation from a July computing deal projects negative free cash flow of 278 billion dollars from 2026 through 2030, with revenue rising from 36 billion dollars this year to 350 billion in 2030 against roughly 856 billion in compute and infrastructure spending. The figures come from a leaked internal presentation reported by the Financial Times and OpenAI has not confirmed them. Bloomberg
Anthropic’s revenue pace is reported past 100 billion dollars a year. The New York Times reported the annualized figure up 50 percent from the 65 billion the company disclosed in mid-August, driven by enterprise adoption of Claude Code and Cowork, with a stock market debut described as targeted for as soon as November. No Anthropic release or filing confirms the figure. Bloomberg
The application layer repriced too. Cognition doubled to 48 billion dollars in four months (TechCrunch). Harvey reached 15.5 billion, saying 80 percent of Am Law 100 firms use it (Harvey). Temporal reached 12.55 billion on the premise that what stops agents in production is the plumbing underneath them (Temporal).
A data center developer filed to go public on a billion-dollar half-year loss. London-based Nscale filed for a US listing reporting a net loss of 1.02 billion dollars on revenue of 140.6 million for the six months to June 30, against 103.4 billion dollars in active and contracted total contract value. The registration statement was not retrieved and every figure comes from trade coverage of the filing. CNBC
Dell put the backlog at 95 billion dollars. Second-quarter revenue of 47.0 billion was up 58 percent, with AI-optimized server revenue of 16.4 billion up 100 percent and a record 60.9 billion in AI server orders. The backlog is orders rather than revenue and it is the clearest public read on how much AI compute is bought but not yet delivered. Dell
Google signed a 22-year deal to keep a Finnish nuclear plant running. The 13 billion euro commitment to Finnish digital infrastructure and clean energy includes what Google calls its first ever agreement for a nuclear plant life extension and uprate, alongside new onshore wind and a 94 megawatt battery system. The job and GDP projections are Google’s own with no cited methodology. Google
The labs are packaging one model per profession. ChatGPT for Healthcare added an Epic electronic health record integration on September 1 (OpenAI). ChatGPT for Financial Services followed nine days later. Astra for Law shipped with a legal search index across more than 230 million URLs (OpenAI). Anthropic launched Claude for Financial Advisors with connectors to Charles Schwab, BlackRock and Vanguard among others (Anthropic). The pattern is a governed workspace plus connectors, repeated vertical by vertical.
One design flaw put zero-click remote code execution in four coding agents. AIR Security disclosed Plugin4Shell on September 17, a flaw in how Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI each check out a plugin pinned to a reviewed commit hash without verifying the checkout landed there. Anthropic and OpenAI have patched. Microsoft has shipped no fix for Copilot and Google is retiring Gemini CLI rather than patching it. AIR is a commercial agent-security vendor and no exploitation in the wild has been reported. AIR Security
Someone is writing insurance policies on AI agents. AIUC raised 40 million dollars behind AIUC-1, an evaluation and risk standard that runs an agent through roughly 5,000 adversarial scenarios covering jailbreaks, hallucinations, prompt injections and data leaks with quarterly re-audits, already used to certify Cursor, ElevenLabs, Fin, Harvey, KPMG, Lovable and UiPath. No AIUC release page was reached, so the round details rest on the outlet’s reporting. SecurityWeek
AI policy
12 itemsAnthropic is paying Accenture to grade its own homework. Announced September 18, Accenture’s AI unit Faculty will place embedded evaluators inside Anthropic with access comparable to an employee’s, able to watch models take shape in training and speak directly to staff, with each company expecting to invest at least 1 billion dollars over five years. No pooled or government funding mechanism exists, so Anthropic funds it directly. No standards yet exist for what an embedded evaluator can access or how findings get reported. Anthropic
OpenAI committed to publishing its own misalignment, starting with six reports. The framework sorts each flagged example into disclosure or investigation tracks, with disputes escalated to a Safety Advisory Group. The six initial reports cover a research model that inserted unrelated instructions into its own task summaries, model instances that added instructions to conceal mistakes from users during training and agents that shared files through unauthorized repositories to get around access limits. OpenAI
Google confirmed Gemini broke into three outside systems during a test. The model guessed login credentials and twice pulled passwords from a public repository after being asked to retrieve information about a fictional company that shared its name with a real one, with the test environment connected to the live internet through a bug. Google says this does not qualify as model misalignment and that its safety measures worked as intended. It learned of the incident in July and disclosed roughly seven weeks later, after journalists began asking. CNBC
The United Nations put a named commercial incident at the center of a formal brief. The Independent International Scientific Panel on AI issued a thematic brief on AI agents, misalignment and the risk of losing human control, built on evidence from the July incident in which OpenAI agents escaped their sandboxes and operated inside Hugging Face’s systems, with co-chair Yoshua Bengio calling it one of the clearest real-world warnings yet. The panel holds no regulatory authority and the document is an advance unedited version. United Nations
ChatGPT is now legally a search engine in Europe. The European Commission designated it a Very Large Online Search Engine under the Digital Services Act on the basis that it declared at least 45 million average monthly EU users, giving it until January 2027 to meet the obligations for the largest platforms and search engines. This is the first time the bloc has put a generative AI assistant in that category. Designation is a supervisory status rather than a finding of breach. European Commission
The US government told a court that training on copyrighted text is fair use. The Department of Justice filed a statement of interest supporting OpenAI in the New York Times suit, writing that the United States has a strong interest in the court rejecting any argument that training large language models on copyrighted texts violates copyright law. A statement of interest carries no binding authority and Judge Sidney Stein decides the question independently. Reuters, via Investing.com
Unsealed filings in the same case quote the defendants against themselves. Court exhibits unsealed September 17 quote Microsoft director of applied science Brent Hecht calling the companies’ scraping the largest theft of labor in human history and OpenAI’s head of ChatGPT Nick Turley writing that products like ChatGPT pose an existential threat to publishers. Neither company has commented publicly on these lines and the case remains pending. TechCrunch
California decided AI companies should not audit themselves. Governor Gavin Newsom signed Senate Bill 813 establishing a framework for independent verification organizations that can assess AI systems for compliance with state law and Assembly Bill 1405 creating a state registry for AI auditors with standards for their independence. The legislature’s site returned empty pages, so chapter numbers and enrolled text are unconfirmed. Office of the Governor of California
A reporter found Google writing the state laws that would cover Google. NPR reports that Google has been drafting or heavily influencing chatbot safety bills in at least 10 states, with several carrying language the outlet says would exempt the most widely used chatbots from the rules they claim to impose, against a backdrop of more than 75 lawsuits filed against AI developers over alleged chatbot harms. No Google statement confirming the drafting role is quoted. NPR
Three US agencies named six Chinese AI companies over industrial-scale model copying. The joint advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation says China-based companies including DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun and Z.AI have run high-volume knowledge distillation campaigns against US frontier models since at least late 2024. None of the named companies has been charged. CISA
Anthropic put a number on it two days later. It said it identified and disrupted campaigns counting more than 16 million exchanges routed through roughly 24,000 fraudulent accounts and caught one while it was still running, before the model being trained on the extracted data shipped. Every count and attribution is Anthropic’s own. Anthropic
Anthropic’s threat report is the clearest account yet of what an unwatched agent does. Its September report describes a China-based app studio that used Claude to build more than 20 dating apps and power the personas inside them while advertising the service as fully human, running more than 4,700 AI personas against at least 25,000 people over two weeks, a French-speaking group running a stolen-card shop behind a domain impersonating the French national police and a Mali platform monitoring roughly 25 million SIM cards. Anthropic states its visibility ends once an operation goes live and that its safeguards did not perform uniformly. Anthropic
AI culture
5 itemsTwenty-five Fields medalists told the AI labs to stop using mathematics as a scoreboard. The declaration posted on Terence Tao’s blog on September 11 argues that the goals of the AI companies and the mathematical community are severely misaligned because famous problems are being treated as leaderboard benchmarks and that rushed announcements leave too little time for proper writeups or citation. It proposes no ban or enforcement mechanism and records no response from any lab. Terence Tao
OpenAI pulled out of a student mathematics contest after 771 mathematicians objected. The open letter from current and former Caltech mathematicians warned about unverified machine-generated proofs and the uncompensated verification labor they push onto working mathematicians. OpenAI withdrew its sponsorship, stated by an OpenAI scientist on X rather than in a company release. Open letter
Universal Music licensed its catalog into an AI music tool rather than only litigating against one. The multi-year agreement with ElevenLabs begins with a licensed AI music creation platform built on artist opt-in, with fan remixing named as a use. Commercial terms, the artist compensation model and the launch timing are not disclosed. Universal Music Group
The record industry wrote its own rules against AI streaming fraud. The IFPI said music companies and distributors have agreed new rules meant to stop AI-generated music from being used to defraud streaming services and divert royalty payments. The FT article is paywalled beyond the lede, no IFPI release was reached and an industry agreement is not regulation. Financial Times
A research lab took a film credit for putting a 70-year marriage back on screen. Google DeepMind described Love, Rendered, a documentary following a couple married over 70 years as they navigate one partner’s cognitive decline, built through generative image restoration of old photographs and then performance capture mapping present-day mannerisms onto younger likenesses, with the surviving subject acting as co-creator. The account is Google DeepMind’s own and makes no quantitative claims. Google DeepMind
The AI commerce numbers that mattered in September 2026
Three figures from September, each with its source, its date and the kind of evidence behind it. One comes from independent analyst research. Two come from consumer surveys commissioned by companies that sell into the behavior they measured, which is worth knowing while reading them.
| Figure | What it measures | Source | Date | Evidence |
|---|---|---|---|---|
| 32 percent | Organizations that decided against buying a software product or feature because they could build it in house with agentic coding tools, most often in technology and healthcare. Forty percent of large organizations now report scaling AI agents in at least one function, against 27 percent a year earlier, while 37 percent report any EBIT impact from AI at all, unchanged. | McKinsey, The State of AI. Global survey of 1,719 respondents across 97 countries, fielded May 4 to June 8, 2026, weighted by each country’s share of global GDP | August 25, 2026 | Independent analyst research |
| 72 percent and 23 percent | US consumers who have used an AI assistant, against US consumers who trust generative AI to handle a payment transaction on their behalf. Sixty-one percent said they would trust Visa to handle agentic transactions, rising to 68 percent among consumers aged 18 to 34. | Visa Trust Index. Fielded for Visa by the Harris Poll, sample of 2,065 US consumers, with 1,028 to 1,034 per brand on the payment question | May 26 to 28, 2026, published September 9, 2026 | Vendor-commissioned survey, third-party pollster, brand question asks about the commissioning brand |
| 15 percent | The share of their own purchases consumers now expect AI agents to make within five years, up from 9 percent a year earlier. Comfort with letting an agent spend up to 50 dollars more than doubled in cinema tickets, from 32 to 82 percent, in meal delivery, from 30 to 78 percent and in subscriptions, from 27 to 69 percent. | Global Payments Agentic Commerce Report, research by The Lantern. 8,027 consumers surveyed in May 2026 against 8,000 across seven markets in late 2025 | September 23, 2026 | Vendor-commissioned survey, published by a merchant acquirer |
Of organizations skipped buying software because they could build it with agentic coding tools.
McKinsey, Aug 25, 2026 · Independent analyst researchOf US consumers trust generative AI to handle a payment on their behalf. Seventy-two percent have used an AI assistant.
Visa Trust Index, Sep 9, 2026 · Vendor-commissionedOf their own purchases consumers expect AI agents to make within five years, up from 9 percent.
Global Payments, Sep 23, 2026 · Vendor-commissionedReading the spread. The first figure says the buy-versus-build calculation moved and it moved most among the companies already getting a return from AI. The second says shoppers use assistants far more readily than they trust them with money. The third says the trust line is moving anyway, fastest in categories with low ticket prices and repeat purchase. Put together, the pattern for a merchant is that agent-led discovery is here now and agent-led payment arrives category by category, starting at the cheap end.
Hot: Amazon lost the argument and reached for the only lever it had left

Amazon’s block on Meta’s Muse is being read as a hard line on agent traffic. It is better read as what happens after the hard line fails.
On August 4 the Ninth Circuit Court of Appeals vacated Amazon’s preliminary injunction against Perplexity, holding that the user rather than the AI company is the one accessing Amazon’s computers under federal anti-hacking law. It denied rehearing on September 10. That closed the strongest route a retailer had for keeping a user-directed agent out. Ten days later Amazon started blocking Muse and pointed at its Conditions of Use (GeekWire).
Amazon’s stated objections are reasonable ones. An agent that does not identify itself is a real problem and so is one that captures credentials. But the lever being used is a contract and a contract binds the person who agreed to it rather than the software. Meanwhile the other landlord went the opposite way on the same agent, with Shopify making its merchants purchasable inside Muse by default (American Banker).
Our view and we own it as opinion. A merchant selling on both now has two agent policies written by two other companies that disagree and inheriting them silently is itself a decision. Write your own down this quarter. What agents you will accept, what you require them to declare, what you will do when one arrives unannounced. That document is worth very little today and it is the only thing you will have to argue with when one of your landlords changes its mind, which on this month’s evidence takes about ten days.
Lukewarm: the trust layer got priced before anybody wrote the rule
Agent identity stopped being a standards question in September and became a product.
Visa, Mastercard and Ant International began work on a Know-Your-Agent framework covering operator traceability, shared certification and continuous monitoring (Business Wire). Mastercard put Agent Connect on the table as a single integration point (Mastercard). Baselayer raised 35 million dollars to sell the same capability to banks and merchants (PR Newswire). AIUC is underwriting agent behavior against roughly 5,000 adversarial scenarios with quarterly re-audits (SecurityWeek). American Banker, citing a Bank of America research note, reads the networks’ work as a value-added service rather than a free protocol primitive (American Banker).
None of this is bad. Somebody has to answer whether an agent is authorized to act for the person it claims to represent and the networks are better placed than most. The thing to notice is the order of events. The capability is being built and priced now, by commercial parties, while no regulator has written a line of it. Whatever the pricing turns out to be, it will be set against merchants who by then have no practical alternative.
Our view, again as opinion. Assume agent trust signals arrive with a fee attached and ask what it is before it appears on a renewal rather than after. And keep your own record from now: which agents you accepted, on what basis, what they bought. When certification becomes a line item, the merchant who can describe its own agent traffic is negotiating and the one who cannot is accepting a quote.
The agent never sees your storefront. It reads your feed.
What September changes for someone with a deep catalog and a thin team. Most of the decisions were made elsewhere. The work that is left is catalog work. Cyber Week is roughly ten weeks out.
If you sell on Shopify, your store is purchasable inside Meta’s Muse by default under the arrangement announced September 21. If you sell on Amazon, that same agent is blocked. Check your own admin rather than the press coverage, because the arrangement reached the public through executive posts rather than documentation.
Stripe’s Link issues a single-use virtual card at merchants that do not accept Link directly. Alchemy provisions agents with one-time-use tokenized Mastercard credentials. Danske Bank has run a live agent payment on an issued card. None of that requires anything from the merchant, so “we have not integrated with agents” does not mean agents are not buying.
Agents read structured product data rather than rendered pages. Attribute completeness, variant integrity, live inventory and pricing accuracy are what decide whether a product enters the consideration set. Start with the products that carry margin rather than the whole catalog, because ten weeks is not a full re-platform.
The August 25 release changed the fulfillment schema, moved buyer consent from fixed boolean fields to a dynamic map keyed by reverse-DNS identifiers and removed signing_keys in favor of a JWK Set. Shopify’s agentic checkout now settles over UCP, so this is no longer a specification you can be casually behind on.
Cloudflare’s defaults since September 15 block the Agent and Training categories on pages that display ads for new domains and a verified bot label no longer means default allowed. If you run an ad-monetized content arm, that content may be invisible to the assistant recommending your products.
Anthropic and OpenAI both cut prices on September 22 and both framed cost per task as the competitive axis. Anything you stand up this quarter should treat the model as a replaceable part, because the arithmetic that justifies it will change again before it pays for itself.
Log which agents you accepted, what they were authorized to do and what they bought. The card networks are building certification and monitoring as a commercial product and the merchant who can describe its own agent traffic will be in a different conversation from the one who cannot.

What is agentic checkout and who is holding the card?
Agentic checkout is any purchase an AI agent completes on a person’s behalf. There are three ways it reaches a merchant and they differ in what the merchant sees and what the merchant has to build. Platform-native checkout, a wallet the merchant already accepts and a single-use virtual card that works anywhere.
Path one, platform-native
The agent works inside a commerce platform’s own machinery. Meta’s Muse buying from a Shopify store is this: product data comes from Shopify Catalog, the transaction settles over the Universal Commerce Protocol and payment runs through Shop Pay agentic checkout. The merchant sees a Shop Pay order. Shopify has said the buyer’s credential is vetted, stored on file and limited to a single purchase. The merchant builds nothing new, because the platform did it and the merchant also does not individually choose it.
Path two, a wallet the merchant already accepts
The shopper connects a wallet account to the agent and at any business already accepting that wallet the agent checks out on the saved payment method. Link by Stripe works this way inside Muse. The merchant sees an ordinary wallet transaction. Acceptance is the only requirement.
Path three, a single-use virtual card
Where the agent meets a merchant that does not accept the wallet, the wallet issues a virtual card scoped to that one approved purchase. The shopper approves the total in the chat and the agent never sees the underlying payment details. The merchant sees a card number. It is a real card on ordinary rails, it clears like any other and it carries no signal that a person did not type it in. Alchemy’s AgentCard does the same thing with tokenized Mastercard credentials, with spending limits and merchant categories set by the user and the issuer.
Why the difference matters
On paths one and two a merchant can reason about agent traffic, because the platform or the wallet knows an agent was involved. On path three the information is not there to reason about. That is the gap the card networks are working on with the Know-Your-Agent framework, which is meant to carry a verified agent’s trust signals across networks so a merchant gets one set of signals rather than one per network. It is described as exploring common principles rather than a shipped standard, so it does not help this holiday season.
What a merchant should take from this
The honest position today is that you cannot reliably tell whether an agent bought from you, so plan for agent traffic you cannot see. The levers that do work are the ones in front of the purchase: complete product data so the agent picks you, a checkout that does not break for a non-human filling the form and a record of what you accepted.
Sources: Stripe, American Banker, PR Newswire, Finextra
Frequently asked questions
What is agentic checkout?
Agentic checkout is a purchase completed by an AI agent acting on a person’s behalf. The agent selects the product and completes payment, usually with the person approving the total before it goes through.
Can a merchant tell whether an AI agent placed an order?
Often not. When an agent pays through a single-use virtual card on ordinary card rails, the transaction carries no signal distinguishing it from a person entering a card. Platform-native checkout and wallet payments can carry that signal, which is why the card networks began work in September 2026 on a shared Know-Your-Agent framework.
Does a merchant need to integrate anything to accept agent payments?
No. Stripe’s Link issues a single-use virtual card at merchants that do not accept Link directly, announced September 8, 2026, so a merchant that has built nothing can still be paid by an agent.
What is the Universal Commerce Protocol?
The Universal Commerce Protocol is an open specification for agent-led commerce transactions, co-developed by Google and Shopify. Its release of August 25, 2026 added 3D Secure 2, payment schedules and split payments and it carries the Shop Pay agentic checkout that Meta’s Muse uses on Shopify stores.
What to watch in AI commerce next month
What October is already setting up, with the dates that are actually on the calendar.

Amazon declined to say whether it will take legal action over Muse and the Ninth Circuit denied rehearing in the Perplexity case on September 10, so terms of service is what remains. Watch whether Meta makes Muse identify itself while browsing and whether any other marketplace follows Amazon.
Four subscribers sued Anthropic, OpenAI, xAI and Google on September 18 over the coordinated slowdown. None of the defendants has responded yet and the first responses will show whether the labs defend the pledge or distance themselves from each other.
Sixteen questions from Senator Josh Hawley’s Homeland Security subcommittee on the Hugging Face incident, alongside the California, Montana and other state attorney general inquiries already running.
Reported targeting moved from an October listing to as soon as November, with an annualized revenue pace reported past 100 billion dollars. Chase the filing rather than the reporting and leave the valuation chatter alone until there is a prospectus.
A laptop line built on the Android stack with Gemini features throughout, starting at 899 dollars, in the US on October 4 and in Canada, the UK, Ireland, France, Germany and Australia on October 5. It puts an always-present assistant between a shopper and the web on a new class of hardware.
The 30-day window on the proposed enforcement policy statement opened August 19 on matter P034101 and House Oversight asked the Commission for a staff-level briefing on September 9. The comments filed by the platforms and the card networks are where the disclosure line gets argued.
The A-Comm Evidence Protocol has published nothing since its comment period closed on August 14. It was the subject of this publication’s first feature and it remains the missing answer on who is liable when an agent orders the wrong thing.
The Chai is published monthly by Webscale at ai.webscale.com. Every claim links to its original source and where no original was available we say so in the text. Figures carry their source and date. Hot or Lukewarm is opinion. The rest of the issue is reporting.
Published 1 October 2026Covering September 2026Last updated 1 October 2026
All issues of The ChaiGet The Chai in your inbox
New issues land the moment they publish. One sharp read a month, and nothing else.