Harsh Mehta, Head of Partnerships for AI and Agentic Commerce at Worldpay, spends his days at the intersection of AI and payments, working with frontier labs, card networks, and merchants trying to figure out what commerce looks like when an agent is the one shopping. He is unusually candid about what is real today versus what is marketing, and he lays out the three problems the industry has not solved: thinning data signals, agent identity, and proving intent and liability at scale.
The discussion gets specific on the parts most people gloss over. Fraud detection is being inverted, because legitimate agent traffic now looks exactly like the machine behavior fraud teams spent twenty years learning to block. Liability may not land where you expect, since a merchant's own bad product data can be the thing that misled the agent. And the question of who owns the trust layer, the record of what a customer actually authorized, is quietly one of the most contested in the entire value chain.
What follows is a breakdown of the strongest points from the conversation, from why B2B procurement may scale faster than consumer shopping, to why the unglamorous work of identity and clean product feeds is what everything else will depend on.
What Agentic Commerce Actually Is Today
- Harsh Mehta defines agentic commerce as any journey where an AI agent is involved somewhere in the flow, whether in product discovery, consideration, decisioning, checkout, or post purchase.
- He draws a sharp line between reactive agents (a user asks for the best running shoes under a set budget and the agent helps compare and build a cart) and proactive agents (the agent knows enough about you to suggest booking an anniversary table because it sees the date and your calendar).
- The proactive, act-on-your-behalf scenario is what Mehta calls the holy grail, and he is explicit that the industry is not there yet despite what conference agendas and LinkedIn feeds suggest.
- Almost everything in production today is human in the loop: the agent does discovery and legwork under frameworks like OpenAI's ACP and Google's protocol, but a human still confirms or takes back control to pay and authenticate.
Why Full Autonomy Is Still Rare
- Browser agents shopping the open web mostly only work where guest checkout is enabled, and even then fraud tools and CDNs like Cloudflare and Akamai are effective at blocking them, producing high latency and low success rates.
- Fraud tools today do not know that legitimate agents are coming, so they block them by default.
- Mehta cites Amazon's "Buy for Me" (its Rufus agent shopping the open web when an item is not in Amazon's own inventory) as the closest thing to real autonomy he has seen, but notes he has not seen it work at scale in the wild.
- Checkouts are simply not built to let a browser agent drop card details into a merchant page, so transactions still stop at checkout and require a human.
The Structured vs Open Web Split
- Mehta notes that Google's structured commerce protocol is live and started deliberately narrowing with retail, with hotel bookings and food delivery to follow.
- The long pole in agentic commerce is not payments, it is everything before payment: product discovery, product data, and structured feeds.
- Google's structured approach now includes embedded checkout as part of the flow, but only for retail to start.
B2B May Outpace B2C
- Mehta argues B2B and procurement are lower hanging fruit because both ends are known entities and the flows are more structured.
- He points to companies like Ramp as showing early activity in the procurement agent space, spanning accounts payable and receivable.
- He would bet on B2B being a larger chunk of agentic transactions than B2C by roughly this time next year, and suggests it is already happening quietly because it does not make for interesting press coverage.
The Three Hardest Unsolved Problems
- Data loss: in agentic flows the rich signal set (who the customer is, their device, their history) gets much thinner, often reducing to guest checkout or less, forcing trust decisions with less information than ever.
- Identity: genuinely knowing an agent is who it claims to be is progressing but not fully solved.
- Intent and liability at scale: proving what an agent did matches what the human asked for, in a way that holds up when something goes wrong, across millions of transactions, thousands of merchants, dozens of agents, and hundreds of banks.
Fraud Detection Gets Inverted
- For two decades, machine speed behavior (checking out in 300 milliseconds with no mouse movement) was one of the most reliable fraud signals.
- Agentic commerce breaks that model because legitimate agent traffic now looks exactly like what fraud systems were built to block.
- Agent driven browsers do not behave like classic bots either: they pause, misclick, and move in a way that is almost human but slightly jerky, sitting between human and bot.
- The core fraud question shifts from "is this a machine" to "is this a legitimate machine acting for a real person within what they authorized."
- Mehta warns the near term fraud problem for many merchants is not a clever new attack, it is their own fraud stack blocking legitimate agents and quietly costing them revenue, a false positives problem he credits to Worldpay's Ravelin CPO Mark Barlow.
The Identity and Delegation Model
- Nick Lambert describes Dock Labs' approach as tying an agent to an individual and binding buyer intent into the same flow.
- In his AI agent identity solution, the agent is its own distinct entity with its own wallet, not the agent using the user's wallet or pretending to be the user, though he acknowledges the law needs to catch up.
- The flow he outlines: a user completes IDV, receives an IDV credential, then delegates authority to an agent through a credential, so the agent can present a signed verifiable presentation showing who it is, who it represents, and who it is bound to.
- Mehta agrees the emerging industry answer is cryptographic, citing the Web Bot Auth approach pioneered by Cloudflare and now used by others, which lets a platform provably verify an agent is who it claims to be rather than just asserting it.
- Mehta observes the incentives line up for identity because reputable platforms do not want to be impersonated, making this far sturdier than maintaining lists of good IP addresses that go stale.
Intent Frameworks and Liability
- Mehta's view is that liability follows wherever the breakdown actually happened, which is why intent frameworks matter so much.
- He cites Mastercard's Verifiable Intent and Google's AP2 as being built to carry a signed, tamper evident record linking three things: the customer's identity, what they instructed, and what was actually bought.
- Mastercard's Verifiable Intent uses selective disclosure so each party sees only what it needs, for example a merchant proving an order was authorized within limits without receiving the customer's full identity.
- A point Mehta says is underappreciated: liability will not always land where expected. If a merchant's own vague or wrong product data misled the agent, that is arguably on the merchant, because the agent bought exactly what the data described.
- Mehta notes EMV adopted Verifiable Intent as a standard roughly a week before the recording, signaling an industry norm for deciding how liability shifts as agents gain autonomy.
Who Owns the Trust Layer
- The mandate verification layer (holding and checking the record of what the customer authorized) sits extremely close to the trust relationship, which is why ownership is contested.
- Mehta lays out genuine claims for AI platforms (closest to the consumer and intent), PSPs and networks (sitting at the transaction, carrying trust and fraud responsibility), and a neutral layer (so no one has to trust a single commercial platform's private incentives).
- Mehta's own bias, which he owns as a payments person's bias, is that it ends up federated: no single owner, different players holding different parts, stitched together by interoperable standards.
- Both Lambert and Mehta converge on shared responsibility, with Lambert arguing for a strong independent layer not controlled by any party with a vested interest, positioned as a technology rather than a single company.
Commercial Models Are Wide Open
- Mehta calls the economics one of the most under-discussed parts of the shift: putting an agent in the middle scrambles a value chain that is currently well understood.
- Open questions include whether the agent platform takes a cut, whether trust and fraud become premium paid services, and whether getting products seen by agents becomes something merchants pay for more than payment itself.
- ChatGPT has ads on its free tier as one monetization path, and Google hinted at a similar model at Google I/O, but both are early signals.
- Mehta's take is that value migrates toward whoever solves the harder problems, which in an agentic world are trust, identity, and discovery rather than payments execution.
The Closing Argument
- Mehta's first takeaway: this is not as far away as it seems, it is the topic of discussion with every merchant he speaks to, and Worldpay has an agentic commerce report coming in August with what he describes as staggering stats on consumer willingness to try the channel, especially for the best deal.
- His second takeaway: the unglamorous work now (getting identity right, verifying agents, keeping evidence, treating your product feed as your storefront) is what everything else will depend on.
- He frames the current human in the loop period as a quiet window before more autonomous flows arrive, and argues that is exactly why now is the moment to build foundations.





