On March 11, 2026, in a controlled production environment, an AI agent completed Latin America's first fully autonomous purchase: someone gave it a product, a maximum price and a delivery deadline, and the agent searched, compared, picked a supplier and paid, with no human touching another button. It took one minute. It happened in Brazil, with Banco do Brasil and Visa.
That same month, more than 5,000 miles away, OpenAI was quietly shutting down what was meant to be Western agentic commerce's showcase feature: "Instant Checkout" inside ChatGPT, after fewer than 15 of Shopify's millions of merchants had ever bothered turning it on.
That's the real picture of this moment: the infrastructure is being built faster than any headline can keep up with, but it isn't advancing evenly, in the same direction, or at the same pace across every region. And the rules -especially in Europe- are several steps behind what the technology already allows.
The stack being assembled: three layers, not one
Talking about "agentic commerce" as a single thing misses the point: it isn't a product, it's a stack of protocols that only just started taking shape, with at least three separate layers competing and combining at the same time.
The catalog and discovery layer is what lets an agent understand what you sell, at what price, with what availability, without relying on someone browsing your site with actual eyes. Google and Shopify have been working on this together since NRF in January 2026, and expanded it in May at Google I/O with what they called Universal Cart: a cart that follows a person across Search, Gemini, YouTube and Gmail, with Google Wallet built in.
The checkout layer is the protocol that connects the buying agent to the merchant to complete a transaction. This is where Stripe came in, together with OpenAI, with the Agentic Commerce Protocol (ACP), published as an open standard on September 29, 2025.
The payment authorization layer is the newest one, and for any business selling into Europe, the one that matters most: it's where AP2 lives, Google's protocol that solves something neither Universal Cart nor ACP solve on their own -verifiable proof that a person actually authorized this agent to spend this money, at this merchant, under these conditions-.
None of the three layers owns the other two. A real agent, today, can perfectly well discover a product through Universal Cart, complete checkout through ACP, and prove consent through AP2. They're complementary layers, not competing protocols -though the three companies behind them are absolutely competing for something else: which one ends up as the infrastructure everyone else depends on-.
What Google is building: less storefront, more plumbing
AP2 (Agent Payments Protocol) was announced on September 16, 2025, with 60+ launch partners, including Mastercard, American Express, PayPal, Coinbase, Revolut and Adyen. Its core piece is mandates: cryptographically signed digital contracts, built on the W3C Verifiable Credentials standard, that leave a tamper-proof audit trail.
There are two kinds. The Intent Mandate captures the person's original instruction -what they want, how much they're willing to pay, under what time limit-. The Cart Mandate gets signed once the agent has finalized the purchase, locking in the exact items and price: what you see is what you pay, literally.
On April 28, 2026, Google took a step that says more about its strategy than any product announcement: it donated AP2 to the FIDO Alliance, the neutral consortium that already governs standards like passkeys, taking it out of its own direct control. In that same update -protocol version 0.2- it added a mechanism called "Verifiable Intent," co-developed with Mastercard, and formalized a flow for operating without a human present at the exact moment of purchase (pre-authorized delegation, with limits already set in advance).
The read here is clear: Google isn't fighting to be the app where you buy. It's fighting to be the trust standard running underneath any app where you buy, yours or a competitor's.
What Stripe is building: the first real stumble, and why it matters
ACP is the protocol behind the most visible attempt at mass agentic commerce so far: "Instant Checkout" inside ChatGPT, which launched with Etsy and later added a dozen Shopify brands (Glossier, SKIMS, Spanx, Vuori). The technical deal is tidy: the merchant stays "merchant of record," the agent only hands over a scoped payment token, and OpenAI keeps a 4% fee on every completed purchase.
The problem wasn't the protocol. It was everything the protocol doesn't solve on its own: US sales-tax remittance, real-time inventory sync, refunds, fraud. The same boring, operational problems any real e-commerce business knows by heart, and that no shiny AI demo solves with a nice API. By March 2026, with fewer than 15 Shopify merchants live out of millions available, OpenAI shut down Instant Checkout as a native in-chat experience and started routing purchases to each merchant's own app instead.
This didn't kill ACP -Stripe and OpenAI are still developing the spec, and PayPal joined as a payment provider in October 2025- but it did leave an uncomfortable lesson for anyone selling the idea that "agentic commerce is already here": the most visible, most hyped piece turned out to be the most fragile. What survived was precisely the boring part: the authorization protocol, not the storefront.
Europe: the technology already runs, the legal framework doesn't exist yet
Here's the core problem for any business selling into the European Union, and it's more serious than it first sounds: today, a payment initiated by an AI agent is subject to exactly the same PSD2 and Strong Customer Authentication (SCA) rules as any human-initiated payment, with no special carve-out at all. It's not that a specific rule is missing: it's that the current rule never contemplated a payment being initiated by something that isn't a person, and nobody has updated it yet.
That leaves open questions with no regulatory answer today: how do you prove, in an auditable way, that the person consented to that specific transaction? Who's on the hook if an agent overspends due to a delegation error? Who is, legally, "the one providing the payment service" in a chain that involves an agent?
The next major update -PSD3, together with the new Payment Services Regulation (PSR)- reached political agreement in trilogue on November 27, 2025, the Council signed off on final compromise texts on April 23, 2026, and Parliament's vote and publication in the Official Journal are expected around mid-2026. But the new rules only start applying 21 months after publication: meaning, at best, late 2027 or sometime in 2028. Agentic commerce is already in production today. The legal framework meant to govern it isn't in force yet.
The AI Act doesn't have a dedicated category for "shopping agent" either: it classifies by function, not by architecture, and several legal analyses agree an agent that influences financial decisions could end up falling into the "high-risk" category -but that's expert reading, not an officially confirmed classification yet. There is one new, concrete rule already in force since June 19, 2026: every online store selling to EU consumers has to offer an electronic "withdrawal button" to exercise the 14-day right of withdrawal, with no dark patterns hiding it. It wasn't written with agents in mind, but it applies just the same when an agent completed the purchase: the person keeps exactly the same right.
The quote that best captures the regulatory mood didn't come from the European Union itself, but from the Bank of England -delivered, fittingly, at the European Central Bank's own forum in Sintra, on June 30, 2026. Deputy Governor Sarah Breeden put it this way: "our frameworks were not built to contemplate autonomous agents, and relying on a human in the loop for all agent actions is unlikely to be realistic," and floated the idea of market-wide "kill switches." The UK, in fact, is one step ahead of the EU on this exact question: HM Treasury opened a public consultation on July 14, 2026, asking directly whether payment rules need to change to accommodate agentic payments.
Meanwhile in Latin America: less debate, more execution
The flip side of this story is that Latin America, with much less regulatory debate behind it, already has real agentic commerce running in production. The Banco do Brasil and Visa transaction from March 2026 wasn't a lab pilot: it ran on Visa Intelligent Commerce, with real bank authentication and tokenization. A month later, in April, Visa launched its "Agentic Ready" program in Brazil with five issuers and processors in the first phase: Banco do Brasil, Bradesco, Dock, Santander and XP.
Mastercard is moving in parallel: it announced in December 2025 it would launch "Agent Pay" in Latin America in early 2026, leaning on something the region has already solved that Europe is still building -close to 100% of Latin American issuers already have tokenization enabled-. The underlying argument is Pix: Brazil's instant payment system processed 64 billion transactions in 2024 alone, and digital payments are projected to go from 48% to 66% of regional e-commerce value by 2030. A mature, high-volume, culturally accepted instant-payment rail is exactly the terrain where a shopping agent has the least friction to operate -nobody needs convincing to drop the physical card, the region already skipped that step-.
None of this means the region has its regulatory house in order. Banxico, Mexico's central bank, warned in June 2026 about a specific risk from AI agents that nobody has quite figured out how to regulate: multiple agents operating at the same time, with no explicit agreement between them, can end up behaving collusively and harming third parties -without any actual conspiracy ever existing to prosecute-. In Argentina, the BCRA has been updating its payment-service-provider framework (the recent "PSP as a Service" category), but there's still no specific rule or communication about AI agents and payments.
The pattern repeating across the region is the same: the payment rails are already ready and proven at scale, technical execution has already started via Visa and Mastercard, and specific regulation for this -like in Europe, though for different reasons- doesn't exist yet.
What we recommend, as a team that builds this every day
With this picture -infrastructure accelerating, regulation lagging in both regions though for different reasons, and the most hyped early attempt (Instant Checkout) stumbling on exactly the boring operational part- the question that matters for any business selling into Europe or Latin America isn't "which protocol do I integrate first?" It's a different one:
Don't bet everything on a single checkout. Instant Checkout showed that the most visible layer is also the most fragile one, because it depends on solving taxes, inventory and refunds in real time, something no protocol solves by itself. What's worth building now, no matter which protocol ends up winning, is the layer underneath: a catalog with real structured data, inventory that responds in real time, programmable pricing rules. It's exactly what we already pointed to the first time we wrote about this, and this new wave of news doesn't change that foundation -it reinforces it-.
Start auditing consent before you're forced to. In Europe, today, an agentic payment is already subject to the same old rules, with no special protection for either the merchant or the consumer -and those rules won't catch up until 2027 or 2028-. That means any business already testing shopping agents is operating in a framework gap right now, not in some hypothetical future. The mandate concept -a signed, verifiable record of exactly what each transaction was authorized to do- behind AP2 isn't just a technical piece of a Google protocol: in practice, it's the standard of care any serious business should already be applying, whether or not it has a formal protocol integrated.
In Latin America, don't wait for regulation to catch up before solving fraud. The region has its payment infrastructure ready ahead of regulation -the exact opposite of Europe-, which is both a real speed advantage and a real risk, exactly as Banxico flagged with agent collusion risk. Solving that can't depend on a rule showing up: it needs to be in the system's design from day one -spending limits, traceability, a human in the loop on the highest-impact decisions-.
Treat this as an architecture problem, not a marketing one. We already saw this with Stripe's wallet and Coinbase's x402 protocol: three large companies building payment infrastructure for machines at the same time, in parallel, is a real signal of where this is heading. But the company that wins won't be the one that integrated this week's trendy protocol: it'll be the one that already had its catalog, inventory and business rules in shape for any system -AI or not- to operate without depending on a person filling out a form by hand.
If your business sells into Europe, Latin America, or both, and you want to understand how exposed you actually are today -not in the hypothetical 2028 when European regulation finally catches up- let's talk. It's exactly the kind of problem we solve every day in our AI process automation solution.