Viewpoint

Agentic Commerce Needs Rules Consumers Can Trust

Written by
No items found.
Benjamin Melnicki, Chief Compliance & Risk Officer, Cross River
September 18, 2026
|
5
min read

Agentic commerce is developing at a pace that makes most emerging technologies look slow. McKinsey projects up to $5 trillion in global agentic commerce volume by 20301. Visa, Mastercard, and major banks are completing live AI-agent-initiated payments right now. Shopify merchants have seen a 14x increase in orders from agentic applications in little over a year2. The technology works and is accelerating.

But governance hasn't kept up. As the Consumer Bankers Association recently concluded3, "the legal and regulatory frameworks governing consumer protection were built for a world where humans authorize each transaction. That world is changing rapidly." Existing rules don't clearly answer the questions consumers need answered: Who is liable when an agent makes a mistake? What decisions is it authorized to make? What protections apply when no human is in the loop?

The conversation around agentic commerce is dominated by extremes: hype on one end and fear on the other. Neither serves consumers with facts or guidance. People hear a lot, understand little, and trust even less. And the data confirms it. Only 14% of consumers trust AI to place orders on their behalf4.

We have seen this before. When crypto emerged, the initial instinct was to shoehorn it into existing governance frameworks built for entirely different instruments. That approach didn’t work. What did work, and what we helped build at Cross River, was a clear risk management framework from the ground up. One that acknowledged the unique characteristics of the technology while maintaining the consumer protections that matter. Agentic commerce is in need of this same treatment.

Disclosure must evolve

Traditional terms and conditions already fail consumers — the language is too dense, too long, and ultimately ignored. If we apply that same model to agentic technology, we'll get the same result: disclosures that technically exist but protect no one.

If we're serious about consumer protection in an agentic world, disclosure has to change. We need frameworks that are clear, concise, and answer the questions consumers actually have: What is this system doing on my behalf? What decisions can it make? What happens if it makes a mistake? Am I liable?

Here’s what purpose-built disclosure this looks like in practice:  

Your grocery agent is authorized to purchase household essentials up to $150 weekly from your pre-approved merchant list. The agent will reorder items when inventory drops below your set threshold. It cannot make purchases outside this category or exceed this limit without your explicit approval. If the agent makes an unauthorized purchase, you will not be liable—the transaction will be reversed within 24 hours, and the merchant will be flagged for review.

Every disclosure should follow this logic: if this happens, then that is the outcome. The bar is simple: a consumer should be able to read it, understand it, and know what they're protected against.

New technology demands new frameworks

Part of the confusion about agentic stems from a regulatory vacuum. There are no frameworks designed specifically for how autonomous agents should operate in financial services.  Current regulation works for what it was built to govern: human-initiated, human-authorized transactions. Current regulation was not designed for this.

There are two schools of thought when it comes to the regulatory approach to agentic commerce. One approach retrofits existing regulation and bolts on new addenda, stretch definitions, hope the framework holds. The other builds purpose-built rules designed for agents from the start. We believe the latter is the only path that works.

Existing consumer protection frameworks assume a human is in the loop making decisions, communicating intent, and bearing accountability. Autonomous agents upend these assumptions. Agents transact on behalf of consumers,, sometimes with a human prompt, sometimes entirely on their own based on historical behavior and inferred needs.

Because this is fundamentally different from what came before, retrofitted rules cannot be expected to hold. We need regulation purpose-built for agentic commerce which accounts for the speed, autonomy, and scale at which agents operation. Frameworks should define boundaries before they’re crossed, not after consumers are harmed.  

The goal isn’t to slow innovation but rather to create guardrails that let agentic AI move forward safely without leaving consumers behind.

Understanding drives adoption

There is a direct line between understanding and trust, and between trust and adoption. People don’t use what they do not understand.

The path forward is transparency. Make the system legible: what protections exist, how agents are monitored, what happens when something goes wrong, and how consumer data is safeguarded. If these answers are clear and accessible, adoption will follow.  

Where we go from here

The financial services industry has a choice. We can let the conversation around agentic commerce continue to be defined by confusion and noise, or we can do what we have done before with emerging technology: build structure, clarity, and consumer protection from the ground up.

At Cross River, we have always believed that compliance and innovation are partners, not opposites. The institutions that get agentic commerce right will be the ones that pair advanced models with clear protections and frameworks consumers can actually trust.

About the author
No items found.
Subscribe to our newsletter
You can unsubscribe anytime.