Thinking

The alphabet soup of agentic commerce

AP2, ACP, UCP, SPT, DPC, MPP and x402 look like the technical foundations of agentic commerce. They are also bids to shape its market structure—who can reach demand, whose authority travels, which functions become common infrastructure, and where control, obligation and value sit.

Agentic commerce moves more of discovery, comparison, choice and purchase into systems that interpret a customer’s intent and act on it. The change is not confined to the agent. The platform, wallet or super app through which it operates can influence the information available, the options it can reach and how the transaction is assembled.

To describe this as another channel underestimates what is moving.

An organisation can remain essential to a transaction and still lose influence over the moment that determines where demand flows and value accrues. A merchant may retain the order, fulfilment and customer obligations. A bank may retain the regulated account and risk. A payment network may continue to validate and route the transaction. Those functions can remain in place while another participant gains the customer context, shapes the consideration set or controls the route to conversion.

The same movement creates openings. Established participants can make authority portable, extend trusted roles, connect fragmented markets or build the infrastructure on which several competing models depend.

That is why the alphabet soup matters. The initiatives are not merely competing labels for the same thing. They address different parts of the transaction, draw different boundaries around what will be shared, and leave commercially important work for someone else to perform.

The acronyms describe different layers

A customer may give an agent an objective and constraints. The agent may search through a platform, compare offers, interact with a merchant, present evidence of its authority, obtain permission to use a payment method and complete the transaction through conventional or machine-native infrastructure.

Different initiatives enter at different points.

Part of the journeyWhat is being enabledRepresentative initiatives
Intent, delegation and evidenceRecording and carrying what the customer authorised, and creating evidence that others can verifyAgent Payments Protocol (AP2) and Verifiable Intent[1]
Commerce connectionConnecting agents, platforms and businesses across discovery, checkout and order processesAgentic Commerce Protocol (ACP) and Universal Commerce Protocol (UCP)[2]
Payment permission and credentialsConstraining payment authority and supporting credential presentation and authenticationShared Payment Tokens (SPT) and EMV Digital Payment Credential (DPC)[3][4]
Machine-payment executionAllowing software to request, make and receive payment programmaticallyMachine Payments Protocol (MPP) and x402[5]
These initiatives are not equivalent in maturity or governance. They range from draft frameworks and beta specifications to proprietary capabilities, released protocols and early commercial implementations.

Several components may participate in the same transaction. AP2 can carry evidence of authority while ACP or UCP connects the agent to commerce functions. SPT or a future DPC implementation may help the payment credential move safely. MPP or x402 may support a paid interaction between machines.

The existence of several layers does not mean the market will settle into one neutral stack. It means the boundaries between them matter.

A standard sets a boundary, not a market outcome

Standards create interoperability by constraining choice. They define what participants can assume, what they must provide and what can be tested consistently. A clear boundary can allow several specifications to work together. Ambiguity merely relocates the integration problem.

But the functions outside the common layer still have to be performed. Someone admits merchants, ranks offers, provisions credentials, interprets incomplete instructions, supplies risk intelligence, handles disputes, retains evidence and decides which implementations can participate on workable terms.

Responsibility also has to be allocated. A technical standard may define roles and verification duties without settling liability. Scheme rules may allocate fraud or dispute exposure. Contracts may distribute operational risk. Legislation may impose duties that participants cannot reassign.

A standard can define how a transaction works without deciding who is responsible when it does not.

Four strategic questions therefore sit across the technical layers.

Authority. Who can create and carry evidence of what the customer authorised, and who will recognise it?

Access. Which agents, merchants, products and services can participate—and who controls what enters the consideration set?

Obligation. Who retains the evidence, carries the risk and can correct the outcome when several systems contributed to it?

Value. Which functions become shared infrastructure, which remain differentiated, and where do margin, customer context and influence accumulate?

Implementation begins to answer those questions. It determines which optional capabilities are supported, which credentials are accepted, what defaults apply, what information travels and how difficult it is to switch. Commercial arrangements determine access, distribution, pricing and support.

An open protocol can widen technical participation while a platform controls the demand surface. A common credential can make a function contestable while wallets, networks or verification services determine how it is used. A capability left outside one specification can become a valuable service—or a dependency—when many participants need someone else to provide it.

The positions are being formed in the way the pieces connect.

The institutional activity reinforces that conclusion. Company-created protocols are moving into foundations and standards bodies. Platforms are building merchant ecosystems. Payment networks are extending credentials and rules into agent-mediated flows. Infrastructure providers are creating ways to operate across several initiatives without betting on one winner.

The participants do not begin from equivalent positions. Some need common protocols to connect customer interfaces, merchants, credentials and payment systems across organisational boundaries. A marketplace, wallet or super app that already spans several of those functions can build across assets it controls and use standards selectively to extend its reach. Interoperability can widen participation without removing the advantage of an already integrated position.

A separate, date-stamped Reference Map tracks who originated or governs the initiatives, who is contributing or implementing them, their current maturity, and where organisations are building commercial positions. It carries the changing institutional detail so that this Signal can remain focused on what the pattern means.

Reference MapWho is assembling the agentic-commerce market?A date-stamped Reference Map — original QURKI analysis of who originates, governs, contributes to, implements and builds commercial positions around each initiative.

Four early moves reveal the contest

The market is still forming. None of the current initiatives proves that a particular model will scale. Together, however, they reveal four different ways in which commercial positions are being pursued.

The agent can shape choice before checkout begins

ACP and UCP expose the contest over distribution.

Search engines and marketplaces already influence how products are found and presented. An agent can move that intervention earlier. It may interpret an open-ended objective, decide which attributes matter, choose which sources to search, exclude options that do not meet its rules or available integrations and present only a shortlist. It may eventually act without presenting alternatives at all.

The most consequential choice may be the one the customer never sees.

The opacity affects merchants as well as customers. A merchant may know which transactions it receives without knowing whether its products entered the consideration set, which rules excluded them or whether available integrations narrowed the field before comparison began.

OpenAI and Stripe’s Agentic Commerce Protocol connects merchants’ commerce capabilities to AI applications. Its current ChatGPT implementation supports product discovery and, for approved partners, checkout within ChatGPT. The checkout is rendered in OpenAI’s interface, while the merchant maintains checkout state, processes payment through its chosen provider, accepts or declines the order and remains merchant of record.[6]

OpenAI is therefore building a potentially valuable position in the route from intent to purchase. It can interpret the request, determine which products are presented and carry the customer through the moment of conversion, while the merchant remains responsible for the resulting order.

Google’s Universal Commerce Protocol approaches the connection through capability discovery and negotiation. A customer-facing surface and a business can advertise the commerce functions and payment handlers they support before carrying out the flow. The business remains merchant of record. UCP’s August 2026 release extended payment security, identity, consent, loyalty and support for additional commerce contexts. Its enlarged Tech Council brings participants from several layers into the protocol’s development.[7]

Both approaches can widen merchant participation. Neither makes distribution neutral.

An open protocol does not necessarily create an open distribution layer.

The question for a merchant is not only whether it can connect. It is what access to demand, customer context and bargaining position remain once that connection becomes a meaningful route to market. For the platform, control of the customer interaction becomes valuable only if enough merchants and payment providers make the route useful, trustworthy and governable.

When the customer is absent, authority becomes infrastructure

AP2 and Verifiable Intent are defining how authority can travel.

Existing payment systems generally assume that a person approves an action on a trusted surface. Autonomous commerce separates the customer’s intention from the later decisions and actions performed on their behalf.

AP2 uses signed mandates to record what the customer authorised, bind payment authority to an assembled checkout and create linked evidence that can be verified later. Version 0.2 supports both human-present and human-not-present flows, allowing an agent to act within constraints approved in advance.[8]

The protocol defines roles for the shopping agent, trusted surface, credential provider, merchant and merchant payment processor, with verification responsibilities for each. One organisation may perform several roles. An open role model does not guarantee that commercial power will be dispersed.

The valuable positions are visible inside the design. A trusted surface can become the place where authority is created. A credential provider can decide what evidence is sufficient to release a payment method. Merchants, processors and networks can become important verifiers. Evidence-retention and dispute services can make the mandate usable when the transaction has to be reconstructed.

Google has contributed AP2 to the FIDO Alliance alongside Verifiable Intent, developed with Mastercard, as inputs to member-led work on trusted agent-initiated commerce. That work is continuing; it is not yet a final FIDO standard.[9]

AP2 can support accountability without allocating legal liability. Catalogue and checkout communication remain outside its scope. Participants still decide which agents, credentials and mandates they will accept.

The infrastructure of authority will shape who can act, whose evidence is trusted and where accountability sits.

A portable credential can reopen the wallet position

DPC addresses a capability now concentrated in proprietary wallet environments.

Apple Pay and Google Pay did not remove banks and card networks from a payment transaction. The issuer continued to provide the account or credit and approve or decline the transaction. The network continued to validate and route it. But the wallet became the place where the customer selected, authenticated and experienced the payment.[10]

The institutions remained necessary underneath. The platform gained the interface above them.

EMVCo’s draft Digital Payment Credential is narrower than a wallet. It is intended to provide a common schema and processes for a verifiable credential used in card-payment authentication. It remains under development and is not a deployed credential system.[11]

In September 2026, EMVCo also released a separate draft framework for card-based agentic payments. It proposes Intent Services: a shared coordination layer through which payment participants could register, retrieve and manage consumer-authorised intent over time. The framework may inform future changes to DPC, tokenisation, 3-D Secure and other EMV technologies. It is a basis for consultation and possible specification development, not an operating standard.[11]

If implemented, DPC could make payment trust more portable across wallets, networks and verification systems. It does not decide who will hold the credential, invoke it or shape the customer experience around it.

That is why wallets are a battleground rather than a predetermined winner. A wallet can bring credentials, identity, authentication and continuing permission together. A super app can add customer context, merchant access and service orchestration. An independent agent may instead try to carry context and authority across several environments. Standards can reopen the position; adoption and implementation will determine who occupies it.

Participation in the standard does not secure a position in the market built around it.

When the request can pay, the unit of commerce changes

MPP and x402 make payment part of the machine interaction.

MPP and x402 reveal a different possibility. Standards may not only reallocate positions around a familiar transaction; they may change what can be sold. Machine-payment protocols allow the paid interaction to become much smaller than a conventional product, order or subscription: an API call, a tool invocation, access to data, a unit of compute or a single result.[12]

One customer objective can then generate many paid interactions across several providers. Services that were previously bundled, prepaid or too small to sell separately can become discoverable and payable by software. Existing services can be unbundled, substituted and recombined at a finer level.

When the request can pay, the request can become the product.

The rails are also becoming more malleable. MPP is payment-method and currency agnostic. Stripe’s implementation supports stablecoins and fiat payment through cards and buy-now-pay-later methods. x402 currently uses crypto-native wallets, signed payment payloads and on-chain settlement across several networks. Under Linux Foundation stewardship, its stated remit extends towards broader payment types.[12]

Their trajectories are beginning to converge. The contest is no longer simply fiat versus crypto. It concerns which request model, payment methods, wallets, facilitators, policy controls and settlement arrangements become easiest for machines to use.

New value pools can form around interactions that were previously too small or difficult to charge for. Existing products can be unbundled; specialised providers can become reachable at the moment their capability is required; infrastructure positions can form around discovery, metering, policy, settlement and reconciliation. The same change creates exposure: one customer objective may trigger many individually trivial payments that are difficult to see or control in aggregate.

MPP and x402 may not define the whole market. Their strategic signal is not simply that machines can use different payment rails. It is that changing the unit of commerce can change which providers participate, how value is packaged and where control becomes necessary.

The market can change before responsibilities do

Across the four examples, control, context and obligation do not necessarily move together.

A merchant may gain a route to market while becoming less visible during discovery and selection. A bank may remain the regulated issuer while a wallet or agent controls the credential experience. A platform may shape demand and checkout while the merchant retains fulfilment and support. A network may extend its rules and evidence into a new market. An infrastructure provider may become essential by making otherwise separate layers work together.

None of those outcomes follows automatically from a specification. They emerge through implementation, adoption, incentives and the assets each participant already holds.

The customer remains part of the mechanism. People can instruct an agent to prefer a brand, use a named merchant, maximise loyalty value or select a payment method. But that instruction operates over the products, data, credentials, policies and connections the environment can reach.

The separation becomes most consequential when something goes wrong. Customers still expect an answer. Merchants still make promises. Regulated institutions still face disputes, supervisors and reputational consequences. An agent may have shaped the decision without being the party required to correct it.

A customer might dispute a purchase selected by an agent within a recorded mandate. The platform may hold the interaction, a credential provider the evidence used to release the payment method, the merchant the order and the issuer the payment record. Each may establish part of what happened; none of those records alone determines who must correct the outcome.

Trust is not only whether a transaction clears. It is whether someone can account for it and correct it.

A valuable opportunity may therefore sit beside the visible agent. Agentic commerce creates demand for machine-readable product and offer data; portable evidence of intent; credentials that can travel; verification, risk and assurance; loyalty rules agents can apply; dispute and correction mechanisms; orchestration across protocols; and machine-native payment and reconciliation.

Some of those capabilities will become common infrastructure. Others will remain differentiated because trust, distribution, quality or operating scale matters.

But a useful capability is not yet a value thesis. Others must have a reason to adopt it, integrate it, rely on it and sustain its economics. An organisation still has to understand what asset it brings, whose problem it solves, which obligations accompany the role and what evidence would show that the position is creating value rather than activity.

Power is crossing the boundaries designed to govern it

Agentic commerce cuts across payments, consumer protection, competition, privacy, identity, automated decision-making and operational resilience.

Each regime sees a different part of the system and rests on assumptions about who acts, who controls the consequential decision and who is responsible when something goes wrong. Agentic commerce can pull those roles apart, leaving formal responsibility in one place while practical control and customer context move elsewhere.

There is a sovereign dimension too. European institutions are supporting instant account-to-account payments and a digital euro partly to reduce dependence on international card schemes and non-European payment providers. The European Central Bank frames that dependence as a question of strategic autonomy, payment data, fees and rule-making power.[13]

Those responses address the market as it exists today. Agentic commerce adds an orchestration layer above the rail—one that may influence which suppliers are considered, which payment method is chosen and where data, margin and strategic control accumulate before payment occurs.

Governments may be redesigning the rails just as value begins moving into the orchestration layer above them.

The regulatory and sovereign questions deserve Signals of their own. They matter here because they show how far the consequences of apparently technical choices can travel.

Waiting for clarity is still a choice

The strategic response is not to select an acronym, build a customer-facing agent because others have one, or attempt to own every layer.

It is to decide what this changing commercial context could do to the organisation’s existing model. Which role matters to its value thesis? Which capability, relationship or right to participate should it shape or preserve? What is it prepared to cede? Which obligations might remain after visibility or control has moved? Which dependencies are being allowed to harden by default?

Ordinary decisions are already answering those questions: which commerce surfaces to join, which credentials to recognise, which standards processes to influence, what evidence to retain and which commercial terms to accept.

No organisation needs to predict the winning stack. But the market does not have to be settled for a position to become difficult to recover.

The governing question is therefore unavoidable:

Are we helping shape the agentic-commerce market, or preparing to accept the market others create?

Waiting for the alphabet soup to resolve itself is not neutral. It is one way an organisation discovers that its place in a different market has already been chosen.

References

[1] AP2 v0.2 defines roles, verification responsibilities, linked checkout and payment mandates and receipts, and human-present and human-not-present flows. Verifiable Intent is an AP2-compatible and protocol-agnostic contribution developed by Google and Mastercard. Both have been contributed to the FIDO Alliance’s continuing member-led work; neither should be described as a final FIDO standard. Sources: AP2 specification; FIDO Alliance — trusted AI-agent interactions; Mastercard — Verifiable Intent.

[2] OpenAI and Stripe co-developed ACP. OpenAI’s current ChatGPT implementation supports product discovery and, for approved partners, checkout rendered within ChatGPT while the merchant controls checkout state and remains merchant of record. Google announced UCP with Shopify, Etsy, Wayfair, Target and Walmart; its current governance spans additional commerce, platform and payment participants. Sources: Stripe — ACP integration; OpenAI — Instant Checkout and ACP; OpenAI — product discovery; Google Developers — UCP; UCP Tech Council.

[3] Stripe describes SPT as a time-limited, transaction-scoped token that allows an agent to pass a customer’s selected payment method and risk signals without exposing the underlying credential. It is a Stripe capability rather than a coalition-governed standard. Sources: Stripe — Shared Payment Tokens; Stripe — additional payment methods.

[4] EMVCo is collectively owned and overseen by American Express, Discover, JCB, Mastercard, UnionPay and Visa. It develops technical specifications and testing processes but does not establish commercial implementation policy. Sources: EMVCo overview; EMVCo organisation structure; What are EMV Specifications?.

[5] Stripe and Tempo co-authored MPP. Coinbase created x402 and later contributed it to the Linux Foundation. The x402 Foundation launched operationally in July 2026 with members spanning payments, cloud, commerce and digital assets. Sources: Stripe — MPP; Coinbase — x402 launch; Linux Foundation — x402 Foundation.

[6] ACP connects seller commerce functions to compatible applications. In OpenAI’s current implementation, the merchant maintains checkout state, processes payment through its chosen provider, accepts or declines the order and remains merchant of record, while the customer-facing checkout is rendered within ChatGPT for approved partners. OpenAI says product results are organic and unsponsored. Sources: Stripe — ACP integration; OpenAI — Instant Checkout and ACP; OpenAI — product discovery.

[7] UCP defines capability discovery and negotiation across catalogue, cart, checkout, order and payment-handler functions. The business remains merchant of record. The 25 August 2026 release expanded payment security, identity, consent, loyalty and support for additional commerce contexts. Sources: UCP overview; UCP checkout; UCP releases; UCP Tech Council.

[8] AP2 v0.2 defines five roles and their verification responsibilities, linked checkout and payment mandates and receipts, and direct and autonomous flows. It allows one entity to play multiple roles. Sources: AP2 specification; AP2 flow examples.

[9] Google contributed AP2 and the AP2-compatible Verifiable Intent work developed with Mastercard to the FIDO Alliance for member-led development. AP2’s agent-authorisation framework also states that the model may have uses beyond its present payment scope. Sources: AP2 agent-authorisation framework; FIDO Alliance — AP2 and Verifiable Intent.

[10] Apple describes a flow in which the wallet creates an encrypted device-specific payment token; the network validates and translates it and the issuer approves or declines the payment. Google describes device tokenisation, device-unlock authorisation and the user’s selection of a default payment application and payment method. The interpretation of this change as reintermediation is QURKI analysis and is developed more fully in Adoption is the value thesis. Sources: Apple Pay planning; Google Pay security; Google Wallet default payment application; Google Wallet default payment method.

[11] DPC remains a draft, payment-card-specific application of verifiable digital credentials intended to create a common approach to card-payment authentication. On 1 September 2026, EMVCo separately released a draft Agentic Payments Framework for public review. It proposes Intent Services for registering, referencing, retrieving and managing consumer-authorised intent and may inform future enhancements to DPC and other EMV technologies. Neither draft is an operating standard or deployed system. Sources: EMVCo — DPC public review; EMVCo — draft Agentic Payments Framework.

[12] MPP enables agents and HTTP-addressable services to coordinate payments programmatically and supports multiple payment methods. Stripe’s implementation supports stablecoins and fiat payments through SPT. x402 enables paid access to APIs and content over HTTP and currently uses crypto-native wallets and settlement across supported blockchain networks. The Linux Foundation describes the x402 Foundation’s broader remit as extending from stablecoins towards other payment types. Sources: Stripe — MPP; MPP multi-method discovery; x402 introduction; x402 network and token support; Linux Foundation — x402 Foundation.

[13] The ECB reports that international schemes account for roughly two-thirds of euro-area card transactions and frames dependence on non-European payment providers as a strategic-autonomy issue. EU instant-payment infrastructure and the proposed digital euro are intended to support European-governed payment options. The proposition that agentic orchestration may create an additional layer of sovereign-value leakage is QURKI analysis. Sources: ECB — card-scheme reliance; ECB — digital euro and payment autonomy; ECB — Europe and monetary sovereignty; ECB — TARGET Instant Payment Settlement.

QURKI Signal

Receive QURKI updates

QURKI does not publish to a weekly schedule. Signals appear when there is something worth sustained attention. Subscribe to hear when a new Signal or occasional related update is published.

By subscribing, you agree to receive email updates from QURKI. You can unsubscribe at any time.