Consumers are curious about AI shopping agents. They are far less eager to give one an open wallet.
In Accenture’s 2026 consumer research, 85% of respondents were open to collaborating with an AI agent to explore options, while only 9% were willing to let it complete a purchase fully autonomously. The dramatic gap is real, but it does not mean “only 9% trust AI.” It measures willingness at two different levels of delegated purchasing in a particular survey.
That nuance points to a better product strategy. Trust in agentic commerce is not a switch. It is a ladder, and every higher rung needs a stronger control.
What the 9% Statistic Actually Measures
The Accenture Consumer Pulse 2026 surveyed 25,590 people across 16 countries. Its agentic-shopping results form a clear gradient:
- 85% were open to working with an agent to explore options.
- 74% were open to assigning a task on request.
- 32% were willing to let an agent select an item while the person completed payment.
- 9% were willing to let an agent make the purchase autonomously.
The final number describes a high-authority scenario. It is not a general approval rating for artificial intelligence, nor a measurement of completed purchases in the market.
Mastercard later cited the same 9% finding in its agentic-commerce trust analysis. It should therefore be attributed to Accenture’s survey, not treated as a separate Mastercard survey that independently found the same result.
Methodology matters because a user can trust an agent to compare products and still refuse permission to pay. Those positions are consistent.
Why Different Trust Surveys Seem to Conflict
Headlines about agentic commerce can appear contradictory. One survey reports high interest. Another finds broad concern. A third says many consumers trust no organization to operate an agent.
The questions are usually measuring different things.
Visa’s consumer trust research, covering the United States, Australia, and New Zealand, explores concerns including security, privacy, accuracy, reliability, and data control. Checkout.com’s 2026 report, based on more than 12,000 consumers across six countries, reports that 27% would trust no organization to run an agent on their behalf.
These findings can coexist with high willingness to use AI for product discovery. Compare five variables before combining any two statistics:
- Task: research, recommendation, choice, payment, or recurring purchase.
- Authority: suggestion only, action with confirmation, or autonomous action.
- Operator: bank, card network, merchant, technology company, or unknown agent.
- Population: country, age, digital experience, and current AI use.
- Measure: stated interest, stated trust, willingness, trial, or actual behavior.
A demand forecast that ignores those distinctions can overestimate both adoption and acceptable risk.
The Six-Step Delegation Ladder
Instead of asking whether a consumer “trusts AI shopping,” define the exact permission being requested.
| Level | Agent permission | Consumer remains responsible for | Control needed to advance |
|---|---|---|---|
| 1 | Research | Defining the need | Source transparency |
| 2 | Shortlist | Comparing finalists | Preference and exclusion controls |
| 3 | Choose | Confirming the selected item | Explainable constraints and easy override |
| 4 | Prepare checkout | Reviewing merchant, price, delivery, and terms | Verifiable cart and final-price lock |
| 5 | Pay once | Approving or delegating one transaction | Bounded token, amount limit, receipt, dispute path |
| 6 | Buy autonomously | Setting policy and reviewing exceptions | Continuous limits, revocation, monitoring, accountability |
This ladder explains why agentic commerce can grow even when autonomous-purchase willingness remains low. Most economic value may arrive at levels one through four before consumers delegate level six.
Research and Shortlisting
Research is the lowest-risk permission, but it still needs evidence. An agent can omit a relevant merchant, repeat sponsored language, hallucinate product details, or compare different configurations as if they were identical.
Useful controls include:
- links to the product pages used;
- timestamps for price and availability;
- separation of sponsored and organic results;
- a list of excluded merchants or product attributes;
- an “unknown” state when specifications cannot be verified;
- side-by-side normalization of shipping, tax, warranty, and return terms.
The user should be able to inspect why an item entered or left the shortlist. A fluent paragraph is not provenance.
Choice and Checkout Preparation
Letting an agent select one item adds preference risk. “Find the best laptop” has no stable answer until the user defines price, workload, operating system, portability, repairability, and delivery needs.
The agent should turn ambiguous preferences into a reviewable constraint set:
Maximum total price: $1,300 including tax and shipping
Memory: at least 16 GB
Storage: at least 1 TB
Delivery deadline: 28 August
Condition: new
Excluded sellers: third-party marketplace sellers without manufacturer warranty
Substitution: not allowed without confirmation
Checkout preparation then needs a verifiable cart. The merchant, legal seller, exact product identifier, quantity, final price, shipping address, delivery promise, return terms, and subscription status should be visible before payment.
An agent’s summary can help. It should not be the only record of what the user is about to buy.
Payment and Recurring Autonomy
Payment changes the risk because an error becomes a financial event. The user’s intent must be bound to the transaction the merchant receives.
A strong one-time payment flow should include:
- a token restricted to one merchant or transaction;
- a maximum amount and currency;
- an expiration time;
- the exact item or cart reference;
- a clear final confirmation when risk warrants it;
- an immediate receipt;
- cancellation, return, and dispute routes.
Recurring autonomy needs additional controls: a cumulative budget, frequency limit, approved category, merchant restrictions, price-change tolerance, pause switch, and exception notifications.
The agent must not be able to create a larger budget for itself. Infrastructure-enforced limits and separation of duties, described in our AWS AgentCore Payments guide, are more reliable than a prompt saying “spend responsibly.”
Controls That Earn the Next Permission
Survey responses improve when people can set limits and take authority back. Checkout.com’s research highlights controls such as spending limits, immediate revocation, and easy cancellation. Those are not cosmetic trust badges. They change the consequences of a failure.
Verifiable intent
The system should prove what the user authorized: product, merchant, amount, currency, delivery destination, timing, and whether the purchase repeats. A vague goal such as “keep the office stocked” should not become a blank payment mandate.
Least privilege
Give the agent the narrowest tool and shortest-lived credential that completes the task. Research does not need a payment token. A one-time purchase does not need a reusable credential.
Visible constraints
Show the budget, approved merchants, categories, and expiry in ordinary language. A person cannot meaningfully consent to a control they cannot inspect.
Immediate revocation
The user must be able to stop a pending task, recurring mandate, compromised agent, or connected payment method without navigating a support maze.
Receipts and evidence
Preserve the user’s mandate, the agent’s proposed cart, the authorized transaction, the merchant’s response, and later refunds. This evidence supports reconciliation and disputes.
Step-up approval
Require confirmation when the merchant is new, the amount exceeds a threshold, terms change, the agent wants a substitute, or risk signals rise.
These controls form the practical side of Know Your Agent: identity must connect to a bounded mandate and an auditable action.
What Merchants and Banks Should Measure
“Agentic revenue” is not enough to understand whether the experience is healthy. Measure the permission ladder.
Funnel metrics
- research sessions that reach a shortlist;
- shortlists that reach a user-approved choice;
- prepared carts that receive payment authorization;
- authorized transactions that complete without substitution;
- recurring mandates that remain active after 30 and 90 days.
Control metrics
- percentage of purchases within the original amount and item mandate;
- step-up approval rate and abandonment after step-up;
- revocation time;
- duplicate-charge and retry incidents;
- refund, return, dispute, and unauthorized-transaction rates;
- percentage of receipts linked to complete authorization evidence.
Trust-recovery metrics
- time to explain an unexpected purchase;
- time to stop future actions;
- time to refund or remediate;
- percentage of affected customers willing to reuse the agent.
The last group matters because no system eliminates every mistake. Trust depends partly on whether a person can understand and reverse what happened.
The Commercial Opportunity Is Between Browse and Buy
Agentic-commerce forecasts often jump from chat-based discovery to autonomous purchasing. The survey evidence suggests a more gradual market.
Consumers can receive value while retaining payment control. Agents can research, normalize offers, monitor prices, prepare carts, identify subscription traps, and check return terms. Banks and merchants can learn which controls earn the next permission before asking for an open-ended mandate.
The wider agentic economy will not be built by pretending software has unlimited agency. It will be built by making delegation specific, observable, and reversible.
The 9% figure is therefore not a verdict against agentic commerce. It is a design brief. People are willing to collaborate long before they are willing to surrender the final click.
Frequently Asked Questions
What is agentic commerce?
Agentic commerce uses AI agents to perform parts of shopping, such as research, comparison, selection, checkout preparation, payment, or recurring purchasing under a user’s mandate.
Do only 9% of consumers trust AI shopping agents?
No. In Accenture’s 2026 survey, 9% were willing to allow a fully autonomous purchase in the scenario presented. Higher percentages were open to research and lower-authority tasks.
What is verifiable intent in agentic commerce?
It is evidence linking what the user authorized, including item, merchant, amount, timing, and constraints, to the transaction the agent attempted.
Which control matters most for autonomous purchasing?
No single control is sufficient. Bounded spending, least privilege, step-up approval, immediate revocation, receipts, and dispute handling work together.
About Enis
AI Engineer specializing in Machine Learning and LLMs. Combining Computer Engineering and Economics to build data-driven financial tools.
AI Prompt Finance