The agent-driven payment fraud that most coverage is bracing for needs something almost no small US merchant has switched on: a checkout an autonomous agent can complete on its own. Instant Checkout, the first mainstream path running from an AI assistant straight into a merchant’s order queue, opened on September 29, 2025 for US Etsy sellers, with Shopify merchants named as next in line, according to Stripe’s launch announcement. Having your store read by an agent requires nothing from you at all.
So agentic commerce reaches a small business in a fixed order. It reads you, then it recommends you, and only much later, and only if you opt in, does it pay you. The instinctive defensive move, block the AI bots, lands on step one. The thing it is meant to defend against lives at step three.
What is actually live right now
The plumbing is real and it has a name. The Agentic Commerce Protocol is an open standard created by Stripe, OpenAI and Meta that defines how an AI agent talks to a business to complete a purchase, and Stripe’s developer documentation puts the current specification at version 2026-04-17. It covers checkout sessions, product feeds, delegated payment tokens, and order webhooks.
The part worth reading twice is who does what after the agent hands the order over. Stripe’s own description of the flow says the merchant “can accept or decline the order, charge the payment method, calculate and remit sales tax, and handle fulfillment and returns, as they normally would.” That sentence is doing a lot of quiet work. The agent finds the customer and assembles the cart. You still charge the card, you still ship the goods, and you are still the party a dispute lands on. Nothing about an agent standing between you and the buyer moves the chargeback somewhere else.
The threat is real, and it mostly points at the buyer
Visa’s payment fraud disruption team has published numbers on where this is heading, and they are not small. Visa reports more than a 450 percent increase in dark web posts mentioning “AI Agent” over six months, and a 25 percent increase in malicious bot-initiated transactions in the same period, rising to 40 percent in the United States.
Read Visa’s three named attack patterns closely, though, and two of the three are aimed past you. Fraudulent storefronts trick an agent into buying from a counterfeit merchant and harvest the payment credentials. Advanced social engineering has malicious agents impersonate trusted brands in conversation to extract data, while talking the victim out of calling their bank. Both of those attack the shopper. Only the third, criminal infrastructure generating fake sites and synthetic business identities at scale, competes with you directly, and it competes for your customer rather than breaking into your checkout.
Our own coverage of the cases where an AI agent broke into three companies using weak passwords makes the point from the other direction: the agent-related breaches that have actually been documented turned on ordinary security hygiene, an exposed debug page and a reused password, rather than on anything specific to agents. The novel-sounding threat and the thing that actually gets you are rarely the same object.
Visa’s answer to the merchant half of the problem is the Trusted Agent Protocol, a framework for verifying an agent’s identity and intent in real time so a legitimate agent can be told apart from an impersonator. That is the right shape of fix. It is also not something a five-person store implements on its own; it arrives through your payment provider when it arrives.
The blunt instrument that costs you the only part that pays
Here is the piece that gets missed, and it is checkable in about a minute.
There is no such thing as “the OpenAI bot.” OpenAI publishes four separate crawlers, each with its own robots.txt token and its own job. GPTBot crawls content that may be used to train foundation models. OAI-SearchBot is what surfaces websites in ChatGPT’s search results. ChatGPT-User handles fetches triggered by something a person asked for in a chat. OAI-AdsBot checks the safety of pages submitted as ads.
Those are four different decisions wearing one label. A blanket rule that blocks everything with “OpenAI” or “GPT” in the name takes you out of OAI-SearchBot’s index, which is the discovery surface, which is the only part of agentic commerce currently capable of sending a small merchant a paying customer. It does nothing whatsoever about checkout fraud, because checkout fraud does not arrive through a crawler. It arrives through a payment.
The result is an own goal that looks like caution. A store owner reads a piece about agent fraud, tells their developer to block the AI bots, and pays for it by disappearing from the recommendation layer while remaining exactly as exposed at the till as they were on Monday.
The honest default for a store that wants agent-driven customers is to allow OAI-SearchBot and ChatGPT-User, and to treat GPTBot as a separate question. Whether you want your product copy and photography feeding model training is a licensing decision about your own work. It is a reasonable thing to say no to. It is not a security control, and filing it under security is how the discovery block gets made by accident.
Four moves, in the order they pay off
- Open your own robots.txt and read it. Type your domain followed by /robots.txt into a browser. It is a plain text file and it is public. Find every user-agent line, and if you cannot say who added it or when, that is the finding. Plenty of stores are carrying blanket AI blocks that arrived inside a plugin default or a security checklist nobody revisited.
- Split the discovery decision from the training decision. Write down two answers: do you want to appear in AI-assisted shopping results, and do you want your content used for model training. Most small merchants say yes and no. That combination is expressible in robots.txt, and it is not what a blanket block gives you. Deciding deliberately rather than by default is the same discipline that mattered when AI tools for small business got an off switch in Teams: the setting existing is worth nothing if nobody ever opens the page.
- Get your processor’s answer on agent-initiated disputes in writing. Email your payment provider or acquirer and ask one question: if an order arrives through an AI agent and the cardholder later disputes it, who carries the loss and what evidence do you want from me. You are not asking them to solve agentic commerce. You are creating a dated written answer, which is the thing you will want later and cannot manufacture retroactively.
- Fix your product data before you chase agentic checkout. Agents recommend from feeds. Wrong prices, missing sizes, and stale stock counts are the ordinary reason a store gets skipped, and they are worth fixing whether or not a single agent ever checks out with you. This is the move that pays regardless of how the rest of it lands.
What the tooling actually costs
Three of the four moves above cost nothing but an afternoon. Where money starts is fraud screening and bot control, and the real prices are modest enough to be worth stating plainly.
Stripe’s published pricing puts Radar, its fraud screening product, at $10.00 per month on the monthly plan or $0.05 per screened transaction on pay-as-you-go, sitting on top of the standard 2.9 percent plus 30 cents per successful domestic card transaction. Radar for Fraud Teams, the version with custom rules, is priced separately and is not listed on that page.
For bot control at the web layer, Cloudflare’s plans run Free at $0, Pro at $20 per month billed annually or $25 billed monthly, and Business at $200 per month billed annually or $250 monthly. Bot Management sits in the paid tiers. For most small stores the free tier plus a robots.txt you have actually read is the correct answer, and the paid tier becomes worth it when you have real bot traffic to shape rather than a theoretical fear of it.
Before adding any of it, check what you already own. If you run on a hosted commerce platform, some fraud scoring is already switched on and already charged for inside your monthly fee, and buying a second layer to sit on top of it is a common way to spend money on a problem you do not have yet. That question is worth asking of any AI capability folded into software you already pay for, which is how we approached AI quoting inside HubSpot’s Revenue Hub.
Where the pitch goes wrong
Everything above this heading is a published figure, a vendor’s own documentation, or a price on a live pricing page. What follows is judgment.
Agentic commerce is being sold, when you strip the language back, as removing the person from the sale. That framing is wrong about small businesses specifically, and believing it leads owners to the wrong purchase.
What an agent does well for a ten-person shop is answer at eleven at night, in a conversation the owner was never going to be awake for. What it cannot do is decide what goes on the shelf, price it against a competitor who just opened two towns over, or judge which customer gets the benefit of the doubt on a return. The store still runs on those calls. An agent is a shelf that can talk, and somebody still has to choose what is on it.
So when a vendor pitches agentic commerce as the route to running the same revenue with fewer people, that is the pitch to walk away from, and not for sentimental reasons. It describes a business that has confused answering questions with knowing the answers. The version worth buying is the one where the same team fields more genuine buyers, because the tedious half of the conversation stopped requiring a human at midnight.
Frequently Asked Questions
Do I need to do anything about agentic commerce right now?
One thing, and it is free. Read your own robots.txt and confirm you have not already blocked yourself out of AI-assisted shopping results. Everything else, including agentic checkout itself, is a decision you can take later without penalty. The blocking mistake is the only one that is quietly costing you something today.
Will AI shopping agents increase my chargebacks?
Not yet, for the simple reason that agent-completed checkout is not available to most small merchants, so there is no agent order volume to dispute. The exposure to plan for is that when it does arrive, you remain the party who charged the card, so the dispute lands with you exactly as it does now. Ask your processor how they will handle it before you enable it, not after.
Should I block GPTBot?
That is a licensing question about your own writing and photography, not a security question, and either answer is defensible. What matters is deciding it separately from OAI-SearchBot, which is the crawler that puts you in front of shoppers. Blocking both together is the common error, and it trades away customers for a protection it does not provide.
Is my store eligible for agent checkout today?
Most are not. Eligibility currently depends on the commerce platform you sell on rather than on anything you configure yourself, because the rollout has moved platform by platform rather than opening to all merchants at once. Check with your platform rather than assuming, and treat a “coming soon” as a reason to fix your product data, not a reason to buy tooling.
Open your robots.txt this week, before anything else on this list. It takes a browser tab and thirty seconds, and the answer is either reassuring or it is the most valuable thing you will learn about your store this month. If there is a blanket AI block in there, the useful question is not how it got in. It is what else arrived the same way.
