Robert Hu
TRH ResearchLiving research

AI Commerce 2027: From Experiment to Operating Model

2026 built much of the infrastructure. 2027 will show whether businesses can turn AI commerce into a governed operating model.

Robert HuPublished September 21, 2026Updated 16 min read

The thesis

2026 was the year a lot of AI commerce infrastructure stopped being a demo. An open protocol for agent to merchant transactions shipped and gained capabilities. A luxury brand made its products buyable inside a chat interface. Payment networks began agreeing on how to identify an agent. A content network split crawler permission into four separate decisions. Merchant side agents arrived with approval gates built in.

What did not arrive was evidence of use. I could not find a single platform, network or retailer publishing transaction volume for agent initiated purchases. That gap is the honest center of this report. 2026 produced capability. 2027 is when capability either becomes an operating model or stays a set of integrations nobody routes real volume through.

Infrastructure exists. Adoption evidence does not. Holding those two apart is the whole discipline of reading this year correctly.

The distinction that organizes everything here is between AI assisted ecommerce, where a person still owns the journey and AI makes the work faster, and AI commerce, where software participates with some combination of identity, delegated authority, structured access to a catalog, permissions and the ability to transact. The first is already normal. The second is being built. The likely 2027 environment is hybrid, and the interesting operating question is not which one wins but which decisions a business is willing to move.

This report does not predict winners. Company names are used as evidence of what architectures are being built, and the argument should survive if those names change. Where something is verified I say so. Where it is my interpretation I say that too, and where the evidence is missing I say that most clearly of all.

AI assisted ecommerce and AI commerce

AI assisted ecommerce

A person owns the customer journey. AI improves search, content, merchandising, advertising, analytics, operations and service. The work gets faster and the accountability does not move.

AI commerce

Software becomes a participant, with some combination of identity, delegated authority, structured product access, tools, permissions, transaction capability and the ability to service what it bought.

These coexist. Nothing in the 2026 record suggests AI assisted ecommerce is going away, and most commerce in 2027 will still be a person on a website or in an app. The useful framing for an operator is that a business now runs both models at once and has to decide, capability by capability, which one a given workflow belongs to.

The AI commerce stack

AI commerce is not one technology. It is a sequence of steps, each owned by different systems and often by different companies, sitting on shared infrastructure. Most current failures are not model failures. They happen where one layer hands off to the next.

The flow

  1. DiscoveryWhere a need becomes a candidate set
  2. RecommendationWhere candidates become a choice
  3. Agent actionWhere a choice becomes a prepared action
  4. TransactionWhere the order is created and owned
  5. PaymentWhere authority is verified and money moves
  6. FulfillmentWhere the promise is kept
  7. MeasurementWhere the result feeds the next decision

The infrastructure underneath

  • Product dataThe record every layer above reads
  • IdentityWhich agent, operated by whom
  • PermissionsWhat it is allowed to do here
  • ProtocolsHow systems exchange the transaction
  • Merchant systemsOrders, inventory, pricing, service
  • GovernanceApproval, intervention, evidence
  • MeasurementWhether any of it worked

An operator reading this diagram should notice how much of it they already own. Product data, merchant systems and measurement are not new responsibilities. What is new is how many other systems now read them.

Eight shifts to watch in 2027

Each shift separates four things: what changed in 2026 and can be verified, what that plausibly enables in 2027, what is still unproven, and the specific development that would strengthen or weaken the argument. Where the evidence only supports a hypothesis, it is written as one.

01

AI shopping moves from recommendation toward execution

What changed in 2026

  • Google launched the Universal Commerce Protocol in January 2026 as an open standard for how agents and merchant stores exchange catalog, checkout and payment information, then added Cart, Catalog and Identity Linking capabilities in March and a cross retailer Universal Cart in May.
  • Tapestry made Coach and Kate Spade products buyable inside Google Search, AI Mode and the Gemini app on September 16, using UCP, with checkout completed through Google Pay and no website redirect. Tapestry states that each transaction requires the consumer's explicit approval.
  • Sabre reported in September that its Model Context Protocol server had reached nearly 80 travel customers piloting or in full production, with servicing capabilities in production rather than in demo.

What that enables in 2027

The pieces required for an agent to complete a purchase now exist in production somewhere, which is different from being adopted everywhere. 2027 is the first year the question can be asked honestly: does meaningful volume actually move through these paths.

Servicing is the underrated half. Sabre is in production with post booking servicing, and a purchase an agent can make but not amend, cancel or refund is an incomplete capability rather than a complete one.

This is the first half of the argument this report makes. Software can increasingly act. Shift eight is the other half: acting reliably, over months rather than in a single task, is a much harder problem, and it is where the evidence is weakest.

What remains unproven

I could not find published transaction volume for agent initiated purchases from any platform, network or retailer. Announcements, integrations and named brands are all public. The number that would settle whether this is a market or a capability is not. Treat every adoption claim in this space as a claim about availability, not usage.

Signal to watchAny operator publishing agent initiated orders as a share of total orders, and any retailer disclosing agent originated returns or servicing volume alongside it.

02

The merchant website stops being the mandatory handoff point

What changed in 2026

  • Google's Universal Cart, announced in May, works across retailers and across Search and Gemini. Shoppers can check out with Google Pay or transfer items to the merchant site, and Google states the retailer always remains the merchant of record.
  • OpenAI's Agentic Commerce Protocol, open sourced with Stripe in September 2025, takes the same position from the other side: orders, payments and fulfillment are handled by the merchant using existing systems, and the merchant stays merchant of record.
  • Tapestry's implementation removes the redirect for single item purchases while keeping Tapestry as the seller.

What that enables in 2027

This separates two things operators have treated as one. Interface ownership is who renders the moment of purchase. Transaction ownership is who holds the order, the money, the customer record and the obligation. 2026 architecture consistently gives the interface away and keeps the transaction.

A merchant can plausibly lose the session without losing the sale. What it loses with the session is less discussed: brand presentation, merchandising context, cross sell, and the behavioral data that comes from someone moving through a site rather than approving a card.

What remains unproven

Nobody has shown what happens to basket size, return rate or repeat purchase when the visit disappears. Websites are not going away, and the honest description of 2026 is that a second path opened, not that the first one closed.

Signal to watchMerchants publishing comparative basket and return data for agent completed versus site completed orders, and whether any retailer declines agentic checkout after testing it.

03

Product data becomes shared commerce infrastructure

What changed in 2026

  • Google made conversational attributes available to retailers globally in May, letting product descriptions reflect how people actually ask, and added Ask Advisor inside Merchant Center.
  • UCP's Catalog capability lets agents retrieve real time product details including variants, inventory and pricing, which makes the catalog an operational dependency at the moment of sale rather than a marketing asset.
  • Bazaarvoice said in September that standard JavaScript rendering creates a blind spot for AI crawlers, and spent 2026 moving review content into crawlable and feed delivered forms.

What that enables in 2027

The same record increasingly feeds organic recommendation, advertising, agent evaluation, checkout accuracy and measurement. That concentration raises the cost of a stale attribute, because the error now appears in more places and is repeated with confidence.

Search debt used to surface as lower rankings. The same debt now surfaces as an agent describing your product incorrectly, or skipping it because a required field was missing.

What remains unproven

There is still no published evidence linking a specific product data improvement to a measurable change in AI recommendation outcomes at scale. The mechanism is documented. The elasticity is not.

Signal to watchAny platform publishing attribute level diagnostics that tie a data field to a visibility or transaction outcome rather than to a feed validation status.

04

GEO starts to become an operating discipline rather than a theory

What changed in 2026

  • Google Search Console shipped a Generative AI performance report showing impressions and pages inside AI Overviews and AI Mode, expanding worldwide on August 31.
  • Google announced AI performance insights in Merchant Center in May, comparing a brand's share of voice on AI surfaces against similar brands, rolling out in five markets.
  • Bluefish and Bazaarvoice published a citation analysis in September covering 237,804 citation instances across three AI surfaces, which is the kind of dataset the discipline did not have a year ago.

What that enables in 2027

Enough instrumentation now exists to run a loop: observe where you appear, form a hypothesis about why, change something, and look again. That is meaningfully better than optimizing blind.

It is not yet a controlled loop. The measurement is platform specific, the denominators are undisclosed, and impressions are not traffic, let alone revenue.

What remains unproven

No published measurement connects an AI visibility change to commercial outcome with a control. Vendor conversion claims for AI referred traffic currently range from roughly 42% better to three to five times better, which is a spread wide enough to indicate the field lacks a shared definition, not merely different results.

Signal to watchConvergence on a cross platform definition of an AI impression, and any measurement product that reports a denominator.

05

Commerce stacks grow a second interface for software

What changed in 2026

  • WebMCP, drafted at the W3C in February 2026 and implemented behind a flag in Chrome Canary, proposes a browser API through which a page declares callable tools to an agent instead of being clicked at.
  • Model Context Protocol servers moved into production commerce operations. Sabre reports nearly 80 travel customers on its MCP server, and software vendors including Helium 10 and Klaviyo exposed their capabilities to agents as tools.
  • UCP addresses a different layer again: not how an agent operates a page or a vendor tool, but how a purchase is structured between an agent platform and a merchant.

What that enables in 2027

These three are not interchangeable and the difference matters operationally. WebMCP is a page level surface. MCP is a tool and server surface. UCP and ACP are transaction surfaces. A merchant may end up exposing more than one.

The durable shape is a storefront with two front doors: a visual interface for people and a structured interface for software, maintained by the same team from the same product record.

What remains unproven

Whether any of these achieve broad adoption is open, and browser support for WebMCP is early. A second interface also doubles the surface that has to be kept accurate, and nobody has published what that costs to run.

Signal to watchA major commerce platform shipping an agent interface as a default capability rather than an app, and the first published incident where the two interfaces disagreed about price or availability.

06

Advertising becomes conversational, and moves closer to the transaction

What changed in 2026

  • OpenAI began testing Sponsored Agents on September 16: after seeing a relevant ad, a user can enter a clearly labeled conversation with a business sponsored agent, which OpenAI states is distinct from ChatGPT's independent answers and separate from the original conversation.
  • OpenAI opened ChatGPT Ads to Shopify merchants the same day, syncing catalog and commerce events from the store into the ad platform.
  • Google began bringing UCP into ad formats, including Direct Offers and Shopping ads on YouTube, so a person can buy from the ad unit itself.

What that enables in 2027

The click is no longer necessarily the end of the ad. A plausible 2027 sequence runs from an independent answer, to a labeled paid placement, to a sponsored conversation, to a merchant transaction.

That adds a governed surface most teams do not have a process for. If a brand run agent answers questions after the click, someone has to decide what product data grounds it and who approves the claims it makes.

What remains unproven

OpenAI has published no performance evidence for Sponsored Agents: nothing on conversion, acquisition cost, or whether a sponsored conversation beats a landing page. It is a test with selected advertisers. The boundary between organic answer, paid placement and sponsored conversation is stated by the platform and has not been independently audited.

Signal to watchPublished performance data for sponsored conversations, and evidence about whether users can still tell which surface they are in three or four turns into a commercial exchange.

07

Trust becomes infrastructure, on two sides at once

What changed in 2026

  • Ant International, Mastercard and Visa began work on a Know Your Agent interoperability framework in September, covering operator traceability, shared certification and continuous monitoring, while explicitly preserving each network's own verification and decisioning.
  • Ant International announced an Account for Agent for businesses on September 18, built on KYA enabled smart contracts with monitoring and intervention, pointing the same identity machinery at the merchant's own operations.
  • Cloudflare separated crawler permissions into search, training and agent behaviors on September 15, and reported that fewer than 1% of sites block search while 17% use some mechanism to block training.

What that enables in 2027

A workable sequence is becoming visible: identify the agent, verify its authority, establish merchant permission, constrain what it may do, execute, and preserve evidence afterward.

Consumer authorization and merchant authorization are different problems. A shopper delegating a purchase is one grant. A merchant permitting an agent to transact against its catalog, inventory and payment systems is another. AI commerce appears to need both, and they are being built by different parties on different timelines.

What remains unproven

Nothing published shows one network accepting another's verification without its own check, which is the moment trust becomes portable rather than merely coordinated. Liability when an agent acts inside its authority and produces a bad outcome remains unsettled, and there is still no established standard for expressing agent permissions at all.

Signal to watchThe first cross network acceptance of another party's agent verification, and the first published dispute framework for a transaction an authorized agent got wrong.

08

Workflow reliability starts to matter more than model rankings

What changed in 2026

  • Merchant side agents began shipping with explicit control surfaces: staged writes and approval gates in Anthropic's merchant agent blueprint, granular tool and permission controls in Klaviyo's MCP server, and human approval before anything reaches a live store in Noibu's agents.
  • A set of long horizon commerce benchmarks appeared, all of them simulations. In E-Commerce Bench, a 365 day simulated store operation from Alibaba's Qwen team, the model that finished with the most assets ranked 16th of 18 on fraud avoidance, routing 18.48% of spend to fraudulent suppliers.
  • MerchantBench, another year long simulation, found the best model configuration reached about 27% of the net assets human participants achieved on the same simulator, with documented activity decay over the horizon.

What that enables in 2027

The unit of automation is the workflow, not the model. Trust in 2027 is more usefully earned by a specific workflow with known permissions, known failure modes and retained evidence than inherited from whichever model is ranked highest this quarter.

The benchmark result worth carrying into operations is the shape of the failure, not the score. An agent can hit the metric it was given while damaging something nobody assigned it to protect, including fraud exposure, margin, inventory position or supplier quality.

Read against shift one, this is the whole tension of 2027. The capability to act arrived first. The evidence that acting holds up over time has not, and a business that adopts the first without testing the second is taking a risk it has not measured.

What remains unproven

Every one of these benchmarks runs in simulation. None evaluates agents operating real merchant accounts, and none should be read as a statement about production performance. What they establish is that side effects are measurable and real in controlled settings, not what rate they occur at in a live business.

Signal to watchAny production merchant publishing agent error, reversal or intervention rates, and whether vendors start reporting the changes their agents got wrong alongside the ones that worked.

The disconfirming case

What would prove this wrong

The thesis is that commerce systems are increasingly being built on the assumption that software may be a participant. Here is the evidence that would undermine it, and I would rather find it early than defend the argument.

  • Consumers decline to delegate purchases

    Every production implementation so far keeps a human approving the transaction. If shoppers never move past approval, agentic commerce stays an interface change rather than an operating model change.

  • Agent originated volume stays negligible

    No platform publishes agent initiated transaction volume today. If 2027 ends and still nobody does, the most likely explanation is that the number is not worth publishing.

  • Merchants withdraw from offsite checkout

    Losing the session costs merchandising context and behavioral data. If comparative data shows lower basket size or higher returns, retailers can simply turn the capability off.

  • Protocols fragment instead of converging

    UCP and ACP already coexist, with MCP and WebMCP addressing different layers. Sustained fragmentation raises integration cost enough that most merchants rationally wait.

  • Fraud and disputes outrun the controls

    Liability for an agent acting inside its authority is unsettled. A visible wave of disputes with no clear recourse path would slow adoption faster than any technical limit.

  • AI discovery produces no measurable commercial value

    Published conversion claims for AI referred traffic currently disagree by an order of magnitude. If better measurement resolves that downward, the investment case weakens considerably.

  • Access narrows for legal or contractual reasons

    Permission controls cut both ways. Publishers and retailers restricting agent access, or platforms restricting each other, would constrain the surface before it matures.

The two models side by side

This is a contrast, not a migration path. Most businesses are likely to operate in both columns at once, and a workflow can sit in the left column while the one next to it sits in the right.

Comparison of AI assisted ecommerce and AI commerce across nine operating dimensions
DimensionAI assisted ecommerceAI commerce
Primary actorA personA person plus an authorized agent
Role of AIAssists the operator or shopperActs inside granted limits
DiscoveryAI supported search and merchandisingAI mediated, often without a site visit
CheckoutHuman led on the merchant sitePotentially agent initiated, with approval
PaymentEntered or approved by a personDelegated within explicit limits
PermissionsApplication and user permissionsAgent identity, delegated authority, merchant controls
GovernanceTool governanceWorkflow and transaction governance
MeasurementEstablished ecommerce metricsEstablished metrics plus agent specific ones
Failure modeA bad recommendation a person can ignoreAn executed action that has to be reversed

What operators should watch in 2027

No score and no probability. These are the developments that would tell an operator whether the operating model is arriving, and roughly in the order they would matter.

  1. Agent initiated orders as a share of total ordersThe single number that would convert this from architecture to market
  2. Merchant adoption of agentic checkout, and any withdrawalsWithdrawal after testing is stronger evidence than another launch
  3. Published performance for sponsored conversationsTests whether the post click surface earns its complexity
  4. A shared definition of an AI impressionMeasurement cannot mature while each platform counts differently
  5. Cross network acceptance of agent verificationThe moment agent trust becomes portable rather than coordinated
  6. A published dispute and liability framework for agent transactionsDetermines who absorbs the cost of an authorized mistake
  7. Agent error, reversal and intervention rates from production merchantsMoves reliability evidence out of simulation
  8. Servicing capability, not just purchasingReturns, amendments and refunds decide whether agents are operationally useful
  9. Comparative basket and return data for agent completed ordersTells operators what the lost session actually costs

2027 AI Commerce Evidence Tracker

Seeded with the strongest verified 2026 developments and updated through 2027 as evidence arrives. Entries record what actually changed, not what was promised, and link forward to the full analysis where one exists.

Tracker of verified AI commerce developments, newest first
DateCompanyDevelopmentAffectsEvidence typeWhat changed
September 18, 2026Ant InternationalAccount for Agent, a business account for agent use built on know your agent enabled smart contractsRead the analysisTrust infrastructureCompany announcementAgent identity machinery pointed at merchant operations rather than only at buyers
September 16, 2026Tapestry and GoogleCoach and Kate Spade purchasable in Gemini and AI Mode through UCP, checkout via Google Pay with no redirectWebsite handoffCompany release, primaryA named brand shipped agentic checkout in production, with explicit consumer approval per transaction
September 16, 2026OpenAISponsored Agents test, plus ChatGPT Ads for Shopify merchantsRead the analysisAdvertisingCompany announcementA labeled commercial conversation appeared after the ad click, separate from the assistant
September 15, 2026CloudflareSeparate search, training and agent crawler controls, with Disallow AI TrainingRead the analysisTrust infrastructureVendor product changeAccess to content became four decisions instead of one
September 9, 2026Ant International, Mastercard, VisaKnow Your Agent interoperability collaborationRead the analysisTrust infrastructureJoint announcementThe industry aligned on the questions about an agent, while each network kept its own decision
August 31, 2026Alibaba Qwen teamE-Commerce Bench, a 365 day simulated store operation across 18 modelsWorkflow reliabilityIndependent research, simulationShowed the top earning model was also among the worst at avoiding fraudulent suppliers
August 31, 2026GoogleGenerative AI performance report in Search Console expanded worldwideRead the analysisGEO disciplinePlatform documentationSite owners got a first party view of appearances in AI surfaces
May 20, 2026GoogleUniversal Cart, UCP in ad formats, AI performance insights in Merchant CenterWebsite handoffCompany announcementCross retailer carts and share of voice measurement entered the same stack
February 10, 2026W3C, Google, MicrosoftWebMCP draft published, early Chrome implementation behind a flagSecond interfaceStandards draftA page level way for sites to declare tools to agents entered standardization
January 2026Google and partnersUniversal Commerce Protocol released as an open standardRead the analysisRecommendation to executionCompany announcementA shared structure for agent to merchant transactions became available

Where this builds on earlier research

This report synthesizes work published across 2026 rather than repeating it. The two pillar pages hold the underlying frameworks: generative engine optimization for how AI systems find and describe products, and agentic engine optimization for what changes when software evaluates and buys.

On the transaction layer, I covered the governance body forming around the protocol and the blueprint that separates intelligence from merchant ownership. On trust, the know your agent collaboration covers buyer side identity, Account for Agent points the same machinery inward, and the rail level argument holds that deterministic systems, not models, should decide that money moves.

On data and measurement, the Google AI Mode teardown established product data as shared infrastructure, customer reviews turned out to be a delivery problem before a content problem, Search Console gave visibility without traffic, and the measurement problem remains the constraint on all of it. Permission sits between retrievability and use.

On the operating side, ecommerce software became infrastructure agents query, controls became the product once agents could write, validation became the harder half of any agent workflow, and the ad click started becoming a conversation.

What 2027 is actually about

The version of this story that gets told loudest is that consumers will hand their shopping to agents. I do not think that is what 2027 is about, and the current evidence does not support it. Every production implementation I can verify still puts a person in front of the purchase.

What has actually changed is quieter and harder to reverse. Commerce systems are increasingly being built on the assumption that software may be a participant. Protocols assume an agent is on the other end. Payment networks are designing identity for something that is not a person. Content infrastructure now asks which kind of machine is asking and what it intends to do. Merchant tools ship with approval gates because the thing using them can act.

That assumption is now embedded in the plumbing whether or not consumers change their behavior next year. It is the reason the practical 2027 question for an operator is not whether to believe in agentic commerce. It is which of your workflows you are prepared to let software execute, under what limits, with what evidence retained afterward.

If software can already transact with your business, what have you actually decided it is allowed to do?

Method and sources

Claims here are drawn from primary sources where they exist: company announcements and product documentation from Google, OpenAI, Ant International, Cloudflare, Sabre and Tapestry, standards drafts, and published research papers. Where a figure comes from a company describing its own product, it is attributed to that company rather than stated as fact.

Benchmark results cited in shift eight come from simulations. None of the published commerce agent benchmarks evaluate agents operating real merchant accounts, and none should be read as evidence about production performance.

Absence of evidence is reported as the limit of my own search rather than as proof of absence. In particular, I found no published transaction volume for agent initiated purchases as of September 2026. If that data exists somewhere I have not looked, the first shift in this report is the one most likely to need revision.