IXOPAY and Zip hosted the inaugural working session of the collaborative to create a Unified Trust Layer this week — the open, cross-industry group we're building to shape how trust is established in agentic commerce, alongside the merchants, orchestrators, and technologists who will actually live with these decisions.
The goal was simple to state and harder to actually do: build the Unified Trust Layer with merchants, not for them. Instead of showing up with a finished roadmap and asking for a thumbs up, we wanted real payment and risk leaders — people already grappling with agentic commerce in production — to shape the framework from their own experience, so it reflects what merchants actually need to trust and accept AI-initiated transactions, rather than being designed inside-out from the networks or the LLMs down.
Put simply: make the merchant experience the foundation of the Unified Trust Layer, not an afterthought. That meant disagreement and pushback weren't treated as a derailment — they were treated as the most useful data in the room.
Here's what came out of it. But first, some context on why this group needs to exist in the first place.
Why trust breaks down in agentic commerce
For decades, ecommerce has run on a simple script: a human browses, a human clicks buy, and a human enters card details. That real-time, human-initiated moment is where the entire payments trust model lives — it's how issuers get comfortable extending credit, how fraud engines separate legitimate shoppers from bad actors, and how liability gets assigned when something goes wrong.
Agentic commerce removes that moment entirely. When a software agent is negotiating, selecting, and paying on a person's behalf, several things that issuers and merchants have always relied on simply disappear:
Behavioral signals vanish. Typing speed, mouse movement, device fingerprinting, even the natural pause before submitting a payment form. All of it depended on a human being at the keyboard. An agent completing a purchase in milliseconds looks a lot like the very pattern that fraud systems are trained to catch, which means legitimate agent activity risks being flagged and declined.
Consent gets ambiguous. In human ecommerce, entering a CVV or clearing a 3-D Secure challenge is the consent signal. An agent acting on standing instructions doesn't generate that same fresh, in-the-moment proof, which opens the door to compromised agents or replayed credentials being used for purchases the person never actually approved.
Liability defaults to the merchant. Without a clear authentication event or a preserved record of intent, an agent-initiated purchase starts to resemble higher-risk, merchant-initiated activity rather than a standard cardholder-present transaction. Until identity, intent, and authorization context are verifiable within the transaction itself, issuers don't have enough confidence to share that risk, so it falls to merchants by default.
Layered on top of this is a protocol landscape that's still being written in real time. Half a dozen agentic commerce protocols are emerging in parallel, from Google's Universal Commerce Protocol to Visa's Trusted Agent Protocol to Mastercard's Agent Pay, and each one makes different trade-offs around privacy, control, and what data actually gets passed to the merchant. None of them fully solves the problem alone, and supporting one can mean losing visibility into transactions that come through another.
This is exactly the gap the Unified Trust Layer is meant to close: a way to normalize agent identity, preserve intent, and aggregate behavioral trust signals across all of these fragmented protocols — so merchants get one consistent way to evaluate agentic risk instead of stitching together a dozen different ones. It's also exactly why we didn't want to build it in a vacuum.
As Jill Willard, IXOPAY's Chief Technology Officer, put it during the session:
"We talk about know your customer, know your agent — but we like to go one step deeper: trust your agent. You know your neighbor, you say hi to them. But if you show up and your neighbor is sitting in your house, that's weird behavior. Are you trusting that?"
The industry is moving, but from the wrong end
A theme surfaced early in the meeting and never really left: most of the protocol work happening right now is being built from the payment network or the LLM outward, not from the merchant back. That gap shows up concretely. Some card network protocols pass transaction intent down to the merchant; others don't yet. That inconsistency is exactly the problem the Unified Trust Layer is meant to solve: a single way for merchants to gain visibility into agent-initiated risk, rather than implementing a different protocol for each network.
The market moved fast in the last two months alone
Participants traded notes on recent developments that are reshaping the landscape:
American Express has signaled it will underwrite certain agent-initiated transaction disputes — a meaningfully different liability stance than what other networks have committed to so far, and one that could reshape how merchants think about accepting agentic traffic.
Google introduced a "universal cart" concept that lets a single cart persist across YouTube, Gmail, and Gemini and follow the shopper across merchants, alongside a push for merchants to expose richer structured product data (sizing, return policy, shipping) so agents can reason about it — with search ranking implications for merchants who participate.
One European payments participant walked the group through a live pilot: real agent-initiated, customer-present transactions running through the Visa network across three European markets, with the cardholder still confirming the final purchase. It's an early, deliberately conservative model — but it's live, not a demo.
Identity, intent, behavior, and a clear winner for "most unsolved"
A meaningful chunk of the session was spent stress-testing what actually makes a good trust signal for an autonomous agent: does it persist over time, is it hard to manipulate, is it predictive, is it contextual, and, most importantly, is it composable with other signals rather than useful in isolation.
Participants floated concrete candidates: transaction velocity, dispute ratios, approval rates, and mismatches between what an agent says it intends to buy and what actually shows up at checkout. There was also real appetite for something like a step-up challenge for agents — a lower-friction default with a "prove it" layer (not unlike 3-D Secure today) when trust signals fall short.
But the most useful outcome of the session was a genuine point of consensus. When asked which dimension — agent identity, intent, or behavior — is the least developed today, every participant on the call independently landed on the same answer: behavior. Identity and intent are being actively worked on across tokenization and network protocols. Understanding how an agent actually behaves over time and using that to build merchant confidence remains largely unsolved. That's a strong signal for where this working group can add the most value.
Where leaders actually are with agentic commerce
Participants ranged from "we haven't seen a confirmed agentic transaction yet" to "we're running live pilots in production." Nobody claimed to be fully ready. That spread is exactly why this collaborative exists — organizations both further along and just starting out are trying to solve the same underlying problem, and there's real value in comparing notes before standards harden.
What's next?
This was session one of an ongoing working group, and we're actively growing it. We're bringing the group together in person in Miami on October 7–8, alongside design-thinking workshops and roadmap sessions focused on the Unified Trust Layer.
If you're a merchant, orchestrator, or risk leader wrestling with what agentic commerce means for your business, we'd like you at the table.
Fill out the interest form to be added to the invite list for our next session.