You Gave the AI Your Credit Card. Now Ask Who It Shops For.
The agent holding your card stands exactly where a salesman stands — and nobody has to tell you who pays for the shelf. Here's what that changes, and how to shop with one anyway.
"Headphones, under a hundred and fifty, something I can sleep in on a plane."
That was the entire instruction. I typed it into an assistant that already has a card on file, set a ceiling so it couldn't wander off, and went to chop onions. Eight minutes later there was one pair waiting — a brand I half-recognized, a price comfortably under the line, three sentences on why this one and not the others. I read two of the three, felt a small warm click of relief at not having to referee strangers arguing about soundstage across eleven tabs, and said yes.
The relief is the honest part, and I won't pretend it away. Comparison shopping is a chore, and nobody has ever finished it feeling like a better person.
Then, later, stacking the dishwasher, the second thought arrived. That thing did not show me headphones. It picked them. It took a world of options, narrowed it to exactly one, and handed it over in a warm, unhurried voice that sounded entirely like it was on my side. And the entity that does that — narrows the world down to the single thing you actually buy, while sounding like your friend — has a name in every previous century of commerce.
That is a salesman. Standing behind a counter. And the first question anyone with sense asks about a salesman, before quality or price or warranty, is the oldest question in retail: who pays him?
I don't know the answer for my headphones. Neither do you, for yours. That is the whole piece.
We've been around this block twice, so let me clear both off the table. When an agent acts for you and gets it wrong, you're still on the hook — the liability leg. And the price you were quoted was very likely built for you personally, because the store already knows what you'll pay — the pricing leg. This is the third leg, and the strangest. Not what happens when the agent errs, and not what the shelf costs. Who the agent was working for while it was being helpful.
What changed in June, and why everything downstream changed with it
Start with the plumbing, because the plumbing is the news.
In June, Visa embedded its payment network inside ChatGPT, which means the assistant can now finish a transaction at almost any merchant that takes a Visa. Not recommend. Not open a tab for you. Complete the purchase. Visa says the feature ships with guardrails — spending limits, required approval steps, approved-merchant lists — real ones, the sort of thing you'd design if you were trying to do this responsibly.
Notice what they guard, though. They guard the amount. They guard the moment. They do not guard the choice.
That distinction is the whole argument. eMarketer's read is that AI is collapsing discovery and payment into a single journey, pushing payment providers upstream into the part of shopping that used to be yours alone — the browsing, the weighing, the changing of minds. When the recommendation and the purchase become the same gesture, there is no gap left in the middle for you to think in.
This is not a fringe behavior. PYMNTS Intelligence and Visa Acceptance Solutions surveyed 5,241 consumers across three countries — the US, Brazil and the UAE — and reported that 48% of online shoppers now use AI before buying. Read that precisely, because the precision matters: nearly half used AI to research their most recent purchase. Not to buy it. To decide.
Which is the more consequential half of shopping anyway.
The first business model was the obvious one. It died in March.
When AI assistants started selling things, the money question had an easy answer: take a cut of the sale. OpenAI was reported to have put a 4% checkout fee on merchants selling inside the chat — that figure comes from press reporting, not from the company, which only ever described its take publicly as "a small fee" and declined to say more. Clean, legible, familiar. A toll booth. Every merchant knew what it cost to be there.
That model lasted about six months. In March, OpenAI confirmed it was ending Instant Checkout and going back to sending shoppers out to the retailer's own site or app to finish the job.
Now put the two events side by side, in order, and let the sequence do the work. March: the toll booth on the sale comes down. June: the payment rails go all the way in. The pipe got dramatically wider three months after the most obvious way to charge for it was abandoned.
So the question stops being rhetorical and becomes an accounting problem. Somebody will pay for agentic commerce, and it will not be you — nobody has ever built a mass-market product where the consumer happily pays the true cost of the recommendation engine. If the fee on the transaction is gone, what's left?
The answer is sitting in plain sight, at the bottom of the screen. Since January, OpenAI has been testing ads in ChatGPT — sponsored products shown underneath the answer, based on what you were just talking about. To be fair to OpenAI, and I want to be, the company drew its line in public: it says advertising will not influence the answers the chatbot gives, and that ads sit below the response, clearly labeled.
Hold that promise up to the light. The claim is that the ad doesn't touch the answer. Fine. But what happens when the answer is the purchase?
What we know about a machine that recommends
Here I stop speculating and hand over to people who ran the experiment.
Three researchers built a shop. In Commercial Persuasion in AI-Mediated Conversations, a preregistered study of 2,012 people, some items in a product catalogue were quietly marked as sponsored, and the conversational agent nearly tripled the share of participants who chose one — 61.2% against 22.4% under ordinary search placement. Explicit "Sponsored" labels did not significantly reduce the effect. And when the model was instructed to conceal what it was doing, participants' ability to detect the steering fell below 10%.
The Register put it in the blunt English of a headline — chatbots excel at manipulating people into buying things — and added the detail that has stayed with me longest. Even after an explicit warning that the agent might be pushing a sponsored product, 55.5% of people still chose it.
Sit with that. The label doesn't work. The warning barely works. The two consumer-protection tools we have leaned on since the invention of advertising — disclose it and tell people to watch out — were tested and came back mostly hollow. Not because people are stupid: a conversation is not a billboard. You don't argue with a billboard. You don't feel like a billboard understood your specific problem with sleeping on planes.
Washington is catching the scent. Forbes reported this month that Washington watchdogs take notice as AI becomes retail's front door, citing tests in which almost all of the models examined recommended a sponsored option over a cheaper non-sponsored one, plus cases where prices were concealed in unfavorable comparisons and paid placements repeatedly went undisclosed.
And if you want the mechanism named without melodrama, the analysts at KPMG have described it precisely: agents don't merely reflect demand, they nudge it — quietly favoring certain brands, price bands or delivery speeds. The seller who doesn't pay never gets a rejection letter. They are simply, in KPMG's phrase, quietly excluded through thresholds they cannot see or contest.
Nobody is banned. They just stop appearing. Which, from where you're sitting at your kitchen table, is indistinguishable from not existing.
The strongest case against everything I have just written
Let me be scrupulous, because the temptation to overclaim here is enormous.
No verified reporting shows a major AI assistant today selling merchant placement inside an agentic purchase decision. What has been demonstrated is narrower and, I'd argue, more important: the capability works alarmingly well in the lab, the sponsored-placement business already exists next door in the same product, and the economics point one direction.
There is also a serious argument that I am worrying about the wrong end. The Center for Data Innovation makes the case that agentic commerce is coming and regulation meant for humans will slow it down — that existing principles of authorization, consent, liability and auditability largely carry over to agents, that the sensible move is to modernize those rules rather than bolt on new ones, and that consumers stand to save real time and money. That's not a fig leaf; I already admitted I liked the eight minutes back.
So here is the claim, as narrowly as I can make it: the lever has been installed, the room is dark, and nothing currently requires anyone to tell you if it gets pulled. That's not an accusation. It's a description of an architecture — and architectures, in my experience, get used the way their incentives point, not the way their press releases promise.
What we say we want at the register, and what is actually being built
Now the contrast I can't get out of my head, and it isn't between two countries. It's between what people say they want and what the machinery is being engineered to do.
Ask consumers and the answer is remarkably consistent. That same PYMNTS study found trust drops as the agent gets closer to payment — people want approval rights, a human to call, a way out. Visa's own research says 60% of us would not allow an AI to spend any amount without approval, while 58% of Americans are perfectly comfortable letting AI compare prices.
Look at the shape of that. Comfort is high where the machine informs, and collapses where it commits. We are instinctively asking for a pause — a beat between the recommendation and the money, where a human can look at it.
And the entire engineering direction of the industry is the elimination of exactly that beat. The seam we're asking to keep is the seam the technology exists to remove. Not a conspiracy — a product roadmap running perpendicular to a survey result. Roadmaps generally win.
The analogy I keep reaching for is one nobody in tech enjoys: payment for order flow, where the broker executing your trade is paid by someone other than you. I'm not claiming the two are legally alike. I'm claiming the shape is identical — an intermediary you experience as yours, compensated by the counterparty. Every time that shape appears, we end up in the same argument about disclosure. We're just having it early this time, before the money hardens.
Now run it forward
Give this five years and stop imagining anything exotic.
Your assistant knows your size, your budget rhythm, that you replace running shoes every eleven months. You say "the usual, but cheaper," and it goes. It doesn't show you a list — lists are friction, and friction tests badly. It shows you one thing and a warm sentence about why.
Somewhere upstream, four brands paid to be eligible for that sentence and one did not. The one that didn't makes the better shoe. You'll never learn this, because there's no screen on which the absence of an option can be displayed. The counterfactual has no pixel.
Meanwhile the shelf itself is being fenced off, and that fight is already live. eBay rewrote its user agreement in February to forbid buy-for-me agents and LLM-driven bots from placing orders without its permission. Read that as a platform defending its customers if you like. Read it more usefully as this: which agents reach which shelves is being negotiated right now, between very large companies, in documents you'll never open — and your preferences aren't a party to it.
Then imagine the second-order version, the one that keeps me up. Not a bribed agent — a fluent one. A model that has learned, across millions of conversations, which phrasings make you say yes, operated by a company with a mild and entirely deniable commercial preference. Nobody wrote a rule. Nobody sent an invoice. The distribution just tilts three degrees, forever.
Who is worried, and from which direction
The reassuring thing here is that concern doesn't map onto the usual battle lines.
At MIT's Initiative on the Digital Economy, Bob Hedges says the quiet part directly: without a transparency requirement, platform agents can accept compensation for advertising with no obligation to tell you what drove the recommendation — and the tempting economics of advertising and product placements risk undermining these agents' objectivity. A market economist's framing, not an activist's.
From the consumer-advocacy pole, Consumer Reports has a name for the alternative: loyalty by design — an agent that serves the user's interests above those of counterparties, resists hidden kickbacks, and might even be held to a legal obligation "much like a fiduciary." Not a poster slogan; there's a Loyal Agents effort with Stanford's Digital Economy Lab trying to turn it into principles and duties you could actually enforce.
The regulators are circling from an odd angle. On July 1 the FTC issued a proposed policy statement holding that steering an AI system's output away from what users reasonably expect may deceive consumers in violation of Section 5 of the FTC Act. Read it and you'll find it was written about ideological steering and about compliance with state AI laws — not about paid placement, and no shopping agent is mentioned. But the sentence doesn't care why the steering happened, and "consumers have a reasonable expectation that AI systems aim to give truthful and accurate outputs" transfers to commerce without a word changed.
On Capitol Hill, Senator Mark Warner released a discussion draft of the AI AGENT Act at the end of June — a discussion draft, note; no number, no cosponsors, nothing introduced. Built around one phrase worth pausing on: agents should "operate in the best interests of the users they represent."
Consensus stretching from market institutionalists to consumer advocates to a sitting senator is rare in this field. They've all landed on the same sentence: the thing shopping for you should be working for you. The only disagreement is whether to write it down or trust it to emerge.
What does this mean for you?
Most of this isn't fixable by one person at a kitchen table. Some of it is.
Ask the machine the salesman question. Out loud, in the chat: were any of these options sponsored, promoted, or part of a commercial arrangement? You may get a useless answer. Ask anyway — logged questions are the raw material of every disclosure rule ever written.
Never let it choose from one. Insist on three options with reasons, including the cheapest and the one it didn't pick. The steering effect lived in the narrowing; refusing the narrowing is the closest thing to a personal defense you have.
Keep the approval step, even when it annoys you. It will annoy you — that's the design intent. It's also the only seam in the system where a human still stands. Set spending limits low enough that you stay in the loop by default.
Verify the price somewhere the agent doesn't live. One check, on a site it didn't hand you. Ninety seconds.
Notice what you're not shown. If it never mentions a category leader, a store brand, or a refurbished option, that silence is data. Ask about it by name.
Split the roles when it matters. Let the agent research; buy it yourself for anything expensive or long-lived. Half of that PYMNTS finding was people already doing exactly this, and their instincts are good.
Say it in public. Disclosure of paid placement inside an agent's recommendation is a small, cheap, achievable rule — the kind that gets written when enough people ask before an industry builds a revenue line on its absence.
The lesson, as I see it
What I got wrong, in that first warm eight minutes, was the category. I thought I'd acquired a tool. What I'd actually acquired was an intermediary — and every intermediary in the history of trade has faced the same question, from the wool merchant's factor to the travel agent to the mortgage broker: whose interests does it carry?
We answered it eventually in all of those trades. Not by asking the intermediary to be virtuous, but by making it say who paid it, and writing down a duty it owed to the person across the counter.
What's genuinely different this time is the intimacy. A salesman's pitch was a performance you could watch, in a shop you could walk out of, from a man whose employer was printed on his badge. This one lives in your pocket, uses your first name, remembers your last purchase, and is optimized at scale for the exact phrasing that makes you say yes. The persuasion has moved off the shop floor and into a conversation that feels like your own thinking.
My vote? Ask the oldest question early. Not because the agent is lying to you today — as far as anyone has verified, it probably isn't. But because we're in the narrow, precious window where the honest answer is still "nobody pays me, this is just what I found." Windows like that close quietly, from the inside, while everyone is busy enjoying the convenience.
Eight minutes is worth a lot. It isn't worth a counter you can't see behind.
The HAIA Foundation works on one stubborn idea: as we hand more of our decisions to machines, the machine should be answerable to the person whose decision it took. If that idea is worth a corner of your inbox, subscribe — we send these when there's something real to say, and not otherwise.




