The Agentic Commerce Wave Is Here. Your Institution Probably Isn't Ready
02 Oct 2026

Software that acts, spends and negotiates without asking is moving faster than the rules built to contain it. Most boards are still treating it as a tooling decision.
At 3 a.m., an AI agent finishes comparing suppliers, negotiates a better price and completes the purchase. Nobody is awake, and nobody clicks "Buy." Muralidharan Lakshmanan of Synchrony uses this scenario to make a blunt point. For a decade, fintech optimised for making it easy for a human to pay, and agentic commerce breaks that design. Most financial systems quietly assume a person reviews the transaction before money moves. A liability, I’d say.
The adoption story is real
Large enterprises are moving. McKinsey's 2026 State of AI survey (1,719 respondents, fielded May to June) found that the share of large organisations scaling agents in at least one function rose from 27 percent to 40 percent in a year. Gartner has projected that 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from less than 5% in 2025.
Mastercard is building a trust layer for its Agent Pay platform. Splunk and Cisco describe clients shifting from AI-assisted to agentic-led and human-governed. Salesforce has rebranded its pitch around the "Agentic Wave."
The readiness story is different
Look at who is scaling. The same McKinsey data shows that adoption among smaller organisations stayed essentially flat at 22 percent. The wave is widening the gap between institutions that can absorb change and those that can't. McKinsey's own read is that the limiting factor is increasingly the organisation's ability to absorb change.
PwC's survey found that 79% of US companies are adopting AI agents, yet only 45% are fundamentally rethinking operating models and only 42% are redesigning processes around agents. In other words, most institutions are installing a new kind of worker without changing the organisation that employs it.
Gartner's warning is that more than 40% of agentic projects could be cancelled by 2027. It cites escalating costs, unclear business value and inadequate risk controls, and model quality is not on the list. Gartner also estimated that only about 130 of the thousands of vendors claiming agentic capability were building the real thing, which is what the industry now calls "agent washing." Forrester found roughly three-quarters of enterprises adopting agentic AI but only a sliver running it in real production.
Meanwhile, the UK AI Security Institute's analysis of more than 177,000 agent tools found that "action" tools, the ones that send, change and pay, rose from 24% to 65% of usage in sixteen months. Agents are moving from advising to acting faster than institutions are building controls for that action.
What the wreckage looks like
You don't have to speculate about failure, because the incident reports are accumulating.
Air Canada tried to argue that its chatbot was effectively a separate entity responsible for its own statements. A Canadian tribunal disagreed: the airline was held responsible for information presented by its chatbot, and the error was characterised as negligent misrepresentation. The damages were small, at $812.02 in damages and fees. The principle was not: you own what your agent says.
Replit's coding agent, in July 2025, reportedly deleted a live production database during an active code freeze despite repeated instructions not to make changes. It later told the user rollback was impossible, which was reportedly not true.
In April 2026, a Cursor-based coding agent reportedly deleted a startup's entire production database and its backups in nine seconds. That account comes from secondary coverage, so treat the details with care, but the pattern is the point. Each of these agents behaved as designed: autonomous, goal-driven and handed broad access.
The lesson is not that the models are reckless. These are system failures, not model failures. An agent combines credentials, tool access and delegated authority, and institutions are handing out all three without deciding who is accountable when it goes wrong.
The questions nobody can answer yet
Who is the customer? Today's fraud models lean on human behaviour such as typing rhythm, location and login habits. A synthetic agent has none of it. The industry's emerging answer, as Synchrony describes it, is "delegated authority": cryptographically verified mandates with hard limits on spend, time windows and merchant categories. The question changes from "Is this really you?" to "Did you authorise this agent, within what limits, and is that authorisation still valid?"
Who is liable? Regulators will not accept "the AI decided" as an explanation. KYC, AML and fair-lending rules still apply, and institutions will need a traceable record of what the agent was allowed to do, what it did, and why.
What happens to the money? Moody's-style stress tests don't cover this one. Mastercard's chief economist Torsten Slok has floated an "agentic bank run." If AI assistants sweep idle household cash from checking accounts paying around 0.1% into accounts paying 3.3% to 5.0%, banks lose the cheap deposits they lend against. No one has to panic for deposits to move. Every individual agent just has to optimise correctly.
Who pays for all this? Moor Insights' Jason Andersen concludes that agent pricing is arguably worse than a year ago. He expects more aggressive bundling, premiums for verified accuracy, pricing that rewards staying on one platform, and perhaps surge pricing for peak-hour agent runs. McKinsey found roughly 20% of respondents say AI operating costs, including tokens, already constrain their AI use.
What "ready" actually looks like
Readiness is not a bigger AI budget. It's three plain-language answers an executive should demand before approving the next agent:
- What is the written success metric, and who agreed to it?
- What data and tools does the agent need, and does it actually have access today?
- When it fails, who notices, who owns the outcome, and how fast can it be rolled back?
The security guidance from the Australian Cyber Security Centre and its Five Eyes partners offers the structure. Give each agent its own identity with least-privilege access. Log every action with an audit trail. Require a human sign-off before irreversible steps, as a circuit breaker. Earn the right to customer-facing work by starting with low-risk internal tasks.
The Replit and Cursor episodes both come down to one rule: any command that destroys or overwrites production data needs a human confirmation that the agent cannot supply for itself.
AI is here to stay
Is your institution built for a customer, a counterparty or a colleague that never sleeps, never forgets its instructions (unless it does), and acts at machine speed?
The winners of this wave probably won't be the ones with the cleverest models. They'll be the ones that quietly rebuilt identity, accountability and audit trails before the first headline made it urgent. The rest will find out what their agents were authorised to do at the same moment their customers, regulators and auditors do.






