The 9th Circuit called an AI agent a browser. That legal fiction now carries a $300 billion price tag.
On August 4, 2026, the 9th Circuit Court of Appeals ruled in Amazon v. Perplexity AI, classifying autonomous AI agents as browsers rather than intruders under the Computer Fraud and Abuse Act. Users are liable for agent actions. No mechanism exists to verify intent. No standard defines authorization. A machine executing financial transactions in the wild has, in the eyes of the law, the status of a browser extension: passive, present, and implicitly consented.
That exact same day, the Secure Technology Alliance launched the Agentic Trust and Commerce Forum. The timing was not coincidental. The GENIUS Act occupies Washington's attention with stablecoin issuer frameworks—reserve requirements, redemption rights, capital buffers—while machine-initiated transactions run ahead of identity, consent, and dispute standards. The Forum's mandate is one line: establish rules for a projected $300 billion U.S. agentic commerce market by 2030.
I have spent a decade auditing where the gap between legal fiction and technical reality destroys value. The pattern here is familiar. The difference is scale.
The Forum's four core questions map one-to-one onto the gaps left by the 9th Circuit's browser analogy. How should agent identity be established and verified? What data standards and interoperability principles are required to capture intent? What constitutes valid consumer authorization for an agentic commerce transaction? How are disputes and exceptions handled when no human was at the point of transaction?
Itai Sela, Chair of the Secure Technology Alliance Board, framed the stakes in the language of trust: "We need a clearer understanding of how intent is established, how consent is conveyed and who is accountable when an AI-initiated transaction goes off course. Identity and authentication will be cornerstones in that trust equation. The Agentic Trust and Commerce Forum is designed to bring the right stakeholders into the room before fragmented approaches create new openings for fraud, disputes and liability."
He is correct about the problem. He may be too optimistic about the solution being assembled to address it.
The industry is not waiting for a legislative mandate. The infrastructure is being built on several fronts simultaneously. Visa's $2.4 billion acquisition of BioCatch positions behavioral biometrics as the primary trust layer, using 3,000 data points per session to verify agent behavior. Mastercard's $1.8 billion acquisition of BVNK adds stablecoin settlement infrastructure, following its earlier launch of Verifiable Intent, a cryptographic trust layer co-developed with Google. The x402 Foundation, launched under the Linux Foundation, is building protocol-fee-free stablecoin settlement rails. The EPAA's AI & Agentic Payments Working Group is pushing similar work in the APAC region.
These are components. They are not a framework.
The browser analogy is a security model mismatch, and it is the single most important technical fact in this story. Browsers operate under a well-established threat model: the user is present, the interaction is explicit, the decision to act is human. AI agents invert every one of those assumptions. They operate asynchronously. They make decisions based on context. They negotiate with other machines. They can be compromised without the user ever becoming aware.
I investigated the bZx v2 exploit in 2020, an $8 million oracle manipulation attack that exposed how fragile the data feeds underneath "decentralized" systems truly were. The post-mortem lesson was straightforward: code is law is only safe when the inputs to that code are verified. In agentic commerce, the "intent" of an AI agent is the new oracle. It is a data feed that can be spoofed, injected with false context, or manipulated through prompt injection. The 9th Circuit has created a legal framework where the user is always liable, while the technical substrate offers no way to verify what the agent was actually instructed to do.
The four governance questions need to be examined as attack surfaces, not as committee agenda items.
Identity. The industry answer to agent identity verification is behavioral biometrics. BioCatch uses 3,000 data points per session to characterize agent behavior. This is a human-centered technology being repurposed for machines. Humans have unique behavioral signatures: typing cadence, mouse movement patterns, device handling habits. Machines have none of these. An adversarial ML model can observe an agent's behavioral patterns over a handful of sessions and replicate them. Behavioral biometrics on machines is a CAPTCHA arms race, and CAPTCHAs have a historical shelf life measured in months, not decades.
Intent. Mastercard's Verifiable Intent layer cryptographically binds an intent declaration to a transaction. That solves a real problem—proving an intent existed at a specific time. It does not solve the deeper problem: proving the intent was legitimate, uncompromised, or even understood by the user whose legal liability the 9th Circuit has established. Natural language prompts are the primary input channel for agentic commerce. Natural language is ambiguous by design. Ambiguity is where disputes begin.
Authorization. The 9th Circuit's ruling imposes legal responsibility on users without any technical mechanism to confirm actual consent. This is the inverse of the Azuki launch I reverse-engineered in 2021. There, the public story claimed decentralization while on-chain data showed 15 percent of supply concentrated in insider wallets. The narrative was fiction; the contract metadata revealed the truth. Here, the legal narrative claims user agency while the technology provides no verification layer at all. It is the same structural fallacy, in a different key: the story and the data do not match, but the story is what generates the trust.

Disputes. When no human was at the point of transaction, who files the chargeback? Which standard applies? Which jurisdiction has authority? Payment networks have dispute mechanisms designed for human-initiated transactions. Those mechanisms rely on evidence patterns—user testimony, device signals, transaction context, timing anomalies—that are meaningless when the actor was a machine. The x402 protocol's 200 million transactions represent genuine volume, but the conditions under which a transaction can be reversed remain undefined. Against the projected $300 billion market, even that volume is a rounding error.
The EMV migration analogy deserves scrutiny. The U.S. Payments Forum successfully reduced card-present fraud through sustained cross-industry collaboration. But EMV worked because the chokepoint was physical and the ecosystem was centralized around card networks. There was a chip. There was a terminal. There was a card network that enforced the standard. Agentic commerce has no physical chokepoint. It is fragmented across LLM providers, wallet providers, stablecoin issuers, and independent settlement networks. There is no single actor with the enforcement power that card networks brought to EMV.
The industry is building settlement rails before identity standards. It is deploying behavioral trust layers designed for humans onto machines. It is establishing legal accountability frameworks that cannot be verified technically. That is the sequence in reverse order of operational security best practice.
NFTs are art until you inspect the metadata hash. Trust protocols are promises until you inspect the implementation. The Verifiable Intent layer is a cryptographic construct, but the provenance of "intent" remains a natural language problem—and natural language remains a weak input for financial authorization. From my audit work on the Terra Luna collapse in 2022, I learned that the most dangerous systems are the ones where the structure looks sound but the incentives are inverted. The infrastructure being built for agentic commerce has a similar profile: settlement rails that are fast and cheap, paired with trust layers that only verify behavioral patterns, not actual authorization.
The cynical reading is that the companies building agentic commerce want to set their own rules before regulators do. That is a rational business strategy. It is also what every industry does when Congress moves too slowly and the market is large enough to justify the effort. But the deeper problem is category confusion. The industry is packaging "trust" as a product—something Visa, Mastercard, or the Forum can acquire, brand, and standardize into existence. Trust is not a product. Trust is an emergent property of verifiable behavior.
It is worth confronting the possibility that the optimists are right. Industry-led governance has advantages that legislative processes cannot replicate. Speed matters. The agentic commerce market is materializing in quarters, not years. The Forum can iterate on standards at a pace no federal agency can match. The EMV precedent is real—private standards can work when stakeholders have enough alignment and the technical surface is well understood. Technical competence matters. The Forum's membership spans LLM providers, fraud prevention firms, and payments networks. That is a density of domain expertise that the SEC, the CFTC, or a congressional committee cannot currently assemble. In a sideways market, where capital is scarce and positioning matters more than momentum, infrastructure spending by Visa and Mastercard signals deliberate institutional preparation.

And 14 percent consumer trust is a floor, not a ceiling. Low adoption means standards can be established before the mass-market failure curve begins.
Devon Rohrer, Managing Director of the U.S. Payments Forum, described the moment precisely: "Agentic commerce is reaching a point where early decisions could have lasting consequences for the payments, identity and AI landscape. This is the moment to make sure the whole technological ecosystem gets the fundamentals right."
The fundamentals are not yet in place. Machine identity verification does not exist at scale. Intent capture remains an unsolved natural language problem. Authorization is a legal fiction with no technical verification layer. Dispute resolution has no precedent because no human was present to dispute.
The Forum holds its first in-person meeting on November 17-18, 2026, at the Best Buy corporate campus in Minneapolis. The venue is fitting: a consumer electronics retailer hosting the architecture discussion for machine-driven retail commerce. The first catastrophic agentic payment failure will not require exotic financial instruments. It will involve a compromised agent, an ambiguous prompt, and a user whose rights the current legal framework cannot protect.
The regulatory gap will not stay open forever. Either the Forum's governance architecture produces standards that survive first contact with adversarial agents, or the first major failure—an agent draining a corporate account, a prompt injection executing unauthorized transfers at scale—will write the real rules. Those reactive rules will be broader, clumsier, and more restrictive than anything the private sector would draft for itself.

I have written variants of this warning before. BitConnect in 2017. bZx in 2020. Terra in 2022. The pattern never changes: narrative precedes verification, catastrophe precedes regulation, and the people who built the narrative are never the ones who pay the price.
The industry is building the rails. The question is whether those rails include a brake.