When AI agents act - and what do to about it


Wednesday 8th July 2026

When AI agents act - and what do to about it

The paper we just co-authored with Visa sets out the principles. This is what to do with them, starting inside your business

Hi, welcome to the Trusted Agents Situation Room.

Each week we help senior leaders in banking, retail and travel make sense of agentic commerce: what's real, what's hype, and what to do about it. This week the paper we co-authored with Visa is public, so we go past the principles to the question we get asked in almost every conversation: what do we do now?

The answer starts closer to home than most expect. Point the agents at yourself first.

In 20 seconds

The prize in agentic commerce is larger than the one dot-com or e-commerce delivered. Because agents don't just automate the old way of working, they make new propositions possible.

Almost none of that is in production yet.

Our house view is that 2027 is when this starts for real, with Holiday 2026 as the first proving ground. So the first move is counterintuitive.

Before you build a customer-facing agent, or open your door to your customers' agents, point agents at your own operation. Learn what they can do, and where your business breaks, on your own ground rather than at a live checkout.

There are five internal enablers to put in place before the summer is over, and they're below.

What we're tracking this week

When AI Agents Act is now public. It's the paper we co-authored with Visa on trust frameworks and governance for agentic commerce.

It sets out the foundations of an agentic mindset: Trust, Delegation and Context; Know Your Agent [verifying the agent's identity and its authority to act]; and the four questions any business should be able to answer before an agent acts on a customer's behalf.

Read it as the way into the subject. It gives you the principles and the language to think clearly about what's coming. Pick up ther paper here.

What the paper sets out to do is establish those principles. The question we get asked in almost every conversation goes one step further: what do we do now?

That's the rest of this edition.

The other number worth reading against the grain this week is the one doing the rounds that says 95% of enterprise AI projects fail detailed in MIT's Project NANDA research paper.

Read as an obituary, it tells you to wait. But read with the right perspective, it says something much more useful. Organisations are learning without putting much into production, which is what this stage of maturity looks like. The technology works well enough to learn from. But the businesses underneath it are not yet fit to carry it into production.

Do you want Situation Room updates delivered to your inbox?

What you can do about it

Point the agents at yourself first

Before you launch an agent your customers can use, and before you prepare to deal with the agents your customers will send you, put agents to work inside your own operation. Internal co-pilots, on your own processes, with your own data.

Two things will happen when you do. You learn what agents are capable of, and where their safe boundaries sit, in a setting you control. And you put your data and your processes under a kind of scrutiny they've probably never had.

That second point carries more weight than it sounds. Because an agent optimises hard for the task in front of it, and it has none of the discretion a person brings.

Today, when someone hits a gap in a process, a hole in the data, or a weak spot in a permission, they work around it out of courtesy or common sense. But an agent goes straight through and uses it.

Picture a monkey loose in a kitchen: quick, capable, and entirely willing to use the knife drawer to open a coconut.

You see, the happy path works. But the exception path is where the damage shows up. You need to find those exception paths on your own systems, where the cost of a mistake is a lesson, not at a customer's checkout, where the cost is trust and possibly a regulator's attention.

This is the bottom-right of the response map we come to below: enable efficiencies, agents working inside your operation. It's the lowest-risk place to start, the fastest place to learn, and where almost every organisation should begin.

The prize is bigger than the last two waves

It's worth being clear about why this is worth the effort. Agentic commerce is not e-commerce with a chatbot on top. The value doesn't come from automating the workflows you already run.

It comes from propositions that only exist once agents are in the mix: a customer who delegates a whole task rather than clicking through your funnel, buying decisions made against their real constraints rather than your merchandising, service that resolves before a person would have thought to call.

Convenience for the customer, lower cost to serve, and growth from places the old channel couldn't reach. When it lands properly, the shift is larger than either dot-com or the move to e-commerce.

Right now, almost nobody is doing that. What's live today is agents doing human-shaped tasks, the old thing automated. The genuinely new propositions are still ahead of us.

Why it isn't ready yet

The hype is running ahead of the infrastructure, and several layers have to mature at the same time for the promise to hold.

The models are stochastic [they produce different outputs from the same input], which makes predictability and testing hard. The economics haven't settled; the cost of running these systems at scale can't stay this high. The payment rails need to be safe by default, which is where the card networks are moving fastest. The security and identity layer has the furthest to go, because the attack surface is enormous and it depends on verifying not just the customer but the agent and the business acting for them. And the protocols that let agents find each other and reach the tools and data they need are maturing but not finished.

Put all those together, and the honest position is that very little is in production.

But that's not a reason to wait. It's the reason to spend the time before production learning where your own gaps are, which is what the internal move above is for.

Our house view on timing: 2027 is when agentic commerce starts to happen for real. Today it’s experiments in labs and a smaller number of working pilots. Expect the noise to peak over Q4 2026 and into Q1 2027, with retail running the first real experiments over Holiday 2026. Through 2027 the learning starts turning into production. Travel follows quickly. Financial services is the barometer worth watching, because as a regulated industry it's where the governance bar, which is easy to underestimate, actually gets tested.

The part that's harder than it looks

An agent, by definition, plots its own path and chooses its own actions. That's what makes it useful, and it's also what makes governing it different from governing any system you've run before.

This is not about approving a fixed process. Instead, you're authorising something that will decide how to reach the goal.

That puts delegation at the centre. Delegation here means the valid, specific authorisation a customer gives for an agent to act on their behalf, and the instruction to the agent about what it may do and how.

It has to live in two places at once: in the customer experience, so the authorisation is real and understood.But also in the audit trail, as a mandate you can later point to and say this is what was permitted, by whom, and when.

Around that you need the rest of the governance apparatus: clear ownership, defined responsibilities, and compliance built in rather than bolted on.

This is the layer that decides whether any of the customer-facing ambition is safe to attempt. It's also the reason to start inside your own walls, where you can build the ownership and the audit habit before a customer is on the other end.

There are five internal enablers to put in place before the summer is over

None of these are customer-facing. That's the point. Each one makes you fit to carry agents into production later, and each one is something you can start now.

  1. Experience AI Agents firsthand, your own and others’.
  2. Get your data and processes in order.
  3. Prepare your systems, and your security perimeter, for agents to access safely.
  4. Establish a governance structure.
  5. Understand where you are on the Agentic Response Map.

Want to go to the next level?

The Trusted Agents Academy is a free 10-day email course: a four-minute read each day, each ending with one question for your organisation. Enough to turn this week's thinking into your own plan. Sign up here.

Until next time,

Gam and Jamie

Subscribe to Trusted Agents