Contents
Share this article
Key Takeaways
Visa reported a 1,200% year-over-year increase in retail site traffic from AI agents. Adobe Analytics tracked 4,700% growth in AI-driven visits to retail sites across 2025.
During Cyber Week 2025, roughly one in five global online orders involved some form of AI influence.
Agentic commerce seems to be gaining some traction. But while the traffic wave has arrived, the infrastructure to handle it has not.
When an AI agent tries to buy something, it runs into problems that never came up in human commerce: whose card does it use, how does the merchant verify it is a legitimate agent and not a bot, what spending limits apply, and who is liable if the purchase goes wrong?

Solving all of these agentic commerce questions requires new infrastructure that a fairly concentrated set of fintech companies has been building, including:
Let’s look at how these fintechs are building agentic commerce infrastructure in 2026, so you can better understand where the industry is at and know who to keep an eye on for the latest developments.
Each addresses a different part of that infrastructure gap. Some focus on the identity layer, some on checkout execution, some on the financial rails underneath.
All of these different developments require expert development talent, with a strong background in fintech and the different regulations that the industry is subject to. That’s where Trio comes in.
Our pre-vetted developers are hand-picked based on your requirements and placed based on their production experience.
| Company | Focus | Funding | Layer |
| Catena Labs | AI-native bank for agent banking | $48M total (a16z, Acrew, GC) | Banking rails |
| Natural | Payment infrastructure for autonomous agents | $40M total (Forerunner) | Payment rails |
| Nekuda | Agentic payments SDK for merchants | $5M seed (Visa + Amex Ventures) | Commerce execution |
| Uptiq | AI agents for bank workflow automation | $25M Series B (Curql, 645 Ventures) | Enterprise banking |
| Basis Theory | Tokenization layer for agent payment access | $33M Series B (Costanoa) | Data/tokenization |
| Skyfire | Know Your Agent (KYA) identity protocol | $9.5M total (a16z CSX, Neuberger) | Identity/trust |
| Rye | Universal Checkout API for agents | $14M seed (a16z crypto) | Checkout execution |
| Firmly | Unified protocol layer across ACP, UCP, AP2 | $5.2M (FJ Labs, Mastercard Start Path) | Protocol abstraction |
Most of the conversation around agentic commerce has focused on what AI agents can do, but Catena Labs focuses on whether they can be trusted with money at all.
The company, founded by Sean Neville (co-founder of Circle, the stablecoin platform) and former Circle executive Matt Venables, builds banking infrastructure designed specifically for AI agents to handle financial transactions while the appropriate oversight is in place.
Essentially, they have realized that giving an AI access to your wallet is the easy part, but providing organizations a governed way to trust that wallet is far more difficult.
Catena's platform lets companies set the guardrails in terms of things like spending limits, approved counterparties, maximum cash balances, and transaction categories. The agent then operates within those constraints, and every action produces a log that human teams see later,
In May 2026, Catena raised a $30 million Series A led by Acrew Capital and Andreessen Horowitz's crypto division, with Breyer Capital, General Catalyst, and QED also participating. That followed an $18 million seed round in 2025, also led by a16z crypto.
On top of that, the company has applied for a national trust bank charter from the OCC, which would allow it to legally hold customer funds and process payments without relying on partner bank infrastructure.
Any fintech company building agent-facing products will eventually need to answer the liability question: if an agent makes a wrong purchase, who absorbs the loss?
You do not want to be the one who puts your money and reputation on the line when your models can’t even be governed.
Catena's framework for governed agent credentials is one of the more thoughtful approaches to that question that we’ve seen so far.
The founding team at Natural noticed that the payment methods humans use (credit cards and ACH) require human authorization steps. These steps often break down entirely when an AI agent tries to use them at computer speed.
To counteract this, Natural builds payment infrastructure designed from the ground up for autonomous agent transactions.
The platform functions as an agent orchestration layer so that, when a company integrates Natural, their AI agents gain the ability to move and store funds, collect payments, and transact with both humans and other agents without triggering the authorization friction that blocks traditional payment methods.
In July 2026, Natural raised $30 million in a Series A led by Forerunner Ventures, bringing total funding to $40 million.
At the moment, it looks like the company has positioned Stripe as its primary competitive reference point, which indicates its ambition. Building infrastructure that can credibly compete with Stripe's distribution requires either a very different go-to-market or a very different technical architecture.
From what we have seen, Natural appears to be betting on infrastructure that simply works better for the agentic use case, rather than trying to out-distribute a platform that already dominates human-facing payments.
Teams building B2B products where agents handle procurement, vendor payments, or subscription management will hit the authorization problem quickly. Natural is building specifically to help you in that moment.
Nekuda raised only $5 million in its seed round, but the investors were made up of some very notable names like Madrona, Visa Ventures, and American Express Ventures.
This means that two of the largest card networks put money into a company building an SDK for agent-initiated payments, suggesting that they see the agentic checkout layer as important enough to back early-stage infrastructure companies working in it.
Nekuda’s product centers on two components. The first is a Secure Agent Wallet, which gives agents a defined financial identity they can use to transact. The second is Agentic Mandates, which lets users set rules governing what the agent can purchase, under what conditions, and up to what value.
Rather than competing with Visa or Mastercard for the authorization step, it looks like the platform is going to sit above those rails to handle the agent-specific credentialing and rule enforcement that the card networks have not yet built natively.
The fee, in theory, stacks on top of interchange.
Merchants who want to accept agent-initiated purchases without redesigning their entire checkout flow are the target customer here.
If your platforms need agent payment capability, Nekuda offers a shorter path than building it from scratch.
Uptiq builds AI agents that automate document-heavy workflows inside financial institutions: loan origination, client onboarding, commercial underwriting, compliance documentation, covenant monitoring.
These processes move slowly, usually because they are limited by humans who are manually reviewing documents that an agent could process in seconds.
Uptiq’s product functions as an orchestration layer sitting above legacy core banking software, and connects to existing document repositories and core systems rather than requiring banks to replace their infrastructure.
The customer base gives some indication of how the product works in practice, with over 140 institutions having gone live, including Focus Financial Partners, Orion, and Broadridge.
In February 2026, the company raised a $25 million Series B led by Curql, with 645 Ventures, Broadridge, and others participating.
It’s important to keep in mind that the human review step is deliberately preserved in the current product. Agents process and organize, but a human still approves before implementation.
That design choice is probably helping with bank procurement conversations, where compliance teams want to see oversight mechanisms before any autonomous workflow goes near a balance sheet.
For engineering teams at banks or credit unions evaluating where to start with agentic AI, Uptiq is one of the more mature examples of what production deployment actually looks like at scale.
Most payment infrastructure discussions focus on the authorization and rails layer. Basis Theory works one level down, on the data layer.
Specifically, the company looks at how payment card information gets stored, protected, and made accessible to AI agents without creating PCI DSS exposure at every touchpoint.
Their product’s main offering is that it converts raw card data into encrypted tokens that agents can use to complete purchases without ever handling the underlying card numbers directly.
This solves the problem created by the fact that standard card infrastructure was designed for humans who can authenticate themselves and accept responsibility for transactions.
Agents cannot do that in the same way, and the security and compliance implications of treating agents like human cardholders are significant.
Basis Theory raised a $33 million Series B led by Costanoa Ventures (approximately $50 million total raised), and has also gone on to found the Agentic Commerce Consortium, which counts more than 20 members working to define frameworks for how merchants accept agent-initiated transactions.
We’re keeping a close eye on their consortium work as well, as it may matter as much as the product in the long run.
Teams building products where agents need payment access without handling raw card data directly will find the tokenization layer essential.
Basis Theory's PCI DSS posture also reduces the compliance scope for companies building on top of it.
The fraud concern in agentic commerce is massive.
Visa reported a 25% spike in malicious bot-initiated transactions over a six-month period, with a 40% surge in the US specifically.
The problem is that, when a merchant cannot reliably distinguish a legitimate AI agent from a malicious bot, the default response is to block all automated traffic, creating issues for companies building legitimate agentic products.
Skyfire addresses this with a "Know Your Agent" protocol, abbreviated KYA by analogy to the KYC standard in financial compliance.
Their system issues verifiable identity credentials to AI agents using JSON Web Tokens, using the same underlying OAuth2 infrastructure that already handles human authentication in most web applications.
When an agent presents its KYA token to a merchant or payment processor, the merchant can verify that the agent is what it claims to be, operating under defined spending authority, without needing to build a custom verification system from scratch.
In March 2026, Skyfire partnered with F5 to integrate KYA tokens directly into F5's bot defense systems, which means that any merchants using F5 can configure their bot detection to allow authenticated Skyfire agents through while continuing to block malicious automated traffic.
Any fintech product that deploys agents to transact on behalf of users needs a credible answer to the question "how does the merchant know this agent is legitimate?" Skyfire is one of the more technically specific answers currently available.
One recurring problem we are seeing in agentic commerce is that most checkout protocols require merchants to opt in and integrate the relevant API.
Shopify's Agentic Storefront requires Shopify. OpenAI's Agentic Commerce Protocol requires merchant-side implementation. What happens when an agent needs to buy from a merchant who has not integrated anything?
Rye's Universal Checkout API handles that case, completing purchases on any e-commerce site without requiring prior merchant integration, using a combination of AI browser agents, DOM normalization, and fraud mitigation.
The company publishes its reliability metrics directly: 99% uptime for Amazon integrations with approximately five-second latency, versus 65% reliability on non-integrated sites at roughly five-minute latency.
While we need to acknowledge that the gap between integrated and non-integrated performance is significant, 65% reliability on the open web without any merchant setup is still a lot better than zero.
Rye raised a $14 million seed round led by a16z crypto, and has also built a Product Data API that returns normalized product information from any merchant site, addressing the discovery layer as well as the transaction layer.
The dual capability matters because an agent that can discover products but not purchase them, or purchase them but not discover them, delivers an incomplete experience.
Teams building consumer-facing shopping agents that need to work across a broad range of merchants, not just those who have adopted specific protocols, will find Rye's approach more practical than building bespoke integrations per merchant.
By mid-2026, the agentic commerce protocol landscape had produced at least six meaningful standards: ACP (OpenAI and Stripe), UCP (Google and Shopify), AP2 (Google), MCP (Anthropic), A2A (Google and Linux Foundation), and Visa TAP.
Each one has genuine support from large platforms, and most merchants we work with are trying to implement at least two or three of them, which means building separate integrations for each.
Firmly sells one integration that covers all of them.
A merchant connects to Firmly's unified "Buy Now" platform once, and the platform handles communication with whichever protocol the incoming agent uses: ChatGPT shopping, Perplexity, Copilot, publisher sites, connected TV.
The company raised $5.2 million from FJ Labs, Ark Invest, and Mastercard Start Path.
If the protocol wars produce a clear winner in the next 12 months, protocol aggregators like Firmly are going to become less valuable. If the fragmentation persists, which currently looks more likely, Firmly's position strengthens as each new protocol adds complexity that merchants cannot afford to absorb individually.
For content sites, social platforms, and publishers looking to add commerce capability without deep technical investment, Firmly also offers a white-label path that preserves attribution and loyalty program tracking through agent-initiated transactions.
Any product that needs to accept agent-initiated purchases from multiple AI platforms without maintaining separate protocol integrations is the core use case here. The Mastercard Start Path involvement adds a signal worth noting for teams evaluating the company's staying power.
The companies on this list are hiring engineers who understand both sides of the stack. They need people to build the technical architecture of agent payment systems and the compliance surface those systems create.
That combination is incredibly complex and difficult to find, since it sits at the intersection of ML engineering, API design, and financial regulation. Engineers who cover all three are genuinely rare.
At Trio, we connect fintech teams with pre-vetted engineers from Latin America who have worked in regulated financial systems. Instead of you needing to source from scratch, we can place the right person, often within days.
Whether your team needs infrastructure engineers familiar with tokenization and PCI DSS, ML engineers with fraud detection experience, or API engineers who understand the emerging agentic commerce protocols, we can match you with the right people.
There are several compliance risks in agentic commerce for fintech companies, and they are not fully resolved yet. Liability for unauthorized or erroneous agent-initiated transactions sits in a gray area in most jurisdictions. Reg E protections for consumers were not written with autonomous agent purchases in mind. AML and KYC obligations still apply to agent-initiated transactions, which means financial institutions need audit trails that meet regulatory standards even when no human directly approved the transaction. Data privacy laws like GDPR and CCPA add constraints on what behavioral and preference data agents can use to personalize purchasing decisions.
Which fintech your engineering team should watch in agentic commerce depends somewhat on which layer matters most for your product. For banking rails and agent governance, Catena Labs is the most closely watched for general payment infrastructure, along with Natural and Nekuda. For enterprise banking workflow automation, Uptiq has the most production-scale evidence. For the identity layer, Skyfire. For checkout execution across the open web, Rye. For tokenization and PCI DSS compliance in agent contexts, Basis Theory. For protocol fragmentation, Firmly.
Know Your Agent, or KYA, borrows the structure of Know Your Customer (KYC) compliance and applies it to AI agents. A KYA protocol provides a mechanism for issuing verifiable identity credentials to an AI agent and presenting those credentials at the point of a transaction, so merchants can confirm the agent’s identity, spending authority, and operating parameters before processing a purchase. Skyfire is currently the most prominent company building a dedicated KYA protocol. Visa’s Trusted Agent Protocol (TAP) addresses a similar problem at the card network level.
In most production deployments, agents today make payments through the use of virtual cards issued through platforms like Lithic, Stripe Issuing, or Marqeta, with programmatic controls set on the card itself. Some agents use stablecoin wallets for transactions that benefit from programmable settlement. A growing number of deployments use the infrastructure being built by companies like Natural, Catena Labs, and Nekuda, which handle payment execution at a higher level of abstraction and add governance layers that virtual cards alone cannot provide.
There is quite a lot of infrastructure that agentic commerce requires that does not exist yet. First, agent identity: a way for merchants to verify that an incoming transaction comes from a legitimate AI agent acting within authorized parameters. Second, governed payment credentials: a mechanism for giving agents spending authority that comes with defined limits, audit trails, and liability structures. Third, checkout execution that works without a human in the browser session. Fourth, fraud detection calibrated for machine-speed transaction volumes, which look very different from human transaction patterns.
Agentic commerce refers to commercial transactions that an AI agent researches, compares, and executes autonomously on behalf of a user, without the user approving each individual step.
Expertise
Subscribe to our newsletter
Related
Content
Continue Reading