After all the talk of agentic AI – involving agents doing things for us like managing calendars and shopping – there are less-discussed practical barriers. For example, anti-bot technologies like CAPTCHA can make the agentic dream fall apart – simply because agents can’t get through the front door.
In other cases, there’s deliberate blocking, such as Amazon’s recent stand against Meta Muse, effectively barring user-defined agentic shopping on its domain. Other domains and ecommerce players are reportedly making similar moves, including Yelp, eBay, Pizza Hut, Adidas, and several airlines.
In the end, the barriers to adoption that are often discussed – such as AI capability and user trust – are a moot point if agents can’t get access to popular web destinations. So it will often come down to case-by-case allowances; and a given site or platform’s stance on agents operating under its roof.
With that backdrop, Shopify became the latest to put up the “open for business” sign for agents on its platform. This week, it announced that agents can complete purchases on its merchants’ sites. This capability will be embedded in the platform, though individual merchants may be able to block agents.
Leap of Faith
For historical context, Shopify has always been agent friendly, having previously allowed them to browse and search for products, and add items to carts. This is all a function of the WebMCP standard that it adopted. But the latest move takes the next step – or leap of faith – towards agentic transactions.
This involves an additional element of the WebMCP standard that Shopify has implemented. And it includes three transaction-related functions: get_checkout, update_checkout, and complete_checkout. These map to typical checkout flows, including opening cart, editing shipping details, and transacting.
That last part is obviously the most concerning in terms of the trust required, and the propensity for rogue agents or (human) bad actors to orchestrate bad things. Meanwhile, the WebMCP standard includes safeguards, such as requiring agents to demonstrate user approvals and authentication.
It’s also worth noting that Shopify offers a hosted MCP server, allowing agents to work server-to-server. But with WebMCP, agents can work inside users’ browsers. This will be a more practical implementation and a way for eCommerce sites to open their doors for agentic commerce – albeit one by one.
Shopping with an agent shouldn’t feel like watching paint dry. 🥱
Today, we’re launching WebMCP support for checkout, including Shop Pay, for all eligible Shopify merchants.Learn how it works, where UCP fits, and what the data shows: https://t.co/U96VtJaeyc
— Gil (@gilgNYC) September 28, 2026
Speed Bumps
That brings us back to the part about adoption at the site/app/platform level. There will be mixed feelings about letting agents through the front door. That means there will be a mixed bag of functionality available across the web. This could in turn diminish user adoption, as agentic commerce is inconsistent.
That puts AI’s most impactful trust issues on the supply side, as opposed to the more-often discussed trust issues among consumers. For ecommerce sites, apps, and platforms, it likely boils down to a risk assessment, as any large-scale fraud or rogue-agent disasters will cost them money and headaches.
As all of this unfolds, there’s a related push to alleviate concerns through standards. For example, a consortium including Meta, Walmart, Stripe, Sierra, Genesys, Rocket, NiCE, and Decagon is working on open standards that govern how AI agents operate, and that can identify good agents from bad.
In the end, this will be sorted, and we’ll look back on this as speed bumps and typical emerging-tech growing pains. Meanwhile, it’s a good reminder and reality check that all the blue-sky claims of AI transformation are a bit further off than they sound on event stages, press releases, and social posts.
Header image credit: Money Knack on Unsplash

