AI shopping agents are software that browse, compare, and in some cases complete a purchase on a customer’s behalf, and every major platform β OpenAI, Google, Shopify, Anthropic β shipped infrastructure for this in 2026. Before deciding whether to make your store “agent-ready,” the more urgent question most guides skip is whether it’s currently safe to let one transact on your site at all: Amazon just won a federal court order blocking an AI agent from doing exactly that without consent, and a fraud-prevention industry CEO warned this month that there’s still no framework for who pays when a customer disputes a purchase an AI made.
The adoption numbers are real growth rates on an unclear base
Every agentic-commerce guide leads with the same kind of figure: AI-driven traffic to Shopify stores up 8x year over year, orders from AI search up nearly 13x, “over 1 million Shopify merchants” already connected to AI shopping channels, per Shopify’s own account of the shift. Those are real reported numbers, and they’re also growth rates and connection counts, not shares of revenue β and the base they’re measured against is itself disputed:
| Tracker | Definition used | Shopify store count |
|---|---|---|
| StoreLeads | Live, active stores | ~2.06β2.83 million (estimates vary by snapshot date) |
| BuiltWith | Live websites running Shopify’s technology | ~6.9 million |
| Various industry trackers | “Merchants,” undefined precisely | Figures ranging from 2.06 million to 5.6 million commonly cited |
Against that range, per independent tracker data, “over 1 million merchants connected” to an AI shopping channel could mean anywhere from roughly a sixth to roughly half the platform, which is a genuinely different story depending on which denominator you believe β and none of the platforms publishing the growth-rate figures have published the denominator themselves.
What Amazon v. Perplexity actually settled, and why it matters even if you’re not Amazon
This is the case worth understanding before treating “AI agents will shop on your site” as settled infrastructure rather than an active legal fight. Amazon detected Perplexity’s Comet browser agent making purchases on its platform in August 2025, sent a cease-and-desist, and filed suit in November 2025 after Perplexity kept the feature running β reportedly by disguising the agent’s traffic as an ordinary Chrome browser session. In March 2026, a federal judge granted Amazon a temporary injunction, finding the retailer had shown strong evidence of unauthorized access, and ordered Comet blocked from making purchases on Amazon’s platform while the underlying case continues. Perplexity disputes the claims and has framed the suit as a large incumbent using litigation to slow down a competitor; the case is still being litigated, and this outcome could still change.
The part that transfers to a small merchant, regardless of how the appeal goes: a platform’s terms of service can currently be enforced against an AI agent acting like a human visitor, at least well enough to win a temporary order, and the ruling specifically turned on the agent concealing that it was automated rather than on agent shopping being unlawful in general. If your own store is ever scraped or purchased from by an agent that isn’t identifying itself and isn’t going through an approved protocol like ACP or UCP, you have real legal standing to say no β you don’t have to treat every AI agent hitting your site as a customer you’re obligated to serve.
The liability gap nobody selling you an “agent-ready” checklist mentions
Anthropic published its own set of commerce-agent blueprints for retailers this month β reference implementations for a shopping agent and a merchant agent, built to be deployed through the Claude API, Amazon Bedrock, Microsoft Foundry, or Google Cloud Vertex AI. The coverage of that release included a detail worth taking more seriously than most of the launch write-ups did: Monica Eaton, founder and CEO of the fraud-prevention firm Chargebacks911, told reporters that agentic commerce “looks likely to create fraud problems for merchants,” and that there isn’t yet a framework for merchants to handle cases where a consumer claims they didn’t authorize a purchase an AI agent made. Her point, in her own words: “Merchants cannot become the insurer of every misunderstanding between a consumer and their AI.” Protocols like ACP and Google’s AP2 do include cryptographic proof-of-authorization mechanisms designed to solve exactly this, but how that proof holds up in an actual dispute with a card network or a chargeback arbitrator is still untested at scale. If you’re a small merchant weighing whether to turn on agentic checkout, this β not the traffic-growth statistics β is the risk that should actually drive the decision, since a wave of disputed AI-authorized purchases with no resolved liability standard would land squarely on you, not on the platform that built the checkout protocol.
Three actual positions, not one recommended path
Almost every guide on this topic ends with the same advice: get agent-ready, structure your data, don’t get left behind. That’s one option, not the only reasonable one. Here are three, honestly:
- Stay out of it for now. If you’re not already seeing meaningful AI-referred traffic in your own analytics, opting out β blocking known agent user-agents, keeping your terms of service explicit that automated purchasing isn’t authorized β is a defensible, low-effort position. You lose nothing you’re currently getting, and you take on none of the dispute-liability exposure described above.
- Be discoverable, not transactable. Structure your product data cleanly (accurate inventory, clear pricing, a well-formed product feed) so AI agents can find and recommend you, but keep checkout itself requiring a human to complete the purchase on your own site. This captures the upside of AI-driven discovery β which the traffic-growth numbers suggest is real β without taking on agent-authorized-purchase disputes at all.
- Go fully agentic. Implement ACP or UCP checkout end to end. This is worth the integration cost specifically for merchants who can already see, in their own numbers, that a meaningful share of traffic and intent is coming through AI surfaces β not merchants acting on an industry-wide growth-rate statistic that may not describe their store at all.
Check your own AI-referral traffic in analytics before picking one of these, the same way we recommend verifying any AI-generated claim against a primary source rather than a summary of one β in this case, the primary source is your own store’s data, not an industry report built on somebody else’s average. If you already keep an internal record of what data goes into which AI tool, this decision belongs in the same place as the rules covered in our piece on shadow AI for small business β a checkout protocol you didn’t deliberately vet is exactly the kind of unreviewed tool-and-data combination that piece warns about.
Where this connects to decisions you’ve likely already made
If you’ve been reading through our recent coverage, this sits next to two decisions already on the table. The liability and dispute-authority question here is the same category of problem covered in our guide to what AI agents can and can’t safely do for a business β an agent acting on your behalf (or a customer’s, on your storefront) without a resolved accountability chain is the same risk regardless of which side of the transaction you’re on. And if you do decide to enable any agent-facing tooling, naming which protocols and vendors are approved belongs in the same document covered in our AI usage policy guide, not treated as a one-time technical setup task with no review date. If you’re still building out your broader AI toolset for the store itself β inventory, marketing, customer service β our AI e-commerce tools guide covers that separately from the agentic-checkout question addressed here.
Who should actually move on this now
Merchants already selling through Shopify’s Agentic Storefronts or with a Shopify Plus-scale operation, where the integration cost is small relative to revenue and analytics already show AI-referred traffic, have a real reason to move now. A solo seller or small team without that traffic signal yet has no urgency here β the legal and liability questions above are still being worked out by companies with legal departments built for exactly this fight, and there’s no cost to watching that play out for another few months before committing engineering time to a protocol that may look different by the time the Amazon v. Perplexity litigation resolves. If you’re weighing this against other compliance-shaped decisions on your plate, it’s worth reading alongside our EU AI Act guide for small business and our small business AI toolkit β none of these are urgent in isolation, but they’re all part of the same “don’t adopt ahead of your own evidence” discipline.
What is agentic commerce, and does it actually matter to a small store?
It’s AI agents handling some or all of a shopping journey β discovery, comparison, sometimes checkout β on a customer’s behalf. It matters more to how customers might find you than to what you need to build immediately; most small stores don’t yet have a reliable signal in their own analytics that meaningfully changes.
Should I let AI shopping agents complete purchases directly on my site right now?
Not urgently, unless you already see clear AI-referred purchase intent in your own numbers. The liability question β who’s responsible when a customer disputes an AI-authorized purchase β isn’t resolved yet, and taking on that exposure ahead of a clear traffic signal is a cost without a matching benefit.
What did the Amazon v. Perplexity ruling actually decide?
A federal judge granted Amazon a temporary injunction in March 2026 blocking Perplexity’s Comet browser agent from making purchases on Amazon’s platform, finding strong evidence of unauthorized, concealed automated access. It didn’t rule that AI shopping agents are unlawful in general β it turned specifically on the agent disguising itself as human traffic in violation of Amazon’s terms. The case is still being litigated.
Who is responsible if a customer disputes a purchase an AI agent made on my store?
There isn’t yet an established framework. Fraud-prevention industry voices have publicly flagged this as unresolved, and while protocols like ACP and AP2 include cryptographic authorization proof meant to address it, how that proof performs in an actual chargeback dispute hasn’t been tested at scale.
How do I find out how many of my own customers are already using AI shopping agents?
Check your store’s own analytics for referral traffic from AI platforms and for unusual patterns in session behavior (very fast, structured browsing followed by an immediate purchase can indicate agent activity). Don’t rely on industry-wide adoption statistics to answer this for your specific store β the range across trackers is wide enough that a platform-level number tells you little about your own traffic.
Do I need to implement ACP or UCP to stay competitive?
Not immediately, for most small stores. These protocols matter most for merchants who can already point to real AI-referred traffic and revenue in their own data. Building for a channel before you have evidence customers are using it to reach you is optional infrastructure, not a competitive necessity.
Shurah is the founder of AI Tools Daily, tracking pricing, licensing and policy changes across AI tools so readers can make decisions without wading through marketing claims themselves.