Agentic Commerce Standards Split Across Protocols, Data and Trust

The W3C commerce workshop exposed a stack, not one standard: transaction protocols, product data, identity, consent, payment and trust still need to interoperate.

Sonar the Answer Whale connects UCP, ACP and MCP to product data and trust layers

Direct answer: Agentic commerce is not converging on one universal protocol. The W3C’s September 2026 workshop showed a layered problem: agents need ways to discover merchant capabilities, understand products, act with delegated authority, preserve consent, complete payment and prove what happened.

UCP, ACP, MCP and WebMCP can each contribute, but none replaces consistent product identity, fresh offer data or a trustworthy transaction record. The practical job for publishers and merchants is to map each customer step to the layer that controls it.

The W3C workshop made fragmentation visible

The W3C Workshop on E-Commerce for Humans and AI Agents brought browser, retailer, payment, identity and standards work into the same room on September 8 and 9. Its agenda included Google’s Universal Commerce Protocol, OpenAI’s Agentic Commerce Protocol, Shopify work around UCP and WebMCP, product identity, digital links and agent-friendly pages.

The important signal is architectural. A checkout protocol can describe an order exchange, but it cannot by itself establish that two catalogs refer to the same product, that inventory is current or that the agent still has permission to substitute an item.

Six layers solve different failures

A protocol name is not a complete commerce system
Layer Question Typical failure
Discovery What can this merchant or tool do? The agent cannot find the capability.
Product data Which exact item, variant and offer is this? Near-identical products are merged.
Delegation Who authorized the agent to act? The action exceeds the user’s scope.
Consent What may be changed or substituted? A preference is lost between steps.
Transaction How are cart, payment and status exchanged? Systems disagree about order state.
Trust How are freshness, origin and reputation checked? The agent acts on stale or unauthenticated data.

UCP, ACP, MCP and WebMCP are not synonyms

UCP and ACP are commerce-oriented protocol efforts. MCP is a broader way for an AI system to use tools and data exposed by a server. WebMCP focuses on exposing actions from web experiences to agents. Implementations can overlap, but a merchant should ask what each interface discovers, what state it owns and where user approval is required.

Start with the transaction you want to make reliable. A product-research assistant may need structured catalog and provenance more than checkout. A reorder assistant may need delegated identity, saved preferences and a durable receipt. Choosing a protocol before documenting that job reverses the decision.

Product identity is the quiet dependency

GS1 identifiers, digital links and schema.org vocabulary can help agents connect a product, variant, seller and offer. The hard cases are bundles, refurbished goods, regional packages, substitutions and listings where a merchant identifier does not map cleanly to a globally recognized item.

Test identity with adversarial examples: two sizes with the same image, a bundle that reuses a component name, an expired offer and a marketplace listing with several sellers. If the agent cannot preserve the distinction, adding a transaction protocol only automates the mistake.

A technical note lists ten unresolved trust gaps

A W3C Community Group technical note identifies gaps including capability discovery, agent identity and delegation, authenticity and freshness, negotiation, transaction state, consent, attribution, substitution, sustainability data and reputation. The document explicitly says it is not a W3C Standard and does not represent W3C consensus.

That disclaimer matters. The list is useful as a design inventory, not as a compliance specification. Teams can use it to find unowned risks while waiting for stronger interoperability and conformance work.

Audit one journey from request to receipt

  1. Write the user’s goal and the decisions the agent may make.
  2. Identify the product and offer fields required at each step.
  3. Record which system is authoritative for price, inventory and order state.
  4. Define the user’s delegation and where renewed consent is required.
  5. Capture the protocol messages and human-visible confirmation.
  6. Test stale data, revoked permission, substitution and duplicate-order failures.
  7. Store evidence that allows a support team to reconstruct the action.

This is also an SEO and AI visibility issue. Structured product information can improve machine understanding, but the goal is not to decorate a page with markup. It is to keep the public claim, machine-readable data and transaction state consistent.

Publishers can explain the stack without inventing a winner

Coverage will often collapse agentic commerce into a protocol race. A more useful editorial approach compares layers, supported actions, governance, adoption evidence and failure handling. Track specifications and implementations separately. A repository announcement is not merchant deployment, and workshop discussion is not a ratified standard.

Our UCP and AI checkout analysis follows the transaction layer. The structured data guide covers machine-readable meaning. This article connects those jobs but does not treat either as proof of agentic commerce adoption.

Download the agentic commerce readiness matrix

Download the CSV readiness matrix. It maps journey step, user intent, interface, product data, identity, consent, payment, trust evidence, owner, failure mode and next test.

The sample rows are marked EXAMPLE-REMOVE. Replace them with a real journey before using the sheet as implementation evidence.

Google’s September rollout moves UCP from protocol to merchant surface

Google says Tapestry is using UCP to sell products in Search, including AI Mode, and Gemini. It also says UCP cart transfer and checkout-flow testing is rolling out in the United States, with Australia and Canada planned for early 2027. This is deployment evidence for named surfaces, not proof that every merchant or product is eligible.

Google reports that lululemon’s conversational attributes were incorporated in 50% of relevant recommendations during a company test. The announcement does not disclose the denominator, sample size, control group or whether the figure is an inclusion rate, engagement rate or sales lift. Preserve it as a company-reported implementation result, not a general conversion benchmark.

The feed-to-purchase trust map
Layer Merchant evidence
Product meaning Stable identifiers, attributes, variants and claims.
Eligibility Market, account, inventory and policy status.
Recommendation Prompt, surfaced product, attribute evidence and timestamp.
Transaction Cart contents, price, availability, consent and handoff state.
Outcome Order, cancellation, return and customer-support evidence.

Evidence note

This analysis uses the W3C workshop overview and agenda plus a Community Group technical note. We compared the problems named in those sources and converted them into a journey audit. The workshop records discussion and proposals; it does not establish one adopted standard or prove deployment by every named company.

Keep learning

Continue this topic

Community discussion

Discuss: Agentic Commerce Standards Split Across Protocols, Data and Trust

Have a question, a useful example, or a different perspective? Join the discussion, share evidence, and help other readers reach a better answer.

0 replies Moderated
No replies yet.

Be the first to ask a focused question, share a practical example, or add useful evidence.

Ask a question or join the discussion

Share evidence, a useful example, or a clear question. Be specific, stay on topic, and challenge ideas without attacking people. First-time replies may be held for moderation.