It is 8:17 on a Tuesday morning. You tell your AI assistant to move your afternoon flight, find an earlier dentist appointment, argue with the cable company about a bill and order breakfast before your first call.
By 9:00, it has opened half a dozen websites, placed three phone calls, changed one reservation and bought you a sandwich. Before changing the flight, it showed you the new departure time and extra charge and waited for your confirmation. You let it negotiate with the cable company without you on the call, but told it to ask before changing your plan or agreeing to a longer contract.
Along the way, it made dozens of model calls and used several paid services. You have no idea what any of that cost.
WIRED’s Reece Rogers was less demanding of his assistant. He just wanted breakfast.
He asked Meta’s Muse to order from a San Francisco bakery. When the website allowed only one cheese, Muse picked cheddar and requested Swiss in a note. It assembled the cart, asked him to add a card through Stripe and waited for his confirmation before it could pay.
Muse had done the shopping; Rogers still controlled the payment. That is the kind of shared responsibility that gets lost in the phrase “agentic commerce.”
I already published one piece on agentic payments a few months ago and still could not tell you, with a straight face, what agentic commerce actually means. Does recommending a shirt count? Does the software have to buy the shirt for it to count? What does either have to do with an HTTP payment standard? The earlier piece looked at who would move the money. This one asks what authority we give the software acting on our behalf.
With Muse and Instinct reaching a broader consumer audience, agent-intermediated purchases are no longer just a proposed use case. WIRED reports that Muse passed 900,000 downloads in its first week, citing Sensor Tower. Instinct founder Noah Shinn says users who make purchases through the platform spend more than $1,300 per month on average through the assistant.
Investors are financing that expansion. Instinct announced a $250 million Series B in August, and The Information subsequently reported talks at roughly a $10 billion valuation. Downloads show reach, and the reported purchases show some consumers already spending through an assistant. The valuations reflect a bet on how much further that behavior can spread.
“Buy me running shoes” is a simple prompt but represents an incomplete financial instruction. Which shoes? Which merchant? How far above the target price can the agent go? If the original pair sells out, can it substitute another one?
Choosing the shoes and getting permission to pay for them are separate steps. Muse and Instinct both use Stripe’s Link wallet for agents to handle the payment step. For US consumers, Muse can use payment methods saved in Link at more than one million businesses; at other businesses, Link can issue a single-use virtual card for the approved purchase. The user confirms the amount before Muse pays, and Muse never receives the underlying card details.
Stripe also plans to let users set spending limits and decide which purchases require their approval. You might let an agent book a Delta flight under $200 without asking. If the flight costs more, the agent must show you the price and wait for your permission to buy it.
Meta has since announced PayPal and Shop Pay as additional payment options for Muse. Shop Pay’s rollout keeps purchase approval with the buyer: the user reviews the purchase in Shop Pay and approves it before anything is charged.
Visa describes its Intelligent Commerce tools as pairing agent-specific payment credentials with authenticated consumer instructions. In that design, Visa’s platform checks requests for credentials against those instructions, and its network applies controls over the merchant and amount.
The merchant must also agree to deal with the agent.
The Merchant Gets a Vote
Amazon refused when it blocked Muse from shopping on Amazon.com. There are competitive reasons Amazon might not want Meta between itself and its customers. Merchants also face an operational problem, regardless of Amazon’s motives.
Suppose an agent buys the wrong size, misunderstands a substitution or exceeds what the customer thought they allowed. The card can be valid and the customer can be real while the purchase is still outside the customer’s instructions.
Authentication helps establish who authorized a payment. Spending limits constrain the amount. Dispute rules govern a contested charge. To investigate an agent’s mistake, the merchant and financial institutions also need evidence of what the customer asked it to do.
Google’s AP2 uses signed mandates to record those instructions and limits. A signed record does not establish that the agent understood the instruction correctly or, by itself, decide who bears a loss. It gives the parties something to check against the purchase.
The checkout needs its own exchange of information. Google’s UCP covers product, cart and checkout information between agents and merchants. OpenAI and Stripe’s ACP also handles that exchange, while the merchant manages orders, payments and fulfillment. Recording permission and passing a cart to a merchant solve different parts of the transaction.
Before Money Changes Hands
Instinct’s examples for its early-access Concierge phone-calling rollout include asking a dentist’s office for an earlier appointment if someone cancels, booking a restaurant that does not take online reservations and sorting out a cable bill.
To lower the cable bill, an agent might need to log into the account, read old invoices, phone the provider and negotiate a different service plan.
You might let it read the bills, sit on hold and negotiate without interruption. Suppose the cable company offers a lower monthly price if you agree to stay for two years. The agent needs permission to accept that commitment. The resulting bills could still go to the card already on file: what changes is what you owe and for how long, not how you pay.
The assistant needs enough instruction to negotiate on its own and a clear point at which to ask you. Requiring your approval for every minor decision would defeat the convenience.
If the agent gets it wrong, there may be a charge, a contract and a loss somebody has to absorb. A disputed payment forces the user, agent developer, merchant and financial institution to work out what authority was delegated.
The negotiation itself also costs money. The assistant uses model calls and phone time whether you accept the cable company’s offer or get no offer at all. On the other end, a customer-service representative has to review the account, explain the options and respond to counteroffers. If software handles that conversation, the cable company pays for the compute instead. Companies already bear these costs. Agents make it easier for customers to initiate the work, and to keep asking. Your assistant can save you an hour without saving anyone else an hour.
Who Pays for the Work?
Even a task that feels simple can involve repeated model calls. The agent plans, searches, reads pages, calls tools, interprets results, notices failures and tries again. It may also use paid search, proprietary data or other APIs.
Those costs may be bundled into a subscription or absorbed by the company offering the assistant for free. Subscription revenue, venture funding and revenue from other businesses can pay the bill. The person typing the prompt usually sees none of the individual charges. (Pro tip: if you run agents yourself, make sure your token usage is visible... your dashboard for monitoring your other dashboards may start to seem less worthwhile.)
This is the $6-Uber phase of personal agents. The price the user sees is not necessarily the cost of providing the service. As AI personal assistant companies move from attracting users to building sustainable businesses, expect prices and usage limits to reflect those costs more closely. Some tasks may remain free to the user, funded by subscriptions or other revenue. The companies still need to know what they cost.
An AI personal assistant company might already pay for the model running its agent and the service placing its phone calls. Those accounts cover those services, not every resource the agent might encounter. BlackRock’s recent paper illustrates this with an AI travel agent that pays for airfare and hotel data before booking the trip. The reservations are only part of what the agent buys. Unless access is already included in an existing agreement, to actually be convenient, the agent needs a way to buy that data without stopping for a person to register and set up billing. The same problem arises if it needs additional compute from another model provider.
You Can’t Return Inference
Once a model runs, the compute has been consumed. The seller cannot recover it if the payment is later reversed. Laolu Osuntokun, CTO of Lightning Labs, described the risk this way:
“Credit cards are the wrong payment network here as inference is irreversible, while credit cards are reversible, creating short term loan risk for the inference provider.”
A seller choosing prepayment still has to consider whether that payment can be reversed. The protocol he helped design, L402, lets a service collect payment before granting access, without requiring a separate customer account. When an agent requests access to a paid resource, such as a model response or a database result, the service sends it a Lightning invoice and a token. The requested service holds back access until the agent returns that token with proof of payment. For inference, that check can happen before the model runs. The initial request still consumes resources; L402 does not make those free.
Coinbase’s x402 and Stripe and Tempo’s Machine Payments Protocol follow a similar sequence: the service quotes a price, and the agent pays to receive the requested resource. x402 supports stablecoin payments and last week added a specification for Bitcoin payments over Lightning. MPP supports stablecoins and cards, as well as Bitcoin over Lightning. A service accepting cards through MPP still has to account for the reversal risk Laolu describes, even though software handles the purchase.
A way to pay does not itself set the budget for the task. Model providers already impose usage and spending limits, but a limit at one provider does not set a budget for an errand using several services. The user or AI personal assistant company paying for the errand needs to see the combined expense and set a stopping point. For a subscription service, that can be the company’s internal budget rather than a new approval from the user. That budget covers the assistant’s spending; the cable company controls what it spends responding.
The cable negotiation can leave your bill unchanged while both sides have paid for the attempt. Permission to accept a new plan and permission to spend money pursuing it are separate decisions. An assistant needs instructions for both.
The multibillion-dollar bet is that agents will let us get more done with less effort. Delivering on that promise means accounting for the work they create for everyone else, too. Permission to spend has to cover the cost of trying, even when there is no result to approve. Otherwise, we risk confusing “my agent did it” with “it was cheap” or “it was more efficient.”
Disclosure: Russell Sechzer is an Enterprise Sales Lead at Halliday and previously worked at Lightning Labs, which is discussed in this article.

