The Authorization Gap: Why Agentic Commerce Can't Scale Without an Identity Layer


AI agents are browsing, comparing, booking, and buying on behalf of hundreds of millions of people. The rails for moving money are built. The infrastructure for proving who authorized the transaction has yet to be specified.
Every major agentic commerce protocol has launched with serious engineering behind it. Google AP2. Mastercard Verifiable Intent. Visa TAP. OpenAI ACP. Stripe MPP. Each defines how authorization records should be structured, how they should flow through commerce infrastructure, and how they should be verified. What none of them defines is who issues the credentials that make those records trustworthy in the first place.
Google's AP2 specification puts it plainly:
"Establishing these 'roots of trust' is a critical area for innovation."
That gap, the identity issuance layer that every protocol assumes but none has specified, is what we're calling the authorization gap.
Why authorization matters now
The fraud risk is only part of the problem. The FBI's 2024 Internet Crime Report recorded $16.6 billion in cybercrime losses, the highest figure in the report's history. Deloitte projects that generative AI-enabled fraud will grow from $12 billion in 2023 to $40 billion by 2027, a 32% compound annual growth rate, driven by AI agents that can execute fraudulent transactions continuously, at machine speed, at near-zero marginal cost.
The dispute infrastructure the payments industry relies on was built for humans. When a human makes a purchase, the transaction carries implicit proof of authorization: a chip terminal, a biometric, a logged session. When an AI agent makes a purchase, it leaves a log of what it did. Under any current protocol, it leaves no cryptographically signed record proving that a specific, verified human authorized that specific action.
Every fraud dispute in the agentic era ends the same way unless this changes: someone claims their agent went rogue, and no record can definitively resolve it.
Why the gap can't fill itself
The protocols have grappled with who could serve as the trusted authority to issue those credentials. Each credible candidate carries a structural conflict that disqualifies it.
AI platforms can't vouch for whether their own agent acted within bounds, because that's asking a contractor to write their own inspection report. Merchants have a direct financial interest in dispute outcomes. Card networks are each building their own key infrastructure independently, creating fragmentation rather than a shared root of trust. Banks are largely absent from the working groups defining these protocols.
What the issuance role requires is a party whose only business is verifying who someone is and issuing the credentials they need to sign their own authorizations, with no stake in the commerce, no interest in purchasing behavior, and no network economics to protect.
What filling the gap actually requires
The technical bar is specific: IAL2 identity proofing under NIST SP 800-63A, Certificate Authority qualification under WebTrust, transaction-bound signatures (Key Binding JWTs tied to a specific transaction and amount, not just proof of login), and selective disclosure via SD-JWT VC so consumers can prove what a merchant needs to see without exposing their full credential.
The legal framework already supports this. ESIGN and UETA, the federal and state statutes governing electronic transactions, both recognize agent-authorized transactions as legally binding. What they require is attribution: a reliable security procedure proving that a specific, identifiable human authorized a specific agent to act. That procedure doesn't yet exist at scale in agentic commerce.
The full picture
To get a complete look at the current state of the digital identity market and gap across the current protocol stack, check out our latest research report: The Authorization G This report, which includes research insights from Liminal, looks at why this gap exists, why current protocols can’t fix it, and what the issuance layer has to look like to secure identity in agentic commerce.





























































.jpg)







































































.png)

.jpg)

