Ask, Don't Click: What Actually Happens When AI Shops For You in 2026
Picture the pitch from eighteen months ago: you tell an assistant "I need running shoes, size 10, under $120, arriving by Friday," it compares the options, picks the best one, and the box shows up. No tabs, no cart, no nineteen-step checkout flow. That was the promise of agentic commerce, and for a while it felt like the next big interface shift — the same way voice search and mobile were supposed to change everything before them.
Eighteen months later, the honest picture is more interesting than the pitch. One version of that dream mostly stalled. A quieter version of it is already moving billions of dollars a year. And a third version of it is showing up in fraud reports as a brand-new way to lose money. All three are worth understanding, because odds are you've already brushed up against at least one of them this summer without fully realizing it.
The version that stalled: "buy it right here in the chat"
In late 2025, OpenAI shipped Instant Checkout — the ability to complete a purchase without ever leaving the ChatGPT window, built on an open standard called the Agentic Commerce Protocol. It was the clearest expression of the original pitch: discovery and purchase collapsed into one conversation.
By March 2026, the numbers told a different story. Only about 30 merchants had gone fully live six months in, and a Walmart executive disclosed that purchase conversion inside ChatGPT ran at roughly a third of the rate of Walmart's own site. The gap turned out to be everything that doesn't show up in a demo: syncing live inventory, handling multi-item carts, honoring loyalty programs, routing returns, resolving a disputed charge when the wrong size shows up. A chat window is a great place to compare four pairs of shoes. It's a much harder place to be a full point-of-sale system, a customer service desk, and a fraud team all at once.
So the industry quietly regrouped around a less flashy model that people are now calling "discover in AI, buy on site." The AI does the part it's actually good at — narrowing thousands of options down to three, explaining the tradeoffs, drafting the comparison you'd otherwise build in a spreadsheet — and then hands you off to the merchant's own checkout to finish the transaction. ChatGPT's March update leaned into exactly this, expanding visual search and side-by-side product comparison rather than pushing harder on in-chat purchase completion. Perplexity has gone further on the checkout side, offering free agentic checkout to all U.S. users with merchants like Wayfair and Ashley Furniture — but even there, "agentic" mostly means a very good research assistant that pre-fills your cart, not a system making judgment calls with your money unsupervised.
The version that's quietly working: shopping you already trust
While in-chat checkout got the headlines, a less glamorous version of the same idea has been compounding in the background: AI folded directly into a retailer you already use, watching for a specific condition and acting on it.
Amazon's Rufus — renamed "Alexa for Shopping" in May 2026 — is the clearest example. It's not a general-purpose agent you point at the open web; it's a shopping assistant scoped entirely to Amazon's own catalog, order history, and reviews, with an Auto Buy feature that will purchase an item automatically once it drops below a price threshold you set. That narrow scope is precisely why it works: Amazon already knows your order history, your delivery address, your saved payment method, and your return policy. The assistant isn't negotiating trust from scratch every time — it's operating inside a relationship you already have. The result is more than 300 million customers using it, an estimated $12 billion in incremental annual sales, and purchase sessions that convert at more than three times the rate of sessions without it.
That's the real lesson in the gap between the two approaches. The version of agentic shopping that's actually moving money isn't the one that tries to be a universal shopping brain across every store on the internet. It's the narrow, boring, single-retailer version that only has to be right about one thing — is this the same item, at a good price, that I already told you I wanted — instead of everything a full checkout stack has to get right at once.
The version that's a warning label: AI agents getting scammed on your behalf
Here's the part worth taking seriously before you hand a shopping agent your card. Security researchers running tests on AI browsers — tools that click, fill forms, and complete purchases autonomously — found them falling for fake storefronts and phishing pages the same way a rushed, distracted human might. Coverage of the research nicknamed the problem "Scamlexity": an agent moving fast enough, and trusting enough, to buy from a shop that doesn't exist.
The fraud side is just as active from the other direction. Security firms have documented bad actors running their own bots to test stolen credit card numbers against merchant checkouts — automated "carding" attacks that exploit the same agent-to-merchant interfaces built for legitimate shopping agents. And it's not hypothetical for the platforms themselves: OpenAI pulled back from handling commerce directly in March 2026, shifting Instant Checkout's payments, cancellations, refunds, and customer complaints into partner apps rather than its own infrastructure — a sign of how much liability (fraud, chargebacks, disputed charges) sits inside that "click to buy" moment. Separately, credit bureau Experian's 2026 fraud forecast named agentic AI a top emerging threat, warning that the same automation making checkout faster for shoppers is making it faster for scammers too.
None of this means the technology is unsafe to use. It means it's unsupervised money movement, and it deserves the same skepticism you'd apply to anything that can spend on your behalf while you're not watching.
The workflow that's actually reasonable right now
Strip away the hype and the horror stories, and there's a workflow here that's genuinely useful today, if you draw the lines in the right place.
Let AI do the research, every time. Comparing eight pairs of hiking boots across price, weight, reviews, and return policy is exactly the kind of tedious, structured task a model is good at and you're bad at doing thoroughly. Paste in a few product links, or describe what you need, and ask for a comparison table with the tradeoffs spelled out — not just a single recommendation. Push back if it recommends something suspiciously fast; ask it to show its reasoning and cite what it's basing the recommendation on.
Keep the actual purchase inside a store you already trust, on a payment method you control. This is the throughline of everything above. Amazon's Auto Buy works because it's scoped to Amazon, your existing account, and a threshold you set. A general-purpose browser agent buying from a storefront it just discovered is a fundamentally different risk. If you're going to let anything purchase autonomously, limit it to retailers with an existing relationship to your account, a real return policy, and a support line you can call.
Set a hard price ceiling, not a target price. If you're using an auto-buy or price-drop feature, the number you enter is a ceiling, not a goal. Set it conservatively, and treat any purchase confirmation as something to actually read, not swipe past.
Verify the merchant before you verify the product. The "Scamlexity" research points at a failure mode worth taking personally: the checkout looked legitimate, but the seller behind it wasn't who it appeared to be. Before completing any AI-assisted purchase — especially one initiated from inside a chat window rather than a retailer's own app — check that the URL you're actually paying on matches a real, known merchant.
Treat "AI picked this for me" as a starting point, not a receipt. Courts and regulators are already treating AI-generated product claims and AI-curated bundles as the seller's responsibility, not a neutral third party's. That cuts both ways for you as a shopper: the agent's recommendation is a well-informed opinion, not a guarantee. Read the actual product page before you buy, the same way you'd double-check a mechanic's diagnosis before authorizing the repair.
What this says about agentic AI more broadly
The shopping story is a small, concrete preview of a bigger pattern showing up everywhere AI touches money and irreversible actions: the general-purpose, do-anything version of the agent is the one that grabs headlines and then quietly underperforms, while the narrow, scoped-down version — operating inside guardrails, with a specific trigger and a known counterparty — is the one that actually earns trust and adoption. That's worth remembering the next time a demo shows an agent doing something impressively broad. Ask what it looks like scoped down to one store, one threshold, one account you already trust. That version is usually closer to what you'll actually want to use.
Related reading on AI Maniacs
- AI Safety & Privacy Checklist — what to check before letting any AI tool touch your payment information.
- AI Model Comparison — how the major assistants differ in tool use and agentic capability.
- Marketing & Sales — how agentic commerce is changing the retail and marketing side of this equation.
- Prompt Library — reusable prompts for product comparisons and research, including the shopping-comparison pattern used above.
This content was developed with AI assistance and is regularly reviewed for accuracy. Statistics on agentic commerce adoption, fraud, and regulatory actions reflect industry and news reports published in 2026; specific figures vary by source and change quickly in a fast-moving space.
