Whoever shops for you does not look at the window.
Picture sending someone to the supermarket with a list: "washing powder, the 2 kg one, if it is under R$ 40". That person does not care about the window display, the music or the poster. They read the label: what it is, what it costs, whether it is there. If the label is smudged, they go to the store next door.
The AI assistant is that shopper, at scale. It does not see the photo or the animated button: it reads the product data sheet written for machines, the structured data that states price, currency, stock, delivery time and barcode. Everything the store polished for human eyes, it skips.
The infrastructure underneath is the same (servers, network, payment rails). What changed is that the same page now has two customers, and each needs a different entrance.
Five pieces, all already in production.
Within a few weeks of 2026, companies that coordinated nothing with each other launched the infrastructure for the assistant to pay, read, search, act and be watched. It is not a roadmap: these are announced products. Below, what each piece does, without acronyms.
- Coinbase: the X402 protocol for machine-to-machine payments
- Stripe: payment tokens with a time and spend limit: the agent buys without seeing the card number
- Visa: trusted agent protocol (NRF, Jan 2026)
- Google: Universal Commerce Protocol, an open standard
Stripe had to retrain its fraud detector from scratch: decades of signals (mouse movement, time on page) are worthless when the buyer is software.
- Cloudflare: "Markdown for Agents": serves the page as clean text when the visitor is an agent
- llms.txt: a sign on the door saying where the machine-readable content is
Cloudflare serves roughly a fifth of the web. When it decides that an agent is a customer, not a pest, the rule changes for many stores at once.
- Brave, Exa, Firecrawl: search and extraction that return data, not a page of links
In an independent test cited in the account, Brave answered in 669 ms and Perplexity Pro in 13.6 s. Across a chain of ten searches, that adds up to minutes.
- OpenAI: Skills and Shell Tools: a real environment to install, run and deliver
- MCP: the standard socket an agent uses to call a system’s functions
The agent stops just advising and starts doing: making a video from a product page, filling in an order, checking stock.
- Isolated containers: the agent runs in a closed box, with a list of what it may reach
- Keys in hardware: spending limits the agent cannot change
The right mental model is to treat the agent as a potential adversary, not a trusted employee. Most stores have not thought about this yet.
Our reading, based on the companies’ announcements and a video account of the "agentic web" (transcript in our notes). The figures quoted in that account, such as X402’s 50 million transactions and the Brave and Perplexity timings, were not checked by us against the primary source.
Amazon shut the door on another company’s agent.
On 20 September 2026 Amazon blocked Muse, Meta’s shopping assistant. According to Amazon, it entered the store without warning, did not identify itself as a robot and seemed to store customers’ passwords. Meta denies it and says the agent runs on the user’s phone.
There is money in the middle: Forbes pointed to Amazon’s US$ 68 billion in ads, which depend on a person looking at the screen. And there is a contradiction: Amazon has its own agents, Rufus and "Buy for Me", which buys in other stores on the customer’s behalf.
The lesson for a smaller store is neither "block" nor "let everything in". It is to decide which door the agent uses: identified, with the functions you chose and without taking anyone’s password. Without such a door, the agent comes in pretending to be a person, and then not even you know who is buying.
What gives the agent power also gives power to whoever fools it.
Every piece in the board above cuts both ways. The rule we take from real 2026 incidents: everything the agent reads is suspect, including your own page, because hidden text can give it orders. And the gate that matters most is the exit: what the agent is allowed to send out, pay for or confirm.
Wallet
Running commands
Searching
Reading the page
The "~70%" comes from the same video account, without the original survey cited: read it as an order of magnitude, not a measurement. The distance between what the infrastructure allows and what people accept is where the risk lives, and where a confirmation gate makes the difference.
The phone in 2007, the agent in 2026.
In 2007 the web worked on phones, technically. But it was built for the desktop, and it took a decade to rebuild. Those who noticed the change of customer early won the following decade. The comparison is our reading, not a forecast with numbers.
| Phone, 2007 | Agent, 2026 | |
|---|---|---|
| The new customer | small screen, touch, GPS, camera | screenless software that reads, decides, pays and acts |
| What was missing | GPS, notifications, tap to pay, app stores | machine-readable data sheets, token payments, search for software, a place to run |
| What the store had to redo | pages that fit the screen; an app | a ready page with the data sheet; a door for agents |
First, see your store through the agent’s eyes.
The free reading shows, with evidence, what a shopping assistant can read in your store today: whether the page arrives ready, whether the data sheet exists and matches the storefront, whether the site’s doorman turns away the wrong visitors, whether the barcode is there.
Then comes the work: fix what is missing, open a door for agents with the functions you choose (see the store’s socket) and put a confirmation gate on anything that moves money.
What the agent checks
The AI that researches, compares and buys for the customer: ChatGPT, Gemini, Muse. It is the "agent".
The page’s structured data: price, currency, stock, barcode, written for software to read without guessing.
The system that turns away automated visitors. If it cannot tell a legitimate agent from any robot, it shuts the door on the new customer.
Where this may be wrong.
Some sources are second-hand
Several figures on this page come from a video account of the agentic web, not from each company’s primary source. We flag where that happens.
Agent traffic is still small
Today, the share of purchases made by agents is small. The point is not today’s volume: it is that the entrance takes time to build and the new customer is growing fast.
Standards may die
Payment, reading and discovery protocols are fighting for room. Not all will survive. That is why we recommend what holds in any scenario: a ready page, a correct data sheet, an identified door.
The specimen simplifies
Each assistant behaves differently, and some do run JavaScript. The real reading of your store is what answers, not this page’s example.
← Agent-ready e-commerce · stickybit.com.br
- Transcript and summary of a video on the "agentic web" and OpenClaw (internal notes): Coinbase/X402, Stripe, Visa, Google UCP, Cloudflare, Brave/Perplexity, ~70% control
- InfoQ, "Cloudflare and AWS … x402 micropayments" (jul 2026)
- Bloomberg, "Amazon blocks Meta’s Muse AI agent from its retail site" (21 Sep 2026)
- GeekWire, "Amazon blocks Meta’s Muse AI assistant…" (Sep 2026)
- Forbes, "Amazon’s $68 billion reason to block Meta’s Muse" (23 Sep 2026)