top of page

When the Agent Chooses the Merchant: Discovery, Ranking and Trust-Signal Manipulation in Agentic Commerce in 2026

  • Writer: TrustSphere Network
    TrustSphere Network
  • 3 days ago
  • 12 min read

The discussion of agentic commerce has concentrated almost entirely on the payment: who authorised the agent, how the mandate is proved, where liability sits when a machine buys the wrong thing. Those questions are important and the infrastructure to answer them is arriving: delegated credentials, mandate frameworks, agent identity standards. But they are questions about the last step of a process whose earlier steps have received far less attention and carry, on current evidence, more immediate commercial risk.


Before an agent pays, it chooses. It decides which merchants exist, which are trustworthy, which product satisfies the user's constraint, and which offer to accept. Those decisions are made by reading machine-readable signals (structured product feeds, review aggregates, return and delivery policies, trust badges, marketplace ratings, availability data) and by weighing them through a model whose criteria neither the merchant nor the consumer can see. The consumer who used to spend twenty minutes comparing three sites now delegates that comparison entirely, and the delegation transfers an enormous amount of commercial power to whatever signals the agent happens to read.


Any signal that determines who gets the sale will be manipulated. This is not a prediction; it is the entire history of search ranking, marketplace buy-box logic and review systems, replayed on infrastructure that is younger, less defended, and consumed by a reader that cannot be embarrassed, cannot smell a fake, and does not experience doubt.


Regulatory and Market Context


Consumer protection law already covers most of the conduct at issue, though it was written with a human reader in mind. Fake and incentivised reviews, misleading availability claims, false urgency, and misrepresentation of a trader's identity or credentials are prohibited under unfair commercial practices regimes across major jurisdictions, and several have recently strengthened the specific provisions on review authenticity and on traders' obligations to take reasonable steps to prevent fake reviews appearing on their platforms. Nothing in those rules turns on whether the deceived party is a person or a machine acting for a person, and firms should assume that a practice unlawful when it deceives a consumer remains unlawful when it deceives the consumer's agent.


Platform and marketplace regulation adds a second layer, requiring transparency about the main parameters determining ranking, prohibiting certain self-preferencing behaviours by designated large platforms, and imposing traceability obligations on marketplace sellers. As agents increasingly consume ranked output rather than presenting it to a human, the practical significance of ranking transparency shifts: the parameter disclosure that was written to inform a shopper becomes, in effect, a specification for anyone wishing to optimise against it. For a bad actor, it becomes a specification for manipulating it.


The payments layer is developing on its own track. Network frameworks for agent-initiated and delegated-credential transactions are progressing, strong customer authentication requirements continue to demand traceability to a properly authenticated consumer instruction, and merchant-side tooling for recognising a mandated agent is emerging. What does not yet exist in any settled form is the inverse: a means for an agent to verify a merchant. Agent identity is being solved because payments require it. Merchant authenticity is being left to the same trust signals that agents are already reading uncritically, and that asymmetry is where the exposure sits.


What the Data Is Showing


TrustSphere's engagement data identifies three manipulation patterns that merchants and payment providers routinely conflate, and which have very different remedies.


The first is feed and structured-data manipulation. Agents read machine-readable product data (structured markup, merchant feeds, marketplace listings) because parsing a rendered page is slower and less reliable. That data is supplied by the merchant, is rarely validated against the merchant's own systems, and is trivially divergent from reality: stock stated as available when it is not, delivery windows that no operation could meet, prices excluding charges that appear at checkout, and product attributes tuned to match anticipated agent queries rather than the item in the box. Much of this is not fraud in origin (it is stale integration and optimistic marketing), but its effect on an agent is categorically different from its effect on a human, because a human reads a delivery estimate as a claim and an agent reads it as a constraint satisfaction input.


The second is trust-signal fabrication, and it is the genuinely adversarial case. Agents lean heavily on aggregate signals (review scores, review counts, ratings distributions, trust marks, policy statements, returns terms) because these are cheap to parse and appear objective. Generative tooling has made volume production of plausible reviews effectively free, and the resulting corpus is not the crude repetition that earlier detection systems were built to catch: it is varied, specific, plausibly imperfect, and distributed across time. Merchants presenting a fabricated reputational profile are being selected by agents at rates that the underlying business quality does not support, and the consumer never sees the signals that would have made a human hesitate: a thin website, an unreachable address, a brand with no history.


The third is competitive suppression, which is the mirror image and is under-recognised. Where selection depends on ranked signals, degrading a competitor's signals is as effective as improving one's own: fabricated negative reviews, false policy-violation reports, spurious counterfeit or intellectual-property complaints that trigger automated delisting, and inventory or availability manipulation on shared marketplaces. Automated enforcement systems designed for scale respond to volume, and volume is the cheapest thing to manufacture.


Two further observations matter for control design. First, the compression of the decision window removes the natural friction that used to limit damage: an agent that selects a fraudulent merchant does so in seconds and at whatever purchase volume its mandate permits, with no browsing, no hesitation and no second visit. Second, agents cluster. Where many agents consume the same underlying signals through similar models, they converge on the same merchant, which means a successful manipulation does not win one sale; it wins a share of the market for as long as it stands undetected.


Implications for Financial Institutions


The first implication is for acquirers and payment facilitators, and it concerns the speed at which merchant risk now materialises. A fraudulent or failing merchant selected by agents can accumulate a very large volume of orders in a compressed window, well before the delivery failures that would normally trigger dispute-based detection. Portfolio monitoring built around chargeback ratios operates on a lag of weeks; the exposure here builds in days. Acquirers should treat abrupt volume acceleration in a newly onboarded merchant, particularly where order origination is heavily automated, as a liquidity and reserve question in real time rather than as a monitoring observation to be reviewed at the next cycle.


The second is that merchant underwriting needs to assess the reputational estate as an asset that can be manufactured. A merchant presenting a strong review profile with a short operating history, thin corporate footprint, recently registered domain and no independent brand presence is describing a pattern, not a track record. This is straightforward to check and is rarely part of underwriting, which historically treated a good review score as reassurance rather than as a claim requiring verification.


The third is that agent-originated order flow should be identifiable and treated as a distinct risk population. Its behavioural properties are different in ways that matter: no browsing history, minimal session duration, high price sensitivity, concentrated timing, immediate purchase on condition satisfaction, and, importantly, no human review of the merchant before payment. Merchants and payment providers that cannot separate agent-originated from human-originated flow cannot measure their own exposure to any of this, and most currently cannot.


The fourth is a genuine strategic opportunity rather than a control. Agents need a way to establish that a merchant is real, solvent and likely to deliver, and no such signal currently exists in machine-readable form. Payment providers, acquirers and networks are among the few parties holding evidence that is hard to fabricate: settlement history, dispute and refund performance, delivery-confirmation records, business tenure verified through onboarding. A merchant trust attestation grounded in payment history and delivered as a signed, machine-readable credential is a product the market will need, and it is defensible precisely because it cannot be manufactured by the merchant. Firms should be thinking about who issues it before the vacuum is filled by whoever moves first.


The fifth is that consumer outcomes require an explicit position rather than an implicit one. When an agent selects a fraudulent merchant on the basis of manipulated signals and the consumer receives nothing, the question of who bears the loss is unresolved. The consumer authorised a mandate, not a merchant. Firms should decide their position now, in dispute policy, in mandate terms and in customer communication, rather than discovering it case by case under complaint pressure, and should assume that regulators will read a mandate the consumer did not meaningfully understand in much the same way they now read a subscription the consumer did not meaningfully agree to.


Conclusion


Agentic commerce moves the point of commercial decision from a person looking at a page to a model reading a feed. Every signal in that feed is now a control surface, and every control surface with money behind it gets attacked. The manipulation techniques are not novel (fake reviews, false availability, competitor suppression), but their leverage has changed, because the reader is fast, literal, unembarrassable and identical to a million other readers making the same decision from the same inputs.


The institutional response has two parts. Defensively, treat agent-originated flow as a distinct population, underwrite reputational signals as claims rather than evidence, and monitor merchant risk on a timescale that matches how fast agent-driven volume can build. Constructively, recognise that the missing primitive in this market is verifiable merchant trust, that payment providers hold the evidence to supply it, and that whoever issues that credential will occupy a central position in how agentic commerce works. The payment problem is being solved. The selection problem is still open.


Suggested Next Steps


  • Identify and tag agent-originated order flow as a distinct population in merchant and acquiring analytics, and measure dispute, delivery-failure and refund performance separately from human-originated flow.

  • Shift portfolio monitoring for newly onboarded merchants from chargeback-ratio review cycles to near-real-time volume-acceleration triggers with automatic reserve and settlement-delay responses.

  • Underwrite the reputational estate as a verifiable claim: assess review-profile depth against operating history, domain age, corporate footprint and independent brand presence, and treat a strong profile on a thin history as an adverse indicator.

  • Develop a machine-readable merchant trust attestation grounded in settlement, dispute, refund and delivery evidence held by the payment provider, and define now, in dispute policy and mandate terms, who bears the loss when an agent selects a fraudulent merchant.


Sources: EU and UK unfair commercial practices and consumer protection frameworks, including provisions on fake and incentivised reviews and availability claims; UK Digital Markets, Competition and Consumers Act; EU Digital Services Act and Digital Markets Act provisions on ranking transparency, trader traceability and self-preferencing; PSD2 strong customer authentication as applied to delegated and agent-initiated payments; Visa and Mastercard agentic commerce and delegated-credential frameworks; UK Finance and


Global Anti-Scam Alliance e-commerce and purchase scam reporting; TrustSphere Risk Index, April 2026.


TrustSphere Risk Index Vendor Spotlight: Ravelin


Ravelin scores 6.5 out of 10 in the TrustSphere RiskTech Index 2026, in the E-Commerce Fraud Prevention category. The capability profile is focused: Fraud Detection 8, Behavioural Biometrics 7, Device Intelligence 7, Enterprise Fraud Risk Management 7, Client Lifecycle Orchestration 6, Transaction Monitoring and Screening 6, with Watchlist Screening 3 and Document Authentication 3. The composite sits above the index mean, and the assessment reads as a specialist with genuine depth in online merchant risk and a deliberate absence of institutional breadth.


The proposition is merchant-side fraud decisioning across payment fraud, account takeover, promotion abuse, policy abuse and marketplace risk, with graph-based linking of accounts, devices and payment instruments and an emphasis on the non-payment abuse categories that conventional fraud tools ignore. The graph capability and the policy-abuse focus are the two properties that matter for agentic commerce, for reasons that are not obvious from the category name.


The relevance is in the shape of the problem rather than the transaction. Agent-originated flow breaks the assumptions underneath most e-commerce fraud models: no browsing session, no behavioural signal from a human, minimal device history, purchase within seconds of arrival, and, critically, many independent agents converging on the same offer at the same moment with no shared credential, device or network characteristic to link them. Velocity and linkage rules find nothing, because there is nothing to link. A platform built around graph reasoning and policy abuse is at least looking at the right dimension, since what is shared is the pattern of interaction with the offer rather than any attribute of the buyer.


The second relevant property is the ability to distinguish populations rather than block them. The single most expensive error available to a merchant in 2026 is treating mandated consumer agents as adversarial automation, declining real revenue and reporting it as a successful mitigation. A decisioning platform that can classify and route rather than allow-or-block is the mechanism for treating agent flow as a distinct population with its own thresholds, which is the prerequisite for measuring it at all.


The limitations are significant for this specific problem. This is a buyer-side control on the merchant's own estate. It scores the order and the account; it does not evaluate whether the merchant the agent selected is real, does not see the review corpus that drove the selection, and has no visibility of the feed the agent read. For the consumer-protection half of this typology (an agent buying from a fabricated merchant), a merchant-side platform is by definition on the wrong side of the transaction.


Second, model performance depends on labelled outcomes, and agent-originated flow is new enough that most merchants have thin and poorly labelled history. Buyers should expect a genuine cold-start period and should insist on the ability to run agent traffic under separate policy while that history accumulates, rather than allowing it to be scored by models trained on human behaviour.


Third, the categories that matter most here (promotion abuse, error harvesting, policy abuse) are frequently owned by trading and merchandising teams rather than by fraud, and the loss lands in margin rather than in a fraud loss line. The tool can detect what nobody is accountable for, which is an organisational problem no vendor solves.


The questions to press are: how do you classify and score agent-originated traffic distinct from human sessions, and what signals do you use where behavioural telemetry is absent; can policy be configured to route mandated agent flow to different thresholds rather than a single allow-or-block decision; how does graph linking perform where independent agents converge on the same offer with no shared identifiers; what is your roadmap for consuming emerging agent identity and delegated-credential signals; and can detections be exported to merchandising and pricing systems rather than only into a fraud console?


The verdict is that Ravelin's 6.5 reflects a capable specialist on the merchant side of a problem that has two sides. It addresses the abuse arriving at the merchant. It does not address the merchant being fabricated, which is the half that produces consumer harm and, ultimately, the disputes that reach the issuer.


TrustSphere Risk Index Vendor Spotlight: Cloudflare


Cloudflare scores 6.3 out of 10 in the TrustSphere RiskTech Index 2026, in the Infrastructure and Bot Defence category. The capability profile is atypical for this index: Device Intelligence 8, Fraud Detection 7, Behavioural Biometrics 6, Enterprise Fraud Risk Management 6, Client Lifecycle Orchestration 5, with Transaction Monitoring 3, Watchlist Screening 2 and Document Authentication 2. Its inclusion at all reflects a judgement that edge infrastructure has become a financial crime control surface, which is the same judgement that placed API observability vendors in this index.


The proposition relevant here is not the general security estate but the emerging work on verified automated traffic: cryptographic mechanisms by which an agent can identify itself and its operator at the edge, and by which a site can express machine-readable policy about what automated clients may do. This is early, contested and unsettled (the standards work is live rather than finished), but it is the most credible attempt currently visible to replace the binary human-versus-bot question with a question about mandate and identity, which is the distinction the market actually needs.


The relevance to trust-signal manipulation is at the reconnaissance layer and at the policy layer. Manipulation of feeds, reviews and availability signals requires sustained observation of the target's estate: measuring how a repricing engine responds, probing which structured-data fields the agents read, testing which review characteristics move a ranking. That activity is edge-visible, and it is visible before the exploitation rather than after it. The policy layer matters for a different reason: a merchant that can express what automated clients may access, at what rate, under what identification, has some ability to make manipulation costly, which is more than most merchants have today.


The second and more strategic property is position. The edge sees the traffic of a very large share of the web, which means an infrastructure provider is unusually well placed to observe automation infrastructure across properties: the same operator probing many merchants, the same pool used to post reviews across many platforms. That cross-property view is not replicable by any individual merchant and is the same structural advantage that makes bot classification work at all.


The limitations are substantial and buyers should be sober about them. This is infrastructure, not a fraud control. It sees requests; it does not see whether a review is fabricated, whether a stock claim is false, or whether an agent bought from a merchant that will never ship. It can tell a merchant that an endpoint is being systematically measured. It cannot tell a consumer's agent that a merchant is trustworthy, which is the missing primitive this typology most needs.


Second, verified agent traffic only works if agents adopt it, and adoption is a coordination problem across model providers, agent platforms, merchants and infrastructure. Firms should treat current capability as directional rather than dependable, and should avoid architecting a control that assumes a standard which may settle differently.


Third, the organisational placement problem is acute. Edge telemetry sits with engineering and security; the teams that need it are fraud, trading and e-commerce; and the data flow between them usually does not exist. This is the same failure identified across every agentic-commerce typology in this series and it remains the most consistent determinant of whether any of these tools deliver value.


The questions to press are: what is your current and roadmap capability for verified agent identity, and how do you treat agents that identify honestly versus those that do not; can policy be expressed per endpoint so that structured product data and pricing endpoints are governed differently from general traffic; can reconnaissance telemetry be exported into merchandising, pricing and fraud systems rather than remaining in a security console; what cross-property intelligence can you provide on automation infrastructure associated with review and feed manipulation; and how do you avoid degrading legitimate mandated agent traffic while doing so?


The verdict is that Cloudflare's 6.3 fairly reflects infrastructure with real and increasing relevance to a problem it was not built for. Paired with Ravelin the coverage is complementary (one governs who may read the signals, the other scores what arrives at the checkout), and neither addresses the central gap. The agent needs a way to verify the merchant, and the parties best placed to supply it are the ones holding the settlement, dispute and delivery evidence. That is a payments product, and it does not exist yet.


TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai

 
 
 

Comments


Recommended by TrustSphere

© 2026 TrustSphere.ai. All Rights Reserved.

  • LinkedIn

Disclaimer for TRUSTSPHERE.AI

The content provided on the TRUSTSPHEREAI website is intended for informational purposes only. While we strive to provide accurate and up-to-date information, the data and insights presented are generated from a contributory network and consolidated largely through artificial intelligence. As such, the information may not be comprehensive, and we do not guarantee the accuracy, reliability, or completeness of any content.  Users are advised that important decisions should not be made based solely on the information provided on this website. We encourage users to seek professional advice and conduct their own research prior to making any significant decisions.  TruststSphere Partners is a consulting business. For a comprehensive review, analysis, or support on Technology Assessment, Strategy, or go-to-market strategies, please contact us to discuss a customized engagement project.   TRUSTSPHERE.AI, its affiliates, and contributors shall not be liable for any loss or damage arising from the use of or reliance on the information provided on this website. By using this site, you acknowledge and accept these terms.   If you have further questions,  require clarifications, or requests for removal or content or changes please feel free to reach out to us directly.  we can be reached at hello@trustsphere.ai

bottom of page