Manuel Heilmann, CEO of compliance platform iubenda, looks at who gives consent for a shopper’s data once an AI agent, not a human, is doing the shopping.
An agent buys a washing machine, books a flight, or signs up for a subscription on your behalf, in a few taps, without you ever leaving the chat window. That’s roughly what agentic commerce looks like: it searches, compares and buys with barely any human input. And somewhere in that hand-off, a question most retailers haven’t thought to ask starts to matter: who gave consent for the data being processed, and is it the kind a regulator would accept?
The scale is hard to ignore.Bain expects agents to drive 15 to 25 per cent of US online sales by 2030, and McKinsey puts the global opportunity as high as $3 to $5 trillion. The ICO reckons personal shopping agents could be part of everyday life within five years, and the pathways already exist: Google’s UCP covers the commerce journey from discovery through to post-purchase, and the Agentic Commerce Protocol that OpenAI and Stripe open-sourced is now backed by PayPal and a growing roster of retailers. OpenAI scaled back its first in-chat checkout in March, but the protocol layer beneath it is holding up.
Consent doesn’t disappear, it changes hands
When an AI agent browses a website or completes a purchase, consent for data processing still has to be given where the law requires it, under the UK GDPR and PECR. That obligation doesn’t disappear. It shifts from the human to the agent. And nobody has yet worked out whether an agent can validly give it on someone’s behalf.
The law hasn’t gone anywhere. It just wasn’t built for any of this. PECR, the UK regulations behind every cookie banner, is built around consent to store or access information on “the user’s terminal equipment”, meaning your own phone or laptop. That made sense when a person did the browsing. Once it runs through a cloud-based agent rather than on your device, the fit comes apart. Some legal commentators think the terminal-equipment rule might not apply here at all. Either way, a rule written for a person at a device wasn’t drafted for a machine acting on their behalf.
The UK GDPR poses its own puzzle. Consent has to be freely given, specific, informed and unambiguous. Can a machine clear that bar, acting on preferences set years ago through a banner nobody really read?
Accountability is further along than most retailers realise. The CMA’sMarch guidance is blunt: the same consumer law applies whether a person or a machine serves the customer, and you answer for your agent as you would for an employee, even when someone else built it. It also wants agents labelled, so customers aren’t misled into thinking a human is serving them, and their workflows fixed promptly when they go wrong. Responsibility cannot be handed upstream to whoever supplied the model.
The questions no one has settled
There’s also a commercial edge to this. The platforms’ safeguards tend to stop at the transaction, securing the payment and sharing only what the order needs. They often restrict how the buyer can be marketed to afterwards. What none of them say much about is what then happens to the data itself, and that afterlife is exactly what many retailers want: the behavioural and contact detail behind retargeting and repeat custom.
The regulators have noticed, and not quietly. The ICOwarned in January that consent will be hard to obtain in agentic settings unless people have a real choice, and the CMA’sresearch paper flagged the dark patterns and loss of agency when shoppers delegate. The sharpest signal came in late March, when the CMA, FCA, ICO and Ofcom jointly publishedThe Future of Agentic AI. It sets no new rules, but is clear that most agents already fall inside existing UK law. The example it works through is a retail assistant: one deployment that can raise questions under data protection, financial, online safety and consumer law at once.
What’s unsettled is narrower than it looks. No one has ruled on whether an agent can give valid consent, or how specific that delegation must be. But the direction of travel on responsibility is no longer ambiguous, and waiting for detailed guidance is not the same as waiting for the obligation.
Getting consent-ready before it scales
So what can a business do while the rules settle? The most useful move is unglamorous: build consent you can prove, not just collect. With no banner to click, what survives a regulator’s question is the record behind it: what was agreed, on what basis, and when. That record only holds up if consent is part of how a business governs its data, not a tag fired at the end of a journey. Payment standards are moving the same way: Google’sAP2 logs a person’s approval with a cryptographically signed “mandate”. It’s worth deciding now, in writing, what an agent’s consent will and won’t cover, so you’re not improvising when a regulator comes asking.
None of this waits for perfect guidance. Under the UK GDPR, proving consent has always been the business’s job, and a regulator asking about an agent-led purchase will want the same proof as ever. Where it doesn’t exist, the consent doesn’t either, and the behavioural data behind your retargeting becomes a liability rather than an asset. The retailers who get this right will be the ones agents actually find and buy from, and the ones on firm ground when the rules catch up.
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
You are in: Home » AI » GUEST COMMENT Agentic commerce is arriving faster than the consent rules
GUEST COMMENT Agentic commerce is arriving faster than the consent rules
Amanda Vlietstra
Manuel Heilmann, CEO of compliance platform iubenda, looks at who gives consent for a shopper’s data once an AI agent, not a human, is doing the shopping.
An agent buys a washing machine, books a flight, or signs up for a subscription on your behalf, in a few taps, without you ever leaving the chat window. That’s roughly what agentic commerce looks like: it searches, compares and buys with barely any human input. And somewhere in that hand-off, a question most retailers haven’t thought to ask starts to matter: who gave consent for the data being processed, and is it the kind a regulator would accept?
The scale is hard to ignore. Bain expects agents to drive 15 to 25 per cent of US online sales by 2030, and McKinsey puts the global opportunity as high as $3 to $5 trillion. The ICO reckons personal shopping agents could be part of everyday life within five years, and the pathways already exist: Google’s UCP covers the commerce journey from discovery through to post-purchase, and the Agentic Commerce Protocol that OpenAI and Stripe open-sourced is now backed by PayPal and a growing roster of retailers. OpenAI scaled back its first in-chat checkout in March, but the protocol layer beneath it is holding up.
Consent doesn’t disappear, it changes hands
When an AI agent browses a website or completes a purchase, consent for data processing still has to be given where the law requires it, under the UK GDPR and PECR. That obligation doesn’t disappear. It shifts from the human to the agent. And nobody has yet worked out whether an agent can validly give it on someone’s behalf.
The law hasn’t gone anywhere. It just wasn’t built for any of this. PECR, the UK regulations behind every cookie banner, is built around consent to store or access information on “the user’s terminal equipment”, meaning your own phone or laptop. That made sense when a person did the browsing. Once it runs through a cloud-based agent rather than on your device, the fit comes apart. Some legal commentators think the terminal-equipment rule might not apply here at all. Either way, a rule written for a person at a device wasn’t drafted for a machine acting on their behalf.
The UK GDPR poses its own puzzle. Consent has to be freely given, specific, informed and unambiguous. Can a machine clear that bar, acting on preferences set years ago through a banner nobody really read?
Accountability is further along than most retailers realise. The CMA’s March guidance is blunt: the same consumer law applies whether a person or a machine serves the customer, and you answer for your agent as you would for an employee, even when someone else built it. It also wants agents labelled, so customers aren’t misled into thinking a human is serving them, and their workflows fixed promptly when they go wrong. Responsibility cannot be handed upstream to whoever supplied the model.
The questions no one has settled
There’s also a commercial edge to this. The platforms’ safeguards tend to stop at the transaction, securing the payment and sharing only what the order needs. They often restrict how the buyer can be marketed to afterwards. What none of them say much about is what then happens to the data itself, and that afterlife is exactly what many retailers want: the behavioural and contact detail behind retargeting and repeat custom.
The regulators have noticed, and not quietly. The ICO warned in January that consent will be hard to obtain in agentic settings unless people have a real choice, and the CMA’s research paper flagged the dark patterns and loss of agency when shoppers delegate. The sharpest signal came in late March, when the CMA, FCA, ICO and Ofcom jointly published The Future of Agentic AI. It sets no new rules, but is clear that most agents already fall inside existing UK law. The example it works through is a retail assistant: one deployment that can raise questions under data protection, financial, online safety and consumer law at once.
What’s unsettled is narrower than it looks. No one has ruled on whether an agent can give valid consent, or how specific that delegation must be. But the direction of travel on responsibility is no longer ambiguous, and waiting for detailed guidance is not the same as waiting for the obligation.
Getting consent-ready before it scales
So what can a business do while the rules settle? The most useful move is unglamorous: build consent you can prove, not just collect. With no banner to click, what survives a regulator’s question is the record behind it: what was agreed, on what basis, and when. That record only holds up if consent is part of how a business governs its data, not a tag fired at the end of a journey. Payment standards are moving the same way: Google’s AP2 logs a person’s approval with a cryptographically signed “mandate”. It’s worth deciding now, in writing, what an agent’s consent will and won’t cover, so you’re not improvising when a regulator comes asking.
None of this waits for perfect guidance. Under the UK GDPR, proving consent has always been the business’s job, and a regulator asking about an agent-led purchase will want the same proof as ever. Where it doesn’t exist, the consent doesn’t either, and the behavioural data behind your retargeting becomes a liability rather than an asset. The retailers who get this right will be the ones agents actually find and buy from, and the ones on firm ground when the rules catch up.
Stay informed
Our editor carefully curates two newsletters a week filled with up-to-date news, analysis and research. Click here to subscribe to the FREE newsletter sent straight to your inbox. Why not follow us on LinkedIn to receive the latest updates on our research and analysis?
Read More
You may also like
Subscribe to our email community