GUEST COMMENT Agentic commerce is arriving faster than the consent rules

24 Sep 2026
Image © Adobe Stock

Manuel Heilmann, CEO of compliance platform iubenda, looks at who gives consent for a shopper’s data once an AI agent, not a human, is doing the shopping.

An agent buys a washing machine, books a flight, or signs up for a subscription on your behalf, in a few taps, without you ever leaving the chat window. That’s roughly what agentic commerce looks like: it searches, compares and buys with barely any human input. And somewhere in that hand-off, a question most retailers haven’t thought to ask starts to matter: who gave consent for the data being processed, and is it the kind a regulator would accept?

The scale is hard to ignore. Bain expects agents to drive 15 to 25 per cent of US online sales by 2030, and McKinsey puts the global opportunity as high as $3 to $5 trillion. The ICO reckons personal shopping agents could be part of everyday life within five years, and the pathways already exist: Google’s UCP covers the commerce journey from discovery through to post-purchase, and the Agentic Commerce Protocol that OpenAI and Stripe open-sourced is now backed by PayPal and a growing roster of retailers. OpenAI scaled back its first in-chat checkout in March, but the protocol layer beneath it is holding up.

Consent doesn’t disappear, it changes hands

When an AI agent browses a website or completes a purchase, consent for data processing still has to be given where the law requires it, under the UK GDPR and PECR. That obligation doesn’t disappear. It shifts from the human to the agent. And nobody has yet worked out whether an agent can validly give it on someone’s behalf.

The law hasn’t gone anywhere. It just wasn’t built for any of this. PECR, the UK regulations behind every cookie banner, is built around consent to store or access information on “the user’s terminal equipment”, meaning your own phone or laptop. That made sense when a person did the browsing. Once it runs through a cloud-based agent rather than on your device, the fit comes apart. Some legal commentators think the terminal-equipment rule might not apply here at all. Either way, a rule written for a person at a device wasn’t drafted for a machine acting on their behalf.

The UK GDPR poses its own puzzle. Consent has to be freely given, specific, informed and unambiguous. Can a machine clear that bar, acting on preferences set years ago through a banner nobody really read?

Accountability is further along than most retailers realise. The CMA’s March guidance is blunt: the same consumer law applies whether a person or a machine serves the customer, and you answer for your agent as you would for an employee, even when someone else built it. It also wants agents labelled, so customers aren’t misled into thinking a human is serving them, and their workflows fixed promptly when they go wrong. Responsibility cannot be handed upstream to whoever supplied the model.

The questions no one has settled

There’s also a commercial edge to this. The platforms’ safeguards tend to stop at the transaction, securing the payment and sharing only what the order needs. They often restrict how the buyer can be marketed to afterwards. What none of them say much about is what then happens to the data itself, and that afterlife is exactly what many retailers want: the behavioural and contact detail behind retargeting and repeat custom.

The regulators have noticed, and not quietly. The ICO warned in January that consent will be hard to obtain in agentic settings unless people have a real choice, and the CMA’s research paper flagged the dark patterns and loss of agency when shoppers delegate. The sharpest signal came in late March, when the CMA, FCA, ICO and Ofcom jointly published The Future of Agentic AI. It sets no new rules, but is clear that most agents already fall inside existing UK law. The example it works through is a retail assistant: one deployment that can raise questions under data protection, financial, online safety and consumer law at once.

What’s unsettled is narrower than it looks. No one has ruled on whether an agent can give valid consent, or how specific that delegation must be. But the direction of travel on responsibility is no longer ambiguous, and waiting for detailed guidance is not the same as waiting for the obligation.

Getting consent-ready before it scales

So what can a business do while the rules settle? The most useful move is unglamorous: build consent you can prove, not just collect. With no banner to click, what survives a regulator’s question is the record behind it: what was agreed, on what basis, and when. That record only holds up if consent is part of how a business governs its data, not a tag fired at the end of a journey. Payment standards are moving the same way: Google’s AP2 logs a person’s approval with a cryptographically signed “mandate”. It’s worth deciding now, in writing, what an agent’s consent will and won’t cover, so you’re not improvising when a regulator comes asking.

None of this waits for perfect guidance. Under the UK GDPR, proving consent has always been the business’s job, and a regulator asking about an agent-led purchase will want the same proof as ever. Where it doesn’t exist, the consent doesn’t either, and the behavioural data behind your retargeting becomes a liability rather than an asset. The retailers who get this right will be the ones agents actually find and buy from, and the ones on firm ground when the rules catch up.

Image © Iubenda

Stay informed

Our editor carefully curates two newsletters a week filled with up-to-date news, analysis and research. Click here to subscribe to the FREE newsletter sent straight to your inbox. Why not follow us on LinkedIn to receive the latest updates on our research and analysis?

Read More

Subscribe to our email community

Created with Sketch.
Receive the latest news
Created with Sketch.
Be the first to hear about our research
Created with Sketch.
Get VIP access to our events