Agentic Commerce for Resellers
Research method and protocol ledger
Reviewed . This page distinguishes a source that describes a current platform path from evidence that establishes an observed effect. Neither is a placement, traffic, or sales promise.
How to read the collection
- Tier A: current specifications, policies, and official documentation establish stated requirements and access boundaries.
- Tier B: peer-reviewed research provides a study-specific finding, with its setting and limits retained.
- Tier D: an owner’s official announcement or implementation guidance can establish what that owner published or intended, but is not independent adoption or outcome evidence.
- Merchant evidence: a merchant should record its own implementation, timestamps, incidents, and observed outcomes without guessing an agent’s identity or causation.
Protocol milestone ledger
| Date and record | Documentation | Access | Testing | Production observation | Governance |
|---|---|---|---|---|---|
Mastercard Agent Pay announcement official program announcement · announcement dated 2025-04-29 | program description; not a vendor-neutral specification | program- and partner-dependent | not established by the announcement | not claimed | Mastercard program |
ACP initial dated specification published · 2025-09-29 | versioned specification | implementation-specific | not established by the specification | not claimed | OpenAI and Stripe founding maintainers |
Visa Trusted Agent Protocol publication official protocol announcement · live specification reviewed 2026-07-30 | merchant specification and payment-network implementation details | optional merchant adoption; approved-agent and scheme dependencies | specification supplies verification procedures | not established by the specification | Visa with stated ecosystem collaboration |
eBay automated-purchasing restriction effective agreement amendment · live agreement | current user agreement | prior express permission required | not applicable | not claimed | eBay policy |
Google AP2 v0.1 implementation guide official guide · v0.1 described | typed mandate examples | open repository referenced by Google | example implementation only | not claimed | Google-led protocol project |
UCP dated specification snapshot published · 2026-04-08 | normative specification and schemas | public | merchant conformance not established | not claimed | Google-led collaborative specification |
ACP cart, feed, orders, authentication, and MCP snapshot changelog entry · 2026-04-17 | versioned specification | implementation-specific | not established by the specification | not claimed | OpenAI and Stripe founding maintainers |
FIDO trusted-agent standards work announced working-group announcement · work announced 2026-04-28 | scope and contributed authorization material | standards-development participation and future artifacts | no completed conformance program claimed | not claimed | FIDO Alliance working groups |
x402 Foundation operational launch official foundation launch announcement · announcement dated 2026-07-14 | governance and stated program scope; not a conformance specification | protocol- and implementation-dependent | not established by the announcement | not claimed | Linux Foundation; protocol contributed by Coinbase, with premier members across payments and infrastructure |
Claim and volatility ledger
| Claim ID | Guide | Class | Volatility | Bounded claim | Source IDs |
|---|---|---|---|---|---|
acp-beta-versioned | acp-protocol-explained | technical requirement | volatile | ACP is currently beta and publishes dated specification snapshots. | acp-spec |
ucp-capability-model | acp-protocol-explained | technical requirement | volatile | UCP separates protocol-version compatibility from capability negotiation. | ucp-spec |
acp-checkout-session-operations | acp-protocol-explained | technical requirement | volatile | ACP checkout defines a merchant-hosted session that can be created, updated, retrieved, completed, and canceled, with responses carrying the computed line items, fulfillment options, totals, and buyer-facing messages. | openai-acp-checkout |
acp-checkout-session-states | acp-protocol-explained | technical requirement | volatile | A checkout session carries an explicit status: not ready for payment, ready for payment, completed, or canceled. | openai-acp-checkout |
acp-idempotent-retries | acp-protocol-explained | technical requirement | volatile | Checkout requests carry an idempotency key so a retried call is recognized as a repeat of an earlier instruction and does not create a duplicate order. | openai-acp-checkout |
acp-delegated-payment-scope | acp-protocol-explained | technical requirement | volatile | Delegated payment issues a scoped credential constrained by a single-use reason, a maximum amount and currency, a bound checkout session, an expiry, and a named merchant, so the merchant never receives raw card details. | openai-acp-payment |
acp-merchant-of-record | acp-protocol-explained | technical requirement | volatile | Delegated payment leaves the seller as merchant of record, so settlement, disputes, refund handling, and compliance obligations stay where they already were. | openai-acp-payment |
ap2-authorization-layer | agent-payment-authorization | current external fact | hot | Google’s AP2 guide describes mandates for purchase authorization and audit evidence. | ap2-guide |
payment-program-boundaries | agent-payment-authorization | current external fact | hot | Mastercard Agent Pay, Visa Trusted Agent Protocol, and FIDO’s agent-interaction work have different owners, publication states, and scopes; their names do not establish interoperability. | mastercard-agent-pay, visa-trusted-agent, fido-agentic-work |
ap2-mandate-types-and-states | agent-payment-authorization | technical requirement | volatile | AP2 defines a checkout mandate and a payment mandate, and each exists in two states: an open state recording the constraints a user set before anything was finalized, and a closed state authorizing one specific finalized transaction. | ap2-spec |
ap2-credential-format | agent-payment-authorization | technical requirement | volatile | Mandates are carried as verifiable digital credentials, described as tamper-evident cryptographically signed objects, and the specification separates human-present flows from human-not-present ones. | ap2-spec |
ap2-mandate-naming-has-moved | agent-payment-authorization | current external fact | hot | The mandate names in wide circulation are not the names the current specification uses, so a summary of this protocol can be confidently wrong about its central vocabulary while remaining internally consistent. | ap2-spec, ap2-guide |
tap-signature-and-key-directory | agent-payment-authorization | technical requirement | volatile | Visa’s Trusted Agent Protocol has a merchant validate HTTP message signatures under RFC 9421, carried in a signature input field and a signature field, with the verifying public key retrieved from a network-operated well-known key endpoint using the key identifier named in the request. | visa-trusted-agent |
tap-replay-window | agent-payment-authorization | technical requirement | volatile | Validation requires the creation timestamp to sit in the past and the expiry in the future within an eight-minute window, and requires the merchant to track nonces so a captured request cannot be replayed. | visa-trusted-agent |
tap-linked-objects | agent-payment-authorization | technical requirement | volatile | Three objects travel in the message body — a consumer recognition object, a payment container, and a browsing acknowledgement used when a merchant answers with a payment-required response — all signed with the same key and tied together by a shared nonce. | visa-trusted-agent |
tap-voluntary-and-bounded | agent-payment-authorization | current external fact | hot | The specification addresses only two merchant interactions, browsing for availability and pricing and processing a payment, states plainly that merchants are not required to use it, and does not cover agent onboarding beforehand or any bilateral agreement between a merchant and an agent operator. | visa-trusted-agent |
x402-governance-boundary | agent-payment-authorization | current external fact | hot | The x402 Foundation announced its operational launch under Linux Foundation governance; that announcement does not establish merchant adoption or production interoperability. | x402-foundation-launch |
openai-approved-direct-feed | get-products-into-chatgpt-shopping | current external fact | hot | OpenAI direct product-feed onboarding is currently limited to approved partners. | openai-start |
openai-delivery-cadence | get-products-into-chatgpt-shopping | current external fact | hot | OpenAI recommends a full daily file snapshot plus intraday API updates for applicable integrations. | openai-start |
shopify-default-exposure | get-products-into-chatgpt-shopping | current external fact | hot | Eligible Shopify stores can have agentic storefronts active by default and products syndicated through Shopify Catalog. | shopify-agentic, shopify-products |
shopify-surface-checkout-differences | get-products-into-chatgpt-shopping | current external fact | hot | Shopify documents ChatGPT shoppers as completing the purchase on the merchant’s own store checkout, whereas its Google AI Mode and Gemini, Microsoft Copilot, and Meta channels can settle the purchase inside the channel when direct checkout is active, each under conditions set out on its own page. | shopify-agentic |
etsy-agent-purchasing-scope | get-products-into-chatgpt-shopping | current external fact | hot | Etsy documents purchasing for some listings through named AI shopping surfaces for eligible US shoppers. | etsy-agent-purchasing |
openai-product-shape | ai-agent-product-feed | technical requirement | volatile | OpenAI’s current API requires stable product and variant IDs and exposes price, availability, condition, media, and seller links. | openai-products-api |
structured-data-representation | ai-agent-product-feed | technical requirement | volatile | Product and Offer vocabularies represent product and commercial facts but do not synchronize inventory. | schema-product, schema-offer |
catalog-research-boundary | ai-agent-product-feed | observed outcome | stable | Peer-reviewed catalog-quality research reports reference-backed repair in its studied large-retailer setting, not automatic transfer to resale inventory. | catalog-quality-research |
ebay-automation-boundary | agentic-commerce-for-resellers | current external fact | hot | eBay’s current agreement prohibits buy-for-me agents, LLM-driven bots, and end-to-end automated orders without prior express permission. | ebay-policy |
language-preference-research | agentic-commerce-for-resellers | observed outcome | stable | Peer-reviewed research found competitive near-cold-start recommendation behavior for language-based preferences in its tested setting. | cold-start-research |
onboarding-and-exposure-are-separate-decisions | agentic-commerce-for-resellers | current external fact | hot | Feed onboarding for one named assistant is documented as currently available to approved partners and entered through an application form, so being findable on a surface and being purchasable on it are settled by two different decisions taken by two different parties. | openai-start |
delivery-cadence-is-a-published-number | agentic-commerce-for-resellers | technical requirement | volatile | One documented integration recommends supplying the whole feed once a day by file and sending changes through an interface across the rest of the day, which puts a published figure on how far behind a transmitted record is expected to run. | openai-start |
a-platform-default-can-supply-a-layer | agentic-commerce-for-resellers | current external fact | hot | A storefront platform documents its agentic surfaces as active by default for eligible stores, so a seller can already occupy a discovery position without having taken any step toward one. | shopify-agentic |
the-transaction-layer-moves-between-surfaces | agentic-commerce-for-resellers | current external fact | hot | Under the same platform documentation one assistant hands the shopper to the merchant’s own checkout while other named channels can settle the purchase inside the channel, so which party runs the transaction depends on the surface the shopper happened to use. | shopify-agentic |
factual-recommendation-boundary | aeo-geo-for-product-sellers | observed outcome | stable | Recommendation research treats factual consistency as a separate quality objective in its benchmark. | factual-recommendation-research |
geo-study-boundary | aeo-geo-for-product-sellers | observed outcome | stable | GEO research measures visibility in a particular experimental setting and does not establish a universal merchant ranking outcome. | geo-research |
google-product-markup-boundary | aeo-geo-for-product-sellers | current external fact | hot | Google documents Product structured data for Google Search eligibility; it is not a guarantee for other systems. | google-product-structured-data |
shopify-early-access-boundary | agentic-commerce-readiness-checklist | current external fact | hot | Some Shopify agentic storefront channels remain early access and are not available to all stores. | shopify-agentic |
policy-currentness | agentic-commerce-readiness-checklist | current external fact | hot | Merchant readiness depends on the current policy and permitted path for each surface. | openai-policy, openai-terms, ebay-policy |
eu-trader-traceability-boundary | law-before-compliance-claims | current external fact | hot | EU Digital Services Act Article 30 sets trader-traceability duties for covered online platforms enabling consumer distance contracts; applicability must be assessed for the actual service and facts. | eu-dsa-trader-traceability |
eu-dpp-framework-boundary | law-before-compliance-claims | current external fact | hot | The EU ESPR creates a framework for product-specific Digital Product Passport requirements; it does not make a passport mandatory for every resale item today. | eu-espr-dpp |
ucp-spec-states-interfaces | ucp-explained-for-merchants | technical requirement | volatile | The UCP specification is versioned and defines discovery, capability negotiation, shopping, fulfillment, and payment-handler models, and it keeps capability negotiation separate from protocol-version compatibility; it does not prove that a particular merchant or surface implements them. | ucp-spec |
ucp-embedded-checkout-gated | ucp-explained-for-merchants | current external fact | hot | Google’s UCP integration documentation states its integration model, its native and embedded checkout paths, and its merchant-of-record position, and describes embedded checkout as limited to specific approved merchants. | google-ucp-developer |
ucp-market-eligibility-fence | ucp-explained-for-merchants | current external fact | hot | UCP-powered checkout is documented as applying to products with eligibility in the United States, Canada, and Australia and to participating merchants and partners, with availability described as phased and select, alongside stated product-attribute requirements. | google-ucp-merchant-center |
ucp-business-profile-document | ucp-explained-for-merchants | technical requirement | volatile | A business participating in UCP publishes a profile document at the path /.well-known/ucp whose ucp object carries a date-based version, a services list binding supported verticals to transports, a named capabilities map, a payment_handlers list, and a keys array of JWK public keys. | ucp-core-concepts, ucp-spec |
ucp-profile-transport-rules | ucp-explained-for-merchants | technical requirement | volatile | Profiles are required to be served over HTTPS with a public Cache-Control directive and a minimum time-to-live of sixty seconds. | ucp-spec |
ucp-server-selects-intersection | ucp-explained-for-merchants | technical requirement | volatile | Negotiation follows a server-selects model: the business intersects its declared capabilities against the set a platform advertises in the UCP-Agent header, matches by name, takes the highest mutually supported version, prunes orphaned extensions, and declares the resulting active set in every response. | ucp-core-concepts, ucp-spec |
ucp-breaking-change-notice | ucp-explained-for-merchants | technical requirement | volatile | Version identifiers are date-based, additive changes do not increment them, and breaking changes are marked with an exclamation prefix and carry two weeks of notice. | ucp-core-concepts |
ucp-handlers-versus-instruments | ucp-explained-for-merchants | technical requirement | volatile | A payment handler is a named specification such as com.google.pay or dev.shopify.shop_pay that a business advertises, while a payment instrument is the token or encrypted payload a platform obtains by executing that handler against a credential provider and then submits onward for processing. | ucp-core-concepts |
ucp-payment-credential-rules | ucp-explained-for-merchants | technical requirement | volatile | Credential flow is one-directional: a business is required not to echo credentials back in its responses, must confirm that a submitted handler identifier matches one it advertised, and must filter its advertised handler list against the contents of the cart in front of it. | ucp-spec |
ai-mode-route-is-gated | google-ai-mode-shopping-for-merchants | current external fact | hot | The documented route into Google’s AI shopping checkout runs through stated market eligibility, onboarding steps, and participation by merchants and partners rather than through a unilateral opt-in. | google-ucp-merchant-center, google-ucp-developer |
ai-mode-platform-path-boundaries | google-ai-mode-shopping-for-merchants | current external fact | hot | Shopify documents its Google AI Mode and Gemini channel as early access and not yet available to all stores, restricts it to stores based in and selling to the United States, United Kingdom, Australia, or Canada, and activates direct checkout by default for eligible stores while letting a merchant deactivate it. | shopify-google-channel |
copilot-eligibility-conditions | copilot-shopping-for-merchants | current external fact | hot | Microsoft documents Copilot Checkout surfaces, Merchant Center store settings, and UCP feed attributes, states that only English-language merchants selling to US buyers in USD are eligible at this time, and marks some store settings as a pilot to select customers. | microsoft-agentic-commerce |
copilot-platform-route | copilot-shopping-for-merchants | current external fact | hot | Shopify’s Microsoft Copilot channel page requires a store to sell to United States customers, activates direct checkout by default for eligible stores, and states that meeting a requirement does not guarantee a checkout block will load. | shopify-direct-checkout |
copilot-unsupported-features | copilot-shopping-for-merchants | current external fact | hot | Shopify documents subscriptions, product bundles, customizable products, and B2B-only products as unsupported in Copilot’s direct checkout, lists local delivery and in-store pickup as unavailable delivery methods, and states that Google Analytics and custom pixels do not fire there. | shopify-direct-checkout |
copilot-is-one-of-several-channels | copilot-shopping-for-merchants | current external fact | hot | Shopify lists Copilot alongside Google AI Mode and Gemini and Meta as channels where an activated direct checkout lets a customer pay without leaving the AI channel, and documents a separate page of conditions for each. | shopify-agentic |
marketplace-positions-differ | marketplace-mediated-agentic-exposure | current external fact | hot | Marketplace positions on automated purchasing differ. Etsy documents purchasing for some listings through named AI shopping surfaces for eligible US shoppers. eBay’s agreement takes the opposite posture, treating shop-on-my-behalf agents, language-model-driven bots, and fully automated order placement as prohibited absent permission granted in advance and expressly. | etsy-agent-purchasing, ebay-policy |
marketplace-permission-not-inferred | marketplace-mediated-agentic-exposure | current external fact | hot | Permission for automated purchasing cannot be inferred from observation, because eBay conditions such automation on its prior express permission, and Etsy’s documented path does not establish eligibility for every listing, seller, shopper, country, or surface. | ebay-policy, etsy-agent-purchasing |
used-goods-identity-strain | used-goods-and-surface-eligibility | technical requirement | volatile | Product specifications require stable product and variant IDs and expose price, availability, condition, media, and seller links, a model that assumes repeatable catalog goods even though every field remains answerable for one-of-one stock. | openai-products-api |
used-goods-attribute-requirements | used-goods-and-surface-eligibility | current external fact | hot | Documented product-attribute requirements for checkout paths are stated as requirements, and some of those attributes are genuinely inapplicable to unique second-hand items. | google-ucp-merchant-center |
used-goods-eligibility-and-permission | used-goods-and-surface-eligibility | current external fact | hot | Whether used stock participates is partly an eligibility question, since documented marketplace purchase paths cover only some listings and shoppers, and partly a permission question governed by marketplace terms on automated purchasing rather than by the kind of goods sold. | etsy-agent-purchasing, ebay-policy |
llms-txt-specified-shape | llms-txt-for-merchants | technical requirement | volatile | The llms.txt proposal specifies a Markdown file at a site’s root path whose only required element is an H1 naming the project or site; every other section it describes is optional. | llms-txt-proposal |
llms-txt-no-adoption-evidence | llms-txt-for-merchants | current external fact | hot | The llms.txt proposal is one named author’s proposal open for community input and carries no statement of adoption or support by any search engine or AI provider; no source here establishes an effect from publishing it. | llms-txt-proposal |
http-signatures-scope | verified-agents-and-web-bot-auth | technical requirement | volatile | RFC 9421 specifies cryptographic signatures over selected components of an HTTP message; it establishes how a request is signed and verified, not who is entitled to access anything. | rfc-9421 |
web-bot-auth-draft-status | verified-agents-and-web-bot-auth | current external fact | hot | Web Bot Auth is an active Internet-Draft and an individual submission not adopted by an IETF working group; it replaced an earlier architecture draft and carries an expiry date, so it is work in progress rather than a settled standard. | web-bot-auth-draft |
verification-is-not-entitlement | verified-agents-and-web-bot-auth | current external fact | hot | Cloudflare’s verified-bot criteria describe one provider’s allowlist, and verification confers no obligation on a site owner to admit a verified client. | cloudflare-verified-bots, cloudflare-ai-crawl-control |
crawler-names-are-published-claims | verified-agents-and-web-bot-auth | current external fact | hot | OpenAI publishes its crawler names, stated purposes, and IP ranges, which documents its own clients only and does not prevent another party sending the same user-agent string. | openai-bots |
robots-protocol-scope | crawler-access-audit | technical requirement | volatile | RFC 9309 specifies robots.txt syntax, caching, parsing limits, and unreachable-file handling for conformant crawlers, and states that the protocol is not a substitute for valid content security measures. | rfc-9309 |
user-triggered-fetch-gap | crawler-access-audit | current external fact | hot | OpenAI states that robots.txt rules may not apply to user-initiated ChatGPT-User fetches, and Google states that its user-triggered fetchers generally ignore robots.txt rules. | openai-bots, google-user-triggered-fetchers |
access-rules-live-in-several-layers | crawler-access-audit | current external fact | hot | Per-crawler allow and block rules and crawler-activity visibility are exposed as infrastructure controls separate from robots.txt, and a verified-bot list is an input to those rules rather than a rule itself. | cloudflare-ai-crawl-control, cloudflare-verified-bots |
posture-can-move-by-platform-default | agentic-commerce-posture | current external fact | hot | A storefront platform can place eligible stores on agentic surfaces by its own default and describe some of those channels as early access, so a merchant’s exposure can change through a platform decision rather than a merchant one. | shopify-agentic |
posture-is-bounded-by-the-marketplace-agreement | agentic-commerce-posture | current external fact | hot | On a marketplace surface the governing answer about automated purchasing is set by the marketplace agreement, which conditions such automation on permission the marketplace grants in advance and expressly. | ebay-policy |
default-on-can-still-be-switched-off | agentic-commerce-posture | current external fact | hot | One documented channel is described as early access rather than generally available, is limited to stores based in and selling to four named countries, has its in-channel checkout switched on for eligible stores, and states a route by which a merchant can switch it back off again. | shopify-google-channel |
eligibility-met-is-not-behaviour-guaranteed | agentic-commerce-posture | current external fact | hot | Documentation for one in-channel checkout states that satisfying its listed requirements still does not guarantee the checkout component will load, which leaves the outcome in the observable column even for a merchant who has done everything asked of them. | shopify-direct-checkout |
identity-fields-assume-repeatable-goods | product-identity-for-unique-items | technical requirement | volatile | Current product specifications require stable product and variant identifiers, and the variant model presumes a class of goods held in multiples rather than a single surviving object. | openai-products-api |
product-and-offer-are-separate-things | product-identity-for-unique-items | technical requirement | volatile | Page vocabularies model the described thing and the commercial terms under which it is sold as separate entities, leaving the identity of the individual physical object for the seller to supply. | schema-product, schema-offer |
condition-is-a-structured-field | condition-and-provenance-evidence | technical requirement | volatile | Condition travels as a structured field on identified products and variants in current product interfaces and as a property in page vocabularies, so a condition fact stated only in a description paragraph is absent from the value that reaches a destination. | openai-products-api, schema-product |
reference-backed-repair-needs-a-reference | condition-and-provenance-evidence | observed outcome | stable | Reference-backed catalog repair reported in peer-reviewed work operates by consulting an authority that already describes the product, which is the ingredient a one-of-one object lacks. | catalog-quality-research |
availability-belongs-to-the-offer | availability-and-removal-latency | technical requirement | volatile | Availability is modeled as a property of the offer rather than of the object, and is carried as a transmitted field in current product interfaces; neither supplies the time at which the value was observed. | schema-offer, openai-products-api |
merchant-of-record-is-documented-per-path | who-pays-and-who-absorbs-the-loss | current external fact | hot | A protocol’s own documentation states its integration model, its checkout paths, and its merchant-of-record position, and describes one of those paths as limited to specific approved merchants, so the commercial role is a property of the documented path. | google-ucp-developer |
commercial-roles-sit-in-live-terms | who-pays-and-who-absorbs-the-loss | current external fact | hot | Participation, product, and merchant-conduct obligations are defined across continuously updated platform terms and policies, so any answer about commercial roles is current rather than permanent and carries the date it was read. | openai-terms, openai-policy |
inherited-eligibility-is-conditional | trust-signals-off-marketplace | current external fact | hot | Documented marketplace purchasing through AI shopping surfaces covers certain listings and shoppers meeting stated conditions rather than everyone on the platform, so participation is held on terms the platform sets. | etsy-agent-purchasing |
inherited-permission-is-revocable | trust-signals-off-marketplace | current external fact | hot | Where a marketplace conditions automated purchasing on permission it grants in advance and expressly, that permission exists only while it is granted, which makes it a borrowed position rather than an owned one. | ebay-policy |
dated-snapshots-record-publication-only | agentic-commerce-timeline | technical requirement | volatile | A dated specification snapshot records that an interface was published in a stated version on a stated day; it carries no statement that any party implemented it or that a merchant can reach it. | acp-spec |
governance-arrangements-are-not-adoption | agentic-commerce-timeline | current external fact | hot | A foundation launch announcement establishes the governance arrangement and stated scope of a project and does not establish merchant adoption or production interoperability. | x402-foundation-launch |
access-narrows-on-dates-too | agentic-commerce-timeline | current external fact | hot | A dated agreement amendment restricting automated purchasing belongs on the same record as capability launches, because access to a venue can narrow on a date as readily as it can widen. | ebay-policy |
a-foundation-launch-has-a-date-and-a-roster | agentic-commerce-timeline | current external fact | hot | The operational launch of a payments foundation under neutral governance carries a July 2026 date and names around forty founding organizations across three membership tiers, settling who has agreed to steward a specification and settling nothing about what any of them has put into production. | x402-foundation-launch |
a-snapshot-can-carry-its-date-in-its-address | agentic-commerce-timeline | technical requirement | volatile | One specification publishes its snapshot date inside the web address of the document, so which version a reader has in front of them is legible before the page has even rendered. | ucp-spec |
the-accessible-column-can-resolve-to-a-queue | agentic-commerce-timeline | current external fact | hot | Where documented onboarding is open to approved partners and entered through an application form, the accessibility question for that entry resolves to a queue rather than to a yes. | openai-start |
default-participation-is-the-rare-accessible-entry | agentic-commerce-timeline | current external fact | hot | An entry where a platform switches eligible stores on by its own decision is one of the few that answers the accessibility question affirmatively with no merchant action at all, which is also what makes it easy to read past. | shopify-agentic |
gated-onboarding-removes-the-task-entirely | is-agentic-commerce-worth-it | current external fact | hot | Where the documented way in is limited to approved partners, an unapproved seller’s honest entry against that line is that no step exists to take, which is a different state from a step they have decided to postpone. | openai-start |
part-of-the-bet-may-already-be-placed | is-agentic-commerce-worth-it | current external fact | hot | Where a platform has already placed eligible stores on its agentic surfaces by default, part of the speculative column has been completed on the seller’s behalf, which lowers the remaining cost of the bet without changing what the bet is on. | shopify-agentic |
no-merchant-outcome-is-established | is-agentic-commerce-worth-it | observed outcome | stable | Language-model recommendation research reports behavior within its own experimental setting and was not designed to predict any individual merchant’s sales, so no expected return can be read off it. | cold-start-research |
large-catalogue-results-do-not-transfer | is-agentic-commerce-worth-it | observed outcome | stable | Catalog-quality research reporting repair in a large-retailer environment states its own boundary and does not transfer to one-of-one resale stock. | catalog-quality-research |
prohibited-venue-limits-the-upside | is-agentic-commerce-worth-it | current external fact | hot | Where a venue currently requires prior express permission for automated ordering, a seller inside it has no unilateral step available, which bounds what any effort there can return today. | ebay-policy |
versioning-discipline-is-observable | protocol-change-risk | technical requirement | volatile | Dated snapshots, a stated beta status, and capability negotiation kept separate from version compatibility are observable properties of a specification that tell an implementer how change will be communicated. | acp-spec |
change-policy-can-be-published-as-a-rule | protocol-change-risk | technical requirement | volatile | A maintainer can publish its change policy as a rule rather than a promise: identifiers drawn from dates, additive changes that deliberately leave the identifier alone, and breaking changes carrying a marker plus a fixed notice period of two weeks. | ucp-core-concepts |
negotiation-bounds-the-blast-radius | protocol-change-risk | technical requirement | volatile | Holding capability negotiation apart from version compatibility bounds how far a change travels, because a feature can appear or be withdrawn without the protocol version moving at all. | ucp-spec |
vocabulary-drifts-under-a-stable-name | protocol-change-risk | current external fact | hot | A protocol’s central vocabulary can be renamed between its announcement and its current specification while the protocol keeps its name, which makes the age of a secondary description a better guide to its accuracy than the confidence or detail of its writing. | ap2-spec |
implementation-can-be-stated-optional | protocol-change-risk | current external fact | hot | A payment network can publish a merchant specification that states in its own text that merchants are not required to use it, which makes participation a commercial decision that a technical reading of the document cannot settle. | visa-trusted-agent |
stewardship-is-a-first-party-fact | protocol-change-risk | current external fact | hot | Who stewards a protocol, and under what governing body, is exactly the kind of fact a first-party launch announcement can settle, while adoption is not. | x402-foundation-launch |
markup-splits-thing-from-terms | product-structured-data-for-ai | technical requirement | volatile | The vocabularies model a product as a described thing and an offer as the commercial terms of sale, which places price and availability on the offer rather than on the object, while item condition is defined on both. | schema-product, schema-offer |
markup-is-eligibility-not-outcome | product-structured-data-for-ai | current external fact | hot | Documented product structured data describes eligibility requirements for one search system’s features; meeting them is not a statement about retrieval, ranking, or any other system. | google-product-structured-data |
injection-taxonomy-is-published | product-data-prompt-injection | technical requirement | volatile | Published security guidance distinguishes direct prompt injection, which arrives in a user’s own input, from indirect prompt injection, which arrives inside content the system retrieves from an external source. | owasp-llm01 |
no-fool-proof-prevention-is-claimed | product-data-prompt-injection | technical requirement | volatile | The same guidance states that it is unclear whether fool-proof prevention methods for prompt injection exist, and recommends containment controls rather than a fix. | owasp-llm01 |
indirect-injection-is-demonstrated | product-data-prompt-injection | observed outcome | stable | Peer-reviewed work demonstrated indirect prompt injection against the language-model-integrated applications the authors tested and derived a taxonomy of the resulting attack classes; none of the tested applications was a product catalog. | indirect-injection-taxonomy-research |
benchmarked-models-were-susceptible | product-data-prompt-injection | observed outcome | stable | A peer-reviewed benchmark found the models it evaluated broadly susceptible to indirect prompt injection, attributing this partly to their not separating informational context from actionable instruction; the result is bounded by that benchmark and those model versions. | injection-benchmark-research |
untrusted-content-principle-is-symmetric | product-data-prompt-injection | technical requirement | volatile | Guidance addressed to the parties building agents holds that external data should be treated as untrusted with a clear boundary between instructions and data; a merchant importing description text is applying the same principle to their own system. | owasp-agent-cheatsheet |
external-data-is-untrusted-by-default | ingest-hygiene-for-cross-listers | technical requirement | volatile | Security guidance for parties building agents holds that all external data should be treated as untrusted and sanitized before entering context, with a clear boundary kept between instructions and data. | owasp-agent-cheatsheet |
structural-controls-over-vigilance | ingest-hygiene-for-cross-listers | technical requirement | volatile | The recommended controls are structural — least privilege, scoped permissions, explicit authorization for sensitive operations — rather than per-item attention, which is the property that lets them survive volume. | owasp-agent-cheatsheet |
named-path-may-be-gated | evaluating-an-agentic-commerce-vendor | current external fact | hot | Some documented onboarding is currently limited to approved partners, which makes a supplier’s partner status, rather than their capability, the operative question about a named path. | openai-start |
named-path-may-be-prohibited | evaluating-an-agentic-commerce-vendor | current external fact | hot | A venue may currently prohibit the automated ordering a proposal assumes, absent prior express permission that neither the merchant nor the supplier holds. | ebay-policy |
arrival-path-decides-the-agreement | agentic-incident-playbooks | current external fact | hot | Which agreement governs a disputed automated order follows from the path the order arrived on, including venue rules that condition automated purchasing on prior express permission. | ebay-policy |
applicable-terms-carry-an-order-date | agentic-incident-playbooks | current external fact | hot | Commercial roles and participant conduct obligations sit in continuously updated terms and policies, so the version applicable to an incident is the one current on the date of the order. | openai-terms, openai-policy |
stale-offer-is-an-offer-property | agentic-incident-playbooks | technical requirement | volatile | Availability is modeled as a property of the offer, so an offer left visibly purchasable after a sale is the thing a second buyer acts on while the cause is still being diagnosed. | schema-offer |
live-documents-carry-a-read-date | keeping-agentic-data-current | current external fact | hot | Continuously updated merchant terms and policies publish no version, so a decision resting on them can only be held by recording the date the text was read. | openai-terms |
self-declared-instability-is-a-schedule | keeping-agentic-data-current | technical requirement | volatile | A beta specification publishing dated snapshots, and an in-progress standards draft carrying a revision and a defined lifespan, each announce how and when they will change. | acp-spec, web-bot-auth-draft |
no-merchant-side-retrieval-method-is-established | retrieval-versus-comprehension | observed outcome | stable | Published generative-engine visibility research reports measures inside its own tested setting and does not establish a merchant-side method that produces ranking, organic traffic, or sales. | geo-research |
catalogue-scale-findings-are-scoped-to-their-setting | retrieval-versus-comprehension | observed outcome | stable | Catalog-improvement research conducted at large-retailer scale with brand knowledge bases available is explicitly scoped to the authors’ own setting and affiliation, so it does not transfer to a shelf of single objects. | catalog-quality-research |
markup-eligibility-is-search-feature-scoped | retrieval-versus-comprehension | technical requirement | volatile | Product structured data is documented as representation that can make a page eligible for particular Google Search features, and that documentation does not govern behavior in other answer or shopping systems. | google-product-structured-data |
consistency-is-scored-against-a-definition | measuring-agent-visibility | observed outcome | stable | Recommendation research treats factual consistency as an objective evaluated inside a defined benchmark rather than as a property assertable about a live commercial system. | factual-recommendation-research |
research-settings-are-not-merchant-feeds | measuring-agent-visibility | observed outcome | stable | Evaluations of language-model recommenders were run in research settings that are not merchant feeds and do not expose any platform’s live ranking behavior. | cold-start-research |
Specifications, documentation, and policy
- Agentic Commerce: Get started · OpenAI ↗
Tier A · current documentation · unversioned live documentation · OpenAI direct product-feed onboarding and delivery models · published continuously updated. Reviewed 2026-07-30.
Limit: Describes OpenAI’s current direct-feed path. It does not establish eligibility, surfacing, placement, traffic, or sales for a merchant.
- Agentic Commerce API: Products · OpenAI ↗
Tier A · current specification · unversioned live API reference · OpenAI product and variant payload fields and upsert behavior · published continuously updated. Reviewed 2026-07-30.
Limit: Defines OpenAI’s API surface; it is not a vendor-neutral item model and does not prove a payload will be surfaced.
- Merchant Feed Terms of Service · OpenAI ↗
Tier A · current policy · live terms · OpenAI merchant-feed participation · published continuously updated. Reviewed 2026-07-30.
Limit: Terms can change and apply only to the covered OpenAI service and merchant.
- Commerce policies · OpenAI ↗
Tier A · current policy · live policy · Products and merchant conduct on OpenAI commerce surfaces · published continuously updated. Reviewed 2026-07-30.
Limit: Applies to OpenAI’s policy surface and does not replace law or another platform’s rules.
- Agentic Commerce Protocol repository and specification · Agentic Commerce Protocol ↗
Tier A · beta · 2026-04-17 stable snapshot; unreleased development tracked separately · ACP checkout, cart, feed, order, authentication, and extension models · published 2025-09-29. Reviewed 2026-07-30.
Limit: A beta specification maintained by OpenAI and Stripe does not prove platform adoption, merchant access, conformance, or interoperability.
- Agentic Checkout specification · OpenAI ↗
Tier A · beta · published alongside the ACP checkout OpenAPI document · Merchant-hosted checkout session lifecycle, request and response payloads, session status values, headers, and error semantics · published 2025-09-29. Reviewed 2026-07-30.
Limit: Documents the interface a merchant would implement; it does not establish that any surface will send requests to a given merchant, or that a platform exposes the interface to its sellers.
- Delegated Payment specification · OpenAI ↗
Tier A · beta · published alongside the ACP delegate-payment OpenAPI document · Scoped payment credential delegation, allowance constraints, provider support, and the merchant-of-record boundary · published 2025-09-29. Reviewed 2026-07-30.
Limit: Describes a delegation model between an agent surface and a payment provider; provider support is a separate commercial question and is not established by the specification.
- Universal Commerce Protocol official specification · Google ↗
Tier A · published specification · 2026-04-08 · UCP discovery, capability negotiation, shopping, fulfillment, and payment-handler models · published 2026-04-08. Reviewed 2026-07-30.
Limit: The specification states interfaces and normative language; it does not prove that a particular merchant or surface implements them.
- Universal Commerce Protocol core concepts documentation · Google ↗
Tier A · continuously updated documentation · unversioned documentation published alongside the dated specification · The business profile document and its fields, the capability negotiation algorithm, payment handlers and payment instruments, and signing-key discovery · published 2026-04-08. Reviewed 2026-07-30.
Limit: Continuously updated documentation carrying no version identifier of its own, so a claim drawn from it is only accurate as at the date it was read; it describes mechanisms rather than establishing that any business publishes a profile or that any platform reads one.
- Agent Payments Protocol specification and documentation · Google ↗
Tier A · published specification under active revision · live documentation reviewed 2026-08-01 · Mandate types and their states, the credential format carrying them, and the human-present and human-not-present transaction flows · published 2025-09-16. Reviewed 2026-08-01.
Limit: The named mandate types have changed since the protocol was first announced, so secondary coverage of it is frequently out of date; the specification describes an authorization model and establishes nothing about processor acceptance, merchant adoption, or how a contested charge is allocated.
- Visa Trusted Agent Protocol merchant specifications · Visa ↗
Tier A · published merchant specification · live specification reviewed 2026-07-30 · Recognition and signed-message model for approved agents interacting with merchants · published 2025-10-14. Reviewed 2026-07-30.
Limit: The specification describes an optional mechanism and Visa implementation details; it does not prove merchant adoption or grant consumer authority.
- Shopify agentic storefronts · Shopify ↗
Tier A · current help documentation · live documentation · Shopify agentic-storefront eligibility, default activation, channel behavior, and checkout posture · published continuously updated. Reviewed 2026-07-30.
Limit: Documents Shopify stores only. Some channels are early access and not available to every store.
- Shopify Catalog and product discovery for agentic storefronts · Shopify ↗
Tier A · current help documentation · live documentation · Eligible-product syndication, product-field mapping, hiding, and B2B exclusions · published continuously updated. Reviewed 2026-07-30.
Limit: Shopify controls this catalog path. Automatic eligibility does not guarantee retrieval or display by an AI channel.
- Selling on Microsoft Copilot · Shopify ↗
Tier A · current help documentation · live documentation reviewed 2026-07-31 · Shopify’s Microsoft Copilot channel: store eligibility, direct-checkout activation, and unsupported checkout features · published continuously updated. Reviewed 2026-07-31.
Limit: Documents the Copilot channel only, for stores selling to United States customers. Shopify restructured this section into one page per channel, so the page states that meeting a requirement does not guarantee a checkout block loads, and makes no claim about discovery or sales.
- Selling on Google AI Mode and Gemini · Shopify ↗
Tier A · current help documentation · live documentation reviewed 2026-07-31 · Shopify’s Google AI Mode and Gemini channel: market eligibility, early-access status, and default direct-checkout activation · published continuously updated. Reviewed 2026-07-31.
Limit: Documents the Shopify-controlled path only. Eligibility is stated for stores based in and selling to the United States, United Kingdom, Australia, or Canada, and the page’s non-guarantee language concerns checkout blocks loading rather than discovery or sales.
- eBay User Agreement · eBay ↗
Tier A · current policy · live agreement · Automated access and purchasing on eBay · published effective 2026-02-20. Reviewed 2026-07-30.
Limit: Applies to eBay and allows automated access only with eBay’s prior express permission.
- Purchasing Etsy items through AI shopping surfaces · Etsy ↗
Tier A · current help documentation · live documentation reviewed 2026-07-31 · Etsy listing purchase paths through named AI shopping surfaces for eligible US shoppers · published continuously updated. Reviewed 2026-07-31.
Limit: Documents Etsy-controlled eligibility and purchasing only. It does not establish eligibility for every listing, seller, shopper, country, or surface.
- Regulation (EU) 2022/2065, Article 30 — traceability of traders · EUR-Lex ↗
Tier A · in-force regulation · Regulation (EU) 2022/2065, Article 30 · Trader-information duties for covered online platforms enabling EU consumer distance contracts · published 2022-10-19. Reviewed 2026-07-31.
Limit: The duty is addressed to covered platform providers and depends on definitions, jurisdiction, and facts. This course does not determine whether a particular service or seller is in scope.
- Regulation (EU) 2024/1781 — Ecodesign for Sustainable Products and Digital Product Passport · EUR-Lex ↗
Tier A · in-force framework regulation · Regulation (EU) 2024/1781 · Framework for product-specific ecodesign requirements and Digital Product Passports · published 2024-06-28. Reviewed 2026-07-31.
Limit: Product-level obligations depend on applicable delegated acts. The regulation does not make a passport mandatory for every resale item today, and this record states no textile implementation date.
- Schema.org Product · Schema.org ↗
Tier A · current vocabulary · live vocabulary · Product representation in structured data · published continuously updated. Reviewed 2026-07-30.
Limit: Vocabulary use represents facts; it does not guarantee crawling, retrieval, ranking, or transactions.
- Schema.org Offer · Schema.org ↗
Tier A · current vocabulary · live vocabulary · Offer and availability representation in structured data · published continuously updated. Reviewed 2026-07-30.
Limit: Offer markup does not synchronize inventory or establish a supported transaction path.
- Product structured data · Google ↗
Tier A · current documentation · live documentation · Google Search product structured-data eligibility and representation · published continuously updated. Reviewed 2026-07-30.
Limit: Google documentation governs Google Search features and does not establish behavior in other answer or shopping systems.
- Universal Commerce Protocol · Google ↗
Tier A · current documentation · unversioned live documentation · Google’s stated UCP integration model, native and embedded checkout paths, and merchant-of-record position · published continuously updated. Reviewed 2026-07-31.
Limit: States Google’s own integration model. It does not establish that a given merchant is eligible, approved, surfaced, or transacting, and embedded checkout is described as limited to specific approved merchants.
- About UCP and UCP-powered checkout · Google ↗
Tier A · current documentation · unversioned live documentation · Stated market eligibility, onboarding steps, and product-attribute requirements for UCP-powered checkout · published continuously updated. Reviewed 2026-07-31.
Limit: Applies only to products with eligibility in the United States, Canada, and Australia and to participating merchants and partners; availability is described as phased and select. Establishes documented requirements, never a placement or sales outcome.
- Agentic commerce with Microsoft Advertising · Microsoft ↗
Tier A · current documentation · unversioned live documentation · Copilot Checkout surfaces, Microsoft Merchant Center store settings, and UCP feed attributes · published continuously updated. Reviewed 2026-07-31.
Limit: States that only English-language merchants selling to US buyers in USD are eligible at this time, and marks some store settings as a pilot to select customers. Establishes documented requirements, not merchant outcomes.
- Overview of OpenAI crawlers · OpenAI ↗
Tier A · current documentation · unversioned live documentation · Named OpenAI crawlers, their stated purposes, robots.txt behavior, and published IP ranges · published continuously updated. Reviewed 2026-07-31.
Limit: Documents OpenAI’s stated crawler behavior only. It does not establish what any other operator’s client does, and it states that robots.txt rules may not apply to user-initiated ChatGPT-User fetches.
- Google user-triggered fetchers · Google ↗
Tier A · current documentation · unversioned live documentation · Google fetchers invoked on a user’s request and their stated robots.txt behavior · published 2026-07-16. Reviewed 2026-07-31.
Limit: Covers Google’s user-triggered fetchers only. The stated behavior is that these fetchers generally ignore robots.txt rules; it is not a statement about Google’s indexing crawlers or about any other operator.
- Verified bots · Cloudflare ↗
Tier A · current documentation · unversioned live documentation · Cloudflare’s verification criteria for bots and agents, and its Web Bot Auth and IP-validation paths · published continuously updated. Reviewed 2026-07-31.
Limit: Describes one infrastructure provider’s allowlist and its criteria. Verification by Cloudflare is not verification anywhere else, and it confers no obligation on a site owner to admit a verified client.
- AI Crawl Control · Cloudflare ↗
Tier A · current documentation · unversioned live documentation · Per-crawler allow and block rules, pay-per-crawl monetization, and crawler-activity visibility on Cloudflare zones · published continuously updated. Reviewed 2026-07-31.
Limit: One provider’s control surface; pay-per-crawl is described as private beta. It establishes what the product can do, not what any given zone is currently configured to do.
Peer-reviewed research
- GEO: Generative Engine Optimization · Association for Computing Machinery ↗
Tier B · peer reviewed · KDD 2024 proceedings · Visibility measures in the paper’s tested generative-engine setting · published 2024. Reviewed 2026-07-30.
Limit: The study does not establish a universal merchant ranking method, organic traffic effect, or sales outcome.
- Large Language Models are Competitive Near Cold-start Recommenders for Language- and Item-based Preferences · Google ↗
Tier B · peer reviewed · RecSys 2023 proceedings · Language-based preference recommendations in the paper’s near-cold-start experiment · published 2023. Reviewed 2026-07-30.
Limit: The evaluated recommender setting is not a merchant feed and does not expose ChatGPT ranking behavior.
- Factual and Personalized Recommendation Language Modeling with Reinforcement Learning · Google ↗
Tier B · peer reviewed · COLM 2024 proceedings · Factual consistency and personalization in the paper’s conversational-recommendation benchmark · published 2024. Reviewed 2026-07-30.
Limit: The MovieLens-based study provides design evidence, not proof of current shopping-platform behavior.
- Using brand knowledge bases and LLM agents to enhance e-commerce retailers’ catalog quality · Amazon Science ↗
Tier B · peer reviewed; publisher-affiliated research · WSDM 2026 proceedings, pages 1343–1344 · Catalog repair and entity matching using brand knowledge bases in the authors’ large-retailer setting · published 2026-02-21. Reviewed 2026-07-30.
Limit: A two-page proceedings contribution rather than a full paper, so method detail is limited. Amazon-authored, large-catalog research does not establish transfer to one-of-one resale stock; affiliation and setting must remain visible.
- Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection · Association for Computing Machinery ↗
Tier B · peer reviewed · AISec ’23 proceedings, pages 79–90 · Demonstrated indirect prompt-injection attack vectors and their taxonomy against the LLM-integrated applications the authors tested · published 2023-11-26. Reviewed 2026-07-31.
Limit: The demonstrations bound what was possible in the authors’ tested systems at the time of writing. They do not establish current behavior of any shopping surface, and none of the tested applications was a product catalog.
- Benchmarking and Defending against Indirect Prompt Injection Attacks on Large Language Models · Association for Computing Machinery ↗
Tier B · peer reviewed · ACM SIGKDD ’25 proceedings, pages 1809–1820 · The BIPIA benchmark results and the two defense mechanisms evaluated within it · published 2025. Reviewed 2026-07-31.
Limit: Benchmark evidence bounded by its own task set and the model versions evaluated. It supports the design position that external content and instructions are not reliably separated; it does not measure any commerce deployment or predict a merchant outcome.
Official announcements and implementation guidance
- Developer’s Guide to AI Agent Protocols: AP2 · Google ↗
Tier D · official technical guide · AP2 v0.1 described · Google’s description of AP2 mandates, authorization, and protocol boundaries · published 2026-03-18. Reviewed 2026-07-30.
Limit: An official Google guide describes intended AP2 behavior; it is not independent evidence of adoption or transaction outcomes.
- Mastercard unveils Agent Pay · Mastercard ↗
Tier D · official announcement · announcement dated 2025-04-29 · Mastercard’s stated Agent Pay program and initial collaborators · published 2025-04-29. Reviewed 2026-07-30.
Limit: An issuer announcement establishes the program’s stated intent, not an open standard, general merchant availability, interoperability, or observed outcomes.
- FIDO Alliance to develop standards for trusted AI agent interactions · FIDO Alliance ↗
Tier D · working-group announcement · announcement dated 2026-04-28 · FIDO’s announced working-group scope and contributed agent-authorization material · published 2026-04-28. Reviewed 2026-07-30.
Limit: Standards work in progress is not a completed FIDO standard, implementation certification, or proof of production interoperability.
- Operational launch of the x402 Foundation · Linux Foundation ↗
Tier D · official launch announcement · announcement dated 2026-07-14 · Linux Foundation governance and stated scope for the x402 Foundation · published 2026-07-14. Reviewed 2026-07-31.
Limit: Establishes the foundation’s operational launch and stated governance scope, not merchant adoption, production interoperability, settlement finality, or liability allocation.
- RFC 9309: Robots Exclusion Protocol · Internet Engineering Task Force ↗
Tier D · published Standards Track RFC · RFC 9309 · robots.txt syntax, crawler caching expectations, parsing limits, and unreachable-file handling · published 2022-09. Reviewed 2026-07-31.
Limit: Specifies conformant crawler behavior. It binds no operator, and it states explicitly that the protocol is not a substitute for valid content security measures.
- RFC 9421: HTTP Message Signatures · Internet Engineering Task Force ↗
Tier D · published Standards Track RFC · RFC 9421 · Cryptographic signatures over selected components of an HTTP message · published 2024-02. Reviewed 2026-07-31.
Limit: A signature mechanism only. It establishes how a request can be signed and verified, not who is entitled to access anything.
- Web Bot Auth: HTTP Message Signatures protocol (Internet-Draft) · Internet Engineering Task Force ↗
Tier D · active Internet-Draft; individual submission, not adopted by an IETF working group · draft-meunier-webbotauth-httpsig-protocol-00, expires 2026-12-28 · Signing and verifying automated HTTP client identity, key discovery, and deployment models · published 2026-06-26. Reviewed 2026-07-31.
Limit: An Internet-Draft is a work in progress and must be cited only as such. It replaces draft-meunier-web-bot-auth-architecture, is an individual submission rather than working-group output, and expires 2026-12-28; nothing in it is a settled standard or an access entitlement.
- The /llms.txt file · Answer.AI (llms.txt proposal) ↗
Tier D · proposal open for community input; not a standards-body specification · unversioned proposal · The file location, Markdown structure, and required and optional sections the proposal itself defines · published 2024-09-03. Reviewed 2026-07-31.
Limit: Establishes only what the proposal specifies. It is one named author’s proposal rather than a standards-body output, and it carries no statement of adoption or support by any search engine or AI provider; no source here establishes that publishing the file produces any effect.
- LLM01:2025 Prompt Injection · OWASP Foundation ↗
Tier D · current community-reviewed guidance; not peer-reviewed research · OWASP Top 10 for LLM Applications, 2025 list · The direct and indirect prompt-injection taxonomy and the mitigation classes the entry itself enumerates · published 2025. Reviewed 2026-07-31.
Limit: Consensus guidance rather than measurement. It records that the taxonomy and mitigations exist and that the entry itself states no method is known to be fool-proof; it does not establish that any named commerce surface is vulnerable, nor how often such an attack succeeds.
- AI Agent Security Cheat Sheet · OWASP Foundation ↗
Tier D · current community-maintained guidance; not peer-reviewed research · unversioned live cheat sheet · The control classes the cheat sheet recommends: treating retrieved content as untrusted, least-privilege tool scoping, and explicit authorization for sensitive operations · published continuously updated. Reviewed 2026-07-31.
Limit: Recommendations addressed to the party building an agent. It does not establish what any deployed shopping agent actually does with merchant-supplied text, and a merchant cannot verify another party’s adoption of it.
What may have changed
Partner access, merchant terms, platform policy, schemas, feed requirements, and protocol versions can change. Re-open volatile Tier A sources before changing operational guidance; do not infer eligibility or interoperability from this research page.
Report or review a correction
If a source, version, status, or limitation is wrong, use the editorial-policy contact. Do not include customer or private inventory data. The public correction history records published changes without silently rewriting the record.
Start with 25 items. Stay for 25,000.
Free for 25 items · No card · Cancel from your account page.