Hi everyone, thanks for coming back to Customer Futures.
Each week I unpack the disruptive shifts around Empowerment Tech. AI Agents, digital wallets, Personal AI in and the future of the digital customer relationship.
If you haven’t yet signed up, why not subscribe:
Hi folks,
This week it’s a post from Trusted Agents, our sister advisory firm. We’re working with companies all over the world on the arrival of Personal Agents, digital wallets and the new digital customer relationship.
Because everyone is getting very excited about automated customer engagement, and bots shopping themselves.
Giving AI agents virtual credit cards and so on. Meta, Google, Amazon, Apple and a host of well-funded and spicy startups are now out and swinging in the consumer market.
Personal Agents are certainly now here. (I first wrote about them in this newsletter in late 2022).
So what will this all mean for retailers, for insurance companies and travel providers? For storefronts and liability? For checkout and fraud?
Well, you need to know that an AI agent isn’t just a new automated shopper. You need to think of it more like a new commercial animal. With new behaviours, and new expectations.
AI agents will have whole new levels of patience (they will be happy to queue for weeks), and yet also new levels of impatience (if you don’t recognise and serve them immediately in the channel they want, they’ll just head over to a competitor that will accept them right now).
Gam Dias, my cofounder at Trusted Agents, posted this piece earlier this week. And it was so important that I wanted to share it again here.
So today we’re going to dive into the reality of agentic commerce - and what’s actually about to happen:
The shoe drop was gone in a second
The agents arrived this month
What - and who - is behind the door?
Refundable inventory just became a major problem
What happens when the agent is wrong?
Are you ready - the next ninety days
A new wind tunnel to find out
With Muse, Instinct, GrokBot, MyClaw, Siri and all the rest now wrestling for our attention, it’s never been more important to understand the future of the digital customer relationship.
Let’s Go.
The shoe drop was gone in a second
Picture a new product drop in November 2026. In fact, imagine exactly one thousand pairs of an exclusive new trainer, live on the website at 9am on a Thursday morning.
You know how that used to go.
People set alarms, sat with the product page open and refreshed every few seconds. A share of the stock ended up going to resale bots, which is why the retailer bought ‘bot management’ tools in the first place. The rest went to customers who were quick and lucky.
But this year, a meaningful number of the people who want those trainers have a personal agent.
That agent doesn’t need an alarm, doesn’t get bored at 8:58, and doesn’t mistype the card. It doesn’t hesitate when it’s asked about shoe size. In fact, it’s been watching the page since Monday.
This time, the new trainer drop allocation is committed in under a second, and the service team spends the week explaining to loyal customers that they never saw the page load.
Then it gets awkward.
Because the retailer’s defences can’t tell those agents apart from the resale bots. In fact, from the outside, they look identical. A browser on a cloud virtual machine, a data centre IP address, machine speed and a single-use payment credential.
So what are the retailer’s options? Well, they can let everything through and lose the allocation in a second, or they can block everything and turn away the customers they spent the year acquiring.
Nobody has offered them a third option.
In fact, their digital store configuration has already chosen one on their behalf.
The agents arrived this month
First, Meta launched Muse on 8th September in the United States, on iOS, Android and at muse.ai.
It sends emails, fills in forms, books travel, negotiates and pays, all running on its own isolated virtual machine with its own browser. And holding credentials it can use but never read. Helpfully, there’s a second agent called Sentinel approving anything it sends out to the internet.
In her review for Lenny’s Newsletter, Claire Vo asked Muse to buy a cinema ticket. The agent opened its browser, found the showing at a Cinemark in Daly City, selected a seat and went through guest checkout with a one time card from Stripe Link.
It would have completed the purchase if she had let it.
Now consider what Cinemark would have recorded. A guest. No account. No loyalty number. No email address it had seen before. And a card that stops working after a single use.
It would have looked like a real customer, real money, and nothing to recognise her by next month.
Then Google followed on 17th September with CC, an agent for families.
Most interestingly, CC has its own verified Google account and a distinct identity. Up to six household members share it, each choosing which emails, calendars and Google Drive folders it can see, and it fast fills in school permission slips.
xAI’s Grok Bot already does the equivalent for work.
So that’s three products, three audiences, and a few things in common. The agent is given its own identity, its own machine, its own credentials and its own set of permissions.
Until this month, personal agents borrowed the human’s browser session, and as far as your systems were concerned, it was the human.
That was impersonation, not true delegation.
What - and who - is behind the door?
Over the last 4 years, GenAI has broken every previous record about consumer adoption of new products. ChatGPT picked up 100M users in just 2 months.
But your new AI agent will go further. Because it plans, reasons and then uses tools to carry out the task. Until now, that has been mostly experimental.
Muse and CC now are consumer-grade products with onboarding, avatars you can name, goals and a morning brief, and the examples on their product pages are permission slips, buggies and family calendars. Consumers will always rush towards tools that save them an hour a day, and then they’ll mention it to other parents at the school gate.
Friend of the Trusted Agents family Dazza Greenwood has set out three things a business now needs from its own web presence:
Accessibility - so the agent can reach your content
Legibility - so it can understand it
Actionability - so it can complete a transaction
And he’s pretty blunt about treating every customer bot as a threat:
“If your site can’t accommodate it, or worse, actively blocks it, you’ve lost a sale to a competitor whose infrastructure was ready.”
But that’s only half the story.
Getting an AI agent through the door is the easy bit. Once inside your website, it’s going to read your content for what its owner asked for. Not what you chose to display.
If you run a hotel, an attractive room description is no longer enough. Because the agent is working through a specific instruction: ocean view at sunset, cot in the room, away from the lifts.
It will check your public claims against reviews on sites that you don’t control, and it needs availability, delivery date, shipping cost and returns policy in a form it can read without guessing.
And if that takes too long to find, it moves on to whoever published theirs properly.
Refundable inventory just became a major problem
Yes, the ‘new drop’ problem is one of speed. AI agents will be faster than humans. But the thing that will cost retailers more is a problem of patience.
You’ll tell your agent to make sure you have a good hotel for a busy week, to keep looking for something better, and not to leave you without a room.
So it books the best room it can find, then the second best because cancellation is free, then the third. It keeps searching, and releases the ones it does not need at the last permitted moment.
Now the market just got flooded with legitimate, verified purchases. The hotel now looks fully booked.
But those are phantom bookings.
It’s just that the room booking policy was design for patient, human customers. Not real-time, high-frequency, verified and limitlessly patient AI agents abusing the cancellation policy.
We would probably do the same with hotel bookings if it cost nothing and took no time. But it does cost us something, which is why we don’t. We human customers have limited patience, we don’t like to cancel on people, and we forget to check back before the cancellation deadline.
Your personal AI agent won’t care about any of that.
‘Free cancellation’ was always a bargain made by the hotel because only a small number of people booking would use it. But revenue management systems weren’t built to price these types of behavior.
Ah, but that’s the funny thing, because none of this is really a new behaviour:
OWASP classifies it as OAT-021, Denial of Inventory, and names hotel rooms, restaurant tables, holiday bookings and flight seats
Delta already prohibits bookings created “to hold or block reservations due to expected demand, customer indecision, or for any reason”
Jin Air found genuine customers unable to book flights because inventory hoarding bots were creating fake reservations.
Every one of those fraud controls assumes the offender is 1) a bad actor bot, 2) a broker or 3) a fraudster who can be blocked on that basis.
And that’s the twist coming with personal agents.
Because retailers have built their entire businesses around detecting and blocking all three types - checking for a ‘bad customer’ vs. ‘good customer’.
An authenticated personal agent is none of those. In fact, it’s a genuine customer, with a valid payment credential, exercising a cancellation right you granted in writing.
Which forces a new question that the retailer’s ‘bot management’ systems were never built to answer.
Does this agent have legitimate authority - a mandate - to hold this much of my inventory, and where would I read it?
What happens when the agent is wrong?
We must remember that AI agents get things wrong all the time.
Why? Because by definition they are probabilistic. They are designed to produce the likely outcome. As opposed to being deterministic, where we can predict the exact outcome every time. It’s an important distinction because if AI agents were entirely predictable, then they wouldn’t be ‘artificial intelligence’ - they’d just be pre-programmed software.
Now look at what happens when it makes a mistake.
When the shopping attempt fails on the colour and size, or the cinema booking is for the wrong film, the complaint doesn’t go to Meta. It goes to the merchant whose name is on the confirmation.
The Fashion Law describes the problem very simply. The payment record, the access token and the merchant’s ledger can all be correct… but nothing always links the customers payment to the task - the intent - that the customer actually gave the agent.
Senator Mark Warner’s AI AGENT Act defines a ‘custodial user agent’ as software allowed to act “in a transparent, documented, limited and revocable manner”. And it asks NIST to develop standards for verifying delegation. Note the term: Delegation. The opposite of impersonation, where the AI agent shows up as you and we can’t tell which is which.
We are a while away from agreeing an answer to all this. And a human confirmation step doesn’t necessarily move the problem elsewhere either.
The NHI Management Group’s position is that “accountability stays with the organisation that designed the workflow and the user who confirms the final action”.
Mesnwhile, consumer protection is showing up faster than merchant protection. Link, the payment method Muse uses, covers purchases through ‘Cover Genius’, with a refund guarantee up to $1,000, and no fee returns up to $250 per claim.
Ok so now the customer is insured, and the merchant is the other party in the transaction. Dazza points to the OAuth 2.1 work on delegated authority, where the agent’s access token carries two identifiers: First, the person who granted permission; and second, the agent performing the action.
Knowing BOTH parts critical. The owner and the agent. It’s what merchants will increasingly check at the storefront, and what will be produced in a dispute. Regular readers will know that I call some of this ‘OBO’ - on behalf of. A new type of verifiable credential that’s going to become as commonplace as KYC and AML.
Are you ready - the next ninety days
So far, so normal for the agentic commerce train that won’t stop. But what should you be doing about it?
Here’s what we are recommending to clients right now:
Get last month’s automated traffic numbers from your network. Your ‘edge defences’. Then split them out by what was challenged, what was blocked and what got through and served. Find out who you turned away and why.
Write down an agent policy, even if its a rough one. Are you going to admit, verify, limit or refuse, and on what evidence?
Make your ‘product truth machine’ readable - including the awkward attributes that customers ask about rather than the ones marketing likes.
Reconsider - and re-price - the assumption that your human customers will be patient and clumsy… vs dealing with agents that will sit in your online queue for a week. Think cancellation windows, cart and seat holds, one per customer limits and returns. Model your next sales drop with agents in the queue.
Decide where the record of a customer’s delegation will live, and who produces it in a dispute.
And here are two questions to ask your leadership team this week:
Which of our commercial promises would become unaffordable if every customer exercised them with machine diligence?
When an agent makes a mistake that reaches our customer, who inside this company owns the apology?
A new wind tunnel to find out
Gam and I have spent over 10 years preparing for this moment. Writing, consulting, persuading, explaining and advising on what’s about to happen. And how companies need to prepare.
Helping businesses work out what a trusted agent means for their marketing and operations, how to verify one, and what to change before they arrive at scale. From several hundred conversations with enterprise teams all over the world, very few have turned a plan into action.
While the agents were experimental, that was defensible.
But AI agents are being marketed to folks right now.
Invite codes are flying around like confetti. Gam and I are expecting at least 100M users in 2027. They’ll arrive with a permission slip in one hand and a payment card in the other.
Which is why we are launching a new Trusted Agents testing capability shortly. A ‘wind tunnel’ for AI agents. To see how ready you really are.
If you’d like to be involved in the pilot and launch, just reply to this email or drop us a note on LinkedIn.
Are you ready for Personal Agents? Really?
And that’s a wrap. Stay tuned for more Customer Futures soon, both here and over at LinkedIn.
And if you’re not yet signed up, why not subscribe:

