Is Your Checkout Agent-Ready? A GCC Merchant Audit Checklist (UCP, ACP, Visa TAP, Mastercard Agent Pay)
An agentic commerce readiness checklist for GCC merchants: discovery and product feeds, verified-agent bot handling, agentic tokens, PCI evidence and disputes.
An agent-ready checkout is not an in-chat buy button. For a GCC merchant in 2026 it means four things: AI agents can discover accurate product data, verified agents get past your bot defences, agents pay with tokens instead of card numbers, and you keep evidence for disputes. Score yourself on the 10-point checklist below. Most merchants we talk to land in the middle, and the gaps are usually fixable in weeks.
The protocol news moves fast, so this post sticks to what has been announced by the networks and platforms themselves, and flags where things are still open.
Why should GCC merchants start with discovery, not checkout?
Because the in-chat checkout bet has already wobbled. OpenAI launched ChatGPT Instant Checkout in September 2025 on the Agentic Commerce Protocol (ACP) it built with Stripe. By March 2026, industry reporting said OpenAI was pulling back: only a small number of merchants had gone live, keeping prices and stock accurate across merchants proved hard, and shoppers tended to research in ChatGPT and then buy on familiar sites. The reported new direction is discovery inside ChatGPT, with the purchase completed in the merchant’s own app or website.
That is good news for most GCC retailers. You don’t need to hand your checkout to a chat surface. You need agents to find you, read you correctly and send the shopper to a checkout that works.
Google and Shopify took a different path with the Universal Commerce Protocol (UCP), announced at NRF on 11 January 2026, which lets shoppers buy inside Google AI Mode and the Gemini app while the retailer stays merchant of record. Native checkout there has rolled out market by market, starting in the US, and we haven’t seen a GCC launch date. Either way, both protocols start from the same place: a clean, current product feed. Our explainers on UCP and ACP cover the mechanics.
What does the agent-readiness checklist look like?
Score each line 0 (not started), 1 (partial) or 2 (done). The maximum is 20.
| # | Check | What “2 points” looks like | Score |
|---|---|---|---|
| 1 | Product feed quality | Feed with GTIN or brand plus MPN, price, availability, variants and images, refreshed at least daily; Arabic and English titles where you sell in both | 0-2 |
| 2 | Policy data | Returns, shipping, delivery areas and VAT treatment published as structured, consistent data, not just a PDF | 0-2 |
| 3 | Crawlable product pages | Key product data rendered in HTML and schema.org markup, not only behind client-side JavaScript | 0-2 |
| 4 | Verified-agent handling | WAF or bot management can validate Web Bot Auth signatures and treat registered Visa or Mastercard agents differently from scrapers | 0-2 |
| 5 | Agent-friendly checkout path | Guest checkout works, no unnecessary CAPTCHA for verified agents, clear error messages, stable form fields | 0-2 |
| 6 | Token acceptance | Your PSP or acquirer supports network tokens and has a stated plan for Visa Intelligent Commerce and Mastercard Agent Pay credentials | 0-2 |
| 7 | No PAN in agent paths | Agents never type a raw card number into your forms; card entry stays inside your PSP’s hosted fields or redirect | 0-2 |
| 8 | PCI payment-page evidence | Script inventory and change detection for the payment page (PCI DSS 6.4.3 and 11.6.1, or the SAQ A script-attack eligibility evidence) | 0-2 |
| 9 | Agent order tagging | Orders record whether an agent was involved, which one, and the signed request or token reference | 0-2 |
| 10 | Dispute evidence pack | A defined bundle (agent identity, authorisation, confirmation sent to the customer, delivery proof) your team can pull per order | 0-2 |
How to read your score:
| Score | What it means | Where to start |
|---|---|---|
| 0-7 | Agents can probably find you but may misread you, block or fail at checkout | Rows 1-3, then 4 |
| 8-14 | Discoverable, but checkout and evidence are fragile | Rows 4-7 |
| 15-20 | Ready to pilot agent traffic with a PSP or network programme | Rows 9-10, then pilot |
How do you let good agents in without letting scrapers in?
This is where many GCC merchants fail without noticing. Bot defences tuned to block automation will happily block a legitimate shopping agent too, and the shopper just sees a failed task.
Visa’s answer is the Trusted Agent Protocol (TAP), built with Cloudflare on top of Web Bot Auth. In plain terms, registered agents sign each HTTP request using HTTP Message Signatures (RFC 9421), and publish their public keys in a directory. The signature carries a timestamp and a nonce to stop replays, plus a tag that says whether the agent is browsing or paying. Cloudflare says Mastercard has built Web Bot Auth into Mastercard Agent Pay, and that American Express will use it too.
What that means for your audit:
- If you’re on Cloudflare, it validates these signatures for you, and it has described managed rules to allow registered Visa and Mastercard agents while your other bot rules still apply.
- If you’re on another CDN or WAF, ask your vendor directly whether they verify Web Bot Auth signatures today. If not, you’re relying on user agents and IP lists, which are easy to spoof.
- Either way, decide your policy: what verified browsing agents can do, what verified paying agents can do, and what happens to unverified automation.
One caveat: Web Bot Auth is still an IETF draft, so expect details to change. Build the policy now and keep the implementation behind your CDN or WAF vendor.
How should agents actually pay you?
With tokens, not card numbers. Mastercard Agent Pay, announced in April 2025, introduced Mastercard Agentic Tokens, built on the same tokenization behind card-on-file and mobile wallets. Visa’s equivalent sits in Visa Intelligent Commerce, which uses Visa’s Token Management Service.
Both networks already have UAE reference points. Mastercard said its first Agent Pay transaction outside the US happened in the UAE in November 2025, with Majid Al Futtaim and the fintech Dataiera, and VOX Cinemas ticket booking described as an early use case. Visa announced what it called the first live Visa Intelligent Commerce implementation in the region with Aldar in December 2025, and launched its Agentic Ready issuer programme in the UAE in May 2026 (we covered what issuers must build).
As a merchant, you rarely integrate with the networks directly. The practical question is for your PSP or acquirer: do you accept network tokens today, and when will you support agentic credentials from Visa and Mastercard? Get the answer in writing.
The other reason tokens matter is PCI scope. If an agent types a full card number into your checkout, the card data flow just got longer and harder to defend. Our sister practice explains the scoping logic in detail in PCI DSS scope for agentic commerce.
What PCI evidence does an agent checkout need?
The same as any e-commerce payment page, with one more reason to have it. PCI DSS requirements 6.4.3 (authorise and inventory every script on the payment page) and 11.6.1 (detect unauthorised changes to payment page scripts and security headers) apply to merchants filling SAQ D or going through an onsite assessment. SAQ A merchants instead confirm an eligibility criterion that their site is not susceptible to script attacks.
Why it matters more with agents: agent traffic multiplies the automated sessions hitting your checkout, and your acquirer will ask how you know the page those sessions load is the page you intended. A current script inventory and change alerts are the evidence. If you can’t produce them, score row 8 as zero.
Who pays when an agent’s purchase is disputed?
Be honest with yourself here: nobody knows yet. We have not found a published Visa or Mastercard rule that specifically assigns chargeback liability for agent-initiated purchases, so your existing dispute rules apply by default. Mastercard’s own launch materials talk about helping clarify agentic transactions that look unfamiliar to the cardholder, which tells you the networks see this as a real risk.
The new dispute pattern to expect is “my agent bought it, but I didn’t want it”. Your defence is evidence:
- Agent identity: the verified signature or agent ID on the session.
- Authorisation: the token used and any authentication result returned by your PSP.
- What the agent saw: price, delivery date and returns terms at the time of order.
- What the customer was told: the order confirmation email or SMS, with timestamp.
- Fulfilment: delivery or collection proof.
Most of this you already have. The work is tagging agent orders (row 9) so you can pull the pack quickly (row 10).
How do you sequence the fixes?
- Fix the feed and policies first. It helps you with every agent surface and with ordinary search.
- Audit your bot rules. Find out what happens today when a signed agent request hits your checkout.
- Get your PSP’s token roadmap in writing.
- Close the PCI payment-page evidence gap.
- Tag agent orders and define the dispute pack.
- Pilot with one protocol or network programme where your PSP is ready, not all of them at once.
Book a fixed-fee agent-readiness checkout audit
We run a fixed-scope agent-readiness checkout audit for GCC merchants. We score your store against this checklist with real evidence: feed and policy data, how your WAF treats signed agent traffic, your PSP’s token and agentic credential support, payment-page script controls and your dispute evidence. You get a scorecard, a prioritised fix list your engineering and payments teams can execute, and a recommendation on which protocol or network pilot to try first.
See our agentic payments consulting service, or get in touch to scope an audit.
Frequently Asked Questions
What does agent-ready checkout actually mean?
An agent-ready checkout is one an AI shopping agent can use reliably and safely: it can read accurate product, price and stock data, it is recognised as a legitimate agent instead of being blocked as a bot, it pays with a network or agentic token, and the merchant keeps a record of what was authorised. It does not require an in-chat checkout inside ChatGPT or Gemini.
Is ChatGPT Instant Checkout still available for merchants?
Not in its original form. Industry reporting in March 2026 said OpenAI pulled back on ChatGPT Instant Checkout after about six months, with very few merchants live, and shifted toward product discovery inside ChatGPT with purchases completed on merchant apps or websites. OpenAI and Stripe still maintain the Agentic Commerce Protocol as a spec.
Can GCC merchants use Google's Universal Commerce Protocol today?
You can prepare for it, but native checkout in Google AI Mode and Gemini has rolled out market by market starting with the US, and we have not seen it announced for the GCC. The groundwork is the same as for UCP anywhere: a clean Merchant Center product feed, accurate policies and a payment provider that supports token-based payments.
How do I stop blocking legitimate AI shopping agents?
Verify signatures instead of guessing from user agents and IP addresses. Visa Trusted Agent Protocol and Mastercard Agent Pay both build on Web Bot Auth, where registered agents sign each HTTP request with a key published in a directory. Cloudflare validates these signatures for merchants on its network; elsewhere, your WAF or bot management vendor needs to support them.
Who is liable if a customer disputes a purchase their AI agent made?
There is no settled answer yet. We have not found a published Visa or Mastercard rule that specifically assigns chargeback liability for agent purchases, so existing dispute rules apply. Capture the agent's identity, the signed request, the token used and the order confirmation sent to the customer, so you can fight a 'my agent did it, not me' claim.
Complementary NomadX Services
Related Articles
Get Started for Free
Schedule a free consultation with our payment infrastructure team. 30-minute call, actionable results in days.
Every engagement is scoped by our principal architect, Adrian Vale: 20+ years in production engineering, 40+ professional certifications. Meet Adrian
Talk to an Expert