AI Agents Will Move $15 Trillion by 2028. Only 11% Are Ready.
The Scope of Agentic Commerce
Nine in ten B2B buyers on EDI plan to abandon it. The average supplier now juggles five commerce channels, up from three and a half two years ago. The 40-year-old rails are giving way — not to another file format, but to AI agents that negotiate, pay, and orchestrate fulfillment on their own.
Agentic commerce refers to AI agents that execute commercial transactions autonomously, negotiating terms, authorizing payments, and orchestrating fulfillment, all within guardrails set by their human operators. Over the past year the technology has matured from compelling one-off experiments into systems that connect to tools and data, complete complex workflows, and orchestrate with other agents. B2C enterprises proved the concept first, using agents to reach customers across channels, present offers dynamically, and reshape the shopping experience. Early signals show customer behavior starting to shift. Now the same architecture is moving into B2B, where regulatory clarity around commercial contracts gives autonomous transactions a firmer footing than in consumer markets.
The numbers outline a market in motion. Deloitte estimates the AI agent market at $35 billion by decade's end, rising to $45 billion if agents are strategically orchestrated and risks mitigated. Gartner projects a far larger figure: by 2028, 90 percent of B2B buying will be AI-agent intermediated, pushing over $15 trillion of spend through agent exchanges — roughly the GDP of China. The same research sees a $58 billion market shakeup through 2027 as GenAI and agents challenge mainstream productivity tools for the first time in 30 years. By 2030, agentic commerce could drive up to $17.5 trillion in total commerce, Deloitte Financial Services' data shows, and one in five monetary transactions will be programmable with terms and conditions embedded for machine execution.
| Projection | Source | Horizon |
|---|---|---|
| $35B AI agent market value | Deloitte | End of decade |
| $45B (with orchestration & risk mitigation) | Deloitte | End of decade |
| $15T+ B2B spend through agent exchanges | Gartner | 2028 |
| $17.5T total agentic commerce | Deloitte Financial Services | 2030 |
| $58B productivity-tool shakeup | Gartner | Through 2027 |
Adoption is uneven and revealing. Nearly 40 percent of B2B buyers already use agentic AI in purchasing, evaluating products, configuring orders, reviewing contracts, and benchmarking prices. Only 24 percent of suppliers use agents in the sales process, though two-thirds plan to. The perception gap is stark: 72 percent of suppliers call their sales processes mostly or highly automated, but fewer than half of buyers agree. Buyers are six times more likely than suppliers to describe B2B processes as mostly manual. That disconnect costs money — suppliers estimate 13 percent of sales bids are lost to negative buyer experiences, while positive experiences drive an estimated 36 percent revenue uplift and buyers spend nearly 30 percent more with suppliers that deliver them.
Experience is a margin lever, not just a satisfaction metric.
The infrastructure is already turning over. Nine in ten B2B suppliers are upgrading or preparing to upgrade their ERP systems. Eighty-five percent of companies anticipate customizing agents to automate aspects of the business. Yet only 11 percent of enterprises report using agents in production. Forty-two percent are still developing an agentic strategy; 35 percent have no strategy at all. Roughly one in five reports a mature governance model for autonomous agents.
Three open protocols are shaping the interoperability layer. Google's Universal Commerce Protocol (UCP) unifies product discovery, checkout, order management, and post-purchase across major commerce and retail players. Agent2Agent (A2A) provides an interoperability layer for agents to discover, authenticate, and collaborate across platforms. Agent Payments Protocol (AP2) extends into trusted, authorized transactions. Together they form the plumbing for agent-to-agent commerce.
The shift is already visible across eight B2B use cases: agentic customer engagement and service; buyer intent and solution discovery; transaction and service orchestration; autonomous commercial negotiation and deal governance; intelligent procurement and supplier orchestration; autonomous payments and financial settlement; predictive fulfillment and inventory optimization; AI-driven sales acceleration and pipeline management.
AI agents matured dramatically over the past year just as enterprises face margin pressure, supply volatility, and labor constraints simultaneously. Each pressure alone would strain a business model; together they make the case for a faster, more agile, more autonomous operating model unavoidable.
From System of Record to System of Action
For three decades, the enterprise software stack settled around a simple premise: the system of record wins. Salesforce, SAP, Oracle, and ServiceNow built moats on implementation complexity, deep product surfaces, and the gravitational pull of business-critical data. Switching costs were so high that few startups even attempted a direct assault. As Bessemer Venture Partners put it in August 2025, "the businesses enjoyed some of the strongest moats in software."
That premise is cracking. Large language models can now read, write, and reason across operational data, collapsing the distance between intent and execution. ITSM and CRM platforms, once passive databases, are becoming autonomous workflow engines. Bessemer's 2025 State of AI report describes it as "a once-in-a-generation shift—from systems of record to systems of action."
The mechanics of the transition are measurable. Code-generation tools and natural-language-to-code translation have compressed implementation timelines by roughly 90 percent. Data migrations that once took years of systems-integrator labor now complete in days because AI can translate between schemas automatically. Historical vendor lock-in, the proprietary data formats and custom integrations that kept customers captive, is becoming nearly obsolete. The return-on-investment calculus has flipped: agentic workflows deliver roughly 10x the ROI of legacy deployments by eliminating professional-services spend and accelerating time-to-value.
New entrants illustrate the pattern. Day.ai and Attio auto-log customer interactions from email, calls, and Slack without manual entry. AI-native ERPs such as Everest, Doss, and Rillet automate financial forecasting and procurement flows. These platforms don't merely store information; they act on it. The strategic imperative for vertical SaaS companies has moved from owning the system of record to powering the system of action.
Architecturally, the interface becomes a dynamic agent layer. The traditional system of record slips into the background as a commodity persistence tier — its strategic leverage ceded to whoever controls the intelligent execution environment employees actually use. Andreessen Horowitz's 2026 Big Ideas brief frames this transition bluntly: the system of record becomes plumbing; the agent layer becomes the product.
The transition introduces new failure modes. A recent technical discussion warned that exposing raw enterprise data to agents without guardrails "will exponentially create more problems than what we have today… infinite scale of 10,000 times the problems." Traditional data-lake tiering, bronze, silver, gold catalogs, doesn't map to agentic workflows; the architecture must move closer to business use cases. The same discussion emphasized a fundamental change from deterministic execution to predictive, multi-loop planning: "you need multiple decision loops… more towards planning and executing, which is going to be very critical."
Only about 6 percent of enterprises can currently build and redefine an end-to-end business workflow autonomously. The gap between the architectural possibility and the operational reality is where the next generation of engineering roles will form.
The Infrastructure Stack for Autonomous Transactions
The first live B2B agentic transaction, in which LoopXPay sourced a product sample, compared suppliers, placed the order, and executed payment within a single workflow, landed in July 2026. It ran on Visa's Agentic Directory and Trusted Agent Protocol. That milestone exposed the stack that now needs building: identity, interoperability, payment execution, orchestration, and data. Each layer has distinct engineering demands, and the companies racing to fill them are doing so in public.
Identity and Trust Layer
Visa's Agentic Directory registers verified agents so counterparties can confirm they're transacting with an authorized entity, not a spoofed script. The Trusted Agent Protocol sits beside it, defining the identity, transparency, and control primitives that let a merchant set spending limits, approval chains, and audit trails before an agent ever initiates a payment. Deloitte's banking research argues that as agent counts scale, institutions will need a detailed, updated agent registry capturing owner, scope, data sets, and risk exposure limits (financial and otherwise) for every agent in production. Natural's architecture bakes this in at the protocol level; Skyfire Systems, backed by DCVC, anchors its equivalent in USD-backed stablecoins. Both approaches treat identity as infrastructure, not an afterthought.
Communication and Interoperability Layer
Model Context Protocol (MCP) is the open standard emerging to define how multiple agents discover, negotiate, and exchange data, tools, and context within a shared environment. Amazon Bedrock, Salesforce Agentforce, Google Agentspace, and ServiceNow each now offer multi-agent orchestration platforms that implement or extend MCP semantics. Intesa Sanpaolo's "HEnRY" framework and BlackRock's Aladdin-integrated agent platform demonstrate how financial institutions are building proprietary overlays on top of these standards. The engineering challenge is composability: agents from different vendors must interoperate without a widened attack surface. Deloitte warns that third-party agents bring interoperability and standardization issues that can magnify systemic vulnerabilities into domino-effect automation risks. A composable, modular design, explicitly recommended by Deloitte's multi-agent architecture guidance, is the only way to contain that blast radius.
Payment Execution Layer
This is where the bottleneck lives. "Today's financial sector relies on financial rails built for human-initiated transactions, not autonomous AI agents," Natural co-founder Kahlil Lalji told TechCrunch in July 2026. Traditional credit-card and ACH networks require human authorization at each step, which breaks the latency budget of agents engineered to operate at compute speed. Natural's $30M Series A (July 2026) and earlier $9.8M seed (October 2025) fund a dual-rail architecture: USD-backed stablecoins for instant, programmable settlement, plus traditional bank payment support for counterparties that haven't onboarded to crypto rails. Skyfire Systems pursues a stablecoin-first model. Stripe, which Lalji names as his primary competitor, is racing its own agentic toolkit for secure financial transactions. The stack must handle authorization, clearing, and settlement without a human in the loop — while preserving the ability to insert one when policy demands it.
Orchestration and Control Layer
The LoopXPay transaction executed within pre-defined spending controls and approval parameters. Public's retail brokerage agents require users to review and approve a workflow before execution; the agent cannot "suddenly do something you never told it to do." BNY tasks agents with payment instruction validation and coding, but keeps humans in the loop for accountability. Deloitte's implementation framework treats this as a spectrum: smart overlay (wrapping an agent around an existing process), agentic-by-design (new autonomous applications from ground up), and process redesign (rejiggering entire workflows). Each approach demands different control-plane engineering — policy engines, audit logs, rollback mechanisms, and real-time risk scoring that can halt a transaction mid-flight.
Data and Analytics Layer
Agents only act as well as the data they ingest. BlackRock's Aladdin integration shows the high-water mark: an agent platform fed by the world's largest asset-manager dataset. Podium Markets' Ivy accesses holdings across brokerage accounts, analyzes portfolios, and tailors responses to user-selected risk levels. Deloitte stresses that agentic AI should use high-quality, accessible data for a better chance at success, and that cloud-based solutions offer the flexibility and computational power these systems need. The engineering implication: data pipelines, feature stores, and real-time streaming infrastructure become first-class citizens in the agentic stack, not backend afterthoughts.
Visa, Lianlian, Natural, Skyfire, Stripe, and the major cloud platforms are shipping components today. The engineers who stitch them together, handling identity propagation across rails, latency budgets measured in milliseconds, and audit trails that satisfy regulators, are defining a new discipline. Regulatory frameworks are now writing the rules for that stack at the level of identity, permission, and inter-agent protocol.
Regulatory Guardrails and Compliance-by-Design
Singapore moved first. In January 2026, the Infocomm Media Development Authority published the world's first cross-sector governance framework for AI agents. MetaComp, a licensed financial institution, took that model and built the StableX Know Your Agent (KYA) Framework — the first governance architecture authored by a regulated entity specifically for AI agents operating in payments, compliance, and wealth workflows. KYA governs agents across their full lifecycle through four pillars: Agent Identity and Registration; Authority and Permission Control; VisionX Behaviour Monitoring and Risk Intelligence; and Ecosystem and Interaction Governance, which extends the FATF Travel Rule to agent-to-agent transactions.
The architecture is deliberate. Every AI agent is anchored to a verified identity linked to a real-world individual or institution through a tamper-resistant registry. Permissions are strictly defined, specifying what the agent can access, decide, and execute, with built-in safeguards requiring human escalation when actions exceed approved thresholds. Continuous, real-time monitoring assesses not just what actions are taken, but how they are executed and whether outcomes align with intent. When agents interact with each other, verified identity and transaction information must be exchanged across the unified architecture, not just between institutions.
This is compliance-by-design. The regulatory requirement becomes a technical primitive.
The UK is following a parallel track. On 6 July 2026, the Financial Conduct Authority published the Mills Review, which projects how AI could reshape retail financial services by 2030. The review concludes that approval at launch followed by periodic reviews will no longer suffice. Governance and oversight must operate closer to real-time, alongside the AI systems they govern. The FCA should lead development of a trusted framework clarifying how agents can be authorised, identified, and held accountable — with clear expectations for consent mandates, identity, control, and liability. The review recommends using Open Finance work to build standardised approaches for AI agents acting with Open Finance data, noting that without standardised delegation and consent frameworks, an agent instructed to switch a consumer's savings product across providers cannot safely execute that instruction end-to-end.
The FCA also envisions an AI-enabled agentic supervisory model — using AI to analyse firm and market data more quickly, systematically, and at scale, while keeping human supervisors responsible for key regulatory decisions. Aggregated monitoring of Consumer Duty outcomes across firms could surface harms that no single firm's internal data would reveal.
In the United States, the July 2025 GENIUS Act created a legislative framework for payment stablecoins, providing regulatory clarity and opening the door for traditional banks to engage with tokenized digital assets. By July 2026, federal banking regulators had established the regulations and guidance required under the Act, with rules taking effect January 2027. Banks must decide whether to issue, custody, process, or partner — and do so quickly as tokenized deposits and programmable money reshape customer expectations. Several crypto firms including Circle, Ripple, and Paxos have already applied for US bank charters, signaling convergence between traditional banking and digital assets.
The FATF Travel Rule data from June 2025 shows the enforcement gap: 73 per cent of jurisdictions have passed Travel Rule legislation, but 59 per cent have taken no supervisory or enforcement action. KYA's extension of the Travel Rule to agent-to-agent transactions addresses this directly — building the enforcement mechanism into the interaction layer itself.
Deloitte's analysis of the MIT AI Risk Database reveals more than 350 risks from autonomous or agentic behavior. The US response has been architectural: agents should be treated as accountable actors, similar to human employees. Unique agent IDs, output tagging, immutable tool-use logs, and real-time monitoring ensure every decision leaves a clear audit trail. A "regulatory adapter layer" allows disclosures and content provenance to be activated per region, product, or channel dynamics. Human-on-the-loop models and AI agent observability are integrated into agentic operations. Guardian agents, systems that monitor agentic behavior in real time, flagging anomalies, policy violations, and ambiguous decisions, provide an added layer of security.
The Moltbook incident demonstrated what happens without this architecture: a social network for AI agents failed to secure its production database, exposing APIs and data that hackers could use to impersonate or manipulate other users' agents.
McKinsey's 2026 State of AI Trust survey found fewer than one in three organisations have adequate governance and controls for AI agents. PwC's Global AI Performance Study 2026 showed Singapore businesses outperform globally on AI adoption (67 per cent vs 41 per cent), yet only 47 per cent have a documented responsible AI framework compared to 63 per cent among global AI leaders. The gap between deployment and governance is the problem these frameworks are designed to close.
MetaComp developed KYA drawing on IMDA's Model AI Governance Framework for Agentic AI, sought IMDA's feedback directly, and is in active engagement with other regulators. They published it openly because, as they put it, this is not a problem any one institution can resolve alone. The technical architecture of agentic commerce is being written by regulatory frameworks — not constrained by them, but shaped at the level of identity, permission, monitoring, and inter-agent protocol.
The New AI Engineer: Skills, Roles, and the Talent Gap
The adoption curve is brutal. Twenty-three percent of companies use agentic AI at least moderately today; within two years that figure hits 74 percent, with 23 percent using it extensively and 5 percent baking it into core operations, per Deloitte's 2026 enterprise survey. The infrastructure sections of this article explain what those systems do. This section asks who builds them — and the answer is not "AI engineers" or "fintech engineers" but a hybrid that barely exists on the market.
Deloitte found the AI skills gap is the single biggest barrier to integration. Education, not restructuring, not hiring, was the number-one talent adjustment companies made, cited by 53 percent of leaders. Yet 84 percent of organizations have not redesigned jobs around AI capabilities. The disconnect is structural: companies are buying agentic tooling while keeping the org chart built for human-initiated workflows.
The new roles have names that sound made up until you see the job specs. Deloitte tracks AI operations managers, human-AI interaction specialists, and quality stewards as emerging titles. At the infrastructure layer, the requirements sharpen. OKX, which suspended India operations in 2024 to navigate crypto regulation, is now applying its exchange-grade fraud detection and compliance stack to a marketplace where AI agents hire and pay each other. Haider Rafique, OKX's chief marketing officer and global managing partner, told TechCrunch the company believes agentic commerce could become a trillion-dollar market in five years, driven by micropayments and autonomous software. That marketplace needs engineers who understand settlement finality across stablecoin rails, card networks, and RTP, and who can write the compliance logic that runs inside the agent's decision loop, not as a post-hoc audit.
Natural, which raised $30 million in July 2026 to rebuild payments for AI agents, puts it differently: today's financial rails were built for human-initiated transactions. The company is redesigning the whole system from the ground up. Its founder, Lalji, hopes development speed lets Natural outpace incumbents and become the financial backbone of AI agents. Jack Dorsey, writing on X, said most companies are late and predicts the majority will reach the same conclusion within a year.
| Company | Roles Added (7 days) | Salary Band (median) | Signal |
|---|---|---|---|
| Anthropic | 37 | $205k–$553k ($395k) | Research engineers, RL data platform, inference engine, chip design RL |
| Databricks | 54 | $140k–$317k ($250k) | Enterprise sales, vertical GTM, lakehouse specialists |
First-party board data from Zero G Talent shows where capital is concentrating. Anthropic's open roles, including Performance Engineer for the Inference Engine, Research Engineer for Takeoff Intel, Staff+ Research Engineer for RL Data Platform, Pre-training Distributed Systems Tech Lead, Research Engineer for Chip Design RL, and Engineering Manager for Research Data Platform, cluster around the compute and data layers that agentic commerce will stress-test. Databricks is hiring vertical GTM leaders for financial services, healthcare, and energy at $350k–$600k, signaling that enterprise deployment, not model training, is the current bottleneck.
The organizational shifts confirm the talent rewrite. Meta laid off 8,000 people while moving 7,000 into new AI-focused roles, roles employees reportedly hate, suggesting the skill mismatch is acute. IBM plans to triple U.S. entry-level hiring for AI and hybrid-cloud roles even as it replaced roughly 200 HR positions with AI agents. Coinbase flattened to five layers below the CEO and COO and is experimenting with "one-person teams" combining engineering, design, and product. Deloitte found 53 percent of organizations have considered pod-based or non-hierarchical models; only 16 percent have moved there to a great or maximum extent.
What the hybrid engineer actually needs: fluency in LLM orchestration and prompt architecture, yes, but also deep knowledge of payment rail semantics (ACH return codes, RTP message formats, stablecoin settlement finality), regulatory primitives (KYC/AML for non-human actors, travel rule compliance, money transmission licensing), and systems-level thinking about idempotency, reconciliation, and audit trails when the counterparty is code. Traditional fintech engineers know the rails but not the agent loop. Traditional AI engineers know the loop but treat payments as an API call. The market pays for the intersection.
The EDI rails that carried B2B commerce for four decades are not being replaced by a newer format. They are being replaced by code that can negotiate, settle, and adapt in real time, governed by identity protocols, watched by guardian agents, and built by engineers who speak both the language of LLMs and the grammar of payment rails. The first live agentic transaction already happened in July. The rest is plumbing.
Working in AI? Zero G Talent tracks the openings: see every open Databricks role, browse AI jobs, openings at Anthropic, and the people building the field.