Every commercial channel has involved someone deciding what the customer gets to see. Department stores chose which brands to stock, search engines ranked results, app stores set review policies and handed out featured placements. The power was real in each case. But the buyer still chose from whatever the channel had put on the shelf.
Agent intermediation is arriving at a different arrangement. When an AI agent interprets what someone needs, assembles candidates, scores them against criteria, and returns a recommendation or simply executes the purchase, the act of selection has moved upstream of the human. Whoever shapes what the agent looks for controls access to the customer in a way earlier channels never quite managed.
That infrastructure is being assembled now, and it has at least three separate doors. The first is technical interoperability: commerce protocols that let a business publish a machine-readable profile declaring its capabilities, endpoints, and payment handling. The second is agent certification. The Know-Your-Agent collaboration announced last week by three major payment networks proposes shared requirements for verifying agent identity and monitoring what those agents transact. The third is admission to the recommendation set itself: ChatGPT's shopping system lists factors including price, reviews, structured product data, and third-party content, while noting that not every product will be shown.
A business must satisfy the protocol layer, the payment-certification layer, and the selection-criteria layer independently — each governed by a different organization with different incentives, none obligated to honor the others' approvals.
Clearing one door does not get you through the next. A business can publish a protocol profile and go undistributed. It can earn certification and find merchants unwilling to accept it. It can qualify for transactions and never enter a recommendation set. An app store was a single gatekeeper with a single rulebook; satisfy it and you were in the market. This is a sequence of unrelated approvals, and nobody is coordinating them on the seller's behalf.
There is a useful structural precedent in the European Commission's investigation of Amazon's marketplace, which found that the Buy Box algorithm first excluded sellers who failed platform-defined criteria, then picked a single Featured Offer, and that the overwhelming majority of sales flowed through that one offer. The platform was already selecting rather than merely ranking. But the Buy Box chose among offers for a product the buyer had already named. Agent systems widen the scope of that choice considerably, from picking a seller to interpreting a loosely stated need and settling on the product, the provider, and the payment path. Whoever writes the agent's selection criteria is therefore shaping not just which seller wins, but which kinds of offering the deciding system can perceive at all.
The IMF describes this as a shift from "click-to-pay" toward "decide-to-pay," while noting that today's implementations mostly stop at finding and comparing, with humans still finalizing most purchases. As that human step thins out, the power held by whoever controls an agent's operating environment grows. In controlled studies, deceptive interface designs diverted agents toward adversarial outcomes in more than 70 percent of tested tasks, against 31 percent for human subjects. Agents that reasoned more extensively were more susceptible, not less. If agents are that responsive to environmental cues, then setting defaults, structuring information, and defining ranking criteria amount to a form of influence traditional channel power could never exert over a human buyer who at least saw the shelf.
EU rules already require platforms to disclose the main parameters behind their rankings. Whether that obligation reaches agent selection criteria is unsettled. So is the harder question of what disclosure is worth when the buyer never sees the alternatives that were rejected on their behalf.

