
Google has revealed the primary draft of Common Commerce Protocol (UCP), an open customary to assist AI brokers order and pay for items and providers on-line.
It co-developed the brand new protocol with trade leaders together with Shopify, Etsy, Wayfair, Goal and Walmart. It additionally has assist from fee system suppliers together with Adyen, American Categorical, Mastercard, Stripe, and Visa, and on-line retailers together with Finest Purchase, Flipkart, Macy’s, The Dwelling Depot, and Zalando.
Google’s transfer has been eagerly awaited by retailers in accordance with retail know-how advisor, Miya Knights. “Retailers are eager to begin experimenting with agentic commerce, promoting instantly by AI platforms like ChatGPT, Gemini, and Perplexity. They’ll embrace and experiment with it. They need to know easy methods to present up and convert in client searches.”
Safety procuring checklist
Nonetheless, it is going to current challenges for CIOs, specifically in sustaining safety, she stated. UCP as applied by Google means retailers will probably be exposing REST (Representational State Switch) endpoints to create, replace, or full checkout classes. “That’s a further assault floor past your internet/app checkout. API gateways, WAF/bot mitigation, and price limits turn into a part of checkout safety, not only a ‘nice-to-have’. Which means that CIOs should implement new reference architectures and runtime controls; new privateness, consent, and contracts protocols; and new fraud stack element integration.”
Data-Tech Analysis Group principal analysis director Julie Geller additionally sees new safety challenges forward. “It is a main shift in posture. It pushes retail IT groups towards deliberate agent gateways, managed interfaces the place agent id, permissions, and transaction scope are clearly outlined. The safety problem isn’t the amount of bot visitors, however non-human actors executing high-value actions like checkout and funds. That requires a distinct mind-set about safety, shifting the main focus away from easy bot detection towards authorization, coverage enforcement, and visibility,” she stated.
The introduction of UCP will undoubtedly imply smoother integration of AI into retail programs however, in addition to safety challenges, there will probably be different points for CIOs to grapple with.
Geller stated that one of many points she foresees with UCP is that “it really works too properly”. By this she signifies that the mixing is so easy that there are governance points. “When brokers can act rapidly and upstream of conventional management factors, small configuration points can floor as income, pricing, or buyer expertise issues virtually instantly. This creates a shift in duty for IT departments. The query stops being whether or not integration is feasible and turns into how variance is contained and accountability is maintained when execution occurs exterior the retailer’s personal digital properties. Most retail IT architectures weren’t designed for that stage of delegated autonomy.”
Google’s AI rival OpenAI launched a brand new function final October that allowed customers to find and use third-party purposes instantly inside the chat interface, on the identical time publishing an early draft of a specification co-developed with Stripe, Agentic Commerce Protocol, to assist AI brokers make on-line transactions.
Knights expects the introduction of UCP to speed up curiosity in and adoption of agentic commerce amongst retailers. “Google stated that it had already labored with market leaders Etsy, Wayfair, Goal, and Walmart to develop the UCP customary. This may pressure rivals to speed up their agentic commerce methods, and can assist Google steal a march on rivals, given that it’s the market chief,” she stated.
For on-line retailers’ IT departments, it’s going to imply additional work, although, in implementing the brand new protocols and in making certain their e-commerce websites are seen to customers and bots alike.

