Manuel Heilmann, CEO of compliance platform iubenda, looks at who gives consent for a shopper’s data once an AI agent, not a human, is doing the shopping.
An agent buys a washing machine, books a flight, or signs up for a subscription on your behalf, in a few taps, without you ever leaving the chat window. That’s roughly what agentic commerce looks like: it searches, compares and buys with barely any human input. And somewhere in that hand-off, a question most retailers haven’t thought to ask starts to matter: who gave consent for the data being processed, and is it the kind a regulator would accept?
The scale is hard to ignore. Bain expects agents to drive 15 to 25 per cent of US online sales by 2030, and McKinsey puts the global opportunity as high as $3 to $5 trillion. The ICO reckons personal shopping agents could be part of everyday life within five years, and the pathways already exist: Google’s UCP covers the commerce journey from discovery through to post-purchase, and the Agentic Commerce Protocol that OpenAI and Stripe open-sourced is now backed by PayPal and a growing roster of retailers. OpenAI scaled back its first in-chat checkout in March, but the protocol layer beneath it is holding up.
When an AI agent browses a website or completes a purchase, consent for data processing still has to be given where the law requires it, under the UK GDPR and PECR. That obligation doesn’t disappear. It shifts from the human to the agent.
Source link







