Cloudflare, Visa, Mastercard, Amex Forge Future of Secure AI Shopping
Cloudflare and payment leaders unite to authenticate AI agents, building a secure foundation for agentic commerce.
October 16, 2025

In a landmark move to secure the future of online retail, connectivity cloud company Cloudflare has announced a major collaboration with payment giants Visa, Mastercard, and American Express.[1][2][3][4][5] The partnership is focused on establishing a new authentication framework for the burgeoning field of "agentic commerce," where artificial intelligence agents conduct online shopping on behalf of consumers. This initiative aims to create a secure and trusted environment for these autonomous transactions, addressing the critical challenge of distinguishing legitimate AI shoppers from malicious bots.[2][5] The collaboration signals a significant step toward building the foundational infrastructure needed for a new era of AI-driven digital commerce, with a broad coalition of other major players in the e-commerce and payments ecosystem, including Adyen, Checkout.com, Circle, Fiserv, Microsoft, Nuvei, Shopify, Webflow, and Worldpay, providing feedback on the framework.[1][3][5]
The rise of sophisticated AI heralds a new paradigm in e-commerce known as agentic commerce, where autonomous AI agents will act as personal shoppers, handling the entire purchasing process from product discovery to payment.[2][5][6] These agents have the potential to offer consumers a more seamless and personalized shopping experience, capable of searching, negotiating, and buying goods or services autonomously.[3] However, this evolution also introduces significant security hurdles for merchants. A primary challenge is the ability to reliably differentiate between a trusted AI agent carrying out a legitimate purchase for a consumer and a malicious bot designed for fraudulent activities like carding attacks or creating fake accounts.[5][7] Without a robust verification system, merchants face the difficult choice of either blocking potentially legitimate automated traffic, risking a poor customer experience, or allowing all bots, which increases the risk of fraud and financial loss.[5][6] This partnership seeks to resolve that dilemma by creating a standardized protocol for authenticating AI agents.
At the core of this new initiative is a technology developed by Cloudflare called Web Bot Auth.[1][5] This protocol allows AI agents to securely authenticate themselves during transactions.[5] Working closely with Visa, Cloudflare has co-developed the "Trusted Agent Protocol," which integrates Web Bot Auth to create a standard for how AI agents identify themselves, verify their intent, and process payments securely.[1][3][8] Visa will incorporate this protocol into its Visa Intelligent Commerce platform.[1][5] Similarly, Mastercard is set to integrate Web Bot Auth into its Mastercard Agent Pay system, and American Express will leverage the protocol within its own agentic commerce program.[1][5] This unified approach ensures that merchants can verify the legitimacy of an AI agent, regardless of the payment network, thereby simplifying security and fostering broader adoption of this new commercial model.[1][6] The system is designed to allow AI agents to use a variety of payment methods, including traditional credit and debit cards as well as cryptocurrencies.[1][5]
The implications of this collaboration are far-reaching for the future of artificial intelligence in the retail and financial sectors. By establishing a foundational layer of trust, Cloudflare and the payment networks are paving the way for developers to build and deploy AI shopping agents at scale. AI agents built with Cloudflare's Agents SDK will soon be able to shop autonomously across millions of global merchants.[2][5] This move is not just a defensive measure against fraud but a proactive step to enable innovation in e-commerce. The broad industry support, from payment processors like Adyen and Worldpay to e-commerce platforms like Shopify, underscores the collective recognition that a standardized, secure framework is essential for the growth of agentic commerce.[3][5] Furthermore, Cloudflare's efforts extend to the promotion of open protocols, including the establishment of the x402 Foundation with Coinbase, to further accelerate the development and adoption of secure, agent-driven commerce.[2][3][5] This collaborative security-first approach is crucial for building consumer and merchant confidence in a future where AI plays a central role in online transactions.