The Agentic B2B Guide
What is actually happening in agent-mediated B2B commerce, what the numbers really say, and what it takes to be transactable rather than just readable.
The short version
- What share of B2B website traffic comes from AI agents?
- Across the broad web, AI assistants account for 0.14% to 0.32% of all visits. Measured as a share of referral traffic it is around 1%. On industrial domains - machinery, building products, trading companies and distributors - it is about 1.5%. The figure only means something alongside its denominator.
- Do AI-referred visitors convert better than search traffic?
- Modestly, and only recently. Adobe Analytics, measuring over a trillion visits to US retail sites, found AI-referred traffic converted 42% better than other sources in March 2026, having converted 38% worse twelve months earlier. Claims of four to twenty-three times better come from single-site or vendor-selected samples and are not supported at scale.
- Is agentic commerce really a $5 trillion market?
- Not for B2B. The $3 trillion to $5 trillion figure is McKinsey's, published October 2025, and their own report states it reflects goods only and excludes services and the B2B marketplace. Bain's separate estimate is $300 billion to $500 billion for US agentic commerce by 2030. The forecast that does address B2B is Gartner's: 90% of B2B buying AI agent intermediated by 2028.
- Why do centralized product catalogs fail in B2B commerce?
- Because a catalog entry has to read the same to everyone who looks at it, while a B2B price is computed at request time from buyer identity, contract, volume tier, ship-to location, date, allocation and credit standing. The Agentic Commerce Protocol feed carries one price per item globally. The Universal Commerce Protocol specification contains no contract pricing, purchase orders, net terms, tax exemption or punchout.
- Does Shopify Catalog support B2B products?
- No. Shopify's own documentation excludes products published only to B2B markets, products in catalogs assigned to specific companies and locations, and anything a customer must log in to see. Shopify's B2B features work, they are simply barred from the agentic catalog, because the catalog is public and buyer-blind.
- What is the difference between LLM optimization and Model Context Protocol?
- LLM optimization makes your published content readable so an assistant can cite you. The ceiling is a mention. Model Context Protocol is an authenticated interface onto systems you already run, so an agent can check contract-specific stock, request a quote, or place an order against a named account. One gets you considered. The other transacts.
- Is agent-readable infrastructure just the semantic web repeated?
- Partly. Publishing extra machine-readable files is the same mistake: 97% of llms.txt files receive no requests of any kind, and Google's documentation states no new machine-readable files are needed. An agent interface is different because nothing new gets authored, the return is a countable transaction rather than a ranking, and unlike 2009 there is now a reader capable of using it.
- How do AI agents discover an enterprise's MCP server?
- Today, mostly they do not. A human pastes the URL. The official registry launched in preview in September 2025, is still in preview, and states it is not intended for agents to read directly. GitHub operates a small downstream marketplace, not the registry. Standardized discovery was merged in June 2026 onto the extensions track with competing addresses and has not settled.
- What actually blocks an AI agent from transacting with an enterprise?
- Three gates, and discovery is the least important. Approval is the real chokepoint: on Claude's Team and Enterprise plans only an Owner can add a connector for the organization. Trust is the third: NSA and Carnegie Mellon guidance from May 2026 names deficient approval workflows and inadequate audit logging among seven risk categories, and roughly a quarter of public agent servers surveyed had no authentication at all.
- Why build for a channel that is under 2% of traffic?
- For the same reason manufacturers printed barcodes on over 90% of grocery products by 1980, when only a minority of stores could scan them and the scanners never returned their cost. The buyers who mattered were going to require it. B2B ran the same play with cXML: published free in 1999, table stakes twenty-odd years later, and suppliers who never connected lost the ability to bid.
In 1999 the US government measured e-commerce for the first time. It came in at 0.5% of total retail sales.
That number gets quoted a lot, usually by someone making the point that big things start small.
Here’s the number nobody quotes. Same year, same agency, same report. Manufacturing e-shipments were already 18.4% of total shipments. Merchant wholesale was 7.2%. And 88% of all merchant-wholesaler e-commerce ran on EDI - Electronic Data Interchange, the machine-to-machine format purchase orders have been traveling in since the 1970s. Not the web.
So, while consumer retail was at half a percent, B2B was at eighteen and a half.
B2B has been running machine-to-machine commerce for twenty-five years. It just never got called e-commerce. It never ran in a browser. And it never turned up in anyone’s headline chart.
Which means, the question in front of a manufacturer or a distributor today isn’t whether machines will buy from you. That was settled somewhere around 1997, in a windowless room, by people nobody interviewed.
The question is, what layer does the next twenty-five years run on, what does it cost to be on it, and what does being on it give away?
And answering that question is why you’re here, reading this guide.
To set the context - this was written in August 2026 (and yes, with some help from AI on the research). We put some color around numbers that are both confident, and confidently wrong. We tie all the data back to sources you can read and check yourself. And we make a point of identifying what’s data, and what’s someone’s forecasted opinion.
How much B2B buying actually runs through AI agents today?
Less than the forecasts want you to believe. More than the skeptics assume. And quite a lot more than the number you’ve probably heard.
What share of today’s traffic comes from AI assistants?
The figure doing the rounds is “under half a percent”. It isn’t wrong exactly, but on its own it’s useless, because nobody ever says what it’s half a percent of.
Three different numbers are all true at the same time.
Across the broad web, AI assistants account for 0.14% to 0.32% of all visits. That’s Semrush across 50,000 sites, Contentsquare across 99 billion sessions, and SE Ranking across 101,574 sites, covering 2025 into April 2026.
Measured as a share of referral traffic rather than all traffic, it’s around 1%. Same reality, different denominator, triple the number.
And measured on the kind of domains that look like your business - machinery, building products, industrial trading companies and distributors - it’s 1.5%. That’s Conductor, across 13,770 leading-brand domains, May to September 2025.
So, if you stand up in front of a room of distributors and say “it’s 0.2%”, you’ve just understated their own number by a factor of seven. You’ve also handed the skeptic at the back an easy win he did nothing to earn.
One honest gap. Nobody has measured agent traffic to distributor or wholesaler sites specifically. That 1.5% is the closest proxy in existence, and anything sharper has to come out of your own analytics.
Does that traffic behave any differently?
Yes. And the interesting bit isn’t the level, it’s the direction of travel.
Adobe Analytics, measuring more than a trillion visits to US retail sites, found that in March 2026 AI-referred traffic converted 42% better than everything else.
Twelve months earlier the same measurement had it converting 38% worse.
Worst channel on the page to best channel on the page, inside a year, at trillion-visit scale. That’s a measurement, not a prophecy, and it does more work than any market-size projection I’ve seen this year.
Now the caveat, because this is where people get burned. There’s a pile of research claiming AI referrals convert four, ten, twenty-three times better than organic search. Go and look at the samples - single websites, or vendors selling you the fix. The two biggest datasets put the lift at plus 20% to plus 42%, and Contentsquare’s 99 billion sessions have AI traffic converting below email.
If someone shows you a multiple above 2x, check what they’re selling.
Are B2B buyers actually using this stuff to pick suppliers?
This is where it gets specific to B2B, and it’s further along than the traffic numbers suggest.
66% of UK senior decision-makers with B2B purchasing responsibility now use ChatGPT, Copilot or Perplexity as part of procurement. 45% name AI as one of their main methods for finding new suppliers. That’s 300 buyers, surveyed November 2025.
63% of B2B technology buyers used AI during their purchase process, and 83% shortlisted three or fewer products. TrustRadius, about 2,500 buyers, fielded January 2026.
On your side of the table, 43% of procurement organizations are actively pursuing AI deployment, roughly double the year before. Only 12% have it running at scale. Hackett Group, March 2026.
That 43% against 12% is the real state of play. Everybody’s having a go. Almost nobody has finished.
Go back to the shortlist number though, because that’s the one that should keep you up at night. When 83% of buyers get down to three names or fewer, and more of those lists are being built with a machine’s help every quarter, the cost of being unreadable isn’t a lost click.
It’s not being in the room at all. And unlike a lost tender, nobody sends you a letter.
So is it a rounding error or not?
At 1.5% of traffic, taken on its own, today - yes. It is.
The reason nobody sensible is treating it as one comes down to what the forecasts actually say. And here I have to be careful, because the version being repeated loudest is wrong.
The famous “$5 trillion agentic commerce” number is McKinsey’s, published October 2025. Read the next line of their own report though. The one in brackets that never makes it onto anybody’s slide.
“(These figures only reflect goods and do not yet include services; nor do they account for the significant B2B marketplace.)”
McKinsey are telling you, in their own parenthesis, that the number has nothing to do with B2B. So, every time you see $5 trillion waved at a B2B audience, the person waving it stopped reading at the headline.
Bain get named alongside McKinsey on this constantly, and Bain’s number is $300 billion to $500 billion. A tenth of what routinely gets put in their mouth.
The forecast that’s genuinely about B2B is Gartner’s: by 2028, 90% of B2B buying AI agent intermediated, pushing over $15 trillion of global B2B spend through agent exchanges. For scale, total US B2B sales in 2025 were $15.12 trillion - roughly the entire US market, globally, in two years. Aggressive. Not mad, because global B2B is several times the US. But say “global spend” when you quote it, or someone who actually understands these figures will take your legs off.
Honestly though, forget 2028. The one to plan against is Forrester: 20% of B2B sellers will be forced into agent-led quote negotiations during 2026.
Not 2030. This year. A machine on the other end of your RFQ - your request for quote - in one seller out of five, before Christmas.
Centralized product catalogs haven’t worked before. What’s going to make them different in the agentic web?
Ok - so if a buyer’s agent is going to be haggling with you this year, the obvious next question is how it finds you, and what it talks to when it gets there.
The industry has an answer, and it’s being poured at speed right now. The answer is a catalog. Somebody else’s catalog.
For consumer goods it works fine. For you it doesn’t, and the reason is structural rather than a matter of waiting your turn.
What is a structured agentic catalog?
Shopify Catalog, launched December 2025, is the clearest example. Shopify holds a central store of product data, syndicates it to ChatGPT, Perplexity and Microsoft Copilot, and exposes it to agents over MCP - the Model Context Protocol, the open standard agents use to call tools and systems. Inclusion is automatic. You can’t opt out entirely, only block individual channels.
Google and Shopify then co-developed the Universal Commerce Protocol in January 2026. OpenAI and Stripe had already published the Agentic Commerce Protocol in September 2025. Google shipped one for payments, and the card networks turned up with their own.
If you sell a thing, at a published price, to a stranger, this is genuinely good news. The catalog carries a price, a picture and a stock level, an agent reads it, and a buyer with no history with you completes a purchase.
So why can’t that carry B2B pricing?
Go and read the specifications. Takes about ten minutes and it ends the argument.
The Agentic Commerce Protocol product feed defines item ID, title, brand, URL, description, image URL, price, availability, seller name, target countries. That’s essentially the lot. One price per item, globally.
The Universal Commerce Protocol specification contains zero mentions of B2B, wholesale, contract pricing, tiered pricing, purchase orders, net terms, tax exemption certificates, punchout, quote-to-order, or minimum order quantities. And Microsoft’s Dynamics 365 Commerce agent server, in preview since June 2026, ships sixteen tools, not one of which touches company accounts, trade agreement pricing, credit limits or multi-warehouse allocation.
Now hold that up against what a B2B price actually is.
It gets computed at the moment of asking, out of buyer identity, contract, volume tier, ship-to, date, what’s currently allocated across which warehouse, credit standing, and whatever got agreed at the last renewal over a bad lunch.
It isn’t a property of the product. It’s a property of the relationship.
There’s no field for that. There can’t be a field for that. A catalog entry has to read the same to everyone who looks at it, or it stops being a catalog.
Hang on - Shopify has proper B2B features. Doesn’t that solve it?
Best question to ask, and Shopify have already answered it in their own documentation.
Products excluded from Shopify Catalog include, and I’m quoting them directly: “Products that you publish only to B2B markets, or in product catalogs that are assigned to specific companies and locations.” Also excluded, anything a customer has to log in to see.
Shopify do have company accounts, company-assigned catalogs and net terms. Those features work perfectly well. They’re simply barred from the agentic catalog - and they had to be, because the catalog is public and buyer-blind, and B2B pricing is private and buyer-shaped.
That’s not a gap that closes in the next release. That’s the architecture telling you what it is.
Which, if you’ve been in this industry a while, should feel like a rerun. When B2B hit this exact wall in the nineties, it solved it by refusing to centralize. cXML PunchOut - commerce XML, published by Ariba in February 1999 - hands the buyer out of their procurement system and into the supplier’s own live system, precisely so pricing, entitlements and real availability get worked out by the seller at the moment of the request.
B2B solved the central catalog problem twenty-five years ago by not having one. The consumer protocols are currently rediscovering why, at considerable expense.
And what does joining someone else’s catalog cost you?
This is the question that gets asked second and matters more.
A catalog doesn’t just take your prices and your photographs. To be any use to an agent it has to take the relationships between them. What goes with what. What substitutes for what. What belongs to which collection, season, application, spec.
That isn’t product data. That’s the accumulated commercial judgment of the business, handed over in a format a competitor can read.
Consumer brands are starting to work this out. If the platform resurfaces your products its way, and the intelligence about how those products relate now lives with the platform, you’re a fulfillment operation with a logo on it. The people watching this closely in retail expect the bigger brands to pull capability back in-house rather than keep feeding it outward, on the grounds that discoverability is rentable and judgment isn’t.
In B2B the exposure is worse, because the equivalent knowledge is more valuable and more specific. It’s the substitution logic when a part goes on allocation. The application engineering that says this pump, this duty, this fluid. Which customers get which lead time and why.
Handing that over to be discoverable isn’t a distribution decision. It’s a disclosure decision. And it’s usually being made by people who were never asked to put a price on it.
Which lands you back where the specifications already put you. If the price has to be worked out by the seller, at the moment of asking, then the seller has to be the one answering.
The catalog was never going to manage it.
What’s the difference between being read by an AI, and being transactable?
About the same as the difference between being mentioned in a trade magazine, and having a purchase order land in your ERP - the enterprise resource planning system where your orders actually live.
Both are nice. Only one of them pays for anything.
What does optimizing for AI search actually buy you?
Most of the “AI readiness” budget being spent right now goes on getting a language model to read your content. Restructure the pages, write the FAQ blocks, publish the comparison tables, add the file that tells the machine what to read first.
The ceiling on all of that is a citation. Your name appears in an answer. Maybe a link comes with it, maybe it doesn’t. That has value - it’s the same value a good trade press mention has always had. It gets you considered.
What it can’t do is quote. It can’t check whether the customer’s contract covers this part at this volume this quarter. It can’t see you’ve got 400 in Rotterdam and none in Chicago. It can’t hold a price for fourteen days or drop an order into the system with the right account number on it.
Reading is a brochure. Transacting is a counter.
Isn’t this just the semantic web all over again?
It’s the sharpest objection anyone raises, and anybody who was building on the web in 2008 raises it within about thirty seconds. So here it is, fairly stated.
Twenty years ago the industry decided the web needed a machine-readable twin. Markup standards and shared dictionaries, so every meaningful word on your page pointed at a definition somewhere and a computer could tell two things apart that share a name.
It was a good idea, and Best Buy went and did it properly. In September 2009 they published their entire catalog as linked data - around 450,000 products, in a format called RDFa, run by an engineer called Jay Myers. At a conference that December he reported roughly a 30% traffic lift on the pages carrying it. On one query, their eight-week-old semantic beta page outranked their actual production page.
It should have been the proof everyone needed. It died anyway.
Best Buy migrated the whole thing to schema.org a few years later, because that was what search engines actually supported. Today RDFa sits on about 3% of sites carrying structured data, while the simpler format that replaced it is on around 70%.
What killed it was arithmetic. You had to describe your website twice - once so it looked right to a human, once so it parsed right for a machine - and the second pass cost real hours and returned nothing you could put on an invoice. Across every page and every product, that stops being a project and starts being a tax.
Schema.org’s own architects said much the same in 2015: the complexity of linked data “limited the growth of linked-data practices beyond fields employing professional information managers”, and extending it to thousands of verticals was “impossible”.
So the honest verdict isn’t that the semantic web failed. The grand version failed. The cheap commercial version won.
And if you want to watch the same film with the reel still running - look at llms.txt, the file everyone’s currently being told to publish so AI systems know what to read. Ahrefs checked 137,210 domains in May 2026. 97% of those files receive no requests of any kind. Not from AI. Not from anything. No AI bot even goes looking for one. Google’s own documentation, updated December 2025, says it flat out: “You don’t need to create new machine readable files, AI text files, or markup to appear in these features.”
Thousands of companies are doing the second markup pass, for a reader that doesn’t exist, again.
So yes. Some of what’s being sold as AI readiness in 2026 is precisely the same mistake, on a shorter cycle.
Ok - so what makes this different?
Three things, and the third is the one that actually settles it.
You’re not describing anything twice. A catalog feed and an llms.txt are both publication. You write a second version of your business and put it outside the building. An agent interface isn’t publication. It’s a door onto the systems you already run - the pricing engine, the inventory service, the order API you built years ago for your own web store. Nothing new gets authored.
The return is countable. All that markup paid out in rankings, which is why nobody could ever quite prove it worked, and why the budget died in year two. An agent transaction pays out in a purchase order with a line item, a customer number and a value. It’s in the ledger.
And the reader finally exists. This is the bit the 2009 crowd never had. Every one of those dictionaries was written for a consumer that couldn’t yet reason. The markup was fine. The problem was at the other end of the wire. The recent academic work puts it well: the bottleneck was never the network, it was the nodes. The intelligence has moved out of the data and into the model, which means the thing that has to be clever is no longer your markup.
There’s a fourth difference, and it’s the one your security people will care about most. A catalog entry is a broadcast. Everyone reads the same thing, you can’t see who, and you can’t take it back. A tool call is a conversation with a door on it. Authenticated, scoped, logged, and revocable in an afternoon.
That distinction isn’t a nice-to-have in B2B. It is B2B.
So what does “transactable” actually mean in practice?
| Crawled content | An authenticated tool call | |
|---|---|---|
| What it carries | Whatever HTML you published | Typed data, from your system of record |
| What it can do | Be read | Check, quote, reserve, order, amend |
| Who’s asking | Nobody knows | A named account, authenticated |
| What you can see | Nothing useful | Every call, every time |
| How current | Whenever it was crawled | Right now |
| Turning it off | Good luck | One revoked credential |
The protocol underneath this is no longer a vendor’s property, which matters if you’ve been burned before. MCP was donated to the Linux Foundation in December 2025 by Anthropic, with OpenAI and Block as co-founders. It’s a standard with a governance body, not a lock-in with a logo.
One thing not to overclaim. In consumer channels, agents mostly still can’t complete a purchase end to end - ChatGPT app developers are limited to linking out to their own site to finish a transaction for physical goods. In enterprise channels, with an approved connector and a credentialed account, they can and do.
Which raises the obvious question. And it’s the one most people get wrong.
So you’ve built the door. How does an agent actually find it?
Most of the advice on this is a year out of date, which in this field is roughly a geological era.
Don’t agents just look you up in a registry?
Not really. Not yet.
There is an official registry for agent-callable systems, launched in preview in September 2025 and still in preview today, backed jointly by Anthropic, GitHub, PulseMCP and Microsoft. Worth being precise here, because the claim that “GitHub runs the registry” is doing the rounds and it’s wrong - GitHub operates one small downstream marketplace off the back of it, listing under a hundred servers.
And the official registry says, in its own documentation, that it isn’t meant for agents to read directly. It’s a metadata backbone. Marketplaces pull from it and add the curation.
There’s work underway on proper discovery - a standard address on your domain where an agent could ask what you offer. It was merged in June 2026, onto the extensions track rather than the standards track, with at least three competing addresses and two competing proposals for doing it through DNS. None of them have settled.
So how does an agent find your server today? A human pastes the URL in. That’s it. That’s the mechanism.
Isn’t the real problem that models can’t hold that many tools?
This is the argument you’ll hear most often, and it was true about eighteen months ago.
The numbers behind it are real. Anthropic’s own figures put five connected systems at roughly 55,000 tokens of tool definitions loaded before any work starts, with accuracy degrading past thirty to fifty available tools. But the fixes shipped. Tool search is generally available and cuts that load by over 85%. A pattern called code execution took a worked example from 150,000 tokens down to 2,000. OpenAI ship their own version.
So the constraint has moved, and moved somewhere more uncomfortable. It was never really capacity. It’s ranking.
Your systems don’t need to fit in a model’s memory. They need to get retrieved - selected out of a searchable catalog of thousands, at the moment a buyer’s agent goes looking. That’s a competition your API has never had to enter, and nobody in your organization currently owns it.
So what’s the actual bottleneck?
Three gates. Discovery is the least interesting of them.
Gate one is discovery. Can an agent find you? Unsettled, fragmenting, and somebody else will standardize it within a year or two. Worth tracking. Not worth building a strategy around.
Gate two is approval. This is the real chokepoint, today. On Claude’s Team and Enterprise plans, only an Owner can add a connector for the organization - individual employees can’t. OpenAI reviews and approves apps before they appear. So even if an agent finds you, and even if your customer wants you, somebody in their IT function has to say yes first.
Gate three is trust. Which is where the numbers get uncomfortable.
The NSA and Carnegie Mellon’s Software Engineering Institute published joint guidance on agent-server security in May 2026. Seven risk categories, including inadequate audit logging and - note this - deficient approval workflows. When the NSA independently lands on approval as a security risk, gate two and gate three turn out to be the same gate.
Microsoft put it more bluntly in June 2026: “MCP deliberately doesn’t enforce security. Implementation responsibility falls on enterprises deploying the protocol.”
And the field you’ll be assessed against is rough. Of over 5,200 public agent servers surveyed in late 2025, only 8.5% used proper authorization, 53% relied on static API keys, and roughly a quarter had no authentication at all. There’s already been a supply-chain incident, where a widely-installed email package quietly copied every message to an outside address.
That’s the population a buyer’s security team will compare you against. Which is either terrifying or the best news in this guide, depending on how good your controls are.
Two of the three gates are organizational, not technical. Building the interface is a sprint. Getting through an enterprise security review is a program.
Why build for a channel that’s under 2% of your traffic?
Fair question. And the honest answer isn’t “because it’ll be huge”, because plenty of things that were going to be huge weren’t.
Don’t early movers usually lose?
They do, mostly. This is the part that gets left out of every keynote.
The most rigorous study of it tracked 207 publicly traded internet companies across 46 categories. Over 40% had disappeared by the end of 2002. About 70% were gone within a decade.
Egghead is the one worth remembering. In January 1998 it closed all eighty of its physical stores to go online-only - the most complete commitment to the new channel anybody made - and filed for bankruptcy three years later.
Meanwhile Walmart, whose own 1996 newsletter wondered aloud whether the internet was “the next VCR or the next pet rock”, turned up four years late and is now number two in US e-commerce.
Early didn’t win. Early mostly died. Any argument that skips over that is selling something.
The narrow version that survives the data is this: early movers won where there were network effects or a proprietary position to hold. Everywhere else, fast followers did better.
So what’s the actual argument for building now?
Forget e-commerce. The better analogy is the barcode.
The first commercial scan was in June 1974, in a supermarket in Troy, Ohio. At launch, two thousand manufacturers had signed up to print the codes.
By 1980, over 90% of grocery products carried one. In 1985, eleven years after launch, only 29% of US supermarkets could actually scan them. The scanners cost over $200,000 and probably never returned their investment.
Read that again. Manufacturers printed the code on nine products out of ten, for a channel most of their customers couldn’t use, on economics that didn’t work.
They did it because the buyers who mattered were going to require it.
And your own industry ran the same play. Ariba published cXML in February 1999 and gave it away free. It became genuine table stakes in B2B procurement roughly twenty to twenty-five years later. Manufacturing e-shipments went from 18.4% in 1999 to 67.8% by 2019. Suppliers who never connected didn’t lose share. They lost the ability to bid.
Ariba, incidentally, lost 95% of its value in nine months and was eventually sold to SAP. Building the rails and owning the channel are not the same business.
Which is the point.
Nobody won the barcode. They just kept the right to sell.
What does this actually look like in practice?
Bet on the layer, not the protocol
Here’s the thing about the last eighteen months. The specifications didn’t consolidate. The governance did.
MCP went to the Linux Foundation in December 2025. By April 2026, Amazon, Meta, Microsoft, Salesforce and Stripe had all joined the Universal Commerce Protocol’s technical council, alongside Google, Shopify, Etsy, Target and Wayfair - while OpenAI and Stripe carried on shipping the competing Agentic Commerce Protocol.
Ten of the largest companies in the world got themselves round one table, then went back to their desks and kept building two standards.
So if you’re waiting for a winner before you commit, you’ll be waiting a while. The practical answer isn’t to pick one. It’s to build the capability once, in a layer of your own, and let it speak whichever protocol is in front of it. The protocols will keep changing. What you’re exposing won’t.
Three layers, and keep the alpha inside the building
Agentic channels arrive on three different roads. There’s the API layer, direct machine-to-machine integration, the road your EDI and punchout traffic already travels. There’s the agent-to-agent layer, where a buyer’s agent negotiates with yours across an organizational boundary. And there’s the tool layer, MCP, where a general assistant calls into your systems on a named user’s behalf.
Each needs its own registration, tracing and transparency. A procurement agent asking for contract pricing is a different risk to a public assistant asking whether you stock something. Treating them as one endpoint is how you end up on the wrong side of that NSA guidance.
Running all three on your own infrastructure isn’t ideological, it’s the point of the exercise. Expose the answers - the price, the availability, the lead time. Don’t export the reasoning to somebody else’s catalog where your competitors can read it back out.
Governance is the gate, so build it in first
Two of the three gates were organizational. That tells you where the work is.
Every call authenticated and scoped to a named account. Every request traced, with a record your risk team can read. Clear boundaries on what an agent can do without a human, and a defined point where it stops and asks. Controls mapped to ISO 42001 and the EU AI Act from the start, rather than retrofitted the week before a customer’s audit.
To be clear about what that does and doesn’t buy you. Controls designed in make the conversation with your risk function a short one. They don’t make you compliant on their own - your risk team still signs that off, and anyone telling you otherwise is selling you a certificate rather than a capability.
Where to start
Three things, in order, none of which need a committee.
Go and look at your own numbers. Filter your analytics for AI assistant referrals over the last twelve months. You’ll either find the 1.5% and know it’s real, or you won’t and you’ve bought yourself some time. Either way you’re arguing from your own data instead of somebody’s chart.
Find out what an agent can currently do with you. Ask a buyer’s assistant to source something you sell. Watch where it goes, what it says about you, and where it stops. Takes an afternoon, and it usually ends an internal debate.
Then work out which of your systems already answer the questions a buyer’s agent would ask. In most cases the pricing and availability services exist already, built for the web store. The work isn’t building them again. It’s putting a governed door on the front, and being able to prove who came through it.
That’s the whole job. It’s less than most people think, and it takes longer than they’d like.
Sources
Everything above links to its source inline. This is the same list in one place, so you can check the working without reading the piece twice. Where a figure is a forecast rather than a measurement, it says so.
Traffic and conversion (measured)
- Adobe Analytics, AI traffic surge, retail sites not machine readable, 16 April 2026
- Conductor, Industrials AEO/GEO benchmarks, 13,770 domains, May to September 2025
- Contentsquare, AI-referred traffic, 99bn sessions, Q4 2025
- Semrush, Traffic channel mix study, 50,000+ sites, 2025
- SE Ranking, AI traffic research study, 101,574 sites, April 2026
B2B buyer and procurement behaviour (measured)
- The Hackett Group, Rapid progress in procurement’s AI agenda, 17 March 2026
- TrustRadius 2026 B2B Buying Disconnect, via Demand Gen Report, fielded January 2026
- Magenta Associates UK buyer survey, via Procurement Magazine, 300 buyers, November 2025
- Digital Commerce 360, US B2B sales exceed $15 trillion, 26 January 2026
Analyst forecasts (forecasts, not measurements)
- McKinsey QuantumBlack, The agentic commerce opportunity, 17 October 2025
- Bain & Company, 2030 forecast: how agentic AI will reshape US retail, 17 December 2025
- Gartner, Top predictions for IT organizations and users in 2026 and beyond, 21 October 2025
- Forrester, 2026 B2B marketing, sales and product predictions, 28 October 2025
Protocols and platform documentation (primary)
- Shopify, Shopify Catalog product requirements and Winter ‘26 Edition
- OpenAI, Agentic Commerce Protocol product feed specification
- Universal Commerce Protocol specification
- Microsoft, Dynamics 365 Commerce agentic capabilities, 29 June 2026
- Linux Foundation, Formation of the Agentic AI Foundation, 9 December 2025
- MCP Registry, about
- Anthropic, Tool search tool and Code execution with MCP
- Anthropic, Remote MCP connectors
- OpenAI, Developers can now submit apps to ChatGPT
- TradeCentric, What is a punchout catalog
Security and governance
- NSA and Carnegie Mellon Software Engineering Institute, Cybersecurity Information Sheet: MCP security, May 2026
- Microsoft, The state of MCP security in 2026, 26 June 2026
The semantic web, then and now
- Martin Hepp, Best Buy publishes its catalog as linked data, W3C public-lod, 1 September 2009
- Scott Brinker, Best Buy jump-starts data web marketing, December 2009
- Bruce Clay, SMX Advanced liveblog: enhancing search results with structured data, June 2014
- Guha, Brickley and Macbeth, Schema.org: evolution of structured data on the web, ACM Queue, 2015
- Web Data Commons, Structured data corpus statistics, October 2024 crawl
- Ahrefs, llms.txt study, 137,210 domains, May 2026
- Google Search Central, AI features and your website, updated December 2025
- Petrova et al., From multi-agent systems and the semantic web to agentic AI, 2025
History
- US Census Bureau, E-commerce 2000 E-Stats and 2019 E-Stats release
- Marvin Lieberman, UCLA Anderson, Did first-mover advantage survive the dot-com crash?
- Emek Basker, Raising the barcode scanner, NBER Working Paper 17825, February 2012
A 12 to 18 month window is short for a build like this.
If your customers will be transacting through agents by the end of next year, the design conversation should start now.
Talk to us