Twenty-three percent of Americans — roughly seventy-six million people — made a purchase using an AI agent in a single month last year, according to Morgan Stanley. None of those transactions took place under a federal framework that defined what an AI agent owed its user, what it could do with their financial data, or who was responsible when it bought the wrong thing.
That changed on June 29, 2026, when Senator Mark Warner released the discussion draft of the Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act — known as the AI AGENT Act — the first piece of U.S. federal legislation written specifically to regulate AI agents as commercial actors. The bill creates a legal category for the agents doing the shopping, obligations for the platforms they shop on, and a federal regulator to referee the whole arrangement. It is a discussion draft, not yet formally introduced in Congress. But its arrival marks a genuine line: Washington now views the AI shopping agent as a subject of federal law, and the rest of the world is watching.
A New Legal Entity: The Custodial User Agent
The Act's foundational move is definitional. It introduces Custodial User Agents — CUAs — as a formal legal category: software agents "expressly authorized by a user to interact with a large online platform provider on that user's behalf in a transparent, documented, scope-limited, and revocable manner."
The word "custodial" is deliberate. It frames the agent not as an autonomous commercial actor but as a fiduciary — an entity with affirmative legal duties to the person it represents. This framing matters enormously. Under prior law, an AI agent that made a purchase on your behalf occupied no clear legal space: it wasn't a consumer (you were), it wasn't a merchant, and existing payment regulation wasn't built for the scenario where a software intermediary — operating on instructions you gave it hours or weeks earlier — initiates a transaction autonomously.
Under the AI AGENT Act, a CUA must:
- Register with the Federal Trade Commission before acting as anyone's representative
- Maintain real-time, auditable records of every action it takes on behalf of users
- Act transparently in the user's best interest at all times
- Signal to third-party platforms that valid user authorization exists
- Give users clear, granular controls to grant or revoke permission
What a CUA may not do is equally defined. It cannot use data gathered while acting for a consumer for advertising, behavioral profiling, sale, or any secondary commercial purpose. The agent can know that you buy running shoes and use that knowledge to find you better running shoes. It cannot sell that knowledge to an athletic-wear advertiser, or harvest behavioral patterns for a data broker. The data serves the delegated task, or it doesn't move. This prohibition directly addresses one of the most commercially sensitive practices in AI agent infrastructure today: many agent platforms currently monetize user behavioral data as a secondary revenue stream, in parallel with the subscription or transaction fees they charge users directly.
Three Layers of Law
The AI AGENT Act operates on three distinct levels, each addressing a different part of the agentic commerce stack.
The user rights layer establishes that customers of large online platforms — services with 50 million or more U.S. monthly customers — have the right to choose at least one FTC-registered AI agent provider to act on their behalf. The platform cannot restrict access to that agent arbitrarily. This is the consumer protection core of the bill: the legal right to delegate.
The platform obligations layer is where the legislation becomes most commercially consequential. Large platforms must maintain interfaces accessible to approved third-party agents on "fair, reasonable, and nondiscriminatory terms" — the FRAND standard borrowed from telecommunications law and standards-essential patents. Functionally equivalent access must be available to competing agents. If a platform changes its interface in a way that blocks or disadvantages an authorized CUA, that change is automatically a violation, and the FTC can act. The platform may block agents for legitimate reasons — revoked user consent, security violations, repeated harmful behavior — but not to protect its own market position.
The federal enforcement layer assigns primary regulatory authority to the FTC, with NIST tasked with developing the technical standards underpinning the framework within 180 days. NIST must identify or develop open protocols for making e-commerce, financial services, messaging, and social media interfaces accessible to custodial agents — covering delegation credentials, revocation mechanisms, identity verification, and auditable action records. Each affected user counts as a separate violation when calculating fines, a provision designed to make large-scale agent misconduct financially existential for providers.
The bill also mandates coordination with the CFPB, FDIC, and OCC on financial services applications — a signal that Warner sees agentic payments as a domain warranting attention from multiple regulators simultaneously, not just the FTC.
The Anti-Gatekeeping Clause
The platform obligations layer deserves more attention than it has received in initial coverage, because it is not just consumer protection legislation. Its practical effect is a sweeping anti-competitive constraint on the largest technology platforms in the world.
Amazon, Google, Apple, Meta, and Microsoft all operate AI agent products of their own. All of them run platforms that qualify as "large online platforms" under the Act's definition. The bill would require all of them to provide equivalent, nondiscriminatory access to competing AI agents — meaning a Google Shopping agent, an OpenAI shopping agent, and a startup's agent must receive functionally the same interface access to Amazon's product catalog, checkout flow, and account management. A user who authorizes a third-party agent to manage their Amazon purchases cannot be funneled away from that agent toward Alexa+ because Amazon controls the interface.
This is not a minor footnote. It is the kind of provision that structurally upends business models built on vertical integration. Amazon's entire strategy with Alexa+ is premised on owning the agent layer that sits on top of the Amazon marketplace. The AI AGENT Act would require Amazon to serve competing agents from that marketplace on equal terms — at the same time that Amazon is investing hundreds of millions in making Alexa+ the dominant consumer agent platform. The same logic applies to Apple's Siri Agent, Google's Gemini in Google Shopping, and Microsoft Copilot in enterprise procurement.
"The coming fight," as one analyst framed it, "is whether security is a genuine shield for users or a convenient moat for incumbents." Large platforms can legitimately block agents that aren't registered, lack valid user consent, or have a history of harmful activity. They will claim those justifications broadly. The FTC will have to adjudicate which claims are genuine and which are anticompetitive theater. The legislative drafters appear aware of this tension: any interface change made with the purpose of blocking an authorized CUA is automatically classified as a violation, placing the burden of justification on the platform.
A Regulatory Pincer: EU + House + Senate, All at Once
The AI AGENT Act doesn't exist in isolation. It arrives at the same moment that two other major regulatory frameworks are converging on agentic commerce — one from Europe, one from the other chamber of Congress.
From Europe, the EU AI Act's full compliance deadline for high-risk AI systems is August 2, 2026 — less than a month away. Agentic commerce systems — agents that make financial decisions, initiate purchases, and access sensitive customer data — are broadly expected to qualify as high-risk under the Act's risk-based framework. Compliance at this level means conducting conformity assessments, registering in the EU AI database, implementing mandatory human oversight mechanisms, maintaining detailed documentation of training data and risk management practices, and establishing transparency obligations with end users. Penalties for non-compliance run to €35 million or 7 percent of global annual turnover, whichever is higher. Any retailer, payment processor, or agent platform with European customers must meet this deadline, regardless of where the company is incorporated.
The EU AI Act is notable for what it doesn't say explicitly: the phrase "agentic commerce" appears nowhere in its 144 pages. Companies must interpret how its general articles apply to their specific agent deployments, and that interpretive work is happening in compressed timeframes, often without clear regulatory guidance.
From Congress, the House's Great American AI Act — a 269-page comprehensive AI governance framework co-authored by Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA), released June 4, 2026 — is simultaneously working through its stakeholder feedback period. The GAAIA takes a different approach from the AI AGENT Act: broad coverage of frontier AI model development, mandatory third-party audits through independent verification organizations, and a controversial three-year preemption of state AI laws (a narrower compromise following the Senate's 99-1 rejection of a 10-year moratorium in July 2025). The GAAIA and the AI AGENT Act are complementary, not competing — one governs how powerful AI models are built, the other governs how AI agents interact with commerce platforms. Together, they describe a federal AI governance architecture that is more complete than anything Congress has produced to date.
Together, these three frameworks — EU AI Act, Great American AI Act, AI AGENT Act — create a regulatory moment that is genuinely unprecedented in scope and simultaneity. In a roughly six-week window this summer, the EU is activating full AI Act compliance, the House is debating comprehensive AI governance, and the Senate is proposing agent-specific commercial law. Agentic commerce is, for the first time, operating in a world where its legal infrastructure is being written in real time on both sides of the Atlantic.
The Structural Debate: Is This Bill Regulating Yesterday's Agent?
The most substantive critique of the AI AGENT Act comes from an analysis published July 8, 2026 by Opus Research, and it is worth taking seriously before the bill's feedback window closes.
The bill, the analysis argues, is built around a specific and fairly narrow vision of how the agent market evolves: consumers subscribe to commercially-hosted AI agent services from providers like Google, OpenAI, or emerging startups; those providers register with the FTC; platforms provide interface access; the FTC maintains the registry. Clean, legible, regulatable.
But there are other ways the market could plausibly evolve in parallel. Self-hosted agents — running on personal hardware, built on open-source models, customized by individuals who don't want or need a commercial provider — could become mainstream as small-model capabilities improve. Enterprise agents — deployed by employers for B2B purchasing, vendor management, and corporate procurement — don't fit neatly into a consumer-authorization model; the "user" in an enterprise setting is often an organization, not an individual. Specialty agents from banks, insurance companies, or healthcare networks operate in sectors with their own existing regulatory frameworks and may not need or want FTC registry status as an additional layer.
If millions of consumers eventually build, customize, or host their own AI representatives, requiring every one to route through an FTC-registered commercial provider starts to look less like consumer protection and more like a barrier to entry that advantages the largest, best-capitalized agent platforms — precisely the entities the bill is meant to constrain.
The Opus Research alternative proposal: shift from certifying organizations to verifying capabilities. Let NIST's standards work become the actual basis for platform access. Any agent that can cryptographically prove its identity, demonstrate delegated authority within defined scope limits, and produce auditable action logs gets platform access — regardless of who built or hosts it. This would make the framework technology-neutral and compatible with the full diversity of agent architectures that may emerge.
Warner's camp would likely respond that capability verification without organizational accountability creates a different problem: who is legally responsible when a self-hosted agent empties a bank account? CUA registration exists precisely to ensure there is a legal entity answerable for agent behavior. Both positions have merit, and the tension between them is the central design question the feedback period is intended to resolve. The answer will determine whether the AI AGENT Act becomes a genuine open marketplace for agent innovation or a credentialing regime that concentrates power in the hands of registered providers.
What Merchants, Brands, and Agent Platforms Need to Do Now
The AI AGENT Act is a discussion draft, not law. But the regulatory direction it signals is unambiguous, and the EU AI Act's August 2 deadline is not a draft at all. Together, they mean that any organization with agent exposure — merchants who want agents to discover and purchase their products, brands who want to influence agent recommendations, and developers building agent platforms — needs to act now rather than waiting for legislation to finalize.
Audit your agent surface area first. Any AI agent that makes purchase decisions, accesses financial data, or interacts with customer accounts will likely be classified as high-risk under the EU AI Act, and as a regulated CUA under whatever form the AI AGENT Act takes. Build a complete inventory of every agent in your stack: the data it touches, the permissions it operates under, the actions it can take autonomously. You cannot revoke what you haven't mapped, and you cannot document what you haven't inventoried.
Implement real-time revocation before it becomes a legal requirement. The single most consequential operational requirement in the Warner draft is user-controlled, real-time revocation of agent permissions — and most enterprise systems cannot currently do this at the required granularity. A right to revoke means nothing until you can specify what is being revoked, from which system, with what immediate effect across every downstream service the agent touches. Analysts reviewing the enterprise governance implications of the bill have flagged revocation as the provision most likely to break existing architectures.
Structure your data for agent legibility. AI agents make purchasing decisions based on structured product data, and the EU AI Act's audit-trail requirements mean your catalog needs to be machine-readable, attributable, and kept current. Investing in clean, standardized, structured product data is simultaneously an AEO (Answer Engine Optimization) strategy for agent discoverability and an early compliance measure for regulatory documentation requirements.
Engage the feedback process directly. Warner explicitly released the AI AGENT Act as a discussion draft before formal introduction — inviting stakeholder input before the bill is finalized. This is genuinely rare legislative practice. The companies operating in agentic commerce have both the incentive and the window to shape what the bill becomes. The formal introduction clock is ticking; the feedback window available today will not exist six months from now.
Watch August 2 closely. The EU AI Act's high-risk compliance deadline is a live event, not a planning horizon. What the European regulators enforce — and what they let pass in these early weeks — will set the practical compliance bar that shapes global industry norms. US companies with EU exposure will be defining their compliance posture in real time. US companies without EU exposure today will be trading with EU companies who have.
The pattern across every major technology transition is that regulation arrives before the market fully understands the technology — and the companies that help write the rules end up better positioned than those who wait to read them. The AI AGENT Act is eleven days old as a public document. The window to influence what it becomes is open right now.
Sources
- Warner Unveils Discussion Draft of the AI AGENT Act — Senator Warner's Official Press Release
- Warner Bill Would Create Federally Vetted List for Secure, Trustworthy AI Agents — CyberScoop
- Senator Warner's Discussion Draft on Securing AI Agents: Top Points — DLA Piper
- US Senator's Draft Legislation Targets Privacy, Safety of AI Agents — Biometric Update
- The AI AGENT Act Assumes One Future for AI Agents. What If We Get Another? — Opus Research
- How the Senate's AI AGENT Act Could Reshape Enterprise AI Governance — CIO
- Consumers Need Protection From AI Agents, Lawmaker Says — CBS News
- Sen. Warner Takes Aim at Runaway AI Agents With First Major Bill — WebProNews
- EU AI Act: What It Means for Agentic Commerce — Edgar Dunn & Company
- EU AI Act Implementation Timeline — artificialintelligenceact.eu
- Unpacking the Great American Artificial Intelligence Act of 2026 — TechPolicy.Press
- Frontier AI Goes Federal: How the Great American AI Act Compares to State Laws — FPF
- Agentic AI in Payments: Key Regulatory Considerations — Taylor Wessing
- Is 2026 the Year of Agentic Payments? — Fenwick
- Senator Warner Proposes AI AGENT Act for Consumer Protection — Global Relay