Agent-to-Agent Commerce

Agent-to-Agent (A2A) Commerce: Selling When Your Buyer Is a Machine

TL;DR

When your buyer is a machine you don’t lose a customer — you lose the ability to persuade one, and gain the obligation to be verifiable to one. A2A commerce swaps the persuasion contract (make the human want it) for a verification contract (let the machine confirm it).

A buying agent has two properties no human shopper has: it acts under a delegated mandate (it satisfies a spec, it has no desire to hijack) and it has persistent memory (it doesn’t re-decide from scratch — it reuses).

Three things move a machine buyer: discoverability, verifiable spec-match, and independent corroboration. The first two are pass/fail gates every competent seller clears. Corroboration is the only one that breaks ties among the qualified, can’t be self-asserted, and compounds through the agent’s memory.

“Optimising for the agent” as if it were a harder-to-please human — running persuasion at a machine — is the central error. Persuasion appears nowhere in the machine-buyer decision pipeline; there is no “desire” stage to hijack.

The instruments: the Machine-Buyer Decision Pipeline (where a seller can and cannot influence the purchase) and the Persuasion-to-Verification Ledger (what every human persuasion lever must become to move a machine). In a market of machine buyers, earned trust is the tie-breaker in the matching function.

1. The buyer with no desire to hijack

Everything the last century of marketing learned, it learned about a human nervous system. The hero image that stops a scroll, the “only two left in stock” that quickens a pulse, the aspirational brand story, the five gold stars glowing above the fold, the retargeting ad that follows you for a fortnight — all of it is machinery for moving a human mind toward wanting. It works because the target has appetites, impulses, memory that fades, and attention that can be captured. Point the same machinery at a buying agent and it hits nothing. The agent has no pulse to quicken, no scroll to stop, no aspiration to flatter, and a memory that does not fade. You are trying to seduce a spreadsheet.

This is the quiet revolution inside agent-to-agent commerce, and it is easy to miss because the loud part is the plumbing — the checkout protocols, the payment rails, the identity standards. Underneath the plumbing sits a change in the nature of the buyer itself. When a machine does the choosing, the entire persuasion contract that governs human commerce is void, and a different contract takes its place. The seller’s job stops being make me want it and becomes let me confirm it. That is not a tactical adjustment. It is a change of what selling is.

The reason this is worth a whole article rather than a memo is that the persuasion instinct is not a tactic you can simply switch off — it is the deep grammar of the entire discipline, and it fails silently. A team that has spent a decade getting better at making humans want things will, confronted with a machine buyer, reach for exactly the levers that no longer work, and the failure will not announce itself as a failure. The pages will still look good. The campaigns will still run. The dashboards will still show impressions. What will quietly happen is that a buying agent, somewhere, will drop the brand at a filter it never knew it failed, and the sale will go to a rival the team never saw. Money spent on persuasion aimed at a machine does not bounce; it is simply absorbed and returns nothing, which is the most expensive kind of spend there is.

A fair objection arrives immediately: almost nobody yet lets an AI fully complete purchases for them. That is true and worth stating plainly — Checkout.com’s June 2026 research found only around 14% of US consumers trust AI to place orders on their behalf, and roughly a quarter say they will never delegate a purchase. But that is the wrong threshold to watch, because the choosing has already gone to the machine even where the clicking has not. Around 43% of US online shoppers used an AI assistant for product research in the last 90 days (MarTech, 2026), and 63% of European shoppers now use AI to compare brands, models, prices and reviews (McKinsey, 2026). Whether or not the agent presses “buy”, it increasingly builds the shortlist — and the shortlist is where selection happens. So “your buyer is a machine” is shorthand for “your chooser is a machine”, and that is not a 2030 forecast. It is the present.

2. From a persuasion contract to a verification contract

To sell to a machine you have to understand what kind of buyer it is, and it is a buyer of a type that has never existed at scale before: a fiduciary with perfect memory. Two properties define it, and neither has any analogue in a human shopper.

First, it acts under a delegated mandate. The human said “find me a quiet burr grinder under £200, delivered by Friday”, and increasingly that instruction is formalised — Google’s AP2, the Agent Payments Protocol built alongside A2A and now backed by more than 60 organisations, encodes the human’s intent as a signed, cryptographic mandate the agent executes against. The agent is not a shopper with a whim; it is an executor bound to a specification. It has no latent desire for your product that clever creative can awaken, because it has no desires at all. It has a constraint set, and it is enforcing that constraint set on the human’s behalf. You are not courting a customer; you are being audited against a spec.

Second, it has persistent memory. A human shopper arrives fresh, forgets last month’s comparison, and can be re-persuaded on every visit. A buying agent remembers. Agentic systems hold cohort-level memory across sessions and channels — in Alhena’s 329-brand dataset, agents that remember a shopper’s history across the journey drove a roughly 4x conversion lift over retrieval-only chatbots. The practical consequence is severe: the agent does not re-open the competition each time. Once it has resolved that your entity best satisfies a recurring mandate, it reuses that resolution rather than re-deriving it, which is why being resolvable as a stable, well-defined entity matters more than any single impression. A won decision compounds; a lost one is not re-litigated on your terms.

Put the two together and the buyer is a memoryful auditor executing a mandate — the exact opposite of the impulsive, forgetful, persuadable human the marketing playbook was written for. This is also why a new discipline, “Know Your Agent” (KYA), is forming alongside the old “Know Your Customer”: when the counterparty is an agent, identity, permissions and behaviour have to be verified rather than assumed. Verification is not a theme of A2A commerce. It is the substance of it.

There is a sharper way to see why this is adversarial to persuasion rather than merely indifferent to it. A good buying agent is, by construction, built to resist exactly the influences persuasion trades in. Its designers know the open web is full of manipulative signals — fake urgency, inflated claims, review padding — and they build the agent to discount them, because an agent that fell for marketing tricks would serve its principal badly and lose to a more sceptical competitor. The commercial pressure on agent-builders runs toward more scepticism over time, not less. So persuasion aimed at a machine is not landing on neutral ground that merely fails to respond; it is landing on ground engineered to detect and down-weight it. The better the agents get, the more completely persuasion inverts from an asset into a liability — a page thick with urgency banners and unverifiable superlatives reads, to a well-built agent, as a signal to be cautious.

3. The instrument: the machine-buyer decision pipeline

If persuasion is void, what replaces it? A procedure. A buying agent resolves a mandate into a purchase by running a pipeline of filters, and a seller can influence some stages and not others. Mapping the pipeline is the whole game, because it shows exactly where effort converts into a sale and where it is wasted. The striking feature, once you lay it out, is what is missing: there is no stage at which the agent forms a desire, so there is no stage for persuasion to act on.

StageWhat the agent doesWhere the seller can influenceGate or tie-breaker?Earnable / buyable?
1. ParseTurns the human’s mandate into a hard spec (budget, “quiet”, by-Friday)Indirect — you choose which specs your product can truthfully meetNeither
2. DiscoverRetrieves the eligible candidate set (feeds, MCP, Agent Cards, its own graph)Discoverability — be machine-readable and in the retrievable setGate (pass/fail)Buildable
3. VerifyChecks each candidate’s claims against the hard constraints; drops the missesStructured, machine-checkable claims — specs as data, not prose or imagesGate (pass/fail)Buildable
4. CorroborateRanks the survivors by trust: reviews, third-party citations, verified reputationIndependent earned corroboration — what others verifiably say about youTHE TIE-BREAKEREarned only
5. SettleConfirms it can transact now — rails, real-time stock, price at this momentEnable the rails (UCP/ACP) and expose real-time availabilityGate (pass/fail)Buildable
6. RecordBuys, then writes the outcome to memory for reuse on the next mandatePost-purchase experience becomes tomorrow’s corroborationCompoundsEarned only

A2A’s own machinery lives in the early stages. Discovery runs on Agent Cards — the JSON-LD capability descriptors A2A uses so agents can find and evaluate one another — and on the feeds and MCP endpoints an agent reads; A2A itself, donated by Google to the Linux Foundation and past 150 supporting organisations at its April 2026 one-year mark, is the coordination layer letting a buyer’s agent delegate to and query a seller’s. But notice where the leverage is. Stages 2, 3 and 5 are gates — pass/fail thresholds any competent competitor will also clear. Stage 4 is the only one that discriminates among the qualified, and stage 6 is the only one that compounds. Everything decisive happens at the two stages a cheque cannot buy.

Dwell on the absence, because it is the whole argument in one observation. A human purchase funnel has an awareness → interest → desire → action shape, and persuasion lives in the middle two stages — it manufactures interest and desire. The machine-buyer pipeline has no interest stage and no desire stage. It goes parse → discover → verify → corroborate → settle → record, and nowhere in that sequence is there a mind to be warmed up or a want to be kindled. There is only a spec to be matched and a reputation to be checked. This is why “make the agent want us” is not a hard problem but a malformed one, like asking what colour a sound is. The agent parses a site the way a reader that is all comprehension and no impulse would: it extracts the facts and discards the mood. Design for the mood and you have addressed a faculty the buyer does not have.

4. Why persuasion goes inert, stage by stage

It is worth walking the death of persuasion deliberately, because the instinct to run the old playbook at the new buyer is strong and expensive. Take the pipeline stage by stage and every classic lever fails to find purchase.

At discovery, an agent retrieves from structured sources; a beautiful page it cannot parse is not “less appealing”, it is absent. At verification, “premium”, “best-in-class” and “loved by thousands” are not weak claims, they are unresolvable ones — the agent cannot check them against a spec, so they contribute nothing; a machine-readable “42 dB noise level” beats a page that merely feels quiet. At settlement, urgency is inert: “only two left” either is or is not true as a real-time availability field, and if it is a manipulation the agent has no adrenal response to exploit. And across the whole pipeline, the agent does not forget between visits, so retargeting — the practice of buying repeated exposure until a human relents — has nothing to wear down. The only thing the agent “remembers” is the verifiable record of what happened last time, which no amount of repeated advertising alters.

The deepest change is at stage 6. Human marketing assumes decay: preferences fade, so you must keep spending to stay front-of-mind. A machine buyer inverts this. Once it resolves a recurring mandate in your favour, it reuses that resolution — it does not re-run the comparison out of forgetfulness, because it does not forget. This turns a single won decision into an annuity and a single lost one into a standing exclusion, and it means the currency of the whole system is not attention captured this quarter but the trust that accumulates and compounds over time. You are not buying moments of desire. You are building a durable, checkable reputation that a memoryful auditor keeps consulting.

Social proof deserves its own autopsy, because it is the lever marketers assume must survive — surely reviews still matter? They do, but not as social proof. To a human, five glowing stars work as a feeling of safety-in-numbers, a vibe absorbed at a glance and easily manufactured with a burst of padded ratings. To an agent, the star average is a data point to be verified, cross-checked against independent sources, and weighed for authenticity — the persuasive glow does nothing, and a suspiciously clean five-star record can actively lower trust rather than raise it. The same input flips from an emotional shortcut into an evidentiary claim. That is the general rule beneath every row of the ledger that follows: assets that once worked by producing a feeling must be rebuilt to survive as evidence, because the machine consumes evidence and is blind to feeling.

5. The Persuasion-to-Verification Ledger

“Optimise for the agent” is good advice stated uselessly, because it does not say what to do with the persuasion assets you already own. The answer is not to discard them but to translate them: every lever that once moved a human has a machine-facing counterpart, and the work is converting a persuasion asset into a verification asset — a structured, checkable, independently corroborated fact. The ledger below does the translation.

Human persuasion leverWhat it does to a machine buyerThe verification asset that replaces it
Hero imagery & designNothing — unparsed pixelsStructured product data: dimensions, materials, specs as machine-readable fields
“Only 2 left!” urgencyNothing — no adrenal responseReal-time availability as a checkable field (true or false, no effect if manipulative)
Brand emotion / aspirationNothing directly — but see §8Third-party corroboration of the qualities the brand claims — earned, not asserted
Star-rating “glow”Read as data, not vibeStructured, queryable reviews plus independent review corroboration the agent can verify
Persuasive copywritingUnresolvable claims = ignoredSpecific, verifiable claims tied to evidence a machine can check against the mandate
Retargeting / remarketingNothing — no memory to wear downA durable corroboration record the agent re-consults on every recurring mandate
“Award-winning” claimIgnored unless verifiableThe award as an independently confirmable third-party citation, not a self-assertion

Read down the middle column and the pattern is stark: most of the persuasion stack does literally nothing to a machine buyer, and the parts that survive survive only once converted into something checkable. The right-hand column is not a list of new tactics; it is the same reputation work — structured facts and the machine-readable, technically sound substrate beneath them — pointed at a reader that verifies rather than feels.

6. The tie-breaker: why corroboration is the only lever that discriminates

Here is the situation any serious seller ends up in. You have made yourself discoverable, your specs are clean machine-readable claims, and your rails are live. So has every competent competitor. The agent runs its pipeline, and at stage 4 it holds a set of candidates that all pass the gates — all discoverable, all spec-true, all transactable. It has to choose among equals, and the gates cannot separate them because they all cleared. What separates them is the one input a seller cannot assert about itself: what independent, trusted third parties verifiably say. Corroboration is the tie-breaker, and in a market where the gates are commoditised, the tie-breaker is the whole contest.

This is not a hopeful claim; it is where the measured signal already points. Ahrefs’ study of 75,000 brands found brand-mention frequency correlated with AI-answer visibility at 0.664, against 0.218 for raw backlink count — corroboration outweighing even the classic link signal. Muck Rack’s May 2026 analysis of more than 25 million citations found roughly 84% of AI citations were earned and 0.3% paid. SE Ranking, measuring citations against referring domains, found sites with up to 2,500 referring domains averaged 1.6–1.8 ChatGPT citations per category prompt while sites above 350,000 averaged 8.4. These are the factors that actually decide which brand an agent names, and they are all species of the same thing: independent parties, at scale, vouching for you in ways a machine can check.

It helps to name the structure this creates. When both sides are represented by agents — the buyer’s agent parsing a mandate, the seller’s catalogue exposed as machine-readable offers — commerce stops being a persuasion funnel and becomes a matching market: a function that pairs mandates with offers. In a matching market the winner is not whoever shouts loudest but whoever best satisfies the match criteria, and once the hard criteria (spec, availability, price) are tied, the match resolves on the soft-but-checkable criterion of trust. This is why commoditisation of the gates is not a threat but the very thing that hands the contest to corroboration: the more competent everyone becomes at being discoverable and spec-true, the more completely the outcome is decided by the one criterion that cannot be commoditised because it cannot be self-issued. A market that clears on trust rewards the party with the deepest independent record.

Corroboration has three properties that make it the durable tie-breaker rather than a temporary edge. It is un-self-assertable — you cannot declare your own corroboration into existence, which is exactly why a verifying agent weights it. It cannot be counter-bid — a richer rival cannot write you out of the independent record with a cheque the way it could outspend you on ads. And it compounds through stage 6 — every corroborated win is remembered and reused, so the reputation that wins this mandate is still there, larger, for the next one. The disciplined way to build it is the ordinary craft of earning independent mentions from the sources that answer engines trust — the same craft catalogued across the link building and digital-PR statistics for 2026.

7. Worked example: Wrenfield sells 40 chairs to a machine

Wrenfield is a UK maker of ergonomic office chairs, roughly £15M revenue, strong human-facing brand, excellent product. A facilities manager at a mid-sized firm needs to re-kit an office and delegates the sourcing to a procurement assistant with a mandate: “ergonomic task chairs, adjustable lumbar, rated to 120 kg, five-year warranty, in stock for delivery within two weeks, budget £350 each, forty units, well reviewed.” No human will browse Wrenfield’s beautifully shot product pages. An agent will run the pipeline.

Wrenfield’s month-0 diagnosis is unkind. Its specs live in marketing prose and inside product photography — “designed for all-day comfort” rather than a structured “120 kg capacity, 5-year warranty” field — so at stage 3 the agent cannot verify the mandate’s hard constraints and drops Wrenfield despite the chair objectively qualifying. Where Wrenfield is discovered and parsed, its independent corroboration is thin: a handful of on-site testimonials, little third-party review presence, few citations in the roundups and trade sources an agent leans on. So on the occasions it clears the gates, it loses the stage-4 tie to a rival with a deeper independent record. The founder’s instinct — commission better photography, add “trusted by 5,000 offices” banners, run a retargeting campaign — is to spend the budget running persuasion at a machine that has no eye, no memory to retarget, and no capacity to take an unverified claim on faith.

The verification plan spends the same money against the pipeline instead. First, clear the gates: convert every mandate-relevant attribute into structured, machine-readable data (capacity, warranty, adjustability, materials, real-time stock), and confirm the rails are live — cheap, fast, and non-negotiable, because a dropped candidate never reaches the contest. Then invest the bulk at stage 4: earn independent corroboration on the attributes procurement mandates actually specify — third-party ergonomic reviews, verified customer reviews at volume, citations in facilities-management roundups, and a genuinely useful interactive tool that earns links and references at scale (an ergonomics-and-warranty comparison the trade press cites), plus corroboration from the technical and practitioner communities that agents treat as trustworthy. Then exploit stage 6: the first forty-chair order, fulfilled well, becomes verifiable history the agent reuses — the reorder next quarter, and the next office, arrive without Wrenfield re-competing for them.

The timeline separates the two plans the way it always does. Month 1: the persuasion plan has prettier pages; the verification plan has clean structured specs and the first independent reviews landing. Month 3: the verification plan clears the gates on the major agents and starts winning stage-4 ties on well-corroborated attributes, while the persuasion plan is still, intermittently, being dropped at stage 3 for unverifiable claims. Month 6: the verification plan is the remembered default for recurring office-fit-out mandates and its wins are compounding through reorders; the persuasion plan has a lovely website and a procurement agent that has never once selected it. Same product, same budget — one spoke to the buyer that exists, the other to the buyer it wished for.

The reorder mechanics are where the machine buyer’s memory turns a win into an annuity, and they are worth making concrete. A human procurement manager might re-run the whole comparison next year, giving every rival a fresh shot. The agent does not; having recorded at stage 6 that Wrenfield satisfied this mandate and fulfilled it well, it treats that as settled and reorders, re-opening the competition only if the mandate’s constraints change or Wrenfield’s verifiable record degrades. So the first forty-chair win is not a one-off £14,000 order; it is the first instance of a recurring order that a competitor now has to dislodge rather than merely win, and dislodging a remembered, well-corroborated incumbent is far harder than beating an unknown. The verification plan’s stage-4 spend, in other words, does not buy a sale — it buys the incumbency that makes the next several sales default to you. That is the compounding the persuasion plan can never reach, because retargeting a buyer with no memory to wear down produces nothing to compound.

8. Where this breaks: the brand bias the machine inherited

The strongest objection to “persuasion is inert” is that the machine is not a blank verifier at all — it is trained on human-generated text and inherits human brand preferences, so the persuasion that built those preferences still moves the machine, just indirectly. The evidence is real and should be conceded without flinching. Studies through 2025–2026 document that LLM recommenders favour globally dominant brands over local ones and carry socio-economic and popularity biases; and a April 2026 analysis by Tandeep Sangra, “Visibility ≠ Credibility”, shows LLMs can surface self-promoted brands as apparently credible purely from co-occurrence patterns in their retrieval data — even eliciting an on-record acknowledgement of the bias from ChatGPT itself. A famous brand does start ahead in the machine’s priors. Persuasion, the objection runs, is not dead; it is capitalised into the model’s weights.

Concede all of it — and then look at what actually carried the advantage across, because it is not what the objection assumes. The brand equity that survives into a model is the equity that left a verifiable third-party trace: the mentions, the reviews, the citations, the coverage. The hero images did not make it in. The urgency banners did not. The retargeting did not. What the model “knows” about a brand it knows because independent sources wrote it down — which means the persuasion that persisted is precisely the persuasion that became corroboration. The objection, followed to its root, confirms the thesis rather than refuting it: the durable form of brand in a machine-read world is corroborated familiarity, and corroboration is earned, not asserted. This is also why the bias skews global over local — global brands have thicker independent records — and why the answer for a challenger is to build that record deliberately, including per-market earned authority where local corroboration is thin.

Two bounds keep the concession from swallowing the argument. First, the inherited prior is a tie-breaker, not a spec-override: the evidence has LLM recommenders showing generally less popularity bias than the collaborative-filtering systems they replace (per Amazon Science’s own study), and a well-specified mandate drops a famous brand that fails the hard constraints — familiarity sits in the same stage-4 slot as corroboration and is itself a form of it, not a licence to skip stages 2 and 3. Second, and less comfortably, the self-promotion finding is a genuine vulnerability: an agent can be fooled into reading manufactured co-occurrence as credibility, which is exactly why the durable tie-breaker must weight independent corroboration over volume, and why timely, genuinely earned coverage — the kind that comes from real newsworthiness rather than self-referential noise — is worth more than a flood of self-published mentions.

It is worth being precise about why independence is the property that matters, because it is the hinge the whole strategy turns on. Co-occurrence you manufacture — your own pages, your own syndication, your own restated claims — is cheap, and anything cheap to fake is, in the long run, cheap to detect and discount; the arms race between manufactured co-occurrence and the agents built to see through it has only one plausible equilibrium, and it favours the sceptic. Corroboration you did not author is expensive to fake precisely because someone else has to choose to say it, which is what makes it informative to a verifier in the first place. So the counter-intuitive discipline is to stop optimising for the quantity of mentions and start optimising for their independence — a smaller number of genuinely third-party, verifiable references outperforms a larger volume of self-referential ones, and gets more robust as the agents improve, not less. The strategy that survives every round of the arms race is the one that was never trying to game the verifier at all.

That points at the real falsifier. If a dominant buying-agent platform began selling selection — letting a brand pay to be preferred over better-corroborated rivals, overriding the verification the agent is supposed to perform — then paid persuasion would re-enter the decisive stage and this argument would weaken. Answer-independence commitments currently fence that off. The day they stop is the day to re-open the question.

9. What to do on Monday

Turn the pipeline into a standing procedure. Before anything else, run what amounts to a mandate-match check on your own offer: pick three realistic mandates a buying agent would receive in your category and ask, for each, whether you are discoverable in the candidate set, whether your mandate-relevant claims are verifiable as structured data, whether independent trusted sources corroborate the attributes the mandate cares about, and whether a good outcome would be recorded and reused. Wherever the answer is no, you have found where a sale is being lost. Run the check per market, too, not just once: because the machine’s inherited bias skews global-over-local, a brand can clear every gate in its home market and still lose the corroboration tie abroad, where its independent record is thinner. The mandate-match check is cheap to run and brutally clarifying — it converts a vague anxiety about “AI shopping” into a specific list of gates you fail and ties you lose.

Then act in pipeline order, because the stages are sequential and effort spent above a failing gate is wasted. Clear the gates first and cheaply: make your specs machine-readable, be present in the feeds and endpoints agents retrieve from, and switch on the commerce rails through your platform — none of it a differentiator, all of it fatal to skip. Then concentrate the real budget where the contest is actually decided, at the earned-corroboration layer that the 15 core strategies keep returning to, prioritising independent sources over self-published volume. Instrument it with the tools that let you audit how agents see and cite you, not just how humans do. And treat every fulfilled order as reputation that compounds, because to a memoryful buyer it does.

The through-line is a single inversion, and it is worth stating as plainly as it deserves. You can no longer make the buyer want you; a machine has no wanting to move. You can only make it able to confirm you — and then, when it must choose among the several offers it can equally confirm, make more independent voices vouch for you than for anyone else. Discoverability and verifiability get you into the contest. Corroboration wins it. That, stripped of everything the old playbook assumed about desire, is the whole of what selling becomes when your buyer is a machine. Get that inversion right and the rest of the playbook rewrites itself; get it wrong and you will keep paying, in full, to court a buyer that cannot be courted.

Leave a Reply

Your email address will not be published. Required fields are marked *

Agentic-Web Protocol Map Previous post The 2027 Agentic-Web Protocol Map: UCP, ACP, A2A and MCP for Marketers
MCP Server Next post Publishing an MCP Server as a Discovery Channel: What It Actually Wins You