AI agents

The sleep app learned to buy. That is the whole game now.

A sleep-tracking game now wants to do your shopping. Not point you to a shop. Do the shopping. That small, slightly absurd promise is the clearest picture yet of where retail is heading, and most retailers are not looking at it.

The app in question is a gamified sleep tracker, and the enthusiasm came from one of its users, a poster who wrote that they “absolutely love that my sleep app is now smart enough to be my own personal shopping assistant” and that “we shouldn’t have to close our game to go buy the things we need to sleep better.” The pitch, in their words: the cute AI agent can “figure out what we need, find the perfect cozy product, and buy it for us right inside the app.” The industry has a drier name for it. Agentic commerce. The user preferred “magic.”

Strip away the glowing shopping bags and the mechanism is stark. The app has your data, the app has your attention, and now the app proposes to have your wallet. Meta is building the same shape at the other end of the scale, with Muse, pitched as a personal AI agent to “get more done” across everyday tasks. A sleep game and a trillion-dollar platform are converging on one idea: the software that sits closest to you should also be the thing that buys for you.

Here is why it matters, and it is not the novelty. For thirty years the contest in retail was for the shelf, then for the search result, then for the feed. Each was a fight to be seen by a human who would then decide. The agent removes the human from the middle of that sentence. The sleep app does not show its user a page of pillows and mist diffusers to browse. It picks one. The moment of truth, the instant an impression becomes a purchase, moves from a shopper’s eye to a model’s judgement. And the model was trained, tuned and paid for by whoever owns the app.

Follow the incentives, because they are the story. When an agent buys “the perfect cozy product,” who defined perfect? The brand that optimised its product page for machine reading, as sellers on the ecommerce forums are already asking how to do. The brand that struck a commercial deal with the platform. The platform’s own private label. Perfect is a slot, and slots get sold. The retailer’s old question was how to rank on the shelf. The new question is what the agent believes about you, and what it costs to change that belief.

There is a harder edge underneath the cosiness, and it deserves naming. To buy for you, an agent needs your payment details, your address and standing permission to spend. One engineer, writing about giving an AI agent shell access, put it plainly: the agent “has everything you have because it is you” as far as the system is concerned. A sleep app that can charge your card while you sleep is a convenience and a surface for things to go wrong, in exactly equal measure. The trust you extend is not to a brand you chose. It is to an intermediary that chose for you.

China worked this out first, as it usually does. Alibaba and JD.com spent a decade collapsing discovery, payment and delivery into a single tap inside a super-app, so the distance between wanting something and owning it shrank to nothing. The West is now arriving at the same destination by a different road, through the AI agent rather than the super-app. The lesson is identical. Whoever owns the last decision owns the margin.

What to watch. Watch for the first agent that buys against its user’s stated wish, quietly steered by a commercial arrangement the user never saw. That is the moment the debate stops being about magic and starts being about disclosure, and it is coming sooner than the glowing shopping bags suggest.

The Roth Read. If you run a brand, stop optimising the page a person reads and start optimising the answer a machine gives. Your next buyer does not have eyes, a budget it can be tempted past, or a reason to remember you fondly. It has permissions, a checkout, and whatever the platform told it about you last.

You gave the agent hands. Did you notice it also has your keys?

Three REST endpoints. Twenty million SKUs. And, if you are not careful, the run of your entire home directory.

The promise being sold for agentic commerce this week is that your shopping bot has a brain and now needs hands. Nobody is putting on the slide what those hands can reach.

The brain-and-hands line comes from CloudStore AI, whose promotion promises to turn any shopping agent into what it calls “a doer”: catalogue, checkout and logistics across 400-plus merchants and 20 million-plus SKUs through three endpoints. It arrives in the same month that Cloudflare launched, on Fortune’s reporting, a permanent identity and wallet for AI agents, with optional guardrails: spending limits and a whitelist of merchants where your agents are allowed to shop. Cloudflare’s own executive told Fortune the first wave will be developers and AI firms buying data, with ordinary consumers a second wave still to come.

Hold those two next to a quieter one. A developer, writing up an afternoon of paranoia, described running a shell tool for his coding agent and only then stopping to ask what “give your AI agent a shell” means at the level of the operating system. His answer, in his own words: the tool “has everything you have because it is you.” SSH keys, cloud credentials, the whole writable home directory, no audit trail. The post is titled, plainly, “AI Agent Has Root”.

Put the three together and you have the real shape of agentic commerce. Not a smarter shopper. A new account holder at the checkout who is not a person.

I have given that instant a name: the Machine Moment of Truth. P&G’s A.G. Lafley gave us the First Moment of Truth at the shelf in 2005. Google’s Jim Lecinski gave us the Zero Moment of Truth at the search results in 2011. Both belonged to the shopper. A hand on the pack, eyes on the ten blue links. The Machine Moment of Truth is the first one that does not. The machine hands the buyer no menu to judge. It returns a verdict, delivered with certainty, and the buyer takes it as the answer. It is the moment the buyer stops choosing and the machine chooses for them.

That is why the hands matter more than the brain. For more than a century the shopper on the other side of your checkout was a human being with a human’s frictions: a moment of hesitation, a second thought at the payment screen, a weakness for a well-placed offer. Retail was built to work on that hesitation. The agent has none of it. It does not linger, it does not take the extended warranty, and it does not forgive a clumsy returns policy. It executes. Every pound spent on persuading a person at the point of sale is aimed at a moment that is quietly moving out of reach.

Now follow the incentives, because that is where the story always lives. Whoever issues the wallet and holds the identity sits between the shopper and every merchant on the whitelist. That is not a payments feature. That is the introduction, owned. Cloudflare is not building a shop. It is building the thing that decides which shops an agent is even permitted to enter. The merchant that is not on the list does not lose the sale. It never gets asked.

The security point is not a footnote. It is the commercial risk. A retailer taking agent traffic is accepting orders from software that, on the developer’s own account, may be running with the full permissions of whoever deployed it. A compromised agent does not abandon a basket. It empties one, at machine speed, across every merchant it can reach, and the fraud desk built for stolen card numbers has never seen that pattern. The limits and the whitelist are not consumer niceties. They are the seatbelts, and they are optional.

Watch who gets to sit in the wallet layer, because that is the new gatekeeper. Watch, too, whether the standards emerging in the West borrow anything from China, where Alipay and WeChat Pay proved long ago that whoever holds identity and settlement holds the ecosystem. The West is about to relearn that lesson through a bot instead of a person.

The Roth Read. Stop asking whether your store is ready for AI shoppers. Ask the colder question: when an agent arrives at your checkout carrying your customer’s credentials and possibly root on its own machine, do you know whether it is friend or foe, and who told you so. The Machine Moment of Truth is already happening, in answers you cannot see, at a speed you cannot interrupt. The hands are here. Decide now whose keys they hold, because the merchant who waves them through blind will not lose a sale. They will lose control of the counter.

The agent will need to prove who it is before it can spend your money

Everyone is racing to build the AI agent that shops for you. Almost no one is answering the question that decides whether it works: when a piece of software turns up at the checkout claiming to act on your behalf, who verifies that it is telling the truth?

That is the quieter half of this week’s agentic-commerce noise, and it is worth pausing on. Amid the fanfare about assistants that run errands, a smaller conversation is happening among the people building the plumbing. Writing on X this week, a GenLayer follower described the project plainly: infrastructure for “the emerging agentic economy”, where AI agents transact and interact autonomously, and candidly admitted that its “direct impact on ordinary daily routines is limited” today. That honesty is more useful than most of the hype around it. It names the gap. The agents are coming; the trust layer beneath them is not built yet.

Hold that next to the other signals crossing the desk this week. One founder put the tension exactly right: everyone wants an assistant that can run errands, nobody wants to hand a chatbot their credit card and hope for the best. Meanwhile the agents are quietly becoming the new front door to commerce, shifting shopping from search-driven browsing to agent-driven decision-making. Two facts, one problem. The demand is real. The guarantees are missing.

Here is why it matters, and it matters most through what I call the machine lens. For a generation, the retailer’s question was how to rank on the shelf, then how to rank in search. The new question is what the machine believes about you, and increasingly, whether the machine at your checkout is even the machine it claims to be. When a human shopper arrives, a brand knows roughly who it is dealing with. When an agent arrives, the retailer faces three unknowns at once: is this agent genuinely acting for the customer it names, does it have the authority to spend, and can the transaction be trusted after the fact if it goes wrong. Answer those badly and you have not built convenience. You have built the most efficient fraud channel in the history of retail.

That is the real work companies like GenLayer are circling. Not the shopping, the settling. Not the recommendation, the reconciliation. An agentic economy does not run on cleverness; it runs on verifiable trust, on some neutral way for one machine to confirm what another machine did and who stood behind it. Get that right and agents become a payment rail every retailer can accept. Get it wrong and every retailer will do what retailers always do with risk they cannot price: refuse it at the door.

This is also where the West should watch China, though not for the reason people assume. China did not win at digital payments by building better wallets. It won by embedding identity, settlement and trust inside a handful of ecosystems, so that when you paid through Alipay or WeChat, both sides knew the transaction would clear and could be resolved. The agentic economy needs the same foundation, and the open question is whether the West builds it as neutral infrastructure or lets a few platforms own the whole rail. That is not a technology choice. It is a power choice.

What to watch. Ignore the demos of agents booking dinner and buying trainers. Watch for the first serious standard that lets a retailer verify an agent’s mandate and settle a disputed agent purchase. The company that owns that verification layer will sit between every brand and every shopping agent, and take a toll on both. That is the position worth tracking, not the chatbot with the friendliest voice.

The Roth Read. Stop just asking whether an AI agent can find your product. Although that in itself is a must. Start also asking whether you can trust the one that turns up to buy it. The retailer that solves verification will accept agents as customers; the one that cannot will treat every one of them as a threat, and in a market where agents are becoming the front door, a locked door is the same as a closed shop.