Sunday, May 3, 2026 Live updated Sunday next in 4h 53m 26s

— A weekly publication —

The Agentic Commerce Report

A weekly read of everything that moved in agentic commerce — protocols, payment rails, retailer pilots, regulation. Summarised, sourced, and stitched to what came before.

Issue 20 Week of April 20–26, 2026 3 events · 7 sources
This week's lead Pilots · Security · Standards

Ulta Beauty Deploys Gemini Checkout; Google Publishes Prompt Injection Study

Ulta Beauty deployed a Google Gemini-powered checkout assistant this week 1, integrating conversational product guidance with direct purchase completion via Google Pay. The assistant handles product recommendations, shade matching for cosmetics, and checkout without leaving the conversation interface. Google’s security team simultaneously published an empirical study on prompt injection in agentic commerce systems 2, documenting attack patterns and success rates across a controlled sample of deployed agent checkout deployments.

The Google Security study catalogued five injection vector categories — system prompt override, tool-call manipulation, data exfiltration via crafted merchant responses, session token hijacking, and scope escalation — and measured success rates against a panel of anonymised deployed systems. The methodology cites vulnerability patterns consistent with those described in Visa’s PERC report from November 2025 3, extending that qualitative taxonomy with quantitative measurements.

The Universal Commerce Protocol (UCP) Tech Council announced additional member organisations this week 4, expanding the standards body formed in January 2026 5. Ulta Beauty’s Gemini deployment is the first specialty retailer pilot in the dataset, following large-format retail (Walmart 6) and marketplace (Amazon Rufus 7) deployments earlier in the tracking period.

Three lanes active in the same week — Pilots, Security, and Standards — matches the multi-lane density of w42, w47, and w13. The Security lane recorded its second event, the first being the Visa PERC report eighteen weeks prior 3; the injection study is the first empirical/measurement publication in the security category.

The chronological register

Today
Event types Product launch Standard / spec Regulation M&A / funding Hollow shapes denote announced, not shipped

Previous issues

21 issues
  1. No. 19 Week of April 6–12, 2026 Visa Launches Intelligent Commerce Connect for Agent Transaction Routing
  2. No. 18 Week of March 23–29, 2026 OpenAI Ends Instant Checkout; FCA Names Agentic Payments a 2026 Priority
  3. No. 17 Week of March 16–22, 2026 Visa Launches Agent-Commerce Certification Programme for European Merchants and Issuers
  4. Archive View all 21 issues