The useful difference between ecommerce agents is where their autonomy stops. PayPal's demo stops at payment, a Shopify store agent left spending and design to a person, and an ad tool waits for approval in Slack. Before giving any agent access, ask what it can see, what it can change and what needs approval.
An AI agent filled the cart and took itself to checkout. Then PayPal stopped it and asked for human approval. @debs_obrien and @eddiejaoude ran it live. Here is what happened. 1. Debbie spoke to an agent. 2. The agent compared products, found the right sizes, added to the cart, and opened the checkout on its own machine. 3. At the payment step the agent stopped. 4. PayPal pushes the request to Debbie's phone. She approves it. No card details typed anywhere. That is the part that makes agentic commerce safe to actually use. Here is a teaser, full YouTube video link below 👇
— PayPal Developer (@paypaldev) · View on X
- The demo: In a video shared on September 9, an agent compared products, picked sizes, filled the cart and opened checkout, then stopped at the payment step while PayPal pushed an approval request to the shopper's phone, according to @paypaldev. This is PayPal presenting its own product.
- Other tools stop at other points: An agent called Helena ran a Shopify dropshipping store for about eight weeks, doing product research, storefront builds and browser checks of live pages, while a person kept spend approvals and design decisions (@thekuchh, @chesny); the posts report $10k+ in revenue, not profit. Creatify's Max prepares ad changes for a team to approve in Slack, per @Nozelcode.
- Agents marketed as fully autonomous: @EXM7777 promotes an ad agent that builds creatives, pushes them into a Meta ad account and runs "24/7, no human input required." The post is a marketing claim and shows no results.
- A checklist before giving access: Ask three things of any agent, whether it touches Shopify, Meta or Google Ads, payments or publishing: what can it see, what can it change, and what requires approval? In a sponsored Search Engine Land article on September 15, Optmyzr describes similar layers for ad accounts: better grounding, a policy layer that keeps changes inside set limits, and a review step before anything goes live (source).
Is agent autonomy all or nothing?
No. In the examples above, the stop point sits at payment, at spending, at design decisions or at ad changes, and one tool claims none. Optmyzr's article describes permissions that separate what a connector may do on its own, what it can never do and what it can do with human approval.
Is a fully autonomous ad agent safe to run?
None of the posts above shows results for an agent without an approval step, so there is no public basis to judge it. Automation can also miss business context: on Search Engine Land, Mike Ryan described Google's AI Max expanding a client into a large competitor's searches that the advertiser had deliberately avoided (source).
Where should the limits live?
Optmyzr argues that a rule set on the account holds whichever way a change arrives, which makes it sturdier than instructions written into a prompt. @biektive adds that if an agent can move its own brief into an approved folder, it can approve itself, so approval should sit outside the agent's write permissions (source).
Sources
- @paypaldev on an agent pausing for approval at checkout
- @thekuchh on the Helena store agent
- @chesny on how the Helena loop is set up
- @Nozelcode on Creatify's Max
- @EXM7777 on an ad agent marketed as fully autonomous
- Search Engine Land (sponsored, Optmyzr): 3 ways to make AI safer in a live ad account
- Search Engine Land: Google Ads AI needs guardrails, not blind trust
- @biektive on approval and agent permissions