TL;DR
Visa published its Trust Index for agentic commerce on 9 September. Harris Poll, 2,065 US consumers, fielded 26 to 28 May 2026.
23% trust GenAI to handle payment transactions on their behalf. 61% would trust Visa to handle an agentic transaction. Same money, 38-point gap.
72% have used an AI assistant. So at most 32% of assistant users would let one pay, and that is an upper bound.
The subgroup numbers point the wrong way for the AI industry: trust in Visa rises to 68% among 18 to 34s and 71% among frequent AI users. More AI experience moves trust toward the rail, not toward the agent.
ERP already solved a version of this. A purchase order has an approval limit, an audit trail and a reversal path. That is what "trust" decomposes into once you stop asking the question as a feeling.
What did Visa actually measure?
Two questions about the same transaction, asked separately, which is why the result is interesting.
The Visa Trust Index was fielded by The Harris Poll between 26 and 28 May 2026 in the United States, with 2,065 respondents matched to US Census data and per-brand questions answered by 1,028 to 1,034 people each.
The headline pair:
Only 23% of U.S. consumers trust GenAI to handle payment transactions on their behalf.
Visa emerged as the most trusted brand for AI-powered payments with 61% of respondents saying they would trust Visa to handle agentic transactions.
Oliver Jenkyn, Group President at Visa, framed the opportunity: "AI has the potential to fundamentally reshape how people discover, buy and pay for goods and services, much like e-commerce and mobile commerce did before it."
Where does the 38-point gap come from?
Not from the technology, because the technology is the same in both questions.
An agentic transaction is an agent initiating a payment. In the first question the respondent is asked whether they trust the agent. In the second they are asked whether they trust Visa to handle it. The money, the mechanism and the risk are identical. Only the named guarantor changes.
trust the agent with a payment 23%
trust Visa with an agentic payment 61%
gap 38 points
Read one way, that is a problem for AI vendors. Read the other way, it is the operating instruction for the whole category: agentic commerce does not need consumers to trust agents. It needs an institution standing behind the agent that they already trust.
That is not a new pattern. Card networks exist because strangers would not extend credit to strangers. What has changed is that the stranger is now software.
The number that should worry the AI industry
The subgroup breakdown, which is being reported as good news and is not entirely.
Visa reports that its own trust score "maintained this leadership across key demographic groups, rising to 68% among consumers ages 18 to 34 and 71% among frequent AI users."
Note carefully what those two figures measure. They are trust in Visa, not trust in GenAI. Both are the 61% question, filtered.
So the finding is this: the people who use AI most are not the people most willing to let AI hold the money. They are the people most confident in the payment brand. Familiarity with AI raises trust in the rail by 10 points and leaves the agent question where it was.
The optimistic reading of any adoption gap is usually "exposure will close it." This data says exposure closed the wrong half.
What about the 72%?
It sets the ceiling, and the ceiling is lower than the headline suggests.
72% of consumers have used an AI assistant. 23% trust GenAI with a payment. Both are shares of the same total sample, so:
23 / 72 = 32%
At most 32% of people who have used an AI assistant would trust one with a payment. That is an upper bound and it assumes every single one of the 23% is also an assistant user, which is the most favourable possible arrangement of the data. The true figure is at or below a third.
Put plainly: roughly seven in ten adults have tried the technology, and no more than a third of those would let it spend their money. Adoption of the tool has run well ahead of delegation of authority to it, and those are different curves.
Why does this matter for a business rather than a shopper?
Because a procurement agent placing a purchase order is an agent-initiated transaction, and it inherits the same problem with a different vocabulary.
When we modelled what a Dynamics 365 procurement agent actually costs, the arithmetic was the easy half. The hard half is the one Visa just measured on the consumer side: who is accountable when the agent commits money, and what does the person approving it get to see.
The useful move is to stop treating trust as a sentiment and decompose it into the four things it actually means in a finance context:
What "trust the agent" really asks. What answers it
Can it spend more than I intended. An approval limit the agent cannot raise
Can I see what it did and why. An audit trail written at decision time, not reconstructed
Can I undo it. A reversal path that does not require the vendor
Who is liable if it is wrong. A named party in a contract, not a model card
Every one of those already exists in a competently run purchasing workflow. ERP solved this problem for humans decades ago, and the controls transfer. The mistake is treating an agent as a new category of actor rather than as a new kind of requester inside a control structure that already assumes requesters make mistakes.
Is Visa's position here as strong as the number looks?
Strong, and worth reading with one eye open.
What is genuine. Visa is measuring something real and it is measuring it against competitors on the same question, with a disclosed methodology, sample size and field dates. That is more rigour than most vendor research in this space, and the 23% figure is not flattering to anyone selling agents, including Visa's partners.
What to hold lightly. This is research published by the brand that wins it. The finding that consumers trust Visa is convenient for Visa, and the survey ran in the US only, over three days, in May. Nothing in it is wrong; it simply does not tell you what a German procurement director thinks in September.
What it does not measure. Whether the trust survives an incident. Every one of these figures is stated intent from people who have not yet had an agent buy the wrong thing. When we compared how four vendors govern agents, the differences that mattered were all about what happens after something goes wrong, and no survey reaches that.
What should a business do with this?
Put a name on the guarantee. The lesson of the 38-point gap is that trust attaches to an accountable institution. Inside a company that means a person who owns the agent's spending limit, not a policy document.
Set the limit before the pilot, not after. An approval ceiling the agent cannot raise is the single control that converts an open-ended risk into a bounded one, and it is trivial to configure before go-live and awkward afterwards.
Write the audit trail at decision time. A log assembled afterwards answers "what happened". A record written as the decision is made answers "why", which is the question that actually gets asked.
Do not wait for the trust number to rise. On this data, more exposure to AI moved trust toward the payment brand and not toward the agent. If your plan depends on people becoming comfortable with agents in the abstract, the plan has no evidence behind it.
FAQ
What is agentic commerce?
Transactions initiated by an AI agent acting for a person or a business, rather than by the person clicking buy.
Who ran the survey?
The Harris Poll, for Visa, 26 to 28 May 2026 in the United States, with 2,065 respondents matched to US Census data.
Do the 68% and 71% figures mean more people trust AI?
No, and this is the most common misreading. Both are trust in Visa, filtered by subgroup. Trust in GenAI itself stays at 23%.
Is 23% low?
For a technology 72% of respondents have already used, yes. The gap between using a tool and authorising it to spend is the whole story.
Does this apply outside the United States?
The survey does not say. It was fielded in the US only.
The last mile
The most quoted number this week will be 61%. The one worth keeping is 23%, and the one worth thinking about is the pair of them describing the same payment.
Consumers have not concluded that agents are unsafe. They have concluded that safety is a property of the arrangement around the agent, and they are looking for a name on it. That instinct is correct, and it is the same instinct a finance director has when they set an approval limit rather than reading a model's documentation.
Which is the practical shape of this for any business putting agents near money. The question is not whether the model is good enough. It is whether the limit, the trail, the reversal and the accountable owner exist inside the system the business already runs on, before the first agent is allowed to commit a single euro. Building that structure, in the systems that already hold the money, is the layer Cognilium works in.
Share this article
Weekly AI engineering brief
One email a week. New model releases, agent patterns, and lessons from production systems we ship.
No spam, no client data sales. Unsubscribe any time.

Ali Ahmed
AI Solutions Engineer, Cognilium AI
Ali Ahmed
AI Solutions Engineer, Cognilium AI
Ali Ahmed is an AI Solutions Engineer at Cognilium AI.
