AGENTIC COMMERCE · VERIFIABLE TRUST

AI agents now buy and sell on our behalf.

WHO VERIFIES THE MANDATE?

In agentic commerce, decisions are instant and automated — and often the only evidence of what happened is what the agent itself claims to have done. We study how to make those actions verifiable by anyone, not just by whoever runs the agent.

THE PROBLEM

When a person or a company delegates authority to an AI agent to act on their behalf in a transaction — searching, negotiating, buying, selling, arranging delivery — that delegation is a mandate. And like any mandate, it has boundaries: what the agent may do, within what limits, for how long, and under what conditions it can be revoked. As long as everything goes well, those boundaries stay in the background. They become the whole question the moment someone — a counterparty, a regulator, or the principal itself, after the fact — needs to know whether they were respected.

Traditional commerce has well-established answers to that question: signatures, documents, intermediaries, and above all time to verify before committing. Agentic commerce has none of these footholds. Decisions happen in fractions of a second, with no human checkpoint, and the record of what happened lives inside the systems of whoever built or operates the agent. Anyone who wants to verify faces a single point of trust: they must believe what the agent — or its operator — claims to have done, with no independent way to check.

This is not a flaw of any particular implementation; it is a structural property of how agentic commerce works today. A counterparty cannot tell an agent that acted within its mandate from one that exceeded it. A principal cannot reliably reconstruct what an agent did in their name. And whoever is tasked with overseeing these exchanges has no third-party vantage point to rely on. As agents take on real economic roles, this asymmetry becomes a limit on trust — and therefore on the adoption of agentic commerce itself.

THE BLIND SPOT

PRINCIPAL — mandate — defined boundaries → AGENT — claim — cannot be independently verified → COUNTERPARTY

The point where trust today has no independent way to be checked.

THE INDUSTRY CONTEXT

This is not a problem we invented. Agent authorization and intent are now recognized as open questions in agentic commerce, and the major international payment networks have launched public initiatives on precisely this front. It is a clear signal that the industry sees the question — who authorized what, and how do you prove it — as a prerequisite for bringing agents into real economic transactions.

Our research starts from one principle: the proof that an agent acted within its mandate should not depend on whoever built or operates that agent. We are working on a trust layer for agentic commerce — a way to make an agent's actions independently verifiable, so that a counterparty, a principal, or a third party can confirm that an action happened as declared without having to take a single party's word for it. We do not describe the mechanism here: this page is about the problem and the direction of our work, not a product.

STATUS

This is ongoing research and development: BinaryCode has filed a patent application in this area and takes part in international fintech innovation programmes. It is not yet a product on the market.

CREDENTIALS

BinaryCode is listed in the Special Section of the Italian Business Register reserved for innovative startups, under Decree-Law 179/2012 — a register supervised by MIMIT, the Italian Ministry of Enterprise — and is a member of the Fintech District community.

What is an agentic mandate?

It is the delegation by which a person or a company authorizes an AI agent to act on their behalf in a commercial transaction. Like any mandate, it has boundaries: what the agent may do, within what value limits, for how long, and under what conditions it can be revoked.

Why is verifying an agentic mandate hard today?

Because in agentic commerce decisions are instant and automated, and the record of what happened lives inside the systems of whoever built or operates the agent. Anyone who wants to verify must trust what a single party declares, with no independent vantage point.

Aren't the agent's or the operator's logs enough?

Logs document what a system claims to have done, but they are produced and kept by the very party that would need to be verified. A counterparty or a third party has no independent way to confirm they are complete or faithful: the point of trust remains a single one.

Does the industry recognize this problem?

Yes. Agent authorization and intent are among the most actively discussed open questions in agentic commerce, and the major international payment networks have public initiatives on this front. It is neither a niche concern nor something we made up.

What is BinaryCode's work on this?

We are working on a trust layer for agentic commerce: a way to make an agent's actions verifiable independently of whoever built or operates it. On this page we stay at the level of principle — it is a research direction, not a product we are presenting.

What is the current state of this work?

It is ongoing research and development. BinaryCode has filed a patent application in this area and is engaged with international fintech innovation programmes. There are no third-party deployments to announce.

Who is BinaryCode?

BinaryCode is an AI-first Italian software house based in Caserta. It is listed in the Special Section of the Italian Business Register reserved for innovative startups, under Decree-Law 179/2012 — a register supervised by MIMIT, the Italian Ministry of Enterprise — and is a member of the Fintech District community.

How can I get in touch about these topics?

Write to info@binary-code.it. We are interested in exchanges with researchers, institutions, and fintech and RegTech practitioners working on agent authorization, verifiability, and governance.

Working on these questions? Let's talk.

Trust in agentic commerce is not a problem anyone solves alone. If you are a researcher, an institution, or a fintech/RegTech practitioner working on agent authorization, verifiability, or governance, we would welcome the conversation. Write to us at info@binary-code.it.

info@binary-code.it