1700년대 초 선박들로 가득찬 영국 런던 항구의 모습(왼쪽). 상인들은 이 배들의 위험을 인수하기 위해 타워 스트리트에 있는 로이드 커피하우스(가운데)에 모였다. 이 그림은 데릭 루커스가 그린 것으로, 17~18세기 사업가들은 개인 사무실 대신 커피하우스에 모여 비즈니스를 하고 정보를 나눴다. 오른쪽 시각물은 AI에이전트가 스마트폰 화면에서 결제 버튼을 누르는 모습을 제미나이를 통해 형상화한 것이다.  [로이드 선급 재단(LRF) 헤리티지 센터 홈페이지]
1700년대 초 선박들로 가득찬 영국 런던 항구의 모습(왼쪽). 상인들은 이 배들의 위험을 인수하기 위해 타워 스트리트에 있는 로이드 커피하우스(가운데)에 모였다. 이 그림은 데릭 루커스가 그린 것으로, 17~18세기 사업가들은 개인 사무실 대신 커피하우스에 모여 비즈니스를 하고 정보를 나눴다. 오른쪽 시각물은 AI에이전트가 스마트폰 화면에서 결제 버튼을 누르는 모습을 제미나이를 통해 형상화한 것이다. [로이드 선급 재단(LRF) 헤리티지 센터 홈페이지]

1688년, 해상 무역에서 가장 가치 있는 부동산은 창고나 조선소가 아니었다. 영국 런던의 타워 스트리트(Tower Street)에 있던 어느 커피하우스였다. 에드워드 로이드(Edward Lloyd)가 운영하던 그곳의 커피 맛은 평범했다. 하지만 그 공간을 특별하게 만든 건 나무 벤치에서 이뤄지던 의식이었다. 상인이 선박, 선장, 항로, 화물, 계절 등 항해에 대해 설명하면 방 반대편에 있던 낯선 사람이 걸어와 펜을 들고 그 설명 아래에 자신의 이름을 서명했다. 배가 돌아오지 못할 경우 자신이 돈을 지급하겠다는 동의였다. 오늘날에도 이 행동을 가리키는 단어가 사용된다. 우리는 그를 언더라이터(Underwriter·인수업자)라고 부른다. 로이드의 커피하우스에서 발명된 건 정확히 말해 보험이 아니었다. 아무도 측정할 수 없는 위험 아래에 기꺼이 자신의 이름을 적어 넣겠다는 의지였다. 결과적으로 그게 대양을 가로지르는 해상 운송을 가능케 한 원동력이었다.

338년이 흐른 지금, 동일한 문제가 새로운 장소에서 나타나고 있다. 자율형 AI 에이전트가 인간을 대신해 행동하려 한다. 여행을 예약하고, 장바구니를 채우고, 계약서에 서명하고, 대금을 결제하는 일들을 인간이 확인하는 것보다 빠른 속도로 처리한다. 최근 연구에서 필자는 이를 ‘측정 가능성 공백(Measurability Gap)’이라고 불렀다. 기계가 값싸게 실행할 수 있는 영역과 인간이 저렴하게 검증할 수 있는 영역 사이의 거리가 점점 더 벌어지고 있는 현상을 말한다. 컴퓨팅 파워는 전자(前者)의 비용을 계속 낮추고 있다. 후자의 비용을 줄이기 위해 평가 시스템, 관측 가능성 인프라, 에이전트가 실제 세계에 투입되기 전 연습할 수 있는 시뮬레이션 환경 같은 새로운 도구가 개발되고 있다. 도구들은 분명 발전하고 있지만, 격차를 좁히진 못하고 있다.

이 공백 속에서 에이전트 상거래(Agentic Commerce)의 결정적 제약 요인은 ‘에이전트가 행동할 수 있는가’가 아니다. ‘그 에이전트가 저지른 행동을 누군가 책임질 용의가 있는가’다. 이 질문이 핵심이 되는 순간, 에이전트 기업들은 더 이상 컴퓨팅 파워로 인해 범용화된 ‘순수 자동화 기술’로 경쟁하지 않는다. 대신 ‘언더라이팅(위험 인수) 능력’을 두고 경쟁하기 시작한다. 이제 상품은 에이전트 그 자체가 아니라 ‘면책이 보장된 결과’다. 일레븐랩스(ElevenLabs)는 이미 보험이 결합된 대화형 음성 에이전트를 출시하기 시작했다. 에이전트의 행동을 공식적으로 언더라이팅해 제품을 출시한 최초의 AI 벤더가 된 것이다. 이른바 ‘서비스형 책임(Liability-as-a-Service, LaaS)’의 등장이다.

소프트웨어는 지난 40년 동안 코드가 무슨 짓을 하든 책임을 부인하는 ‘있는 그대로(AS IS)’ 조항 하에 판매돼 왔다. 하지만 코드가 사용자를 대신해 돈을 쓸 수 있게 된 순간, 이러한 태도는 더 이상 유지될 수 없다.

뱅크아메리카드(BankAmericard·비자카드의 전신)는 1958년 캘리포니아주 프레스노 지역에서 낯선 이들에게 요청받지 않은 카드 6만장을 무작위로 우편 발송하며 시작됐다. 이것을 성공하게 만든 건 플라스틱 카드가 아니었다. 마을의 어떤 상인이든 어떤 고객의 카드라도 아무런 관계 없이 받아들일 수 있도록, 은행이 소비자 신용 위험을 흡수하겠다고 내린 결정 덕분이었다. 페이팔(PayPal)은 한 세대 뒤에 똑같은 마술을 부렸다. 온라인 상거래는 인터넷 속도에 맞춰 낯선 사람 간의 거래를 안전하게 느껴지도록 만들어 줄 누군가를 기다리고 있었다. 페이팔은 두 당사자 사이에 서서 사기 피해를 스스로 떠안았고, 이를 통해 이베이(eBay) 경제의 빗장을 풀었다. 아마존(Amazon)은 동일한 논리를 소비자 경험으로 전환했다. 고객은 판매자를 평가할 필요가 없다. 아마존이 처음부터 반품과 환불 비용을 비즈니스 모델에 반영해 발생하는 모든 실망스러운 상황을 자신들의 비용과 일정으로 해결해 주겠다고 사전에 동의했기 때문이다.

이 혁신들은 당시에는 결제나 유통의 혁신처럼 보였다. 하지만 실제로는 모두 ‘책임(Liability)의 혁신’이었다. 참가자들이 스스로 인수할 수 없었던 위험의 범주를 누군가가 대신 떠맡았고, 그 대가로 수십 년 동안 독점적 이익을 누렸다.

이 가운데 어느 것도 기술의 실패가 아니다. 인터넷 초기 시절의 패턴이 반복되고 있는 것뿐이다. 듣지도 보지도 못한 판매자가 엮인 거래, 혹은 내가 직접 만들지 않아 완전히 신뢰할 수 없는 시스템이 개입된 거래를 누군가 총대 메고 보증해주기 전까지는, 한쪽이 다른 한쪽을 이미 완전히 책임지고 있는 ‘안전한 울타리’ 안에서만 거래하는 게 안전한 기본값(default)이다. 초기 이커머스 시장이 그랬듯, 개방형 AI 에이전트 커머스의 문을 여는 비결도 결국 동일하다. 사용자가 마주할 생소한 위험 요소를 기꺼이 대신 떠안아 줄, 믿을 만한 제3자가 나타나는 것이다.

아메리칸 익스프레스는 자사의 폐쇄형 분쟁 해결 시스템을 등록된 에이전트들로 확장했다. 비자와 마스터카드 역시 에이전트 전용 토큰과 신뢰 기반 프로토콜을 바탕으로 개방형 분쟁 해결 시스템을 출시했다. 이들의 뒤를 받치고 있는 건 수천억 건의 카드 거래 데이터를 학습한 사기 예측 모델로, 전 세계에서 가장 방대한 결제 사기 데이터 집합이다. 스트라이프(Stripe) 역시 지난 10년간 이와 맞먹는 규모의 온라인 거래 데이터를 바탕으로 자체 모델을 구축해 왔다. 하지만 이 중 그 어떤 것도 아직 완벽한 정답은 아니다. 이 시스템들은 아무도 검증하지 않은 일반 상점들 사이에서 AI 에이전트들이 자유롭게 결제하고 다닐 수 있기 위해, 반드시 선행돼야 할 ‘금융 리스크 책임 기반(언더라이팅 레이어)’이 어떤 모습일지 미리 보여주는 예고편에 불과하다.

판매자(상점) 측 역시 똑같은 문제의 또 다른 버전을 겪고 있다. 오늘날의 웹사이트들은 캡차(CAPTCHA), 사기 방지 규칙, 네트워크 외곽 방어 시스템 등 ‘자동화된 트래픽(봇)은 기본적으로 적대적’이라는 전제 아래 봇의 접근을 막는 데 최적화돼 있다. 하지만 AI 에이전트가 정당한 구매자로 부상하면서 질문은 정반대로 뒤집힌다. ‘좋은 편’과 ‘나쁜 편’의 기준이 더 이상 ‘인간’과 ‘봇’으로 깔끔하게 나뉘지 않는 상황에서, 어떻게 해야 올바른 에이전트는 들여보내고 불량한 에이전트는 걸러낼 수 있을까. 최근 떠오르는 해법은 금융권의 고객 확인 제도(KYC)를 의도적으로 패러디한 ‘에이전트 확인 제도(KYA·Know Your Agent)’라는 이름으로 불린다. 이는 앞서 언급한 리스크 책임(언더라이팅)이 한 축을 담당하는 거대한 문제에서, ‘신원 인증’이라는 나머지 절반의 축을 구성하는 개념이다. 이 두 가지 축 중 어느 하나도 홀로 작동할 수는 없다.

신원 확인만 있고 리스크 책임이 없다면 미완성에 불과하다. 게다가 리스크 책임은 훨씬 더 풀기 어려운 숙제다. 그동안 카드 네트워크는 도난당한 카드 번호나 물건을 보내지 않는 상점처럼, ‘측정 가능한 위험’의 단가를 산정하는 데 수십 년을 바쳐왔다. 하지만 에이전트 커머스가 가져올 위험은 그 형태부터 다르다. 인간이 실시간으로 감시할 수 없는 타임라인 속에서 사용자를 대신해 내려지는 자율적인 결정들, 여러 에이전트가 연쇄적으로 작동하며 인계 단계마다 책임이 흐려지는 처리과정이 바로 그것이다. 이 시스템이 작동하려면, 누군가가 새로운 세기를 향한 에드워드 로이드의 질문에 답을 내려야만 한다. 과연 누가 이 위험천만한 ‘에이전트의 항해’ 밑에 자신의 이름을 기꺼이 서명하며 책임을 지겠다고 나설 것인가.

카드 네트워크는 지난 50년간 분쟁 해결, 사기 예측 모델, 대차대조표, 가맹점 네트워크 등 정확히 그 일을 해내기 위한 기반을 다져왔다. 출발선은 그들이 확실히 앞서 있다. 하지만 ‘그들이 올바른 데이터를 쥐고 있는가’는 완전히 별개의 문제다. 그들이 보유한 거대한 데이터 세트는 어디까지나 카드 번호 도난, 가맹점의 사기 공모, 차지백(환불) 악용 같은 ‘카드 거래의 실패 기록’일 뿐이다. 환각 현상으로 엉뚱한 상품 식별 코드(SKU)를 만들어내거나, 권한을 넘어서는 구매를 하고, 프롬프트 주입(Prompt Injection·AI 가짜 명령어 공격)에 당하거나, 다중 에이전트 협업 과정에서 목표를 잃어버리는 등의 ‘새로운 방식의 AI 오류’는 그 데이터에 존재하지 않는다. 사실 아직은 그 누구도 이런 데이터를 가지고 있지 못하다.

에이전트 커머스의 성패를 가를 ‘검증의 선순환 바퀴’는 이제 겨우 구르기 시작했을 뿐이다. 에이전트의 오류가 실제로 발생하는 지점에 가장 가까이 있는 플레이어들이, 기존 카드 네트워크가 결제망을 확장하는 것보다 더 빠르게 이 플라이휠을 돌릴 수 있다고 주장하는 것도 제법 일리가 있다. 거대 언어 모델(LLM) 공급자들은 에이전트의 판단 과정을 실시간으로 들여다본다. 에이전트 거래의 파이프라인을 구축하고 있는 핀테크 기업들은 에이전트와 상점이 만나는 접점에 위치해 있다. 클라우드플레어(Cloudflare)는 개방형 웹 트래픽의 5분의 1을 관측하며 에이전트들의 움직임을 감시한다.

신원 확인 역시 양 진영이 맞붙는 독자적인 전장이다. 소비자 측면에서는 애플과 구글이 그 누구도 흉내 낼 수 없는 방식으로 에이전트를 실제 검증된 인간과 결속시킬 수 있다. 반면 상점 측면에서는 인간 판매자를 검증하던 KYB(기업 확인 제도)를 에이전트 흐름으로 누가 확장할 것인가가 열린 과제다. 이미 온라인 커머스의 상당 부분에서 이 인프라를 운영 중인 스트라이프가 카드 네트워크를 제외하면 가장 유력한 후보자다.

결국 ‘서비스형 책임’이 거대한 해자(moat·垓字)가 될 것이다. 그리고 이 해자를 차지하는 주인이 과연 누가 될 것인가가 다가올 10년의 가장 결정적인 질문이다.

(Left) The Port of London filled with ships in the early 1700s. Merchants gathered at Lloyd’s Coffee House on Tower Street (Center) to underwrite the risks of these voyages. This painting by Derek Lucas depicts how 17th and 18th-century businessmen met in coffee houses to conduct business and exchange information instead of having private offices. (Right) The visual representation on the right, generated via Gemini, illustrates an AI agent pressing a payment button on a smartphone screen. [Source: Lloyd’s Register Foundation (LRF) Heritage Centre Website]
(Left) The Port of London filled with ships in the early 1700s. Merchants gathered at Lloyd’s Coffee House on Tower Street (Center) to underwrite the risks of these voyages. This painting by Derek Lucas depicts how 17th and 18th-century businessmen met in coffee houses to conduct business and exchange information instead of having private offices. (Right) The visual representation on the right, generated via Gemini, illustrates an AI agent pressing a payment button on a smartphone screen. [Source: Lloyd’s Register Foundation (LRF) Heritage Centre Website]

Bot Chargebacks, Voyages, and AI Liability

In 1688, the most valuable real estate in maritime commerce wasn’t a warehouse or a shipyard. It was a coffeehouse on Tower Street. Edward Lloyd ran it. By most accounts, the coffee was unremarkable. What made the place was the ritual that happened on its wooden benches. A merchant would describe a voyage - the ship, the captain, the route, the cargo, the season - and a stranger across the room would walk over, take a pen, and sign his name under the description. He was agreeing to pay if the ship didn’t come back. We still use the word for what he was doing. We call him an underwriter. What was invented at Lloyd’s wasn’t insurance, exactly. It was the willingness to put a name under a risk nobody could measure - and that turned out to be what made it possible to ship across an ocean.

Three hundred and thirty-eight years later, the same problem is showing up in a new place. Autonomous AI agents are about to act on our behalf - book trips, fill carts, sign contracts, settle bills - faster than any human can check what they did. In recent work, we’ve called this the Measurability Gap: the widening distance between what machines can cheaply execute and what people can cheaply verify. Compute keeps pushing the first down. We are building new tools to lower the second - evaluation harnesses, observability infrastructure, simulated environments where agents can rehearse before they touch the real world. They are getting better. They are not catching up.

In that gap, the binding constraint on agentic commerce isn’t whether the agent can act. It’s whether anyone is willing to stand behind what it did. Once that becomes the question, agentic firms stop competing on raw automation - which compute has commoditized - and start competing on underwriting capacity. The product is no longer the agent. It is the indemnified outcome. ElevenLabs has begun shipping its conversational voice agents with insurance attached - the first AI vendor to ship product with the agent’s actions formally underwritten. Liability-as-a-Service.

Software has been sold for forty years under an “AS IS” clause that disclaims liability for whatever the code does - a posture that becomes untenable the moment the code is allowed to spend money on a user’s behalf.

This isn’t a new pattern. Every wave of payments innovation has, in retrospect, been a Liability-as-a-Service moment. BankAmericard launched in Fresno in 1958 by mailing 60,000 unsolicited cards to strangers. What made it work wasn’t the plastic - it was the bank’s decision to absorb the consumer-credit risk so that any merchant in town could accept a card from any customer, no relationship required. PayPal did the same trick a generation later. Online commerce had been waiting for someone to make stranger-to-stranger transactions feel safe at internet speed; PayPal stood between the two parties, ate the fraud, and unlocked the eBay economy. Amazon turned the same logic into a consumer experience. The customer doesn’t have to evaluate the seller, because Amazon has agreed in advance to make any disappointment go away - at its own cost, on its own timeline, with returns and refunds priced into the model from day one.

Each of these looked, at the time, like a payments or retail innovation. Each was actually a liability innovation. Somebody underwrote a class of risk the participants couldn’t underwrite themselves, and captured the rents on it for decades.

For now, agentic commerce mostly happens behind walls. Walmart’s Sparky lives inside Walmart’s app. Amazon’s Buy For Me runs on Amazon’s stored credentials and Amazon’s chargeback record. Alipay’s AI Pay does the same thing for Chinese merchants and is currently moving faster than any U.S. equivalent -over 100 million users and a single week last quarter that cleared 120 million agent-initiated transactions. OpenAI scaled back its broader Instant Checkout effort last spring after only a handful of merchants went live; ChatGPT now handles discovery and routes the actual purchase back to the retailer’s own app. None of this is a failure of the technology. It’s the early-internet pattern repeating: until somebody is willing to stand behind transactions involving merchants you’ve never heard of and agents you didn’t write yourself, the safe default is to transact only inside walls where one party already underwrites the other side. The unlock for open agentic commerce is the same as it was for open e-commerce - a credible third party willing to absorb the unfamiliar.

American Express has extended its closed-loop dispute machinery to registered agents. Visa and Mastercard have shipped open-loop equivalents built around agent-specific tokens and trusted-agent protocols. Behind them sit fraud-underwriting models trained on hundreds of billions of card transactions - the most comprehensive corpus of payment fraud anywhere. Stripe has spent the last decade building its own model on online-transaction data at comparable scale. None of these is the answer yet. They are previews of the underwriting layer that has to exist before agents can transact freely across merchants nobody curates.

The merchant side has its own version of the same problem. Today’s websites are optimized to keep bots out - CAPTCHAs, fraud rules, edge defenses, an entire industry built on the assumption that automated traffic is hostile by default. As agents become legitimate buyers, the question inverts: how do you let in the right ones and keep out the wrong ones, when “right” and “wrong” no longer map cleanly onto “human” and “bot”? The emerging answer goes by the name Know Your Agent, deliberately echoing KYC. It is the identity half of a problem whose other half is underwriting. Neither half works alone.

Identity without underwriting is incomplete; underwriting is the harder half. Card networks have spent decades pricing risks they could measure - a stolen card number, a merchant who never ships. Agentic commerce introduces a different shape of risk: autonomous decisions taken on a user’s behalf, over horizons no human watches in real time, in workflows where multiple agents act in sequence and responsibility blurs at every handoff. That works only when somebody has answered Edward Lloyd’s question for the new century: who is willing to put their name under each agentic voyage.

The card networks have spent fifty years building exactly that machinery - disputes, fraud models, balance sheets, merchant relationships. They have the head start. Whether they have the right data is a different question. The corpus they own is a record of card-transaction failure: stolen numbers, merchant collusion, chargeback abuse. The new failure modes - hallucinated SKUs, scope-violating purchases, prompt-injected agents, goal misgeneralization across multi-agent workflows - are not in it. Nobody’s is.

The verification flywheel that will matter for agentic commerce is barely turning. The players closest to where agent failures actually happen have a plausible claim to building it faster than the networks can extend theirs. Foundation-model providers see the agent’s decision. The fintechs assembling the plumbing for agentic transactions - Stripe most visibly - sit at the seam between agent and merchant. Cloudflare watches agent traffic across a fifth of the open web.

Identity is its own contest, with two sides. On the consumer side, Apple and Google can bind an agent to a verified human in ways nobody else can. On the merchant side, the open question is who extends KYB from human merchants to agentic flows - Stripe, which already runs that infrastructure for a meaningful share of online commerce, is the most plausible non-network bid.

Liability-as-a-Service is the moat. Whose moat it becomes is the next decade’s question.


hongi@heraldcorp.com