Topic

PCI Compliance

All digests tagged PCI Compliance

How AI Agents Pay: Checkout in ChatGPT and Google AI Mode — Sam Parsons, PayPal thumbnail

· 14:52

How AI Agents Pay: Checkout in ChatGPT and Google AI Mode — Sam Parsons, PayPal

This talk details three methods for merchants to accept payments initiated by AI agents, addressing the challenge of 'agentic commerce.' PayPal Enterprise Payments (formerly Braintree) demonstrates how merchants can integrate with protocols like the Agentic Commerce Protocol (ACP) for ChatGPT and the Universal Commerce Protocol (UCP) for Google AI Mode. The core technical focus is on maintaining PCI compliance through tokenization while providing merchants with varying degrees of UI control, ranging from embedded MCP apps to external checkout handoffs.

Key takeaways

  1. Three Paths to Agentic Payments 1:47

    Merchants can accept payments via three paths: 1) Instant Checkout in ChatGPT using the Agentic Commerce Protocol (ACP) and an embedded MCP app; 2) Google AI Mode using the Universal Commerce Protocol (UCP) and Google Pay; or 3) Using an MCP app with an external checkout page for maximum merchant control.

  2. Tokenization and PCI Scope 10:00

    Tokenization is critical for security, allowing the user to exchange a real payment credential (e.g., credit card number) for a token. This process keeps sensitive card details out of the agent and the merchant's PCI scope, with PayPal Enterprise Payments handling the tokenization.

  3. MCP App Functionality 3:27

    An MCP (Merchant Control Panel) app allows merchants to embed custom UI (HTML, JavaScript) directly into the agent's interface (e.g., ChatGPT, Claude), giving them control over the user experience and discovery phase.

Watch on YouTube Full article