Lukas Helminger, CEO and co-Founder of TACEO
For anyone watching to see when agentic commerce would start breaking through into everyday online infrastructure, this July’s move from Cloudflare to launch their Monetization Gateway was probably the most significant yet. This means any website, API or dataset can charge AI agents directly for access. It is one of the clearest signs yet that the infrastructure for agentic commerce is here, and that the internet’s advertising-based model could soon give way to a world where software pays automatically for what it uses. However, as all of these payments are public by default, it coopts companies into accepting major privacy risks as part of this shift. Inadvertently, this creates a dream scenario for onlooking competitors to quickly infer highly sensitive corporate strategy – a reality that no compliance team can live with.
Agentic commerce is rapidly gaining traction. By 2028 Gartner predicts that 90% of Business-to-Business (B2B) transactions will be intermediated by AI agents, channelling over $15 trillion through automated exchanges. The majority of these payments will not be happening via legacy finance rails as the average transaction is only around $0.30, below the minimum viable credit card spend of $1.00. For companies to rapidly buy pay-per-use services like APIs, data and compute, agents will need to purchase these resources on blockchains using crypto wallets.
For this reason, the x402 Foundation was launched under the Linux Foundation, working with a coalition of legacy finance and decentralised economy players such as Coinbase, Cloudflare, Google, Visa, Mastercard, Stripe, AWS, Microsoft, Circle and Shopify. This leading open payment standard references the HTTP 402 ‘Payment Required’ status code – a placeholder that sat unused on the web for almost thirty years.
This setup automatically triggers a payment when an agent requests a resource, enabling it to pay instantly without the need for an account, subscription or API key. Agents are already spending at scale on this new payment frontier, with over 100 million payments processed since its launch. The latent demand is larger still, with Cloudflare serving a billion HTTP 402 responses daily across its network. While this momentum is impressive, serious privacy concerns are creating an obstacle to further adoption.
Every transaction is a public record
As x402 payments take place on public blockchains, every transaction is fully visible by default – meaning that anyone with a block explorer can see the amount paid as well as the sender, receiver, and the time of the transaction. This total transparency would be unthinkable for card payments, as providers like Visa and Mastercard do not publicly broadcast who is buying what and when for good reason.
This level of exposure is particularly inappropriate for B2B transactions, which are usually private by default to prevent competitors from getting an insight into company strategy and supplier relationships. For example, a procurement agent buying compute on behalf of a company would have every one of its purchases logged on a public ledger with the amount, vendor and time of transactions fully visible.
A competitor watching that ledger would be able to see all of this and could determine which vendors it uses and at what frequency, infer the rates it has negotiated, identify which services it is scaling up or winding down, and piece together its deployment patterns and operational priorities. This enables competitors to have a continuously updated map of a company’s internal operations. There is a real risk that organisations experimenting with agentic payments might adopt x402 and be unaware of the level of exposure they are subjecting themselves to, especially if they lack experience of blockchain technology. In competitive markets, this can be detrimental.
Adding a privacy layer to agentic payments
Addressing this privacy gap does not require abandoning x402 and building a different infrastructure from scratch. The cryptographic tools needed to bring privacy to this payment standard already exist and have been tested at scale in other contexts. A combination of two well-established techniques: multi-party computation (MPC) and zero-knowledge proofs (ZKPs) can be used to encrypt payment information. MPC allows sensitive data to be processed across multiple independent parties without any single party seeing the full data set. ZKPs enable parties to prove a claim, such as a transaction, without revealing the underlying information – thereby verifying that the MPC was performed correctly and everything is reconciled.
This technology already underpins World ID’s iris-matching verification process, which enables proof-of-human verification for 18 million people across 160 countries. The same cryptographic foundations can be used in payment infrastructure to prevent the disclosure of sensitive details. Applied to x402, these techniques make it possible to keep certain data obscured while still allowing the network to process valid and compliant payments. This approach could begin by obscuring payment amounts and account balances and then progress toward fully private transactions. Regulators and auditors can also be given selective, scoped access to verify compliance, without this disclosure extending to competitors or the open web.
The future of x402
The question is not whether x402 succeeds, with such an influential coalition of companies backing it, it will. The success of this payment standard relies on if users understand that – without a privacy layer – they are publishing their operations online. We can see that agentic payments’ shift into infrastructure is well underway, and the technology to obscure sensitive data already exists. It’s the organisations that can implement it first that will reap the benefits, leaving less prepared peers to juggle the costs of inertia or transparency vulnerabilities.

