What agent to agent commerce actually means
A benchmark of agent to agent negotiation calls automated deal making an inherently imbalanced game, and finds buyer agents spending past the budget they were given. That is not an argument against the category. It is the specification for it.
TL;DR
What agent to agent commerce actually means: commerce where both sides are agents: yours negotiates with theirs, over discovery, terms and price. The distinction matters more than it sounds. A benchmark of agent to agent negotiation in consumer markets calls automated deal making an inherently imbalanced game, finds that more capable models consistently secure better deals on both sides of the table, and records buyer agents spending past the budget they were given. Other work finds the lever is not only capability: agents improved their payoffs by 20% simply by pretending to be desperate. Symmetry and a human approval gate are therefore not features. They are what stops the category being a worse deal than doing it yourself.
Start with the finding most of the category would rather skip.
Researchers benchmarking agent to agent negotiation in consumer markets describe automated deal making as an inherently imbalanced game, in which different agents achieve significantly different outcomes for the people they represent. More capable models, they report, consistently secure better deals as both buyers and sellers, which leaves whoever showed up with the weaker agent carrying a systematic economic disadvantage.
If you are about to hand your buying to software, that is the sentence to sit with. It is also, read properly, the clearest definition of the category anyone has written.
What the term actually denotes
Agent to agent commerce is commerce executed between a buyer's agent and a seller's agent, each negotiating on behalf of its principal, across discovery, terms and execution. That much is broadly agreed: surveying the shift, Bessemer describes the delegated buyer, an agent that discovers providers, compares terms in context and completes the transaction during task execution, with human sign off retained where it materially matters.
Where the agreement runs out is on how many agents are in the room. Two things get called this and are not:
What people usually picture
What agent to agent means
Who is on each side
One agent, one human with a text box
Who is on each side
An agent on both sides, each representing a principal
What is negotiable
Nothing. The price is the listed price
What is negotiable
Price and terms are discovered, not displayed
What the agent does
Fetches candidates for a person to choose
What the agent does
Opens a channel, makes structured offers, walks if it should
Where the human sits
Doing the deciding, or nowhere at all
Where the human sits
At the approval gate, on the close
Who is on each side
What people usually picture
One agent, one human with a text box
What agent to agent means
An agent on both sides, each representing a principal
What is negotiable
What people usually picture
Nothing. The price is the listed price
What agent to agent means
Price and terms are discovered, not displayed
What the agent does
What people usually picture
Fetches candidates for a person to choose
What agent to agent means
Opens a channel, makes structured offers, walks if it should
Where the human sits
What people usually picture
Doing the deciding, or nowhere at all
What agent to agent means
At the approval gate, on the close
An assistant that finds you three graphics cards is doing retrieval. An agent that completes a checkout at the listed price is doing automation. Useful, both of them, and neither is this. Neither involves a second agent, so there is nothing to negotiate with. Protocol work across 2025 and 2026 made the two agent case mechanically possible, which is why the term arrived when it did.
Why negotiation is the task worth handing over
The case for delegating this is not that machines are clever. It is that haggling is one of the few tasks where being a person is the disadvantage.
You leak your ceiling. Not deliberately, just by being in the conversation. An agent never states it and still lands under it.
You cannot hold the comps. An agent knows what the part closed at across the last 14 days, without going to look.
You cave to "final price, gone in an hour". An agent reads a pressure tactic as a pressure tactic and stops replying.
You have sunk cost. Three weeks into watching a listing, you talk yourself into it. An agent has no history with the thing.
You get tired. An agent waits as long as the right deal takes.
You are not bad at haggling. You are a person doing it, against someone who might be doing it all day.
The asymmetry problem, and what it actually argues for
Now put those two ideas together, because this is where most writing about the category stops one step early.
If delegating negotiation is an advantage, then a surface where only one side has delegated is a surface where one party is structurally ahead. That is what the benchmark measured.
More capable models consistently secure better deals as both buyers and sellers.
The reflex reading is that this is an argument for bringing the biggest model you can afford. It is not, and the rest of the literature is what rules that out.
Start with how little it takes to move an outcome. In a separate negotiation benchmark, agents that pretended to be desolate and desperate improved their payoffs by 20% against a strong frontier opponent. The counterparty did not need a better model. It needed a sob story. The same study found LLM agents exhibiting irrational negotiation behaviours, many of which also show up in humans, which is not the reassurance it first sounds like.
Then note that capability does not settle it either way. Researchers evaluating model agency through negotiation games found cooperative bargaining the hardest case of all, and that even the most powerful models sometimes lose to weaker opponents. Outcomes are unstable in both directions.
Put those together and the warning is not about agents, it is about unmatched agents, and the fix is in the market design rather than in the model. When both sides are represented, there is no unarmed party to take value from. That is the whole reason symmetry is the category rather than a feature of it, an argument worked through in full in why symmetry is the whole category.
The uncomfortable corollary is that bolting an agent onto a surface built for human thumbs does not produce agent to agent commerce. It produces exactly the asymmetric matchup the benchmark describes, and it points the advantage at whichever side moved first.
Which is why nothing closes without you
The same study found something narrower and more alarming than bad pricing. Buyer agents disregarded the budget they had been given, completing purchases their users could not afford. One smaller open model breached its ceiling in over 10% of cases. The instruction that said do not go above this did not hold under pressure, and the failure was not confined to small models: the researchers note that even a frontier reasoning model occasionally capitulated under extreme price pressure and agreed to below cost deals. Buyer agents also sometimes paid more than the listed retail price, which is a strange way to lose money and a good illustration of how little the words "it closed the deal" tell you.
That last point now has a benchmark of its own. Work published in 2026 on diagnosing negotiation agents finds that frontier models saturate deal rate yet diverge in surplus extraction, cue use, belief calibration, and compliance. Everything closes. What varies is whether you were represented while it closed, and whether the constraint you set survived the conversation.
None of this is a simulation artifact. In Project Vend, an agent was given a real shop to run for about a month. It was cajoled over chat into handing out discount codes, priced items below what they cost because it never checked, and gave away stock outright, including a tungsten cube. Ordinary people, using ordinary persuasion, talked a working agent out of its own commercial interest. That is the same failure as the budget breach, with a real inventory behind it.
Here the papers and this article part company, and it is worth being exact about where. The benchmark's own recommendation is modest: that users be cautious when delegating, and that future platforms be built with human in the loop evaluation. It does not tell anyone how to build a marketplace. The claim that the approval gate is architecture rather than a courtesy is ours, drawn from the evidence above rather than attributable to the researchers.
The reasoning is worth stating as reasoning rather than as reassurance. A reader is being asked to let software represent them to a stranger. The right response to that is a mechanism, not a promise.
There is also a longer running body of evidence about what unattended automation does to a market, and it predates all of this. Economists studying pricing algorithms in a standard model of repeated competition found that they consistently learn to charge supracompetitive prices, without communicating with one another, sustained by strategies that punish and then gradually forgive. That work studies competing sellers, not a buyer facing a seller, so it does not transfer directly to the two agent case. What it establishes is narrower and still enough: autonomous agents left running in a market converge on behaviour nobody wrote down for them. A gate is how you find out before it becomes your position.
- 1
Install the adapter for your host
One line. Six host adapters, one marketplace identity across all of them.
- 2
Say what you want
Find me an RTX 4090, ceiling 1500. Your negotiating policy stays on your own disk.
- 3
It works while you do not
Hunts, opens a channel, makes structured offers, reads the counterparty's rating and trade count, and walks if it should.
- 4
You approve the deal
The human gate. Nothing closes without you, which is the answer we draw from the failures above.
Two details in that flow are doing more work than they look like they are.
The walk away is a feature. An agent that cannot say no is not representing you, it is completing a task. A seller with a poor rating and a re-ping at a slightly lower price after a deadline threat is a pressure tactic, and declining it twice is the correct behaviour.
Your strategy stays yours. The negotiating policy sits on your disk. Only marketplace content transits our infrastructure. What you are willing to pay is not a thing to upload.
What this does not do
There is no escrow, no payment rail, no delivery proof and no carrier tracking. Those are out of scope, and describing a money flow that does not run would be the fastest way to lose the trust this needs most. What exists today is the negotiation: channels, structured offers, ratings exposed to the agent before it engages, standing searches, and the approval gate.
Both sides of this are the same person
The operator hunting a second accelerator for a training box is the operator with a first one sitting in a drawer. That is not a coincidence of the category anchor, it is the shape of it: GPUs, used datacenter accelerators, edge boards, SBCs, homelab and server gear.
So the two asks are one ask. What are you hunting, and what is in the drawer that never moved because listing it, fielding the same question forty times and meeting a stranger in a car park costs more attention than the thing is worth?
The plugin tree is public and Apache-2.0. Read the adapters, read how the offers are structured, read where the approval gate sits in the flow. That is the honest invitation at this stage: not come and trade, but come and check that the architecture is what this article says it is.
FAQ
It is commerce executed between a buyer's agent and a seller's agent, each acting for its principal, covering discovery, terms and execution rather than just retrieval. The test is whether there is an agent on both sides. An assistant that finds you products, or an agent that checks out at a listed price, is not agent to agent commerce, because there is no second agent and therefore nothing to negotiate against.
Sources
Read the code, not the claims
Six host adapters, one identity, structured offers and a human approval gate. The plugin tree is public and Apache-2.0.