AI Shopping’s Attribution Problem: When Agents Claim Credit for Sales They Did Not Create
AI shopping agents can influence a purchase long before a click, execute a click the shopper never saw, or arrive at checkout after demand was already created. If merchants pay whichever system leaves the last identifier, agentic commerce will industrialize attribution error.

Short answer: Merchants should stop treating an agent's last click as proof that the agent created the sale. Measure four separate roles—discovery, recommendation, referral, and transaction execution—then pay only for the role that was actually performed. Use stand-down rules, visible user intent, deduplication, holdouts, and incrementality tests before allocating affiliate or media credit.
Attribution has always been an argument over a counterfactual: would the customer have purchased anyway?
The industry often avoids that question by paying the last identifiable touchpoint. It is simple, auditable, and wrong often enough to sustain entire categories of coupon interception, toolbar overwrites, and branded-search capture.
AI shopping makes the weakness structural. An agent may research products without sending a click, recommend a brand inside a conversation, open a merchant page in the background, apply a coupon at checkout, or complete the purchase through another platform. Every one of those actions can generate a technical signal. They do not deserve the same economic credit.
The Phia allegations are a warning, not the whole story
In July 2026, researcher Ben Edelman published testing alleging that shopping app Phia generated forced affiliate clicks and failed to stand down when another publisher had already referred the shopper. Phia characterized the behavior reported at the time as a bug and said it had fixed the issue.
The important lesson is not to adjudicate one company's intent from outside. It is that the affiliate system could record a payable “click” without meaningful shopper action and then attach credit near the end of an existing purchase journey.
Agentic interfaces increase the number of moments where this can happen. Software can load pages, follow links, refresh cookies, compare sellers, test coupons, and submit orders faster than a person can observe. If the measurement rule asks only which identifier was present at checkout, automation will optimize for presence at checkout.
Four roles that attribution must separate
| Role | What happened | Appropriate evidence |
|---|---|---|
| Discovery | The agent introduced a product or brand the shopper had not considered | Exposure log, matched user journey, holdout lift |
| Recommendation | The agent materially influenced selection among alternatives | Ranked answer, rationale, interaction, experiment |
| Referral | The shopper deliberately followed the agent to a merchant | Affirmative click or clear handoff event |
| Execution | The agent completed a purchase already decided | Mandate, cart binding, transaction record |
An agent can perform one, several, or none of these roles. A replenishment agent might execute a routine order without creating demand. A research assistant might influence the choice but never touch checkout. A coupon extension might reduce price after the merchant and another publisher did all the acquisition work.
One commission rule cannot represent all four.
Why last click becomes less defensible
Agents create invisible influence
A recommendation inside a closed conversation may shape the purchase without producing a conventional referrer. The merchant sees direct traffic or a later branded search and undercounts the agent's discovery role.
Agents can manufacture visible activity
The reverse is also possible: software can create a redirect or affiliate event the shopper did not choose. The merchant sees a clean tracking parameter and overcounts the agent.
Execution sits closest to conversion
The service that submits the order will usually have the strongest final signal. But execution is not necessarily persuasion. Paying it an acquisition commission can reward the system that arrived latest rather than the one that changed behavior.
Agents can split one journey across identities
Research may happen anonymously, selection under a platform account, and payment through a wallet token. Conventional analytics can treat these as separate users or give all credit to the only deterministic identifier.
Paid and organic recommendations can merge
If an agent receives affiliate compensation, sponsored-placement fees, or merchant incentives, the commercial relationship may affect which options appear. The FTC's endorsement guidance says material affiliate connections should be disclosed clearly and conspicuously. A machine-generated recommendation should not make that obligation less important.
The new fraud surface
| Pattern | Mechanism | Control |
|---|---|---|
| Forced click | Software triggers a referral without affirmative shopper action | Require signed interaction event and minimum visibility |
| Cookie overwrite | Agent replaces an earlier publisher near checkout | Stand-down rules and original-referrer preservation |
| Cookie refresh | Old credit window is silently extended | No refresh without a new intentional handoff |
| Self-referral | Agent claims credit for traffic already inside the merchant | Suppress commission after merchant session begins |
| Branded-demand capture | Agent intercepts a customer already seeking the brand | Separate navigation from discovery and test incrementality |
| Execution inflation | Checkout tool receives acquisition credit for fulfilling intent | Pay service fee separately from demand-generation commission |
| Cross-device laundering | Weak identity matching turns correlation into claimed influence | Confidence thresholds and no deterministic claim without evidence |
The control principle is simple: no economic credit should be created by an event the customer did not knowingly initiate or by a technical action required merely to execute an already-formed decision.
Attribution and incrementality are different questions
Attribution assigns observed outcomes according to a rule. Incrementality estimates what changed because the intervention occurred.
Google's Conversion Lift documentation describes the basic causal design: compare a treatment group exposed to an intervention with a control group that was not, then measure the difference in downstream conversions. Agentic commerce needs the same discipline even when the intervention is a recommendation rather than an advertisement.
A channel can show high attributed revenue and low incremental revenue. If the agent primarily serves loyal customers who were already going to reorder, its execution may be valuable while its acquisition claim is not.
A merchant measurement model
1. Create role-specific events
Record recommendation exposure, product inclusion, shopper interaction, merchant handoff, cart creation, checkout authorization, and purchase separately. Do not translate them all into “click.”
2. Preserve provenance
Carry the first known discovery source, material recommendation sources, last affirmative handoff, and executing agent. Prevent later tools from erasing the earlier history.
3. Require affirmative referral
A commissionable referral should have a user-visible action or a user mandate that explicitly allows the agent to open the merchant. Background retrieval needed for comparison is not automatically a referral.
4. Deduplicate claims
Define priority and sharing rules when a publisher, search ad, agent, coupon tool, and wallet all claim one order. Return machine-readable rejection reasons so partners can audit disputes.
5. Run holdouts
For eligible populations, withhold the recommendation or agent promotion from a randomized group. Measure incremental orders, revenue, margin, new customers, returns, and long-term value—not only checkout conversion.
6. Price the role
Discovery might justify an acquisition payment. High-quality recommendation might justify media or service compensation with disclosure. Transaction execution might earn a processing or platform fee. Coupon savings might earn a share only when the discount was genuinely discovered and used.
The metrics that expose bad credit
- Affirmative-click rate: commissionable referrals with a documented user action.
- Stand-down compliance: sessions where the agent preserved a prior eligible referrer.
- Preexisting-intent rate: referred sessions already containing the merchant, brand, or product in the journey.
- Time-to-purchase distribution: suspicious clustering immediately before checkout.
- Attributed-to-incremental ratio: credited conversions divided by experimentally estimated incremental conversions.
- New-customer lift: incremental first-time purchasers, not tagged first-time purchasers.
- Incremental contribution margin: lift after discounts, commissions, returns, fulfillment, and service costs.
- Publisher displacement: orders where an agent replaced an earlier eligible partner.
A very high attributed-to-incremental ratio does not by itself prove fraud. It does prove that the commercial model is paying for more than causal growth.
What merchants should put in contracts
Define an affirmative click, prohibited background redirects, stand-down conditions, cookie duration and refresh rules, required disclosures, allowed sub-affiliates, audit-log retention, source-code or independent audit rights for high-risk software, and clawbacks for invalid traffic.
Also define what happens when the agent acts under a delegated mandate. If the customer instructed an agent to buy a known product, the agent may deserve an execution fee but no referral commission. The mandate itself can help classify the role.
The harder strategic problem
Merchants want agents to send demand, so they may tolerate generous attribution while the channel is small. That is how measurement debt accumulates.
Once agent platforms control meaningful discovery, weak rules become expensive to renegotiate. The platform can point to years of attributed revenue; the merchant cannot prove how much would have happened anyway. Retail media went through a version of this problem when closed-loop measurement blurred the difference between observing a sale and causing it.
Agentic commerce offers a chance to build better rules at the beginning. The merchant should know whether the agent discovered, persuaded, referred, or executed. The customer should know when compensation might influence the answer. And the partner should be paid for measurable value, not merely for leaving the last cookie.
Frequently asked questions
Is every agent-generated affiliate click invalid?
No. A click or handoff can be valid when the shopper intentionally asks the agent to visit a merchant or the mandate clearly authorizes that action. The event should be visible, attributable to the active task, and compliant with stand-down rules.
Can server-side tracking prevent attribution fraud?
It improves integrity and observability, but it cannot decide causality. A perfectly authenticated event can still claim credit for a sale the agent did not create.
Should merchants eliminate affiliate commissions for agents?
Not necessarily. They should match compensation to role, require disclosure and evidence, and test incremental value. Discovery deserves different economics from coupon application or transaction execution.
How can a small merchant run incrementality tests?
Start with time-, geography-, or audience-based holdouts where randomization is feasible, keep the test narrow, and measure margin as well as orders. If volume is low, aggregate longer and avoid treating noisy results as precise.
References & Further Reading
Continue Exploring
The Agentic Commerce KPI Stack
Connect AI visibility and assisted discovery to incremental revenue and contribution margin.
AI Shopping Could Break Retail Media
See how conversational discovery changes sponsored influence and retail-media economics.
Retailer-Owned Agents May Become the Next Retail Media Gatekeeper
Explore who controls eligibility, ranking, and measurement when the retailer owns the agent.
