72% Have Used an AI Assistant. 23% Trust One With Money. The Gap Is Your Product Spec

Surya Pratap
By Surya Pratap

September 10, 2026

11 min read

AI & Technology
A descending staircase of consumer willingness to let an AI agent act, from 72% who have used an AI assistant at all, to 56% who would let one search and compare products, 51% for loyalty programmes, 35% who would grant access to saved card details and 23% who would let it make the payment — set beside the same payment question asked with a trusted payment brand attached, which scores 61%, rising to 68% among 18 to 34 year olds and 71% among frequent AI usersThe same agent, five different asksHover to explore
The bars fall as the action becomes harder to undo, not as it becomes harder to perform. That ordering is the useful part.

Most survey coverage picks the scary number and stops. This one has five numbers, and the order they come in is the finding.

Visa published its Trust Index for agentic commerce on 9 September 2026. The headline everyone ran was that 23% of US consumers trust generative AI to handle a payment on their behalf. The interesting part is what sits above that number.

1. What the survey actually found

The Visa Trust Index, as published

One sample, asked to delegate progressively more

  • 72% of consumers have used an AI assistant.
  • 56% would let an agent search and compare products.
  • 51% would let an agent manage loyalty programmes.
  • 35% would grant an agent access to saved payment credentials.
  • 23% trust generative AI to handle a payment transaction on their behalf.
  • Asked the same payment question with Visa attached, 61% said yes — 68% among 18 to 34 year olds, 71% among frequent AI users.
  • Fielded by the Harris Poll across 2,065 US adults, 26 to 28 May 2026, census-matched. Brand questions used 1,028 to 1,034 respondents each.

Read down that list and notice what is not varying. It is the same technology in every row. Comparing products across a dozen retailers is arguably a harder inference problem than pressing pay on a cart the user already assembled. Willingness still halves between them.

2. The staircase tracks consequence, not difficulty

Users are not rating your agent's competence. They are rating their own exposure when it is wrong.

Sort those five actions by how hard they are to perform and you get one order. Sort them by how hard they are to undo and you get the survey.

A bad product comparison costs nothing — you scroll past it. A mismanaged loyalty balance is annoying and usually recoverable. Saved card access is a standing risk rather than a single event, which is why it sits lower than the reversible tasks and above the irreversible one. A wrong payment is money that has left, and getting it back is a process you have to run, against a counterparty, on someone else's timetable.

That is a coherent risk model. It is the correct one. And it means the 23% is not a verdict on model quality that better models will fix.

The uncomfortable implication

If accuracy were the binding constraint, the number would move when the models improve. It mostly has not, across three years of models that got dramatically better at exactly this class of task. Consumers are answering a question about recourse, and no benchmark score is an answer to it.

3. What the 61% is actually measuring

Here is the part worth sitting with. The same respondents, the same delegated action, a different name on it — and the number nearly triples.

Nobody in that sample believes a payment network writes better agent code than a frontier lab. That is not the claim. What a payment network has is fifty years of established answer to "what happens to me if this is wrong": a dispute process, a chargeback, a liability rule that puts the loss somewhere other than on the cardholder.

61% is not trust in the agent. It is trust that someone else eats the mistake.

Which is genuinely good news for founders, because that is a buildable property. Accuracy is a research problem you are mostly a consumer of. Recourse is an engineering and business decision you control entirely.

4. Engineering recourse into an agent product

Make the undo real, not a promise

Reversibility
Every agent action should have a defined inverse and a window in which it runs. A draft that sends on a delay, a transaction that can be voided before capture, a change written to a new version rather than over the old one. Users will delegate far more when the worst case is a click, and the delta between "we'll fix it, contact support" and a visible undo button is a large part of what those 38 points are made of.

Bound the damage before you need to

Blast radius
Per-action ceilings, daily aggregates, a whitelist of counterparties, a category the agent may never touch without a human. The point is not to prevent mistakes — it is to make the maximum mistake small enough to state out loud in your onboarding. An agent that can spend at most £40 per action and £200 per week is a fundamentally different product to ask someone to trust.

Someone recognisable in the loop

Borrowed accountability
This is what Visa is selling and it is available to you as a component. Settling through established rails, authenticating with a bank credential, or running on a protocol with a defined liability model lets a new product inherit an old answer to the recourse question. Building your own payment path saves fees and forfeits precisely the thing the survey says users are buying.

Say who pays when it goes wrong

A written guarantee
The single most underused move. Most agent products are silent on liability, which users correctly read as "you eat it." A specific, bounded commitment — we reimburse any incorrect charge the agent initiates, up to X, no questions — converts an abstract fear into a priced risk on your side. Price it, then publish it.

5. Sequencing a roadmap against the staircase

The survey is also a launch order, and most agent products get it backwards by leading with the most impressive demo rather than the most delegable action.

The reversible tier

Ship first
Research, comparison, drafting, triage, anything where the output is a proposal the user accepts. This is the 56% band and it is where a new product is actually allowed to operate. It also generates the thing you need next: a visible record of the agent being right.

The standing-access tier

Earn into
Persistent credentials, background execution, acting while the user is away. The 35% band. Gate this on accumulated evidence rather than an onboarding checkbox — after the agent has produced N correct proposals this user accepted, offer the upgrade with the ceiling attached. Delegation is granted for a track record, not a permissions dialogue.

The irreversible tier

Ask last
Money leaving, messages sent to third parties, records changed outside your system. The 23% band, and the one you should reach only with reversibility, ceilings, an accountable rail and a stated guarantee already in place. Asking for it on day one is how a product gets the answer the survey got.

The mechanics of the middle tier — scoped credentials, approval gates, audit trails — are a solved engineering problem, and I have written about what an agent permission system needs to contain. The sequencing question is the one founders get wrong.

6. What I would not conclude

This is Visa's research, and it finds Visa most trusted. That is not disqualifying — the Harris Poll methodology is disclosed, the sample is census-matched, and the brand question was run across multiple brands. But the framing of a study commissioned by an incumbent will tend to land on the conclusion that incumbency is valuable. Take the staircase, which is a general finding, more seriously than the specific 61%.

The fieldwork is older than the publication. Responses were collected 26 to 28 May and published on 9 September — over three months in a field where three months is a long time. Treat every figure as a May reading.

Stated willingness is not behaviour. Survey respondents systematically under-report what they will actually do once a flow is smooth and a default is set. The staircase's shape is robust; its absolute heights are soft, and probably conservative.

And 23% is not a small market. A quarter of US adults is an enormous addressable population for a product that only needs early adopters. The number is a design constraint, not a verdict on the category.

The honest summary

Consumers have already accepted AI assistants — 72% have used one. What they have not accepted is agents taking actions they cannot take back, and their willingness declines in near-perfect order with irreversibility.

The gap between 23% and 61% is the whole product opportunity, and it does not close by waiting for better models. It closes by building the thing a payment network spent fifty years building: a clear, published, funded answer to what happens to the user when the agent gets it wrong.

Most teams are competing on the capability half of that sentence. The survey says the other half is where the customers are.

Sources: Visa, "New Visa Research Finds Consumer Trust is Accelerating the Path to Agentic Commerce" · PYMNTS, "Consumers Use AI Assistants but Hesitate to Hand Over Their Wallets" · Finextra, "Consumer trust in agentic payments continues to lag" · All percentages and the Harris Poll methodology are as published by Visa; the reading of the staircase as a function of irreversibility, and every design recommendation, is mine. For the parallel finding among engineers rather than consumers, see the gap between how much developers trust their agents and how often those agents fail.

IdeaToMVP Academy

Want to build with AI — not just read about it?

4-week live cohort for founders. Learn to ship AI agents, scope MVPs, and automate your business — taught by the same team that writes these guides.

Explore the Academy →
Share this post :