How AI commerce actually works

The map from asked to proven.

One shopper, one question, one $148 order. Follow it across four parties and six steps and you'll see everything that has to be true before an AI-mediated sale can happen at all — including the last piece, which nobody has built yet.

6 steps · 4 lanes · 1 purchase
panel · 5 models
honest states throughout
Geography

States on this map reflect availability in our markets. In-chat checkout is live in one geography, with one AI provider — not ours. Everywhere else, the answer still has to send her somewhere.

One question

waterproof trail shoes for wide feet, under $200, ships to Germany

waterproof trail shoes

Can a model name Acme in this category at all?

02 · retrieves
for wide feet

Does the catalogue expose width — and does the model know who's asking?

03 · shortlists
under $200

Is the price current, and is there a reason to buy now?

04 · checks
ships to Germany

Can the answer end somewhere she can actually buy?

06 · buys

Four clauses. Four different things that have to be true. Miss one and the sale dies quietly — and nobody ever learns it happened.

The receipt comes back. The last piece doesn't.

01 — This is what happens when someone shops through AI. Six steps, about four seconds. 02 — Three ways it can end. Acme is the merchant in all three. 03 — Five surfaces do this today. We think thousands will. 04 — Two points where we carry the data. Two where we measure it. Two — the question and the money — never. 05 — The receipt comes back. The last piece doesn't.
asks
retrieves
shortlists
checks
chooses
buys
Customer the shopper
Frontier AI ChatGPT · Claude · Gemini · Perplexity · Grok
AI apps our thesis: thousands of them
Acme the brand
not in our markets
◍ Herm where the data moves
01
never
02
03
04
05
06
never
07
08
The return right to left, beneath
question
answer a71f
order $148
receipt #8412
a71f ↔ #8412
Continuously true the floor
Facts a model can read Brand Visibility
A catalogue an agent can quote Product Readiness
Shoppers who have consented Customer Intelligence

None of this is a step. It's the floor. It has to be true before 01 and stay true after 08.

solid — happens today, in our markets dashed — doesn't yet
In sequence: she asks in full sentences; five frontier models retrieve who is eligible, shortlist a few names and check whether the answer can close; the answer reaches her carrying the identifier a71f; she chooses; she buys — on Acme.com, which happens today in our markets, or in the chat, which is live but not in our markets, or in an AI app, which does not happen yet. The same three retrieval steps repeat one lane down as an echo row, dashed, because thousands of AI apps do not exist yet. Beneath the lanes a segmented track shows where Herm sits at each step: nowhere at the question, measuring at retrieval and shortlisting, carrying at the check, nowhere at the choice, nowhere at the money by design, carrying at the receipt, and not yet at the join. The receipt returns from the purchase to Herm, solid, because that happens today. The leg from the join back to retrieval is dashed and stops short of arriving, because no answer yet carries an identifier a receipt can be joined to.
Layer 01 · the spine

This is what happens when someone shops through AI. Six steps, about four seconds.

01 The question Customer · asks
02 Who's eligible Frontier AI · retrieves
03 The shortlist Frontier AI · shortlists
04 The check Frontier AI · checks
05 The choice Customer · chooses
06a Buys on Acme.com Acme · buys
Layer 02 · the fork

Three ways it can end. Acme is the merchant in all three.

06a Buys on Acme.com happens today, in our markets
06b Buys in the chat not in our markets
06c Buys in the app doesn't yet
05′ A reason to buy now offers on AI surfaces — doesn't yet
Layer 03 · the echo row

Five surfaces do this today. We think thousands will.

02′ Who's eligible in an AI app — doesn't yet
03′ The shortlist in an AI app — doesn't yet
04′ The check in an AI app — doesn't yet
Layer 04 · where Herm sits

Two points where we carry the data. Two where we measure it. Two — the question and the money — never.

01 The question never, by design
02 Who's eligible measures
03 The shortlist measures
04 The check carries
05 The choice not yet
06 The money never, by design
07 The receipt carries
08 The join not yet
Layer 05 · the return

The receipt comes back. The last piece doesn't.

07 The receipt comes back verified — today
08 The join a71f ↔ #8412 — doesn't yet
solid — happens today, in our markets dashed — doesn't yet
Step reader select any node above Every entry is shown below, in sequence.
before anything 00
Continuously true the floor

Three things have to be true before she asks.

A model can only name what it can read, quote what it can parse, and personalise for someone who has agreed to be known. None of that is a step in the transaction — it's the ground the transaction stands on. It has to be true before she opens the app, and stay true long after she's closed it.

On the map: the band beneath the lanes. It has no column and no arrow, because it never stops being required.

Herm sits: carries
Related suite
Brand VisibilityProduct Readiness

Live and self-serve, and in early access with design partners.

Explore the suite →
asks · Customer 01
Customer the shopper

She asks in full sentences.

Four requirements in one line: category, fit, price, delivery. A search box would have got two of them. The intent is richer than anything your analytics have ever seen, the shortlist is shorter than any results page, and you will not see this moment happen. It is the last time in this map that the shopper is entirely on her own.

On the map: top-left, in the Customer lane. The rail beneath it is a gap — we are not in her conversation, and we will not be.

Herm sits: nowhere, by design
Related suite
Brand Visibility

We can't see her question. We can see the questions like it, put to five models every week.

Explore the suite →
retrieves · Frontier AI 02
Frontier AI the five-model panel

Before you're chosen, you're filtered.

The model assembles its picture of the category from the open web and its licensed sources, and decides which brands are even candidates. Most brands lose here, silently, before any comparison happens. There is no impression, no bounce, no line in your analytics. Absent from the retrieval is absent from the running.

On the map: first node in the Frontier AI lane, with its dashed echo one lane down. The rail is hatched — we measure this, we don't carry it.

Herm sits: measures
Related suite
Brand Visibility

Five models, weekly, personalisation-free, with the reasoning attached.

Explore the suite →
shortlists · Frontier AI 03
Frontier AI the five-model panel

Two or three names, with reasons attached.

The model narrows to a handful and says why — which claim tipped it, which source it leaned on, which competitor already owns the phrase. That reasoning is the actionable part, and it is the part every visibility tracker stops short of. Being named is table stakes. Being named for the right reason is what survives the next question.

On the map: the shortlist is where the answer is born — the line labelled answer a71f leaves from here and climbs back to her. The check at 04 is what decides whether that answer can actually close.

Herm sits: measures
Related suite
Brand Visibility

The reasoning, not just the rank, and a typed brief for every gap.

Explore the suite →
checks · Frontier AI 04
Frontier AI the five-model panel

Can it quote you, and can it send her somewhere real?

Specs, price, stock, and — the one everyone forgets — whether the destination ships to Germany. Where in-chat checkout operates, models work from merchant-submitted feeds rather than crawling. In our markets they still crawl, which means your own pages are the catalogue. Either way the failure is the same: an answer that can’t close is an answer that recommends someone else.

On the map: a gate off the shortlist, not a stop on the way. The rail is solid here — this is data we carry.

Herm sits: carries
Related suite
Product Readiness

A continuously synced, agent-readable mirror with region eligibility and brand-ranked routing.

Explore the suite →
chooses · Customer 05
Customer the shopper

She picks one, for a reason you didn't write.

Personalisation is the rung most brands skip, because it looks like a CRM problem and isn't. The model is choosing for a person it barely knows, from a shortlist it just built, in a conversation you can't read. The lever you have is consented, receipt-verified preference — on your own surfaces today, and on more surfaces as they open.

On the map: back up in the Customer lane, with a dashed ghost beneath it — a reason to buy now, on an AI surface, which doesn't exist yet.

Herm sits: not yet
Related suite
Customer Intelligence

Derived attributes only, never the raw data — and our API serves your own AI surfaces, not frontier answers.

Explore the suite →
buys · Acme / Frontier AI / AI apps 06
Acme · Frontier AI · AI apps the fork

Three ways it can end. Acme is the merchant in all three.

Today, in our markets, the answer routes her to Acme.com and she checks out there. In one geography, with one provider, she never leaves the chat — real, but not where you sell. As more surfaces open, the same fork appears again in the third lane. What doesn't change: orders, payments and refunds stay on Acme's own stack, and no version of this passes through us.

On the map: the busiest column, three nodes in one — one solid, two dashed. The rail is a gap by design. We are never in the money.

Herm sits: nowhere, by design
Related suite
Product Readiness

Own store first, region-eligible fallbacks after — because the sale that dies at a shipping boundary never shows up in any report.

Explore the suite →
the return · Herm 07
Herm the return

The only part of this that comes back verified.

She bought it. The receipt confirms what, where, when and for how much — consented, itemised, revocable, and true across every retailer she shops, not just yours. This is live, and it is the one artefact in AI commerce that nobody else in the category holds. It proves the purchase happened. It does not yet prove what caused it.

On the map: the return leg, right to left beneath everything. Solid, in the accent — this half genuinely comes back.

Herm sits: carries
Related suite
Customer Intelligence

Receipt-verified attributes, derived only. We hold the sensitive data so you don't have to.

Explore the suite →
the return · Herm 08
Herm the return

a71f ↔ #8412 — and the loop closes.

An answer with an identifier, met by a receipt that verifies the sale, is proof that a specific recommendation caused a specific purchase. Nobody can do this today. Answers don't carry an id we can hold, and the surfaces that could pass one haven't. This is the only dashed line on the map that matters, and it is why the third lane filling up is not a nice-to-have.

On the map: the leg out of 08 is dashed and stops short of arriving. That gap is the honest version of the whole page.

Herm sits: not yet
Related suite
AI Distribution

The rungs below are prerequisites, not teasers — an agent can't sell what it can't quote, won't personalise what nobody consented to, and can't prove what no receipt verifies.

Explore the suite →
What the receipt proves

The loop comes back. The last piece doesn't.

Happens today
Verified receipt consented, real
Purchase confirmed it happened
Cause unknown which answer?
Doesn't yet
The answer carries an id one integration
The receipt joins it a71f meets #8412
Cause proven first time anyone can

One provider, in one geography, can already tell a merchant that an order came through its own chat. That is the channel, not the answer — and it stops at the edge of that provider. It says nothing about the shopper who asked on Tuesday and bought on Acme.com on Friday, which is most of them. Attribution that survives across surfaces has to be built on receipts, or it doesn't get built.

A stated belief

Why we think the third lane fills up.

Consumer buying is not a requirements document. People buy a perfume because they liked it, not because it scored well against criteria. Five general assistants can serve the rational half of that. They are much weaker on taste, on wardrobe, on occasion, and on the hundred niches underneath — and the apps that are good at those things are already appearing. Stylists that hold your wardrobe and tell you what’s missing exist today.

So we think that lane fills with thousands of them, each good at one segment. We can't prove it. It's why we're building for it, and we'd rather say so than draw it as a fact.

The plumbing

Five standards. One of them is ours to publish, not ours to declare.

Standard Owner State
Product feed schema Industry ● Live
Agentic checkout Industry — more than one, not converging ◑ Live, scoped
Consent handshake Herm ● Live, Herm-side
Receipt & attribution spec Herm ● Live, Herm-side
Cross-agent brand identity Herm ○ Proposed

“Herm-side” means we have built and published our half. It runs the moment a counterparty implements the other half. There is more than one agentic checkout protocol and they are not converging yet — which is the whole argument for a layer that sits above all of them.

Where you are on this map

You can find out in about four minutes.

The Readiness Score runs your brand through the same five-model panel and reports which of these steps you'd survive today — visible or not, quotable or not, closeable or not. Free tier is real: score, model cards, competitor bars, a sample of the questions you're missing.