On this page
The problem: the tools can already spend your money
Most brands met AI through software they already pay for. Gorgias says its AI Agent resolves 60% of tickets and can run "130+" actions, including refunds, cancellations and order edits (vendor claim)[49]. Klaviyo shipped a Marketing Agent and a Customer Agent to its 193,000-plus customers in September 2025[7]. Shopify lists its Sidekick assistant and agent storefronts among "a suite of AI-enabled features integrated across the Shopify platform"[6]. Each runs inside one tool, under that tool's own settings and limits.
Buyers are also arriving by a new route. AI-referred traffic to US retail sites rose 393% year over year in Q1 2026, and by March it converted 42% better than other traffic, a year after converting 38% worse (Adobe, which sells analytics)[48]. Shopify says AI-driven traffic and orders to its merchants tripled year over year by Q2 2026[52].
Pricing mistakes surface within weeks. Instacart ran AI price tests that showed the same item at prices up to 23% apart; within weeks the FTC opened an inquiry, New York's Attorney General asked questions, and the tests stopped[42,43].
And there is little margin to absorb a mistake. Among eight public online brands, most ran at operating margins between -1.6% and +6.1% in their latest year[3]. One uncapped discount code, a doubled refund or a weekend of runaway ad spend matters more here than a slightly better chatbot answer. Before choosing another agent, settle who said each one could refund, discount, publish or send, and up to what amount.
AI-enabled vs AI-native in an ecommerce brand
The help desk's AI agent answers order status and can refund. Klaviyo's agent drafts flows, Meta's automation spends the ad budget, and Shopify's assistant writes product copy. Each tool has its own settings, keys and log. Nobody can say what AI did to this customer's order, this price or this product page last week, or who approved it.
Agents do the first pass of catalog, support, returns, retention and reconciliation inside Shopify, the help desk, the 3PL and the marketplaces. Each acts for a named person, with no more access than that person. Every refund, discount, price change, product claim and full-list send passes a rule or an approval and lands in one record. And the product data is accurate enough for other companies' shopping agents to sell from.
The test is whether you can state each agent's access, limits and history for a given order, price or product page. A brand can be AI-native with fewer AI tools than an AI-enabled one.
The missing layer
A brand will not replace Shopify, its help desk, Klaviyo, the 3PL or Seller Central to become AI-native. Agents work across all of them, and none governs an agent working in the others: the help desk does not know which refund the returns app already issued.
The missing layer asks, before any agent acts: who is it acting for, does a rule allow this refund, discount, publish or send, and if not, who must approve? Then it keeps one record. OrchKernel is built to be that layer. It does not replace Shopify or any system of record, score fraud, run ads, or govern the outside agents that buy from your store. Details are in the OrchKernel blueprint.
Here is one refund request passing through it:
- 01Customer message· Untrusted input
"My order never arrived. Refund me and send a replacement to my new address." Order total $186.
- 02Proposal· Support agent
Acting for the CX lead, the agent reads the order, carrier scans and 3PL status, then proposes a $186 refund. It does not propose the address change: the parcel has shipped.
- 03Check· OrchKernel
In policy? Under the $100 cap for this reason? Any earlier refund on this order line? This customer's claims in the last 90 days? The amount is over the cap, so the refund is held.
- 04Decision· People and systems
The CX lead sees the exact refund, the carrier scan showing delivery and the customer's history, and approves a reship to the original address instead, not to the new one in the message. Her reason is kept.
- 05Run once and record· OrchKernel
The reship order is created in Shopify under the CX lead's authority, exactly once. Request, check, decision and result go to the log.
Where the money and the hours go
Where the revenue dollar goes
US online retail sales reached $340.2 billion in Q2 2026, 17.1% of all retail, up 12.2% on a year earlier while total retail grew 6.7%[1]. Price minus landed cost (factory price, freight and duty) gives gross margin. Gross margin then pays for acquisition, fulfillment, payment fees, returns, fraud, service and the team. Public online brands show the shape[3]:
- FIGS FY2025Operating margin +6.0%
Goods 33.5% · marketing 14.8% · other 45.7%
- Revolve FY2025Operating margin +6.1%
Goods 46.5% · marketing 14.3% · other 33.1%
- Hims & Hers FY2025Operating margin +4.5%
Goods 26.2% · marketing 39.2% · other 30.1%
- Chewy FY2025Operating margin +2.0%
Goods 70.2% · marketing 6.5% · other 21.3%
- Wayfair FY2025Operating margin +0.1%
Goods 69.8% · marketing 11.4% · other 18.7%
- Warby Parker FY2025Operating margin -0.6%
Goods 46.0% · marketing 13.1% · other 41.5% · costs exceed revenue
Stitch Fix (-1.6%) and Allbirds (-52.5%) are left off the chart; the second would not fit on it. Across all eight, marketing costs 6.5% to 39.2% of revenue, and fulfillment-type lines run 17% to 23% where broken out. People costs are not reported by function, with one exception: Wayfair spends 3.8% of revenue on customer service and merchant fees combined, with "over 2,000 full-time" service staff "supplemented by" AI tools[4].
For a marketplace-led brand, the fee stack is the cost structure. Marketplace Pulse estimates that a typical private-label Amazon seller paid Amazon 50% to 60% of sales in 2023 across referral, fulfillment and advertising fees[41]. Amazon earned $68.6 billion from advertising in 2025[5], much of it from sellers.
Duty is now a margin line for small parcels. Duty-free entry for parcels under $800 was suspended for every country from 29 August 2025[9]. It has stayed suspended after the Supreme Court's February 2026 tariff ruling, and a 2025 statute ends the exemption from 1 July 2027[10]. A brand that ships direct from an overseas factory now classifies goods and pays duty on every parcel.
Where the hours go, and why the evidence is thin
We found no independent study of how staff time splits inside ecommerce brands, nor an independent figure for the share of tickets asking "where is my order" (WISMO). What can be said with sources:
- Returns carry a judgment call each time: retailers expected 19.3% of online sales back in 2025 and class 9% of all returns as fraudulent[40].
- Fraud and chargebacks cost more than the loss itself: more than $5 in total for every $1 lost, by a fraud-tool vendor's count, including staff time on reviews and disputes[50].
- Catalog work (copy, images, alt text, translations, listings, feed fixes, marketplace suppressions) now feeds shopping agents as well as shoppers. No time-use data exists.
So treat any "hours saved per week" figure as a vendor claim, and measure your own baseline before Stage 1.
Two fronts: agents that work for you, agents that buy from you
An ecommerce brand has to govern its own agents and get ready for other companies' agents buying from it. Inside, the question is who an agent acts for and who said it could. Outside, it is which agents you accept orders from, on what terms, and what your product data tells them.
- Support agent: acts for the CX lead
- Catalog agent: acts for the catalog owner
- Returns agent: acts for the ops lead
- Retention agent: acts for the retention lead
- Finance agent: acts for the controller
Rules, caps and approvals; each agent limited to its person's access; credentials held here, not by agents; every request written to one tamper-evident log.
- Shopify
- Help desk
- Klaviyo
- 3PL
- Amazon and other marketplaces
- Payments
- Ad accounts
- ChatGPT Instant Checkout (ACP)
- Google agents (UCP, AP2)
- Amazon Buy for Me
- Browser agents (Comet and others)
What they read: product feeds, structured attributes, the FAQ. What decides their orders: checkout settings, the protocol's payment token, fraud tools and your written policy on which agents you accept.
What changed in twelve months
- September 2025: OpenAI's Instant Checkout and the Agentic Commerce Protocol launched with Stripe. The merchant can "accept or decline the order" and handles fulfillment and returns; payment uses a token "scoped to a specific merchant and basket total"[57].
- January 2026: Google announced the Universal Commerce Protocol with Shopify, Etsy, Wayfair, Target and Walmart, alongside its agent payments protocol[58].
- March 2026: Amazon expanded Buy for Me, its agent that completes purchases on other brands' sites, with product feeds from feed-management companies[60]. Reports that some brands were listed without consenting are to be confirmed.
- March 2026: World launched a beta tool to verify that a human approved an agent's purchase[61].
- August 2026: the Ninth Circuit vacated the injunction that had kept Perplexity's shopping agent off Amazon, holding that on the facts before it the user accessed Amazon with the agent's help[38].
- September 2026: Shopify opened checkout to browser-based agents, while Amazon and Adidas block them[59].
A caution. We found no public figure for the share of orders that agents complete. Ron Johnson, who built Apple's stores, argues people will not let an agent buy a $1,000 to $2,000 item unseen[62]. Shopify says traditional search still brings "roughly a third of all storefront sessions"[52]. Plan for agents as a growing channel, not the main one.
Both fronts share the product data: what your catalog agent drafts is what an outside agent reads. That is why the staged path starts there.
The workflow end to end, and where AI already works
Evidence grades: A is independent or primary evidence of results; B is company statements or large vendor datasets; C is vendor positioning only. Vendors are named as examples, not recommendations.
Thirteen of the fourteen steps rest on company or vendor evidence. The one step graded A, compliance, is there because of an FTC order, not a result.
What the evidence says, and where it is thin
- Large retailers: 85% use AI to detect or prevent return fraud[40]. The sample is 358 retailers, all above $500 million in revenue, so it says little about a $20 million brand.
- Shoppers: in an Adobe survey of 5,000+ US consumers, 39% said they had used AI for online shopping (vendor)[48]; in a Shopify survey, 64% said they were likely to use AI when buying (company)[51].
- Growth from a small base: Shopify reported AI-referred traffic up 7x and AI-driven orders up 11x between January and Q3 2025[51]. Percentages like these say nothing about absolute volume.
- Small and mid-size brands: we found no current independent adoption figure. The Census Bureau's business survey put AI use across all US firms at 3.7% to 5.4% between September 2023 and February 2024, with no retail breakdown[2]. It is dated.
- No brand has yet reached scale because it runs on agents, as far as we found. Meanwhile "an AI store that runs itself" is an FTC fraud category: the FTC acted against Ascend Ecom and FBA Machine, which sold such stores[18]. Treat AI-native as an operating model for the brand you already run.
- Switched on is not the same as trusted. No platform publishes the share of merchants who let an agent act without review.
The staged path
Six stages. The order runs against the one most help-desk vendors sell, where a bot that refunds comes on day one. Catalog work comes first because it is the lowest-risk work with the widest reach now that shopping agents and AI search read product data. Refunds, prices and sends come later because that is where the sector's failures cluster (see when agents fail). A brand can run different product lines or channels at different stages.
- Stage 0Inventory the AI you already run
Gate before the next stage: Five written limits, an owner per tool, write scopes listed
- Stage 1Catalog and content
Gate before the next stage: An approved attribute and claims list with a named owner
- Stage 2Support, then capped actions
Gate before the next stage: Refund cap in force and tested on a measured trial
- Stage 3Returns, fraud and money operations
Gate before the next stage: Every refund runs once per order line; a person files disputes
- Stage 4Growth operations under rules
Gate before the next stage: Consent ledger, discount floors, price bands, a clean cancel path
- Stage 5Operating model, and selling to agents
Gate before the next stage: A written policy on which outside agents you accept
- 0
Stage 0: Inventory the AI you already run
About a month: days 1 to 30 of the first 90
What to do
- List every AI feature switched on: the help desk's agent, Klaviyo's agents, Advantage+ or Performance Max, Shopify Sidekick, review apps, repricers, chat widgets. Record what each can change and whose login it uses.
- Review Shopify app scopes that write orders, products, discounts and price rules, and every marketplace and ad token. Revoke those of people who have left.
- Write five limits: a refund cap, a discount floor, no new product claims without approval, no full-list send without approval, no price change outside a band. Name an owner per team.
Why now
Most brands already have an agent that can move money. Gorgias lists "130+" actions for its AI Agent, including refunds, cancellations and order edits (vendor)[49]. Its limits are whatever that tool's settings say.
In place first
- Admin access to every tool, and the refund, return and shipping policies in writing.
What to measure
- Share of AI features with an owner and written limits
- Apps and tokens with write scopes; tools that can refund or send without a person
Common mistakes
- Counting tools instead of permissions. One app that can write discounts matters more than five that only read.
- Leaving a former contractor's app token live.
- 1
Stage 1: Catalog and content first; people publish
Starts as Stage 0 ends; one product line first
What to do
- Build an approved attribute and claims list (materials, origin, care, sizing, ingredients, certifications, warnings) with an owner. Agents draft from it; a person publishes.
- Write the FAQ that shopping agents read; Shopify's Knowledge Base app is one way[53].
- For EU sales, keep the product safety fields on every listing: manufacturer, EU responsible person, identifiers, warnings[37].
Why now
Half of AI-referred sessions on Shopify stores land on a product page, and 75% of AI-attributed purchases fall outside the top 100 categories (Shopify, Q2 2026)[52]. Product data is what a shopping agent reads before it recommends you, and a draft a person publishes moves no money.
In place first
- One source of truth for product data with a named owner: Shopify, a PIM, or a spreadsheet someone answers for.
What to measure
- SKUs with every required attribute filled
- Marketplace suppressions; claims stopped before publish
- AI-referred sessions and conversion
Common mistakes
- Publishing AI text nobody read. At minimum, a rule that rejects refusal text ("I'm sorry, but I cannot") and empty attributes.
- Letting a supplier's spec sheet become a product claim (scenario S3).
- 2
Stage 2: Support first pass, then capped actions
First stage that can move moneyDrafting from day 31 in one queue; first capped action after a measured trial
What to do
- Agents tag, route and answer order status from Shopify, carrier and 3PL data, and draft replies from approved policy. After a measured trial, low-risk replies go out unreviewed.
- Then actions open one at a time, each capped: an address edit before the 3PL picks, a cancellation before handoff, an in-policy refund under a set amount. Everything else goes to a person.
- Tell customers they are talking to AI; in the EU, Article 50 of the AI Act requires it from 2 August 2026 unless it is obvious[46,47].
Why now
Most of the sector's evidence sits here, all from companies: Klarna says its assistant handled two-thirds of chats in its first month with 25% fewer repeat inquiries[64]. It is also where a tribunal held Air Canada liable for a refund policy its chatbot made up[67].
In place first
- Written policies the agent can quote; 3PL pick and ship status visible to it; the Stage 0 caps enforced outside the help desk.
What to measure
- Repeat contacts within 7 days of an AI-handled ticket
- Share of drafts sent unedited
- Refund dollars issued by agents against approved by people
Common mistakes
- Counting a ticket as resolved because the customer stopped replying.
- Letting the bot promise ship dates from the product page instead of live stock (scenario S8).
- 3
Stage 3: Returns, fraud and money operations
Refunds, disputes and payoutsAfter Stage 2's caps have held through a busy month
What to do
- Check eligibility against the window and final-sale tags; offer an exchange first; refund on the 3PL's return scan, once per order line.
- Flag repeat claimers to a person; agents never block customers. Agents assemble chargeback packs; a person files them.
- Audit 3PL invoices against contracted rates and reconcile payouts across Shopify Payments, PayPal, marketplaces and buy-now-pay-later providers.
Why now
Retailers expected 19.3% of online sales back in 2025 and class 9% of returns as fraudulent[40]. Money moves here, so it waits until Stage 2 has shown that caps and approvals hold.
In place first
- 3PL scan, returns-app and processor dispute data reachable by the agent; refund caps and blocking rules agreed with finance.
What to measure
- Return rate by SKU and reason, against NRF's industry figure
- Duplicate refunds (target: zero); days from scan to refund
- Chargeback win rate and dispute ratio (network thresholds to be confirmed)
Common mistakes
- A refund path that can run twice, from support and from returns (scenario S1).
- Filing dispute evidence nobody checked.
- 4
Stage 4: Growth operations under rules
Prices, consent and the whole listWhen the consent ledger, discount floors and price bands exist
What to do
- Agents draft campaigns and segments, and propose promotions, price changes and budget moves inside bands and caps. Full-list sends and anything outside a band wait for a person.
- Agents moderate reviews only for the reasons the FTC allows, each logged[17], and answer subscription requests with a clear way to cancel.
Why now
Marketing is 6.5% to 39.2% of revenue at the public brands above[3], and review, pricing, consent and subscription law concentrate here.
In place first
What to measure
- Contribution margin per campaign
- Discount depth against the floor; opt-out and complaint rates
- Hidden reviews, by reason
Common mistakes
- Personalized pricing by accident: a tool that uses customer data without anyone deciding it should.
- Codes with no usage limit (S2), hidden negative reviews (S4), save offers that block cancelling (S6).
- 5
Stage 5: Operating model, and selling to agents
Once Stages 1 to 4 run with stable approval queues
What to do
- Redesign roles around owners of the catalog, the policies and the money gates; review each agent's scorecard quarterly.
- Decide which outside agents and protocols you sell through, and on what terms: order limits, returns and fraud rules for agent orders[54,57,58].
- Hand replenishment and purchase order drafts to agents under value and unit thresholds.
Why now
AI-driven orders to Shopify stores tripled year over year by Q2 2026[52], Shopify opened checkout to browser agents in September 2026[59], and courts are still deciding who may shop on whose behalf[38].
In place first
- Stable approval queues at Stages 2 to 4; finance's agreement to purchase order thresholds.
What to measure
- Operating margin and contribution margin per order
- Share of orders from AI surfaces, and their fraud and return rates (no public benchmark)
Common mistakes
- Treating agent channels as a feed project with no policy on terms.
- Assuming agent orders carry the same fraud and return profile as other orders.
Your first 90 days
Stage 0, one product line through Stage 1, and drafting only in one support queue. The baseline you take in the first month is what tells you in the third whether it worked.
- Days 1 to 30
Stage 0. List every AI feature and every app scope that can refund, cancel, send, spend or publish. Write the five limits. Name an owner for each team's AI. Pull last quarter's refunds, discount codes and full-list sends as the baseline.
- Days 31 to 60
Stage 1 on one product line: an approved attribute and claims list, agent-drafted copy and alt text, a person publishes. Start Stage 2 drafting, not sending, in one support queue. Measure repeat contacts and the share of drafts sent unedited.
- Days 61 to 90
Turn on the first capped action: address edits before the 3PL picks, or in-policy refunds under the cap, with approval above it. Hold the first scorecard review with each owner. Agree the Stage 3 scope with finance and the 3PL.
How the operating model and roles change
The first point has a source. The others are our inference from where the work moves; we found no survey of how brands have reorganized.
- 1
The catalog becomes a product with an owner
AI-referred visitors land on product pages[52], and shopping agents read structured attributes and FAQs. Someone owns the approved attributes and claims that every agent, feed and listing draws from. In a 20-person brand that is part of a merchandiser's job; at 200 people it may be a role.
- 2
Support becomes an exceptions and policy team
If agents take routine order-status and policy tickets, CX leads spend their time on damage claims, fraud flags, VIP customers and reviewing what the agents decided. They also write the policy the agents quote, so a vague line in the returns policy becomes a pattern of wrong answers.
- 3
Growth marketers approve more than they build
Platforms already run ad delivery, and email platforms ship agents that build campaigns. The marketer's job narrows to the budget, the offer, the claims and the consent rules, and to saying no to sends that break them.
- 4
Ops and finance own the money gates
Refund caps, reship caps, discount floors, purchase order thresholds and 3PL invoice exceptions become settings someone in ops or finance owns and reviews, not defaults inside each tool.
- 5
Three owners that did not exist before
An agent owner per team (its playbook, its rules, its scorecard); a catalog and claims owner; and someone accountable for agent-facing commerce: feeds, protocols and which outside agents the brand accepts. We found no brand-level data on headcount effects, so we make no claim about them.
What not to fully automate
An agent can prepare every one of these. A named person makes the decision, and the record shows who.
The rules that bite
Software does not change who is responsible. Most of these rules were written for people and apply unchanged when an agent writes the product page, states the ship date, sets the price or sends the text. A few are aimed at AI directly: the review rule's ban on AI-written fake reviews, New York's pricing disclosure, the EU's chatbot disclosure.
Reviews and product claims
An agent that writes product pages, answers product questions or moderates reviews is making the brand's claims.
Shipping promises and order changes
A support agent that states a ship date is making a promise under federal rules.
Prices set or changed by software
A repricer, a price test or a fee added at checkout is a pricing decision, whoever or whatever made it. New York and California have rules that reach software-set prices and fees.
Subscriptions and cancellation
A retention agent that answers "cancel" with an offer is running a regulated flow.
Marketing messages
An agent can build a send to the whole list in minutes. A text without consent, or an email that ignores an opt-out, is counted per message.
Customer data, chat and payments
The help desk's AI vendor sits in every customer conversation, and checkout scripts are in payment scope.
Product safety, import and accessibility
Agents can draft these; a person signs them.
AI transparency and platform terms
Rules aimed at AI itself, and the contracts that decide what your agents may do on someone else's platform.
When agents fail
The expensive failures in ecommerce involve money, prices and claims. The untrusted inputs are chat messages, return reasons, review text and supplier spec sheets; the ways out are refunds, codes, prices, sends and product pages.
Real cases
Instacart's AI price tests (December 2025)
Shoppers saw the same item at prices an average 13% apart, up to 23%, set by AI pricing software[42]. Instacart said the tests were random and used no personal data[65]. The FTC opened an inquiry and the tests ended on 22 December 2025[43].
Control 3: price tests are a decision a person approves.
Rytr, an AI review generator (2024)
The FTC said it produced reviews with details that "had no relation to the user's input", and barred it from selling them[18].
Control 5: agents never write reviews.
accessiBe (2025)
A $1 million FTC order over claims that its AI widget could make any website accessible[19].
Control 21: claims about AI, including a vendor's, need substantiation.
Amazon v. Perplexity (2025 to 2026)
Amazon won an injunction against Perplexity's shopping agent in March 2026[39]; the Ninth Circuit vacated it in August, finding the user, not Perplexity, accessed Amazon[38].
Control 19: blocking agents in court is uncertain, so decide which agents you accept and on what terms.
Nate, an "AI" shopping app (charged 2025)
Claimed purchases "without human intervention"; prosecutors said automation was "effectively 0%", with contractors doing the work[63].
Control 20: judge vendors on your own scorecard and logs, not their claims.
Air Canada's chatbot (2024)
The bot described a refund policy the airline did not have, and a Canadian tribunal held Air Canada liable[67].
Control 6: policy answers come from an approved source.
Klarna's support assistant (2024, a success claim)
Two-thirds of chats handled by AI in month one and 25% fewer repeat inquiries, by Klarna's own account[64].
Control 6: measure repeat contacts and keep a path to a person.
Agent failures to design against (scenarios)
Scenarios, not reported cases. Each is what an agent with too much access could do, and each maps to one of the control points.
The OrchKernel blueprint for an ecommerce brand
OrchKernel is the layer between your agents and the systems they act in, as drawn in the missing layer. Agents ask it before they act; it checks the rules, holds what needs a person, runs what is allowed with its own credentials, and records what happened.
What it is not. It does not replace Shopify, your order management system, the help desk, the 3PL's warehouse system or the ERP; records stay there, and every write is checked against the live record. It does not score fraud, run ads, manage consent or sit in the card-payment flow. It does not govern outside shopping agents that buy from your store. And it is not a compliance certification.
The mechanisms
- Approvals
- The action waits for a named person, who sees exactly what will happen: the refund and its order line, the price and the band it breaks, the send list. Once approved, it runs once.
- Rules
- Checked at the moment of action, across every tool: refund caps, discount floors, price bands, allowed review-removal reasons. A rule allows, holds or denies, with a reason.
- Acting on a named person's authority
- The support agent acts for the CX lead, with no more access than she has. Revoking her delegation stops it.
- Data access by role and field
- A catalog agent never sees addresses; a support agent sees the order it is working on. No agent sees card data.
- Tamper-evident audit log
- Every request, check, approval and result, chained so an edited or deleted entry shows. Any run can be replayed.
- Human queue
- Fraud blocks, safety reports, customs questions and anything an agent is unsure of land with a named owner.
- Connections to your systems
- The brand connects Shopify, its help desk, its email and SMS platform, payments, the 3PL, marketplaces, ad accounts and Slack through MCP servers or REST adapters. OrchKernel holds the credentials, so agents never do.
Twenty-one control points, and what enforces each
What an AI-native brand needs in place whatever tools it uses, who owns each one, and how OrchKernel enforces it. Numbers match the scenarios above. Where OrchKernel does only part of the job, the last column says what does the rest; control 19 is outside it entirely.
Money
What customers are told
Safety, import and outside agents
Access and the record
The governed actions API, its TypeScript and Python clients, the MCP gateway and a dry run that explains what a policy would decide are arriving in this release. Single sign-on and SIEM export are later. OrchKernel is source-available under the Business Source License and runs on your own servers, so you can read the code that enforces these controls.
Scorecard by stage
Take the baseline before Stage 1 and track the same numbers at each stage. Public benchmarks exist for return rates and for margins at large public brands. For almost everything else they do not, and we have not quoted vendor figures as if they were benchmarks.
Sources
Sources were read in October 2026; dates are publication or data dates. Cost ratios are our arithmetic from each company's 10-K data.
Primary sources
Government agencies, regulators, legislatures, courts and SEC filings. Cost ratios were computed from each company's own 10-K data.
- 1Quarterly retail e-commerce sales, 2nd quarter 2026 (CB26-133). US Census Bureau, 18 August 2026.
- 2
- 3EDGAR company facts (XBRL) for Warby Parker, FIGS, Revolve, Smartbird (Allbirds), Stitch Fix, Chewy, Wayfair and Hims & Hers. US Securities and Exchange Commission, 10-Ks filed February to September 2026; downloaded 5 October 2026.Ratios are our arithmetic: each line item divided by revenue
- 4Wayfair Inc., annual report on Form 10-K for 2025. SEC EDGAR, filed 19 February 2026.
- 5Amazon.com, Inc., annual report on Form 10-K for 2025. SEC EDGAR, filed 6 February 2026.
- 6Shopify Inc., annual report on Form 10-K for 2025. SEC EDGAR, filed 11 February 2026.
- 7Klaviyo, Inc., annual report on Form 10-K for 2025. SEC EDGAR, filed 10 February 2026.
- 8Chewy, Inc., annual report on Form 10-K for fiscal 2025. SEC EDGAR, 2026.
- 9Suspending duty-free de minimis treatment for all countries (Executive Order 14324). The White House, 30 July 2025.
- 10Indefinite suspension of the de minimis exemption for merchandise arriving through all modes other than the international postal network (interim final rule). US Customs and Border Protection, Federal Register, 24 June 2026.Describes Learning Resources v. Trump, Executive Order 14388 and the statutory repeal
- 1119 U.S.C. 1484, Entry of merchandise. Legal Information Institute, Cornell Law School.
- 1219 U.S.C. 1592, Penalties for fraud, gross negligence, and negligence. Legal Information Institute, Cornell Law School.
- 13Trade Regulation Rule on the Use of Consumer Reviews and Testimonials (final rule). Federal Trade Commission, Federal Register, 22 August 2024; effective 21 October 2024.
- 14Federal Trade Commission announces final rule banning fake reviews and testimonials. Federal Trade Commission, 14 August 2024.
- 15Consumer Reviews and Testimonials Rule: questions and answers. Federal Trade Commission.
- 1616 CFR 465.2, Fake or false consumer reviews, consumer testimonials, or celebrity testimonials. Legal Information Institute, Cornell Law School.
- 1716 CFR 465.7, Review suppression. Legal Information Institute, Cornell Law School.
- 18FTC announces crackdown on deceptive AI claims and schemes (Operation AI Comply). Federal Trade Commission, 25 September 2024.
- 19FTC approves final order requiring accessiBe to pay $1 million. Federal Trade Commission, 22 April 2025.
- 20Health Products Compliance Guidance. Federal Trade Commission.
- 2116 CFR 323.2, Made in USA Labeling Rule: prohibited acts. Legal Information Institute, Cornell Law School.
- 22Made in USA Labeling Rule (final rule). Federal Trade Commission, Federal Register, 14 July 2021.
- 23Complying with the Made in USA standard. Federal Trade Commission.
- 24Guides for the Use of Environmental Marketing Claims (Green Guides), 16 CFR Part 260. Federal Trade Commission, 11 October 2012.
- 25Business guide to the FTC's Mail, Internet, or Telephone Order Merchandise Rule. Federal Trade Commission, edited January 2025.
- 26New York General Business Law section 349-a, Personalized algorithmic pricing. New York State Senate.
- 27SB 478: hidden fees. California Attorney General, in effect 1 July 2024.
- 28Trade Regulation Rule on Unfair or Deceptive Fees (final rule). Federal Trade Commission, Federal Register, 10 January 2025; effective 12 May 2025.
- 29AB 2863, Automatic renewal and continuous service offers. California Legislature, chaptered 24 September 2024; operative 1 July 2025.
- 30Custom Communications, Inc. v. FTC, No. 24-3137 (opinion vacating the Negative Option Rule). US Court of Appeals for the Eighth Circuit, 8 July 2025.
- 31Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277. US Court of Appeals for the Eleventh Circuit, 24 January 2025.
- 32Advanced Methods To Target and Eliminate Robocalls (consent revocation). Federal Communications Commission, Federal Register, 5 December 2025.
- 33Declaratory ruling: AI-generated voices are "artificial" under the TCPA. Federal Communications Commission, 8 February 2024.
- 34CAN-SPAM Act: a compliance guide for business. Federal Trade Commission.
- 35CCPA updates, cybersecurity audits, risk assessments and automated decisionmaking technology regulations. California Privacy Protection Agency, approved 22 September 2025; effective 1 January 2026.
- 36Text of regulations (definition of "significant decision", section 7001). California Privacy Protection Agency.
- 37Regulation (EU) 2023/988 on general product safety. EUR-Lex, Official Journal of the European Union, applies from 13 December 2024.
- 38Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (opinion). US Court of Appeals for the Ninth Circuit, 4 August 2026.
- 39Amazon.com Services LLC v. Perplexity AI, Inc., N.D. Cal. 3:25-cv-09514 (docket). CourtListener, filed 4 November 2025.
Industry bodies and independent research
Trade associations, standards bodies, consumer groups and independent analysts. Trade-body surveys describe their own members.
- 40Consumers expected to return nearly $850 billion in merchandise in 2025. National Retail Federation and Happy Returns, 15 October 2025.Survey of 358 retailers, all above $500 million in revenue. Happy Returns is a UPS company that sells returns services
- 41Amazon fees only go up. Marketplace Pulse, 18 March 2024.
- 42New report exposes Instacart's hidden price games. Consumer Reports, Groundwork Collaborative and More Perfect Union, 9 December 2025.
- 43Instacart stops AI pricing experiments. Consumer Reports, 22 December 2025.
- 44New information supplement: payment page security and preventing e-skimming. PCI Security Standards Council.
- 45Now is the time for organizations to adopt the future-dated requirements of PCI DSS v4.x. PCI Security Standards Council.
- 46EU AI Act, Article 50: transparency obligations for providers and deployers of certain AI systems. Future of Life Institute (artificialintelligenceact.eu).Unofficial text; the Official Journal is authoritative
- 47EU AI Act implementation timeline. Future of Life Institute (artificialintelligenceact.eu), updated 31 August 2026.
Vendor sources
Published by companies that sell the product being measured. Directional, not an industry benchmark.
- 48AI traffic to US retailers rose 393% in Q1, and it's boosting their revenue too (Adobe Analytics data). TechCrunch, reporting Adobe, 16 April 2026.Vendor sourceAdobe sells analytics software to retailers
- 49
- 50True Cost of Fraud study, US and Canada retail and ecommerce. LexisNexis Risk Solutions, 2026 edition.Vendor source513 respondents. LexisNexis sells fraud tools
Company and press
Company announcements, news coverage, law-firm commentary and encyclopedia summaries. Company figures are the company's own claims.
- 51Shopify says AI traffic is up 7x since January, AI-driven orders are up 11x. TechCrunch, 4 November 2025.
- 52Shopify says AI search is driving more traffic and sales, not replacing Google. TechCrunch, 5 August 2026.
- 53Shopify Editions, Summer '25. Shopify, 2025.
- 54Shopify Editions, Winter '26. Shopify, 2025.
- 55Shopify API License and Terms of Use. Shopify, updated 27 February 2026.
- 56
- 57Stripe powers Instant Checkout in ChatGPT and releases the Agentic Commerce Protocol. Stripe, 29 September 2025.
- 58Google announces a new protocol to facilitate commerce using AI agents. TechCrunch, 11 January 2026.
- 59Shopify opens checkout to browser-based AI agents. TechCrunch, 28 September 2026.
- 60Amazon expands a program that lets customers shop from other retailers' sites. TechCrunch, 11 March 2026.
- 61World launches tool to verify humans behind AI shopping agents. TechCrunch, 17 March 2026.
- 62The man who built Apple's stores doesn't buy Silicon Valley's bet on AI shopping. TechCrunch, 21 September 2026.
- 63Fintech founder charged with fraud after AI shopping app found to be powered by humans in the Philippines. TechCrunch, 10 April 2025.
- 64Klarna AI assistant handles two-thirds of customer service chats in its first month. Klarna, 27 February 2024.
- 65The truth about pricing tests on Instacart. Instacart, 18 December 2025.
- 66New York's algorithmic pricing law. Data Protection Report (Norton Rose Fulbright), December 2025.Law-firm commentary on NRF v. James
- 67
- 68