The Claim Under Test
Every ranking of ecommerce AI agents you will read this year is built on a number that the vendor invented, defined and invoiced. Open five of them and you will find the same shape: this agent resolves 70% of tickets, that one deflects 60%, a third contains 85%. Those are printed as though they were measurements taken by someone. They are not. They are counts of a unit each seller defines for itself, published by the seller, with no methodology and no neutral party checking a single one.
The claim under test here is narrow: can a DTC operator rely on any published performance figure in this category? After checking every vendor page in this roster on 23 August 2026, our answer is no — and the reason is not that vendors are lying. It is structural. Zendesk's own support documentation explains that an automated resolution is counted after 72 hours of inactivity, subject to an LLM verifying the reply was relevant, where the shopper either gave positive feedback or gave no feedback at all, and where no human agent replied. Read that as an operator rather than as a buyer of software. A shopper who asked a question, got an answer that did not help, gave up and bought elsewhere leaves no feedback and generates no human reply. Seventy-two hours later, that abandonment is counted as a resolution and billed to you as one.
It gets worse before it gets better, because the vendors in this market do not even bill in the same kind of unit. Across the thirteen products we examined we found five mutually incompatible billing units — per resolution, per seat, per order, per credit and per share of your GMV. A buyer comparing $0.90 to $0.99 to $2.00 is comparing three definitions written by three different sellers, at least one of which includes a $750 monthly floor before the first ticket is touched. That is not a price comparison. It is a category error with a spreadsheet around it.
So this ranking does something narrower and more useful. It scores only attributes you can re-check yourself in under an hour with a browser, it records the unit in every pricing cell rather than just the number, and it names what it refused to score and why. This piece sits inside a wider set of vertical rankings built on the same method; the cross-industry version is our guide to the top AI agents in 2026. What follows is the ecommerce edition, written for a brand somewhere between $2M and $100M in revenue, not for an enterprise retailer with a procurement department.
One piece of context worth having in front of you while you read: the market is not shrinking, and nobody needs to sell you a crisis to justify the spend. The US Census Bureau's Quarterly Retail E-Commerce Sales report for the second quarter of 2026, released 18 August 2026, puts adjusted US retail e-commerce at $340.2 billion, 17.1% of total retail sales, growing 12.2% year over year against 6.7% for retail overall. That is a real, dated, primary figure from a statistical agency, and it is the only kind of number in this article you did not have to take from a seller.
How We Ranked, and What We Refused to Rank On
We start with the refusal, because it is the more important half.A resolution is a billing definition set by the seller, not a performance metric — so resolution rate, deflection rate, containment rate, automation rate, CSAT lift, hours saved and ROI are all excluded from the scoring. Not because they are unimportant, but because there is no neutral instrument measuring any of them, and printing two vendors' self-reported rates side by side implies a common standard that does not exist.
The evidence for that refusal is not an opinion we formed. It is on the vendors' own pages. Zendesk's automated-resolutions documentation states that a resolution is counted after 72 hours of inactivity where the end user gave positive feedback or gave none, provided no human agent responded, and that each resolution is verified by an LLM rather than by a person. Gorgias's published pricing page uses a comparable 72-hour window to decide whether a later human touch is re-billed. Both are defensible engineering choices. Neither is a measurement of whether a shopper was helped, and neither vendor claims it is — that claim gets added later, by marketing, and then by listicles.
What we scored — every attribute re-checkable by the reader
- Published pricing AND the unit it is billed in — per resolution, per seat, per order, per credit, per GMV band, or not published at all
- Whether the vendor publishes compliance documentation on its own trust page, and at what level of detail — SOC 2 Type II is a different assurance from an unqualified “SOC2”
- Whether a trust page exists at all. Two vendors here return 404 on their security URL, and that is a verified absence rather than a gap we paper over
- Named integrations documented on the vendor's own site, not on a partner's marketing page
- Standalone versus locked to a suite or a platform
- Ownership and corporate status from public record — SEC filings, completed acquisitions, dated press releases
- Whether any independent evaluation of the product exists
- Data residency, retention and DPA availability as published, not as promised on a sales call
On the independent-evidence question, we want to be precise rather than sweeping. No independent benchmark of these commercial products exists — we looked and located none as of 23 August 2026. That is a narrow claim. Independent evaluation does exist elsewhere in AI agents; it just measures models or modalities rather than the specific tools you would actually buy. In ecommerce specifically, there is nothing: no head-to-head, no third-party accuracy measurement, no standard definition of the unit being counted.
What does exist is the one occasion a US regulator audited a vendor's published AI performance metrics, and it is worth knowing what happened. In In the Matter of Presto Automation Inc., Securities Act Release No. 11352, Administrative Proceeding File No. 3-22413, entered 14 January 2025, the SEC addressed a company that had told investors its drive-thru voice AI delivered “over 94% accuracy even in noisy environments” and 95%–99% automated order completion. The Commission found the product “lacked the capability to take orders on their own and required substantial human involvement,” with “human order takers located abroad (primarily in the Philippines and India), who processed the vast majority of drive-thru orders.”
Three framing points are mandatory and we will not skip them. Presto consented to the order without admitting or denying the findings. The remedy was a cease-and-desist order with no civil penalty — it was not a fine. And the findings are against Presto only; the order's “Supplier A” is a different company against whom the SEC made no findings whatsoever. It is a restaurant technology case, not an ecommerce one. We cite it for a single, transferable proposition: this is what happened the one time a regulator with subpoena power checked a vendor's published AI performance metric, which is why we score only what a buyer can verify.
| The claim | Where it actually comes from | What we print instead |
|---|---|---|
| “Our AI resolves 70% of tickets” | The vendor, about itself, using a unit the vendor defines. Zendesk's own documentation counts a resolution after 72 hours of silence with no feedback | The published definition of the billing unit, quoted from the vendor's own documentation, and a written RFP question asking how a resolution is counted |
| “70% of carts are abandoned” | Baymard's average of 50 studies published between 2006 and 2025, ranging 55.00% to 84.27%, most from vendors selling abandonment remedies | Baymard's own primary research: 42% of US online shoppers have abandoned a cart because they were just browsing. Plus the actionable causes — cost, delivery speed, trust, checkout length |
| “It costs 5× more to acquire a customer than to retain one” | Untraceable. The attribution shifts between at least three sources and the multiplier quoted in the wild ranges from 5× to 25× | Nothing. We could not establish an origin, so we do not print it — and a vendor who quotes it at you should be asked where it comes from |
| “120M+ packages stolen in 2024, theft surging 34%” | A vendor homepage, unsourced on the page itself | Nothing. The figure appears on a vendor's corporate site with no citation attached, so it does not travel |
| “5× ROI guarantee” | A vendor pricing page headline. We verified that the claim appears; we did not verify that any ROI was measured | The fact that the claim exists and that the same page publishes no prices — which tells you more about the sale than the guarantee does |
| “95% of GenAI pilots fail” | A study of 52 interviews and 153 conference surveys about custom-built tools, laundered into a universal statistic | Nothing. It does not describe buying a commercial ecommerce agent and should not be used to price fear |
Five Incompatible Billing Units — the Column Most Comparisons Leave Out
The single most useful thing you can do before comparing any two vendors in this market is write down the unit next to the number. We found five kinds of unit across thirteen products, and they are not variations on a theme — they are five different theories of what you are buying. You are buying an outcome, or a seat, or an order, or a credit, or a share of your revenue. Those are not comparable quantities, and no amount of spreadsheet formatting makes them one.
| Vendor | Unit billed | Published figure | Who the unit quietly favours |
|---|---|---|---|
| Gorgias | Per resolution, plus per ticket | $0.90 annual / $1.00 monthly per AI resolution; $1.50 per automated interaction over allowance | The vendor, when resolutions are counted generously — but the buyer, at low automated volume, because there is no platform floor |
| Siena AI | Platform fee plus per automated ticket | $750 per month, plus $0.90 each | The vendor at low volume, because the floor is paid before the first ticket. The gap closes as volume rises |
| Intercom Fin | Per outcome, plus per seat | $0.99 per outcome; $29 / $85 / $132 per seat per month | Neither, unusually — because Intercom publishes the definition of an outcome and will run per-outcome only on a third-party helpdesk |
| Zendesk | Per automated resolution, plus per seat | $2.00 pay-as-you-go per resolution | The vendor, because its own documentation counts a resolution after 72 hours of silence with no feedback |
| Richpanel | Per order band, per user, and flat unlimited resolutions | $50–$600 per month; $29–$99 per user per month; $120 or $360 per month unlimited | The buyer at high volume — the flat tier is the only structure here that removes the vendor's incentive to count generously |
| Octane AI | Per credit | $50 / $200 / $500+ per month; $0.10 per overage credit | The vendor, because a credit is an internal unit the buyer cannot audit from outside |
| Loop Returns | Per month, tiered | From $155 / from $340 | Predictable for the buyer; the risk is band creep at renewal rather than usage drift |
| Triple Whale | Per GMV band | $0 / $219 / $1,290 per month | The vendor, structurally — the invoice rises with your revenue whether or not you used the agent more |
| Rep AI | Not publicly disclosed | No dollar figures on the pricing page | Unknowable from outside, which is itself the finding |
| Narvar | Not publicly disclosed | Routes to a demo booking | Unknowable from outside |
| Kustomer | Not publicly disclosed | Pricing page is client-rendered and returned nothing to us | Unknowable from outside |
The cleanest demonstration is two vendors publishing the same headline figure. Gorgias publishes $0.90 per AI Agent resolution on annual plans. Siena publishes $0.90 per automated ticket. Identical numbers. But Siena's structure adds a $750 per month platform fee before the first ticket. At 300 automated tickets a month, that is $1,020 against $270 — a 3.8× difference hidden entirely inside the unit. At 3,000 tickets a month the gap narrows to $3,450 against $2,700, and by 10,000 the platform fee has become a rounding error. Neither vendor is being deceptive. The headline figure is simply not the price.
Then there is the structure nobody talks about. Triple Whale prices on GMV bands — free, $219 a month, and a tier shown at $1,290 a month, with bands running from “up to $2M” through “$7M+”. Read that as an operator: the vendor's revenue rises with yours whether or not you used the agent more. For a brand between $2M and $100M in revenue, that is the single most consequential pricing structure in this roster, because it is the only one where a good year automatically costs you more software.
And exactly one vendor has removed its own incentive to count generously. Richpanel publishes a flat monthly automation tier at $120 and $360 with unlimited resolutions, positioned explicitly against per-resolution competitors. Whether the product suits you is a separate question we have no independent evidence to answer. But structurally, a flat rate is the only arrangement here where the vendor gains nothing from a liberal definition of the word being counted — and that is a checkable, scoreable property, which is precisely the sort of thing this method rewards.
The Comparison Table — Ten Vendors, Verifiable Attributes Only
Every cell below is either a citation you can open or the literal words “not publicly disclosed” / “not verified”. Nothing is estimated. A low position is not a verdict on product quality — it means less was verifiable from a browser on 23 August 2026, which is the only thing this method claims to measure.
| Vendor (checked 2026-08-23) | What it actually is | Pricing UNIT — the number means nothing without it | Published price | Published compliance | Ownership of record |
|---|---|---|---|---|---|
| 1. Intercom — Fin | Autonomous resolution agent, plus a separately priced Inbox copilot — the only vendor here that prices the agent/copilot distinction | Per outcome, plus per seat. Runs on a third-party helpdesk at per-outcome only | Fin $0.99 per outcome on every plan; seats $29 / $85 / $132 per month; Copilot $29 per agent per month annual | The most comprehensive in this roster: SOC 2 Type II, ISO 27001, ISO 27018, ISO 27701, ISO 42001, HIPAA; Fin separately AIUC-1 certified; residency US, EU, AU; 99.8% uptime SLA | Intercom, privately held. Ownership not re-verified from a public filing this session |
| 2. Richpanel | Helpdesk plus self-service portal with an automation tier — the transparency outlier | Three units published side by side: per order band, per user, and a flat “unlimited resolutions” monthly | Self-service $0 / $50 / $600 per month by order band; helpdesk $29–$99 per user per month; automation tiers $120 and $360 per month unlimited | Not verified — we did not fetch a trust page this session | Not verified this session |
| 3. Gorgias — AI Agent | Autonomous resolution layer sold on top of a rules-and-macros helpdesk built for ecommerce | Per AI resolution, plus per ticket. Explicitly “never priced per agent” | AI Agent $0.90 per resolution annual, $1.00 monthly; $1.50 per automated interaction over the included allowance; ticket overage $0.36–$0.40 | SOC 2 Type II stated on its own security page, report on request; Google Cloud infrastructure. No ISO 27001, no PCI claim, no residency or retention commitment, no DPA link found on that page | Gorgias, privately held. Not re-verified from public record this session |
| 4. Klaviyo | Lifecycle and retention platform that moved into service in 2026: Klaviyo AI, Customer Agent, Customer Hub, Helpdesk, Reviews | Per active profile, plus per send for email and SMS | Publishes list pricing scaled by active profiles; our fetch was geo-served the French site and we do not print figures we did not read from a US context | A Trust Center exists but rendered as navigation only for us — not verified | The only public reporting company in this roster: Klaviyo, Inc., CIK 0001835830, NYSE: KVYO, Form 10-K filed 10 February 2026 |
| 5. Loop Returns | Returns, exchanges and post-purchase tracking. Primarily a workflow and rules engine, not an autonomous agent | Per month, tiered by volume band | Checkout+ free; Essential from $155 per month; Advanced from $340 per month | States “SOC2 certified” — the type is not specified, and Type I and Type II are materially different assurances. No PCI DSS attestation located. Sub-processor list published; DPA not located | Loop Returns; acquired Wonderment, now marketed as Loop Tracking. Acquisition date not established |
| 6. Octane AI | Quiz, pop-up and zero-party data builder with AI assistance. A merchandising tool, not an autonomous agent | Per credit | Basic $50 / Plus $200 / Enterprise $500+ per month, at 400 / 2,200 / 7,250+ credits; overage $0.10 per credit | Not verified this session | Not verified this session; no evidence of acquisition found |
| 7. Triple Whale — Moby | Attribution and analytics with an agent-positioned assistant. Whether Moby acts or advises is not established from the pricing page | Per GMV band — the vendor's revenue rises with yours, regardless of agent usage | Free $0; Foundation $219 per month; a higher tier shown at $1,290 per month; bands from “up to $2M” to “$7M+” | Not verified this session | Not verified this session |
| 8. Siena AI | Commerce-focused agents: Customer Service, Shopping, Reviews, QA. GA status per agent is ambiguous on the site — some are marked coming soon | Platform fee plus per automated ticket | $750 per month platform fee plus an automation pack at $0.90 per automated ticket; implementation is contact-sales | No trust page located — siena.cx/security returned 404 for us. Recorded as a verified absence | Privately held, venture-backed. Aggregator funding totals conflict, so we print none |
| 9. Zendesk — AI agents | Enterprise-scale helpdesk with AI agents. Its own documentation defines an automated resolution as counted after 72 hours of inactivity | Per automated resolution, plus per seat. The unit changed on 18 May 2026 to a resolution-tier model | $2.00 per pay-as-you-go automated resolution; committed usage documented as cheaper than overage. Seat figures were geo-served a non-US locale, so we do not print them | Not fetched this session — we assert nothing | Taken private in 2022 by an investor group; not re-verified from public record this session |
| 10. Shopify — Sidekick | A copilot by Shopify's own word — “assistant”, not agent. Answers questions and performs merchant-side admin tasks | Bundled — no separate unit | Included with Shopify plans; we could not verify which plans include it because help.shopify.com returned 403 to us | Not assessed separately from Shopify platform compliance | Shopify Inc., public company |
Two observations about the shape of that table are worth more than any individual row. First, compliance posture could not be verified for 7 of the 13 vendors we examined, and for two of them the security URL returned a 404 — there is no trust page to read. Second, ownership of record is unverified for four of them, in a market where an acquisition happened during our research window. Both facts are findings, not gaps in our work, and we score them as findings.
The Ten Entries
1. Intercom — Fin
What it does: an autonomous resolution agent for customer support, sold alongside a separately priced Inbox copilot. Intercom is one of the very few vendors that prices the agent-versus-copilot distinction rather than blurring it, which makes the taxonomy concrete instead of rhetorical.
What is verifiable: pricing is fully published — Fin at $0.99 per outcome on every plan, seats at $29, $85 and $132 per month, Copilot at $29 per agent per month on annual billing. Fin will run on a third-party helpdesk at per-outcome pricing with no seat cost, subject to a minimum monthly commitment. Its security page is the most detailed in this roster: SOC 2 Type II, ISO 27001, ISO 27018, ISO 27701 and ISO 42001, HIPAA, a separate AIUC-1 certification for Fin, data residency in the US, EU or Australia, and a 99.8% uptime SLA covering the AI agent and core platform.
What is not disclosed: nothing material on the compliance side, which is unusual. Who it fits: a brand that wants the agent decoupled from the helpdesk, or that already runs Salesforce. Who it does not: a brand whose volume is low enough that the per-outcome minimum commitment bites. Ownership: privately held; we did not re-verify from a public filing. AIUC-1 is a certification, not a comparative benchmark — do not let anyone present it as one.
2. Richpanel
What it does: an ecommerce helpdesk with a customer self-service portal and an automation tier. Its distinguishing property is commercial rather than technical: it is the transparency outlier.
What is verifiable: it publishes three different units side by side — self-service priced by monthly order band (free to 1,000 orders, $50 at 3,500, $600 at 10,000, with annual equivalents), a help desk priced per user ($29 and $99 monthly, $20 and $85 annual), and AI tiers at a flat $120 and $360 per month marketed as unlimited resolutions. It positions the flat tier explicitly against per-resolution competitors. For a high-volume brand, flat versus per-resolution is the entire decision.
What is not disclosed: compliance. We did not locate or fetch a trust page this session, so we assert nothing about SOC 2, and ownership is likewise unverified. Who it fits: a brand with high ticket volume that wants a predictable line item. Who it does not: a security-led buyer who needs an attestation before signature — that has to be requested and read.
3. Gorgias — AI Agent
What it does: an autonomous resolution layer sitting on top of a rules-and-macros helpdesk purpose-built for ecommerce. The honest framing is an autonomous layer inside a rules-based product, not a clean-sheet agent.
What is verifiable: published, ticket-based plans across Starter, Basic, Pro and Advanced, explicitly “never priced per agent”; AI Agent resolutions at $0.90 on annual plans and $1.00 on monthly; $1.50 per automated interaction beyond the included allowance; ticket overage of $0.36 to $0.40 depending on tier. Its security page states SOC 2 Type II with the report available on request, names Google Cloud Platform as infrastructure, and describes encrypted backups and SSO for Google and Microsoft 365.
What is not disclosed: no ISO 27001, no PCI claim, and no data residency, retention commitment or DPA link on that page. Billing mechanic to model: a conversation the AI resolves is billed as a resolution, and a subsequent human touch within 72 hours is treated under the helpdesk ticket price rather than double-charged. Model both the resolution fee and the ticket fee, because your blend of the two is the actual invoice. Who it fits: a Shopify-centric brand that wants ecommerce-native workflows out of the box.
4. Klaviyo
What it does: lifecycle and retention, and as of 2026 rather more than that. Klaviyo now markets Klaviyo AI, a Customer Agent, Customer Hub, a Helpdesk, Composer, Reviews and its data platform. Klaviyo has moved into customer service and agents — a 2026 fact that most rankings of this category have not caught up with.
What is verifiable, and it is unique here: Klaviyo is the only public reporting company in this roster. Klaviyo, Inc., CIK 0001835830, NYSE: KVYO, filed a Form 10-K on 10 February 2026. Ownership, financials and risk disclosures are on the public record, audited, with a filing date. No other vendor here offers that, and under this ranking's own logic it is a real transparency advantage rather than a branding one.
What is not disclosed to us: pricing. Klaviyo publishes list pricing scaled by active profiles and separately by email and SMS sends, but our fetch was geo-served the French site and we will not print figures we did not read from a US context. Its Trust Center exists but rendered as navigation only. The compliance note that matters: Klaviyo ships a Reviews product, which puts it inside 16 CFR Part 465 in exactly the way discussed below.
5. Loop Returns
What it does: returns and exchanges, and now post-purchase tracking too. Call it what it is:primarily a workflow and rules engine — automated return policies, workflows, carrier rate shopping, auto returns processing — rather than an autonomous agent. This is the “rules automation marketed in an agent-shaped market” category, and the distinction is worth holding.
What is verifiable: published pricing — Checkout+ free, Essential from $155 per month, Advanced from $340 per month, with Advanced adding Shop Now, Instant Exchange, Bonus Credit and fraud prevention. Loop acquired Wonderment; the product is now Loop Tracking.
What is not disclosed, and it matters here: Loop touches refunds, instant exchanges and store credit, so it sits adjacent to payment flows. Its security page says “SOC2 certified” without specifying the type — Type I and Type II are materially different assurances — and we located no PCI DSS attestation. A sub-processor list and vulnerability disclosure policy are published; a DPA was not located. Ask for the report type in writing before signature.
6. Octane AI
What it does: quizzes, pop-ups and zero-party data capture with branching logic and AI assistance. It is a merchandising quiz tool with AI features, not an autonomous agent, and its own feature list — A/B testing, analytics, advanced logic branching — says so plainly. We include it because it is genuinely useful and because the category needs at least one honest example of classic automation wearing an agent-shaped label.
What is verifiable: credit-based pricing — Basic $50 per month ($43 annual) with 400 credits and a two-quiz limit; Plus $200 ($170) with 2,200 credits, unlimited quizzes and A/B testing; Enterprise and Unlimited at $500+ ($425+) with 7,250+ credits or unlimited. Overage is $0.10 per credit. Klaviyo and Shopify sync are named on the pricing page.
What is not disclosed: compliance is unverified. The unit warning: a credit is an internal accounting unit you cannot audit from outside. The vendor states a quiz consumes roughly 0.3 credits, which is a vendor figure — model your own consumption during the trial rather than from the marketing page.
7. Triple Whale — Moby
What it does:attribution and analytics for DTC brands, with an agent-positioned assistant called Moby marketed as “your AI operator” across the product and Slack.
What is verifiable:a fully published, GMV-banded pricing calculator — free, $219 per month for Foundation, a tier shown at $1,290 per month, with bands from “up to $2M” to “$7M+” and annual billing described as two months free.
What is not disclosed: whether Moby acts autonomously or advises is not established from the pricing page, and compliance is unverified. The structural point: GMV pricing directly contradicts the per-resolution model. Your invoice tracks your revenue, not your usage. For a $2M–$100M brand that is worth modelling across three years of growth before signing an annual term.
8. Siena AI
What it does:commerce-focused agents — a Customer Service Agent, a Shopping Agent, a Reviews Agent marketed as putting review management on autopilot, and a QA Agent — plus “Ask Siena,” marketed as an agent built for brand operators.
What is verifiable: an unusual and fully published pricing structure — a $750 per month platform fee covering the core engine and unlimited sandbox, plus an automation pack at $0.90 per automated ticket, with support and implementation contact-sales. The page also notes pricing is based on ticket volume and team structure, so quoted deals may vary.
What is not disclosed: compliance, entirely. siena.cx/security returned a 404 for us and we located no trust page at all. That is a verified absence and we score it as one. Some agents on the product page are marked coming soon and the rendering was ambiguous about which, so we do not claim the Shopping or QA agents are generally available. The compliance flag: a Reviews Agent is the single most rule-exposed product in this entire roster — see the binding-constraint section, which was largely written because this product exists.
9. Zendesk — AI agents
What it does: enterprise-scale customer service with AI agents layered across email, web, messaging and voice. It is the largest platform in this roster by a distance, and its rank here reflects verifiability on the date checked, not capability.
What is verifiable, and it is the most important documentation in this article: Zendesk publishes exactly how an automated resolution is counted — after 72 hours of inactivity, with LLM verification of relevance, where the shopper gave positive feedback or no feedback, and where no human agent responded. Resolutions are counted per conversation, not per user. Pay-as-you-go automated resolutions are documented at $2.00 each, with committed usage cheaper than overage.
What changed in 2026: Zendesk's own documentation states it describes the platform in place prior to 18 May 2026 and refers to a newer model of resolution tiers. Any comparison using pre-May-2026 Zendesk pricing is already stale, which is a good argument for re-checking a ranking rather than copying one. What is not disclosed here: our pricing fetch was geo-served a non-US locale mixing currencies, so we print no seat figures; we did not fetch its trust page; and we did not re-verify ownership from public record.
10. Shopify — Sidekick
What it does: Shopify markets Sidekick as “your AI assistant with an obsession for commerce.” By the vendor's own word it is an assistant, not an agent — it answers merchant questions and performs admin tasks inside Shopify. That makes it the cleanest copilot-versus-agent contrast available anywhere in this category, and the definitional anchor for the rest of the roster.
What is verifiable: it exists, it is listed as a first-class Shopify product, and it is the maximal case for lock-in — Sidekick exists only inside Shopify admin. If you leave the platform, it does not come with you, and no data export makes it portable.
What is not disclosed to us: plan availability. help.shopify.com returned a 403 to our fetcher, so we record only “included with Shopify; plan availability not verified 2026-08-23.” We also make no claims at allabout Shopify's agentic-commerce surfaces — catalogue, knowledge base, universal cart — because we could not confirm what has shipped or whether it is generally available. That area moves fast and a stale claim there would be exactly the error this method exists to avoid.
Considered and Not Ranked — Including Three Names You Will See in Other Lists
Three products are widely listed in this category and should not be. Naming them is more useful than adding an eleventh entry, because a stale roster is the failure mode that gets a ranking dismissed by the operator it was written for.
- Wonderment — acquired by Loop Returns. Its site now serves a page titled “Wonderment is now Loop Tracking!”, with a canonical URL pointing at loopreturns.com and a banner announcing the acquisition. Ranking it as an independent post-purchase vendor in 2026 is a factual error. We could not establish the acquisition date, so we do not print one.
- “Zoe by Gorgias” — no such product exists on Gorgias's own pricing page, which names Starter, Basic, Pro, Advanced and AI Agent. Under this method, a product we cannot confirm exists in 2026 does not get listed.
- Daydream — a real, trading company, but an SEO and AI-search visibility firm combining agents with dedicated human experts, whose named clients are B2B and technology businesses. That is an agency-plus-software service, not a DTC ecommerce agent product. Out of scope, not defunct.
Three further vendors are real, trading, and relevant, but did not rank because too little was verifiable. Rep AI has the best-documented corporate record in the entire roster — a $6.2 million strategic follow-on round announced 28 May 2026, led by Silicon Road Ventures with Osage Venture Partners, Flashpoint Venture Capital and Zendesk as a strategic investor, following an $8.2M Series A in August 2024. That last detail is worth holding: Zendesk invests in Rep AI, which is legitimate context when you are comparing the two. But Rep AI's pricing page contains no dollar figures at all— only a trial offer and a “5× ROI guarantee” — and hellorep.ai/security returned a 404. Its Helpdesk is labelled beta on its own site.
Narvar markets agentic post-purchase products and has the broadest documented integration set we found — Shopify, Zendesk, BigCommerce, Klaviyo, Magento, Gorgias, Salesforce and Attentive named on its own site — but publishes no pricing and routes to a demo. Its homepage also carries four striking statistics about package theft, delivery-issue costs and consumer trust, none of which is sourced on the page, so none appears in this article. It is enterprise-weighted, and for a $2M–$100M brand that is a fit question before it is a capability question. Kustomer is trading and positions as an AI customer service platform and CRM, but its pricing page is fully client-rendered and returned nothing to us, and — more importantly — we could not establish who owns it in 2026 from public record. It has been acquired and divested before. We do not state ownership we have not verified, and an unresolved owner is a genuine procurement risk, not a footnote.
The Numbers We Refused to Print, and Why
Two statistics dominate ecommerce AI sales conversations and neither should travel in the form it usually arrives. Refusing them is not pedantry — a vendor who opens with an unsourceable number has told you something about how the rest of the deck was assembled.
“About 70% of carts are abandoned.” The figure is real and its provenance is public. Baymard Institute publishes 70.22% and states on the same page that the value is an average calculated from 50 different studies, gathered so people could cite one number instead of fifty. The inputs span 2006 to 2025 — the oldest is a 2006 study at 59.80%, the newest a 2025 one at 71.72% — and the range across the set runs from 55.00% to 84.27%. Most of the sources are vendors selling abandonment remedies. Baymard itself adds the caveat almost nobody quotes: a large portion of cart abandonments are a natural consequence of how users browse ecommerce sites, and are largely unavoidable.
Baymard's own primary research is the citable part, and it is more useful anyway: 42% of US online shoppers have abandoned a cart because they were just browsing or not ready to buy. Excluding that group, the leading causes are extra costs too high (40%), delivery too slow (20%), not trusting the site with card details (19%), forced account creation (18%), and checkout too long or complicated (17%). Baymard also finds the average US checkout shows 23.48 form elements against an ideal of 12 to 14.
“It costs five times more to acquire a customer than to retain one.”We went looking for the origin and could not establish one. The attribution shifts between at least three different sources, and the multiplier quoted in the wild ranges from five to twenty-five depending on who is repeating it. Under this article's own standard, an untraced statistic is refused — so we do not print it, in any multiplier, attributed or not. If a vendor quotes it at you, ask where it comes from and watch what happens.
The same refusal applies to every deflection, containment, automation and resolution rate in this market, and to the cluster of pilot-failure statistics that circulate as ambient dread — “95% of GenAI pilots fail” describes 52 interviews and 153 conference surveys about custom-built tools, not a purchase decision about a commercial ecommerce agent. Fear priced from a misread statistic is still a misread statistic.
The Binding Constraint: Reviews, Cancellation, and the Signal You Must Honour
The constraint that decides whether any of this works in ecommerce is not model quality. It is that three of the most commonly automated workflows — reviews, cancellation and personalisation — each sit directly on top of a rule with penalties attached, and the market is confidently wrong about all three.
| Constraint | Status on 2026-08-23 | What it actually requires | Which agent it binds |
|---|---|---|---|
| FTC reviews rule — 16 CFR Part 465 | In force, unamended, effective 21 October 2024. § 465.3 codified [Reserved] | No fake reviews, no sentiment-conditioned incentives, no undisclosed insider reviews, no company-controlled site posing as independent, no rating-based suppression, no fake influence indicators. Penalties to $53,088 per violation | Any reviews agent — Siena ships one, Klaviyo ships a reviews product. The § 465.5 insider provisions and the § 465.7 suppression provisions are the two an automated system trips first |
| ROSCA — 15 U.S.C. § 8403 | In force, unaffected by the vacatur | Clear and conspicuous disclosure of all material terms before billing information is taken; express informed consent before the charge; simple mechanisms to stop recurring charges | Any subscription, replenishment or membership agent that enrols, upsells or handles cancellation requests |
| 2024 FTC “click to cancel” rule | Vacated in its entirety — Custom Communications, Inc. v. FTC, 142 F.4th 1060 (8th Cir. 2025) | Nothing. The CFR was conformed at 91 FR 6507 effective 12 February 2026, restoring the 1973 prenotification rule at 16 CFR Part 425, which governs book-and-record-club style plans and does not reach a typical DTC subscription box | None directly — but do not let a vendor sell you a compliance feature against a rule that no longer exists |
| California ARL — BPC § 17602(d) | In force, and it is a click-to-cancel law | Online termination exclusively online, at will, without further steps that obstruct or delay: a prominently located direct link or button, or an immediately accessible termination email. Plus renewal reminders, retainable acknowledgment and three-year consent records under § 17602(a) and (b) | Any cancellation-handling or retention agent. A save-offer flow an agent runs before honouring a cancellation is exactly the friction this section addresses |
| Global Privacy Control — CCR § 7025(b) | Mandatory now | A business that sells or shares personal information shall process a conforming opt-out preference signal as a valid opt-out of sale or sharing. An HTTP header or JavaScript object is the named example format | Any personalisation, recommendation, retargeting or lifecycle agent fed by data that is sold or shared |
| CCPA ADMT — CCR Art. 11 | Effective 1 January 2026; compliance for significant decisions by 1 January 2027 | Applies only to “significant decisions” — financial or lending services, housing, education, employment, healthcare (§ 7001(ddd)). Installment payment plans are inside financial services, which is the one ecommerce-adjacent edge | Not your recommendation agent. Possibly an agent deciding pay-over-time eligibility. Raise it with counsel rather than assuming either way |
| EU AI Act Article 50 | Applicable from 2 August 2026 — not deferred by Regulation (EU) 2026/1744 | A person must be informed they are interacting with an AI system unless it is obvious from the circumstances | Any customer-facing chat, email or voice agent serving EU shoppers. The Digital Omnibus deferred high-risk obligations only, to 2 December 2027 and 2 August 2028 |
Start with reviews, because a vendor in this very roster ships a Reviews Agent. The FTC Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, took effect 21 October 2024 and is in force and unamended as of 23 August 2026 — we confirmed that by pulling Part 465 live from the eCFR and by searching the Federal Register for any amending or vacating document since September 2024, which returns nothing.
And now the trap that most published summaries fall into: the rule does not ban review hijacking. Proposed § 465.3, which would have addressed reusing a review written for a substantially different product, was never finalised. The Commission decided not to proceed with it, dropped the associated definition, and the section is codified [Reserved]. An article — or a vendor datasheet — that says the rule bans review hijacking has printed a false statement of law.
What it does reach is fake reviews and testimonials, buying reviews the business knew or should have known misrepresent that the reviewer exists or used the product, incentives conditioned on sentiment, undisclosed insider reviews from officers, managers, employees or their relatives, company-controlled sites posing as independent, review suppression through groundless legal threats or rating-based filtering, and fake indicators of social media influence. The operative text never uses the word “AI.” AI coverage comes from footnote 35 of 89 FR 68034, where the Commission wrote that AI tools make it easier for bad actors to pollute the review ecosystem by generating large numbers of realistic but fake reviews, and that AI-generated reviews are covered by the final rule. Cite it that way or not at all.
The maximum civil penalty for a violation of a section 18 trade regulation rule is $53,088. There is no 2026 adjustment — we searched for one and none exists. If a vendor quotes a higher, more current-sounding figure, ask which document sets it.
— 16 CFR 1.98(d), as amended at 90 FR 5581 (17 January 2025)
The two provisions an automated system trips first are § 465.5 and § 465.7. An agent that mass-solicits reviews from staff, or from anyone with an undisclosed material relationship, is inside the insider-review provisions. An agent that routes negative reviews away from display — or applies a “quality” filter that happens to key on star rating — is inside the suppression provisions, and the carve-outs there are explicitly for sentiment-neutral criteria such as defamatory content, personal information or off-topic posts. A sentiment filter is the opposite of sentiment-neutral. This is the hardest human-in-the-loop line in the article, and it should be enforced by removing the capability rather than by instructing the model not to use it.
Where does that bite in practice? Anywhere reviews are collected and displayed on your own storefront. Our Grillz custom jewellery build is a Shopify Plus store whose delivered feature set includes a customer review system with photos alongside Klaviyo email and an Instagram feed — an ordinary, well-built DTC review surface. The moment an agent is given write or moderation authority over a surface like that, Part 465 is the governing document, and the audit log of what was suppressed and on what stated ground is the artefact you will be asked for.
For a subscription brand the practical translation is short. Do not let a vendor sell you a compliance feature against a rule that no longer exists — and do not read “vacated” as permission to make cancellation harder. If you ship to California, § 17602 also requires renewal reminder notices (3 to 21 days before a trial or promotional period of over 31 days ends, and 15 to 45 days before an annual-or-longer term renews), a retainable acknowledgment containing the cancellation policy, and retention of proof of consent for three years. Other states have their own automatic-renewal statutes with different notice triggers; we verified California only, so we say “state automatic-renewal laws, of which California's is the strictest we verified” and leave the enumeration to your counsel.
On privacy, the burden is widely misplaced. The CPPA's CCPA updates, cybersecurity audit, risk assessment and ADMT regulations took effect 1 January 2026, and CCR § 7200(b) sets ADMT compliance for significant decisions at 1 January 2027. But “significant decision” is defined at CCR § 7001(ddd) as one resulting in the provision or denial of financial or lending services, housing, education enrolment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. Product recommendations, merchandising, marketing personalisation and support triage are not significant decisions, and behavioural advertising did not survive into the final scope. The one edge worth flagging rather than asserting: § 7001(ddd)(1) includes installment payment plans within financial or lending services, so an agent deciding pay-over-time eligibility may be in scope.
What binds a personalisation agent today is the Global Privacy Control, under CCR § 7025(b) — mandatory now, not in 2027. The regulation provides that a business which sells or shares personal information shall process a conforming opt-out preference signal as a valid request to opt out of sale or sharing, and names an HTTP header field or JavaScript object as an example format. If your recommendation, retargeting or lifecycle agent is fed by data that is sold or shared under the CCPA, an inbound GPC signal must switch that off for that visitor. It is testable in about a minute from a GPC-enabled browser, it is far more commonly breached than the ADMT rules are, and it is the first thing we check in a vendor security review.
And if you ship to Europe, one more live obligation. EU AI Act Article 50 transparency obligations applied from 2 August 2026 — three weeks before this was written. A person must be told they are interacting with an AI system unless that is obvious from the circumstances. It is a common and expensive mistake to believe the EU delayed the AI Act to 2027: Regulation (EU) 2026/1744, the Digital Omnibus, entered into force 27 July 2026 and deferred only the high-risk obligations — Annex III standalone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. Article 50 was not deferred. The remedy is a disclosure line rendered by your platform rather than generated by the model, because a model can be talked out of its own disclosure and a template cannot.
Finally, the constraint nobody has solved. Prompt injection is unsolved. Any agent reading untrusted input — customer email, review text, supplier documents, return-reason free text — is exposed to instructions embedded in that content. There is no vendor in this roster, or anywhere else, who has fixed it. Treat it as a blast-radius problem: the agent identity that reads external content should not hold the credential that moves money, changes prices, or publishes to a public surface. That separation survives a successful injection. Model quality does not.
A Worked Example You Can Rebuild in Ten Minutes
This is an illustrative scenario, not a client result. Every figure below is either a published vendor price or arithmetic we performed on published vendor prices, and you can redo it with your own numbers in a spreadsheet. Consider a DTC brand doing roughly $18M a year, running about 2,400 support conversations a month, of which the agent handles 1,000 without a human reply.
- 1.Gorgias: 1,000 AI resolutions at $0.90 on an annual plan = $900 per month, plus the ticket-based plan fee for the remaining 1,400 conversations and any automated-interaction overage at $1.50.
- 2.Siena AI: $750 platform fee plus 1,000 automated tickets at $0.90 = $1,650 per month, before implementation, which is contact-sales.
- 3.Intercom Fin: 1,000 outcomes at $0.99 = $990, plus seats — six seats on the $85 tier adds $510, for roughly $1,500 per month. Or run Fin on a third-party helpdesk at $990 with no seat cost, subject to the minimum commitment.
- 4.Zendesk: 1,000 automated resolutions at the published pay-as-you-go rate of $2.00 = $2,000 per month, plus seats, with committed usage documented as cheaper than overage.
- 5.Richpanel: the flat automation tier at $360 per month, marketed as unlimited resolutions, plus the per-user helpdesk and per-order-band self-service lines as configured.
The same 1,000 conversations cost somewhere between $360 and $2,000+ a month depending only on which theory of the unit you bought.That is a 5.5× spread before a single question about quality, and it is entirely visible on public pricing pages. Now layer the definitional problem on top: on Zendesk's published counting rule, some unknown share of those 1,000 “resolutions” are shoppers who never replied because the answer did not help. You are billed for those at $2.00 each, and they appear in the vendor's dashboard as successes.
Two of our own ecommerce builds are worth naming here for what they say about the surfaces an agent would touch, and it is worth being exact about what they were. The Players Choice CBD platform is a Shopify Plus store built with Recharge for subscriptions, age verification and compliance systems, lab result transparency, a certificate-of-analysis viewer, a loyalty programme and an affiliate system. It was a storefront and subscription-commerce build, not an AI agent deployment, so nothing about its reported outcomes transfers to an agent business case — and we will not pretend otherwise. What it does illustrate is the shape of the exposure: a brand with recurring billing and a compliance-sensitive category is exactly where ROSCA § 8403 and California § 17602(d) land, and where a retention agent inserted into the cancellation path would be the riskiest thing on the roadmap.
The honest conclusion from the arithmetic is unglamorous. Before you shortlist anything, export ninety days of your own helpdesk data, tag the top ten contact reasons, and find out how many of them are answerable from data you already hold. If order status and returns are 60% of your volume, the winning vendor is whichever one is cheapest at your volume in a unit you can predict — and that is a spreadsheet question, not a demo question.
What Breaks First
Ecommerce agent deployments do not usually fail by hallucinating. They fail by drifting — in catalogue data, in billing units, in cancellation friction, and in permissions nobody re-checked after a tag manager change. Each row below pairs the failure with the signal that catches it early and the rollback that limits the damage.
| Failure mode | How you find out | Detection signal to instrument | Rollback |
|---|---|---|---|
| Catalogue drift — a price, variant or stock status changes and the agent's index does not | Shoppers are quoted prices you no longer charge, or promised variants you no longer stock | Nightly diff of the agent's product snapshot against the storefront export; alert on any delta older than one business day | Freeze the agent to policy-and-order answers and route product questions to humans until the diff is clean |
| The billing unit runs away from you | The invoice grows faster than ticket volume, or faster than revenue | Track cost per contact and cost per order in the same dashboard as the vendor's own resolution count, and reconcile them monthly | Move to a committed tier or a flat-rate vendor; renegotiate at renewal with your own volume data, not theirs |
| Prompt injection through customer email, review text or a supplier document | The agent follows instructions embedded in content it read, not instructions you wrote | Log every tool call and alert on any write action initiated in a session that read external content | Revoke the write credential for that agent identity. Injection is unsolved; the control is blast radius, not detection |
| A retention flow quietly becomes a cancellation obstacle | Steps-to-cancel creeps up as someone adds one more save offer | Instrument median clicks and median seconds from “cancel” intent to confirmed cancellation, weekly | Cut the flow back to a single offer; California § 17602(d) is a bright line and a regulator can walk your funnel |
| GPC stops being honoured after a tag manager change | Nobody finds out, which is the problem | Automated weekly check from a GPC-enabled browser that the sale/share signal actually switches personalisation off | Disable the personalisation agent's data feed until the signal is honoured again |
| A reviews automation starts filtering by sentiment | A configuration default, a new “quality” filter, or a well-meaning threshold on star rating | Audit log of every review suppressed and the stated ground; alert on any rule whose criteria reference rating or sentiment | Disable the rule immediately. § 465.7 attaches civil penalties, and the log is what you will be asked for |
| Refund automation meets a fraud ring | A cluster of small refunds inside one day, each individually under the ceiling | Daily aggregate cap and velocity alerting on refunds per customer, per address and per payment instrument | Aggregate cap trips automatically and routes everything to a human — the cap is the control, not the model |
| The vendor changes the model or the unit without telling you | Behaviour or invoices shift overnight with no release note — Zendesk changed its automated resolution model on 18 May 2026 | Golden-set regression suite of recorded conversations replayed weekly; a contractual right to advance notice of model and pricing changes | Pin previous behaviour if the contract allows; otherwise increase human coverage until the suite passes |
| The integration you bought disappears in an acquisition | A partner logo quietly leaves the vendor's page and a connector deprecates — Wonderment is now Loop Tracking | Check ownership and changelogs quarterly on a calendar, not when something breaks | Keep an exportable order, ticket and customer data path so switching costs stay bounded |
The one that surprises operators most is the second row. A per-resolution or per-credit contract can grow faster than your ticket volume without anybody doing anything wrong, because the counting rule and your traffic mix both move. The defence is boring and it works: reconcile the vendor's resolution count against your own cost per contact every month, and put a written right to advance notice of pricing and model changes into the contract. Zendesk changing its automated resolution model on 18 May 2026 is the proof that this happens on the vendor's schedule, not yours.
The Human-in-the-Loop Boundary
Write these boundaries into configuration, not into a prompt.A prompt is a request; a tool permission is a constraint. Anywhere the consequence is money leaving, a price changing, or a public surface being written to, the boundary should be enforced by the absence of the capability rather than by the model's cooperation.
| Action | Autonomy level | Why that line | The control that enforces it |
|---|---|---|---|
| Answer order status, shipping timelines, sizing and policy questions from your own records | Agent alone | Retrieval from a source you control, no commitment, fully reversible | One source of truth for order and policy data; log every answer with the record version it was drawn from |
| Recommend products and build a quiz result | Agent alone, subject to signals | Not a significant decision under CCR § 7001(ddd), so ADMT does not reach it — but GPC does | GPC honoured server-side before personalisation runs; test it quarterly with a GPC-enabled browser |
| Draft a public response to a customer review | Agent drafts, a human sends | Review text is untrusted input and prompt injection is unsolved; one bad automated reply outlives every good one | Draft state in your own system; no send credential in any session that reads review or email text |
| Write, solicit or incentivise a review | Never the agent | 16 CFR §§ 465.2, 465.4 and 465.5. A mass-solicitation agent that touches staff or relatives, or ties an incentive to sentiment, creates strict rule liability | Hard block at the tool level, not a prompt instruction. Remove the capability rather than asking the model not to use it |
| Filter, hide or route negative reviews away from display | Never the agent | 16 CFR § 465.7 reaches suppression based on rating or negative sentiment. Sentiment-neutral criteria are carved out; a sentiment filter is the opposite of sentiment-neutral | Written moderation criteria, human-owned, versioned, with an audit log of every removal and its stated ground |
| Process a cancellation request | Agent alone, immediately, with at most one offer | ROSCA § 8403 requires simple mechanisms to stop recurring charges; California § 17602(d) bars further steps that obstruct or delay | Cancellation is a one-hop path with no gated retention loop; instrument the median steps-to-cancel and alert if it rises |
| Issue a refund or store credit | Agent alone below a hard ceiling; approval queue above it | A refund is an irreversible outbound payment. Accuracy does not recover the money; a limit does | Per-action value cap, daily aggregate cap, idempotency keys so a retry cannot double-refund |
| Approve or release a held order flagged for fraud | Agent proposes, a human commits | Card-not-present chargeback loss sits with the merchant by default under private card network rules, not statute | Review queue with the signals shown; confirm your own liability position with your acquirer, in writing |
| Change a price, a discount or a shipping promise | Never the agent unattended | A pricing error propagates to every shopper simultaneously and is an advertising claim the moment it is displayed | Merchandising changes go through the same approval path as a human merchandiser's, with a diff and a rollback |
| Disclose that the shopper is talking to an AI system | Always, automatically | EU AI Act Article 50 applies from 2 August 2026 for EU users, and it costs nothing to do everywhere | Disclosure rendered by the platform, not generated by the model — a model can be talked out of its own disclosure |
The reviews rows are the ones to enforce hardest, because they carry statutory penalties rather than commercial ones, and because they are the rows most likely to be crossed by a well-meaning default. Nobody sets out to build a sentiment filter. Someone adds a “hide reviews below three stars while we investigate” rule during a bad week, and § 465.7 does not care that it was temporary.
Cost and Timeline
These are our standard bands, published so you can benchmark any proposal — ours or anyone else's — against a real number rather than a range invented on a call.
| Engagement | Range | Timeline | What it covers for a DTC brand |
|---|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks | A contact-reason baseline from your own helpdesk export, a unit-by-unit price model against your real volume, a cancellation-flow and GPC audit, vendor contract review focused on the model-training and data-retention clauses, and a shortlist with the questions we would put in writing |
| Single-workflow agent | $28k–$70k | 4–9 weeks | One workflow end to end — order status, returns intake, or subscription management — with escalation paths, hard monetary ceilings on any money-moving action, AI disclosure, and an instrumented review queue |
| Multi-workflow platform with system integration | $70k–$180k | 9–16 weeks | Several workflows across the storefront, helpdesk, 3PL and ESP, catalogue synchronisation with drift detection, a golden-set regression suite, GPC enforcement server-side, and an operator reporting pack that reconciles vendor resolution counts against your own cost per contact |
| Enterprise / multi-site / regulated build | $180k–$420k+ | 14–24 weeks | Multi-brand or multi-region rollout, per-market configuration for EU disclosure and state privacy rules, full audit logging with attribution, role-based access control, disaster recovery and restoration testing, and a documentation package your counsel can review |
Senior-led work is $150–$225 per hour; ongoing retainers run $2,500–$9,500 per month. Every engagement carries a 30-day post-launch warranty, and full source-code and IP ownership transfers to you — there is no vendor lock on what we build. We deliver a fixed-price phased proposal within 5 business days of a discovery call. Frenchy Digital is a senior-led Black-owned agency in Los Angeles, reachable at +1 (424) 272-5601.
A note on where the money actually goes in an ecommerce build. It is rarely the model. It is the catalogue and order-data plumbing, the escalation design, the monetary ceilings and idempotency around anything that moves money, the GPC and disclosure work, and the instrumentation that lets you reconcile a vendor's counting against your own. Whether that work belongs inside a purchased platform or in something you own is the real decision, and it is the one we work through in our build-versus-buy analysis for AI agents.
Model Your Own Volume Against Every Published Unit
Bring 90 days of helpdesk data and we will build the unit-by-unit comparison with you — per resolution, per seat, per order, per credit and per GMV band — using each vendor's own published figures.
Red Flags When Evaluating a Vendor
- A resolution, deflection or containment rate presented as neutral fact, with no published definition of the unit being counted. Ask for the definition in writing before you ask for the number.
- A compliance badge whose certificate belongs to the hosting provider rather than the vendor's own legal entity. Confirm the certificate names the vendor, not its cloud.
- “SOC 2” without a type. Type I attests to design at a point in time; Type II attests to operating effectiveness over a period. One vendor here states “SOC2 certified” and does not say which.
- No trust page at all. Two vendors in this roster return 404 on their security URL. That is not an oversight to work around; it is the answer to your question.
- A pricing page with no dollar figures but a quantified ROI guarantee. The guarantee is a marketing claim; the missing price is the actual disclosure.
- A compliance feature sold against the FTC “click to cancel” rule. That rule was vacated in 2025 and struck from the CFR in February 2026. Selling against it in 2026 means the datasheet has not been read since it was written.
- Any claim that the reviews rule bans review hijacking. Proposed § 465.3 was never finalised and is codified [Reserved].
- Any claim that the EU delayed the AI Act to 2027. The Digital Omnibus deferred high-risk obligations only; Article 50 applied from 2 August 2026.
- A retention or save-offer flow marketed as a cancellation feature. ROSCA and California § 17602(d) both point the other way, and a regulator can walk your funnel as easily as a customer can.
- A model-training clause that lets the vendor use your customers' conversations to improve its own models. Strike it or narrow it, and get deletion schedules in writing before signature.
- A promise that prompt injection is handled. It is not handled anywhere by anyone. The right answer describes blast-radius controls and credential separation.
- An integration list that lives only on the vendor's marketing page and not in its documentation. Ask for the docs URL; if the connector is real, it has one.
Limitations and What We Could Not Verify
This section is part of the product, not a disclaimer bolted to the end of it. Everything below is something we tried to check on 23 August 2026 and could not, or could only check partially. Naming it is the difference between a ranking and a sales page.
- No independent benchmark of these commercial products exists. We located none. Every performance figure in this market is vendor-published about the vendor's own product, using a unit that vendor defines.
- Compliance posture is unverified for 7 of the 13 vendors we examined. Siena AI and Rep AI have no locatable trust page at all — both security URLs returned 404. Kustomer, Richpanel, Octane AI, Triple Whale and Narvar were not fetched this session. Only Intercom (comprehensive), Gorgias (SOC 2 Type II) and Loop (SOC 2, type unstated) are verified.
- No PCI DSS attestation was located for any vendor here, including those that touch refunds, instant exchanges and store credit. Any PCI claim in a proposal needs a fresh check against the vendor's own attestation.
- Ownership is unverified for Kustomer, Zendesk, Narvar and Triple Whale. Kustomer is a known acquisition-trap name — it has been acquired and divested before, and we do not state a 2026 owner we did not confirm.
- Klaviyo and Zendesk pricing were geo-served non-US locales during our fetch, mixing currencies and locale-specific plans. We print no seat or profile figures for either, rather than printing numbers we did not read from a US context.
- Shopify's agentic-commerce surfaces — catalogue, knowledge base, universal cart — were not verified at all; help.shopify.com returned 403 to our fetcher. We make no claims about what has shipped or whether it is generally available, and neither should a ranking written before yours.
- The integration matrix is thin. Only Narvar (eight named platforms), Rep AI (Shopify, Klaviyo, WooCommerce, Salesforce) and Octane AI (Shopify, Klaviyo) had integrations verified from their own pages. BigCommerce, ShipStation and Recharge support was not verified for any vendor except Narvar's BigCommerce listing.
- The Wonderment acquisition date could not be established — the announcement URL returned 404. We say the product is now Loop Tracking and we do not date the transaction.
- Siena's product page marks some agents as coming soon and the rendering was ambiguous about which. We do not claim the Shopping Agent or QA Agent are generally available.
- Gorgias's tier-to-price mapping was extracted from structured data on its pricing page rather than from the rendered layout. Re-read the rendered page before you bind a specific number to a specific named plan in a contract.
- Allegations circulating in third-party blogs about systematic double-billing by one vendor were not verified against that vendor's documentation, so they do not appear here as anything other than this sentence.
- Card-network liability allocation for card-not-present fraud, and the 3-D Secure liability shift, are governed by Visa and Mastercard operating rules — private contracts we did not obtain. We state the principle and tell you to confirm your position with your acquirer.
- We verified California's automatic-renewal law only. Other states have their own statutes with different notice triggers, and we deliberately do not enumerate them.
- The FTC's Consumer Sentinel 2025 Data Book is not published at the FTC's standard URL as of 23 August 2026 — it returns 404 and the newest indexed edition is 2024. No 2025 Sentinel figure appears in this article.
- The FTC's July 2026 proposed policy statement on suppression of accuracy in AI systems (91 FR 41638) is a proposed policy statement, not an adopted rule, and it is tangential to ecommerce agents. It governs nothing today and we rely on it for nothing.
- Vendor customer counts, integration counts and funding figures are as published by the vendor or reported in a dated press release, and we did not independently audit any of them.
Want an Honest Read on Your Ecommerce AI Shortlist?
Book a free 60-minute discovery call. You leave with a contact-reason baseline from your own helpdesk export, a unit-by-unit price model against your real volume, and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1US Census Bureau — Quarterly Retail E-Commerce Sales, 2nd Quarter 2026 (release CB26-133, 18 August 2026)↗
- 2US Census Bureau — E-commerce retail sales programme landing page↗
- 3Custom Communications, Inc. v. FTC, No. 24-3137 (8th Cir. 2025) — published opinion vacating the 2024 Negative Option Rule↗
- 4Federal Register — Revision of the Negative Option Rule, conforming the CFR to the Eighth Circuit vacatur, 91 FR 6507 (published and effective 12 February 2026)↗
- 5eCFR — 16 CFR Part 425, Use of Prenotification Negative Option Plans (source note 91 FR 6509, Feb. 12, 2026)↗
- 6Federal Register — Advance Notice of Proposed Rulemaking, Rule Concerning the Use of Prenotification Negative Option Plans, 91 FR 12318 (13 March 2026)↗
- 7ROSCA — 15 U.S.C. § 8403, negative option feature requirements (Cornell LII)↗
- 8ROSCA — 15 U.S.C. § 8404, enforcement as a section 18 rule violation (Cornell LII)↗
- 9California Bus. and Prof. Code § 17602 — automatic renewal law, including the § 17602(d) online cancellation requirement↗
- 10Federal Register — Trade Regulation Rule on the Use of Consumer Reviews and Testimonials, 89 FR 68034 (22 August 2024), including footnote 35 on AI-generated reviews↗
- 11eCFR — 16 CFR Part 465, Rule on the Use of Consumer Reviews and Testimonials (§ 465.3 codified [Reserved])↗
- 12eCFR — 16 CFR 1.98(d), civil penalty maximum of $53,088 (last amended 90 FR 5581, 17 January 2025)↗
- 13California Privacy Protection Agency — CCPA updates, cybersecurity audits, risk assessments and ADMT regulations (effective 1 January 2026)↗
- 14CPPA — approved regulatory text, including CCR § 7001(ddd) “significant decision”, § 7025(b) opt-out preference signals and § 7200(b) ADMT compliance date↗
- 15Regulation (EU) 2024/1689 — the AI Act, including Article 50 transparency obligations applicable from 2 August 2026↗
- 16SEC — In the Matter of Presto Automation Inc., Securities Act Release No. 11352, Admin. Proc. File No. 3-22413 (14 January 2025)↗
- 17Zendesk — About automated resolutions for AI agents (the 72-hour inactivity counting rule; notes the platform in place prior to 18 May 2026)↗
- 18Gorgias — published pricing, including AI Agent resolutions at $0.90 annual / $1.00 monthly↗
- 19Gorgias — security page (SOC 2 Type II stated, report on request)↗
- 20Siena AI — published pricing ($750/month platform fee plus $0.90 per automated ticket)↗
- 21Intercom — security and trust page (SOC 2 Type II, ISO 27001/27018/27701/42001, HIPAA, AIUC-1 for Fin, US/EU/AU residency)↗
- 22Intercom — published pricing (Fin at $0.99 per outcome; Essential/Advanced/Expert seats)↗
- 23Richpanel — published pricing across three units (per order band, per user, and flat unlimited resolutions)↗
- 24Octane AI — published credit-based pricing with $0.10 overage per credit↗
- 25Loop Returns — published pricing (Checkout+ free, Essential from $155/month, Advanced from $340/month)↗
- 26Loop Returns — security page (states “SOC2 certified”, type unspecified; sub-processor list published)↗
- 27Triple Whale — published GMV-banded pricing calculator↗
- 28SEC EDGAR — Klaviyo, Inc. (CIK 0001835830, NYSE: KVYO) Form 10-K filed 10 February 2026↗
- 29Shopify — Sidekick product page (“your AI assistant with an obsession for commerce”)↗
- 30Rep AI — pricing page (no dollar figures published; carries a “5× ROI guarantee” marketing claim)↗
- 31PR Newswire — Rep AI raises $6.2 million in strategic follow-on funding, led by Silicon Road Ventures with Zendesk as a strategic investor (28 May 2026)↗
- 32Wonderment — page now titled “Wonderment is now Loop Tracking!”, canonical to loopreturns.com↗
- 33Baymard Institute — cart abandonment rate list (70.22% average of 50 studies; page last updated 22 September 2025)↗

