All articles
Explainer

AP2 and SAP Order-to-Cash: What Mid-Market Teams Need to Know

Google's AP2 protocol lets AI agents authorize payments, but it doesn't place orders in SAP. Here's the gap mid-market distributors need to close before customers' buying agents show up.

Chris BensonSeptember 28, 20264 min read

AP2, the Agent Payments Protocol Google launched in September 2025 and expanded at Google I/O 2026 with the Universal Commerce Protocol (UCP), lets an AI agent execute a payment on a buyer's behalf inside a cryptographically signed "mandate." It does not place an order inside SAP. Authorization and order creation are two different problems, and as of today SAP has not published a position on AP2, ACP, or UCP — which means the last mile into an SAP sales order is still something mid-market distributors have to build themselves.

What AP2 actually solves

AP2 addresses three specific failure modes in agent-led buying: proving a user actually authorized an agent to spend money (authorization), proving the agent's request reflects real user intent (authenticity), and establishing who is liable when something goes wrong (accountability). Google's specification does this with "Mandates" — signed, verifiable-credential records. An Intent Mandate captures what the buyer asked for and any constraints (price ceiling, timing); a Cart Mandate is the signed approval of the final cart once an agent has assembled it. Together they create an audit trail from request to payment (Google Cloud, September 2025).

At Google I/O 2026, Google folded AP2 into a broader stack: the Universal Commerce Protocol (UCP) for agent-to-agent product discovery, inventory checks, and checkout, plus a cross-merchant "Universal Cart" surfaced in Search and Gemini. Amazon, Meta, Microsoft, Salesforce, and Stripe joined the UCP Tech Council, according to coverage of the announcement (Efficiently Connected, May 2026). Notably absent from that reported list: SAP.

What UCP and AP2 don't do

Neither protocol touches ERP order creation. AP2 authorizes a payment; UCP standardizes how agents discover products and negotiate a cart. What happens after the cart is authorized — turning that authorized intent into a sales order, checking available-to-promise inventory in S/4HANA, applying the right pricing condition records, triggering credit management — is entirely outside the protocol's scope. That's the same gap SayfeAI (sayfe.ai) has been solving for order-to-cash with BAPI-level, simulate-before-create integration since before AP2 existed, and it's why "my customer's agent speaks AP2" is not the same claim as "my customer's agent can place an order in my SAP system."

Why this matters for mid-market SAP shops specifically

If you sell to other businesses and any meaningful share of your buyers start using AI shopping or procurement agents, those agents will eventually try to check your catalog, get a price, and submit an order using whichever payment protocol their platform has adopted. Enterprise-scale SAP customers with large integration teams can build a bridge from AP2/UCP checkout events into SAP order entry. Most mid-market SAP shops cannot — not because the SAP side is harder, but because nobody on staff owns "watch three competing agentic-commerce protocols and wire the winner into our S/4 sales order process" as a job.

This is also a governance question, not just a plumbing one. An agent-initiated order still needs the same guardrails a human-entered order gets: a real SAP user context (or a governed service account, never a shared one), inventory and credit checks before commit, and a simulate-before-create step so a malformed or fraudulent Cart Mandate doesn't land as a live sales order. AP2's Cart Mandate gives you a signed record of what the buyer's agent agreed to — that's useful evidence, but it's not a substitute for validating the order against your own SAP business rules before it's created.

What to do about it now

Nobody should re-architect their order-to-cash process around a protocol landscape that's still three-way contested between UCP, ACP (OpenAI/Stripe's approach), and x402. But three things are reasonable to do today: confirm whether any of your top customers' procurement platforms have announced AP2 or ACP support, make sure whatever touchless order intake you already have (EDI, portal, or an agent-based flow like SayfeAI's easyOrder) enforces the same validate-before-create discipline these protocols are trying to standardize, and treat "can we accept an AI agent's order safely" as a governance question you answer once, not per-protocol.

Frequently asked questions

Does SAP support AP2 or UCP today? SAP has not published an official position on AP2, ACP, or UCP as of this writing. Coverage of the UCP Tech Council (Efficiently Connected, May 2026) lists Amazon, Meta, Microsoft, Salesforce, and Stripe as members; SAP is not reported among them. Treat any claim that SAP has "adopted" one of these protocols as unverified until SAP states it directly.

If a customer's AI agent completes an AP2 payment, does that automatically create an SAP sales order? No. AP2 authorizes and records a payment; it does not integrate with ERP order entry. Turning an authorized cart into a valid SAP sales order — with inventory, pricing, and credit checks — requires a separate integration layer that the protocol doesn't provide.

Should we build AP2 support before it's clear which protocol wins? Not as a priority. What's worth building now is protocol-agnostic: a governed, validate-before-create intake path for AI-originated orders, so that whichever protocol your buyers' platforms settle on, the SAP side already enforces the same checks a human order would go through.

AP2Agentic CommerceSAP Order-to-CashA2ASayfeAI

See SayfeAI in your own environment

Self-hosted agentic AI for mid-market SAP. Book a 30-minute walkthrough of easyOrder and the platform.

Book a demo

Keep reading