# Independence From Influence - Why Buyers and Their AIs Both Want the Receipt

*Buyers now research on their own, ask an AI, and save the person for the last step: to confirm, not to persuade. That independence only lasts where it is safe, which rewards the house that shows its sources and keeps its data chain clean.*

By **Jenny Huang Goodman MPA MSc MHSA, Principal** — The Stash Edge, Hako Shikin LLC.
Published 2026-09-19.

Canonical: https://www.pops4.com/stash/articles/independence-from-influence
Tags: B2B buying, AI agents, self-service, trust, agentic commerce, SEC filings, procurement, brand safety

---

A buyer used to meet a company through a person. Someone called, took them to lunch, walked them through a deck and told them what to think about it. The information and the influence arrived together, in the same suit.

That is no longer the order of events. The buyer now arrives having already read, compared and asked an AI. The person comes last, and not to persuade. They are there to confirm.

Independence has one condition: it has to be safe. A buyer who serves themselves, or sends an AI to do it, is trusting that the data beneath every screen was handled properly, by the company and by everyone the company hired. Where that trust holds, people and machines buy on their own. Where it breaks, both go looking for a person they can hold to account.

## The buyer has already left the room.

Gartner surveyed about 645 business buyers in August and September 2025. **67%** said they prefer a rep-free buying experience, and **70%** prefer one that is completely digital and self-service. The average buyer consulted **seven** information sources along the way.

None of that is a rejection of expertise. It is a rejection of being steered. Buyers want to form their own view first, from sources they choose, at a pace they set.

## The machines are in the room too.

**45%** of those buyers had used generative AI in a recent purchase, mostly to gather information on vendors and products. On 29 September 2025 OpenAI went further and introduced Instant Checkout in ChatGPT, built on the open Agentic Commerce Protocol with Stripe, so an AI agent can complete a purchase on a person's behalf.

An agent cannot be flattered, rushed or charmed. It reads what is structured and verifiable and acts on it. Influence has nothing to grip. Only evidence does.

## Nobody fully trusts the middleman.

Asked where they are more likely to meet misleading information, buyers split almost down the middle: **51%** said generative AI, **49%** said a vendor's rep. When both channels are doubted equally, the tiebreaker is not a better pitch. It is a fact with its source attached, one the buyer can check without asking anyone.

## The person moves to the end.

The human conversation has not disappeared. It has moved. **69%** of buyers turn to a person to validate what AI told them, and Gartner projects that by 2030 **75%** of business buyers will prefer experiences that put human interaction ahead of AI. The last step is still a person. It is simply a different job: not to persuade, but to confirm.

*Figure 1: About 645 business buyers surveyed August and September 2025. Source: Gartner press releases of 9 March 2026 and 20 May 2026.*

## What clicks, and what we chose not to do.

The largest study of headlines to date, published in Nature Human Behaviour in 2023, ran **22,743** randomized tests across roughly **5.7 million** clicks. Each additional negative word raised click-through by **2.3%**, and positive words lowered it.

That is the influence economy measured to the decimal. We read it and built the opposite. Where our work names a clock, a cost or an exposure, it is the reader's own, stated plainly, with the source one tap away. It is never alarm about somebody else.

## What we would like the law to protect.

Independence only works if what people and machines read is clean. Today it often is not. The same screen can carry a vendor's feed posting material no shareholder would choose to stand beside, and that shareholder's own personal data: a name, a holding, an address, a face. The person never agreed to that company. The AI reading the screen cannot tell the difference. It takes in both, and carries both forward into whatever it says next.

Personal data rules already point the right way. Europe's GDPR requires personal data to be collected for specified purposes and not used in ways that conflict with them. Japan's APPI requires a business to state the purpose it will use personal information for. We would like data and AI law to go one step further and protect both readers at once: people, from having their personal data placed beside or used by unethical content, and AI systems, from being fed data gathered or displayed unethically. A model is only as honest as the screens it was allowed to read.

The post and the private data are rarely as separate as they look. The FTC has documented how a single login, or a shared network, lets companies tie a laptop, a phone and a tablet to one person or household. When the device that holds shareholder or staff records is also the one used to post, a federal warrant can authorize seizing the whole device for later review, and a lawsuit can reach it through discovery. The posts and the private data travel together.

Take an illustrative case, not a real one. A vendor prepares a company's proxy mailing, welcome cards, staff communications, or perhaps holiday event media services. They did not ever meet data privacy laws and think data privacy is something that is too much of a bother. The shareholder names, staff addresses and guest lists all sit on the owner's laptop. The same laptop, signed into the same accounts, runs the owner's social feeds, where the posts cheer on violence against a racial group and trade in things that should never be traded. To a tracking system, that is one person. To an investigator holding a warrant, it is one device. The shareholders did nothing, and their names now sit in the same evidence file. Getting those names redacted, in an age when data is spread out into an ocean, is rarely simple, and the shareholders become the ones who end up paying for the poor judgement and data security views of an outdated old network that thinks a conversation is more important than keeping its customers safe.

The chain rarely stops at the vendor. Proxy mailings, welcome cards, staff communications and event media all pass through subcontractors: the photographer, the editor, the mail house, the data-entry shop. In media especially, very few of those hand-offs come with a written data agreement. When a vendor does not pay its subcontractors on time, the files it handed them do not come back, and in our experience that data is traded on to third parties more often than buyers think. Nothing in an agreement that was never written stops it. We made the same point in Your Brand Is a File Somebody Else Is Holding: most of a brand now sits with third parties, under agreements written for a different purpose. Europe's GDPR at least closes the gap on paper. A processor may not engage another processor without the controller's written authorisation, and the same data protection obligations must be passed down to every subcontractor by contract.

*Figure 2: Illustrative, not a real company. Device linking: FTC Staff Report, Cross-Device Tracking, January 2017. Seizure of storage media: Federal Rule of Criminal Procedure 41(e)(2)(B). Subcontractors: GDPR Article 28(2) and 28(4).*

Until then, the standard has to be set by the houses themselves. Ours is written down and published, and our vendors are held to it.

## What the security laws already require.

Security law is further along than privacy law, and it already reaches the vendor. Europe's GDPR requires both the company and anyone processing data on its behalf to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Virginia's Consumer Data Protection Act requires a controller to establish, implement and maintain reasonable administrative, technical and physical data security practices. The FTC's Safeguards Rule tells financial institutions to oversee their service providers: choose ones capable of maintaining appropriate safeguards, and require them by contract to do it. The SEC's amended Regulation S-P gives the service provider of a broker, adviser, fund or transfer agent **72 hours** to report a breach of customer information. Virginia's breach law requires notice to the Attorney General and to every affected resident without unreasonable delay. And public companies now report material cybersecurity incidents on SEC Form 8-K, Item 1.05. The POPS4 Breach Clock lists every one the day it is filed.

The numbers explain why. Fortinet's 2026 Global Cybersecurity Skills Gap Report surveyed more than **2,750** IT and security leaders in 32 countries and locations: **86%** of organizations reported one or more breaches in the past twelve months, and **52%** said breaches cost them more than **$1 million**. Its 2026 Global Threat Landscape Report found that most confirmed cloud incidents in 2025 began with stolen, exposed or misused credentials rather than broken infrastructure, and it recorded a further **79%** increase in data theft. An identity, once taken, opens everything bundled behind it. As Fortinet's chief information security officer, Dr. Carl Windsor, put it, cybersecurity is not simply a technical issue but a strategic business risk.

*Figure 3: Source: Fortinet 2026 Global Cybersecurity Skills Gap Report (survey of 2,750+ IT and security leaders in 32 countries and locations, 28 April 2026) and Fortinet 2026 Global Threat Landscape Report (FortiRecon intelligence, 30 April 2026).*

## What independence looks like on a working desk.

POPS4 publishes SEC filings the day they are filed, on eight public boards: breaches, mergers, officer moves, charter amendments and more. Every row links to the filing itself, and the same facts are served to people as a page and to AI agents as machine-readable data.

Each board now carries three steps. Watch a company and hear the day it files. Price the program that filing usually calls for, live from the catalogue at wholesale, without speaking to anyone. Then, and only then, check it with a person. The same three steps are open to an AI agent, which can watch a company or price a program and is told who confirms it. Nothing on the boards asks for more than an email address.

The buyer stays independent all the way down. So does their AI.

> **In plain terms.** Buyers now research alone, use AI to do it and save the person for last, to confirm rather than persuade. They stay independent only where it is safe: where the data beneath every screen, and every vendor and subcontractor behind it, is handled properly. The house that shows its sources and keeps its chain clean gets that last call.

## About us.

Hako Shikin LLC has been making things for other people's brands since 1997, out of Virginia Beach, Virginia. It is the brand partner for brands that cannot afford a bad headline: one house that stays accountable from the first conversation to the pallet on the dock, rather than a chain of vendors each holding a piece and none of them holding the date. Four arms do the work. **Huang Goodman** for public relations, strategy and program management. **Hako Shikin** for production, routed across more than **1,400** vetted American manufacturers. **POPS4** for the catalogue, **70,000+** products across **200+** brands. **Prosecco4** for events. The people who call are usually holding something that matters and a date that will not move, and what they are looking for is rarely a proposal. It is somebody who picks up, gives them the real number, and is still standing there when the truck arrives.

If you are building from what is left, you are not finished.

-Jenny Huang Goodman MPA MSc MHSA jenny@huanggoodman.com

## The takeaway

Two thirds of business buyers would rather not be steered, nearly half already use AI to research, and the person they call last is there to confirm. Facts with their sources attached win both the human and the machine, and a data chain kept clean all the way down, vendors and subcontractors included, is what lets them keep buying on their own.

## Sources

1. Gartner - 67% of B2B buyers prefer a rep-free experience (9 Mar 2026) — https://www.gartner.com/en/newsroom/press-releases/2026-03-09-gartner-sales-survey-finds-67-percent-of-b2b-buyers-prefer-a-rep-free-experience
2. Gartner - 69% of B2B buyers turn to reps to validate AI-generated insights (20 May 2026) — https://www.gartner.com/en/newsroom/press-releases/2026-05-20-gartner-survey-finds-sixty-nine-percent-of-b-two-b-buyers-turn-to-sales-reps-to-validate-ai-generated-insights
3. Gartner - By 2030, 75% of B2B buyers will prefer human-prioritized experiences (25 Aug 2025) — https://www.gartner.com/en/newsroom/press-releases/2025-08-25-gartner-says-by-2030-that-75-percent-of-b2b-buyers-will-prefer-sales-experiences-that-prioritize-human-interaction-over-ai
4. OpenAI - Buy it in ChatGPT: Instant Checkout and the Agentic Commerce Protocol (29 Sep 2025) — https://openai.com/index/buy-it-in-chatgpt/
5. Robertson et al. - Negativity drives online news consumption, Nature Human Behaviour 7, 812-822 (2023) — https://pubmed.ncbi.nlm.nih.gov/36928780/
6. EU General Data Protection Regulation (EU) 2016/679, Article 5 - purpose limitation — https://eur-lex.europa.eu/eli/reg/2016/679/oj
7. Personal Information Protection Commission, Japan - Act on the Protection of Personal Information (APPI) — https://www.ppc.go.jp/en/legal/
8. FTC Staff Report - Cross-Device Tracking (January 2017) — https://www.ftc.gov/system/files/documents/reports/cross-device-tracking-federal-trade-commission-staff-report-january-2017/ftc_cross-device_tracking_report_1-23-17.pdf
9. Federal Rule of Criminal Procedure 41(e)(2)(B) - warrants for electronically stored information — https://www.law.cornell.edu/rules/frcrmp/rule_41
10. Federal Rule of Civil Procedure 26(b)(1) - scope of discovery — https://www.law.cornell.edu/rules/frcp/rule_26
11. GDPR Article 28(2) and 28(4) - subprocessors need written authorisation and the same obligations by contract — https://gdpr-info.eu/art-28-gdpr/
12. The Stash Edge - Your Brand Is a File Somebody Else Is Holding — https://www.pops4.com/stash/articles/your-brand-is-a-file-somebody-else-is-holding
13. GDPR Article 32 - security of processing — https://gdpr-info.eu/art-32-gdpr/
14. Code of Virginia 59.1-578 - Consumer Data Protection Act, controller duties — https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-578/
15. FTC Safeguards Rule, 16 CFR 314.4(f) - oversee service providers — https://www.law.cornell.edu/cfr/text/16/314.4
16. SEC Regulation S-P, 17 CFR 248.30 - service provider breach notice within 72 hours — https://www.law.cornell.edu/cfr/text/17/248.30
17. Code of Virginia 18.2-186.6 - breach of personal information notification — https://law.lis.virginia.gov/vacode/title18.2/chapter6/section18.2-186.6/
18. POPS4 Breach Clock - SEC 8-K Item 1.05 filings, same day — https://www.pops4.com/boards/breaches
19. Fortinet - 2026 Global Cybersecurity Skills Gap Report (28 Apr 2026) — https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2026/fortinet-report-reveals-cybersecurity-hiring-stalls-as-nearly-half-of-it-leaders-face-corporate-pushback
20. Fortinet - 2026 Global Threat Landscape Report (30 Apr 2026) — https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2026/fortinet-2026-global-threat-landscape-report-reveals-surge-in-ai-enabled-cybercrime-increase-ransomware-victims-year-over-year
21. Hako Shikin - Vendor Standards — https://hakoshikin.com/vendor-standards
22. POPS4 - SEC filing boards — https://www.pops4.com/boards

---

## Publisher

**Hako Shikin LLC** — Virginia Beach, Virginia. Founded 1997. ASI 217876 · DUNS 18-204-6339.
Principal and author: **Jenny Huang Goodman MPA MSc MHSA**.

- Author: https://www.huanggoodman.com/about
- LLM context: https://www.pops4.com/stash/llms.txt
- MCP endpoint, for AI agents: https://mcp.pops4.com/mcp
- Client dashboard: https://dashboard.pops4.com/
- Catalogue: 70,000+ products, 200+ brands
