AI agents are already buying things on behalf of real cardholders.
Research suggests these agents will orchestrate $1 trillion in sales from the US alone by 2030. And a recent survey found that roughly half of consumers are ready to let agents shop for them.
The card networks have each built a way for AI agents to check out online using a tokenized card. Which means any business that accepts card-not-present payments on their website could be processing these transactions without even realizing it.
But the guardrails haven’t kept up with the technology. Agentic commerce is moving faster than the rules related to the payment infrastructure those transactions get run on.
And chargeback liability is the most obvious gap.
Typically, card liability has always come down to who did what and how the card was used. But none of those rules were written with a piece of software sitting between the cardholder and your checkout.
Liability Shift Rules Haven’t Caught Up to AI Agents
Card networks rely on liability shifts to decide who absorbs a fraud loss. The simplest way to understand this is that whoever has the weaker security usually pays.
For example, if a counterfeit chip-enabled card is dipped or tapped at a chip terminal during an in-person sale, liability is on the issuer. But if that same card is swiped or keyed in, liability shifts to the merchant. The online equivalent is 3D Secure authentication. When used at checkout, the issuing bank is liable.
Every single liability shift rule that’s currently in place is tied to fraud. Meaning the cardholder is saying they never made the purchase.
None of these cover a customer who made a purchase they didn’t like. Those have separate chargeback codes altogether.
So what happens when an AI agent buys something on behalf of a cardholder, but the cardholder claims the agent wasn’t authorized to make this specific purchase or bought the wrong thing?
The honest answer is that there’s still no concrete liability rule in place yet for agentic commerce.
AI Agent Fraud Mostly Follows Existing Token Rules
For a straightforward fraud case, purchases coming from AI agents will typically fall into the rules that the networks already have in place. As long as the agent comes in through the right door.
Card networks don’t want AI agents holding real card numbers. So instead, agents get a token, which is a stand-in credential linked to the cardholder’s account. But before it can get a token, the agent must be registered and verified through the network’s program, like:
- Visa Intelligent Commerce
- Mastercard Agent Pay
- American Express ACE Developer Kit
Verification is what moves the fraud risk.
So when a registered agent pays with a token that’s been properly issued, the transaction should fall under the same rules the networks use for authenticated, tokenized payments. Since the issuer did the verifying, the issuer also carries the fraud risk (much like the chip and 3D Secure examples mentioned earlier).
If it turns out a fraudster was behind the purchase, the merchant is generally off the hook.
But the catch here is the word “registered.” An AI agent that skips those programs and simply types a card number into your checkout page looks like any other card-not-present sale.
In that scenario, fraud liability sits where it always has: on the merchant (unless the transaction was successfully authenticated with 3D Secure).
It’s also worth noting that American Express has launched its own Agent Purchase Protection program, which is a commitment to back cardholder purchases made by registered agents. This is designed to protect the cardholder, but it doesn’t explain what the merchant absorbs in disputes about the agent’s behavior.
When an Authorized Agent Gets the Order Wrong
This is where things get dicey for merchants.
Let’s say an agent was legitimately given access to someone’s credit card. The consumer set everything up and inked the proper credentials so the agent can shop on their behalf.
Now the cardholder is saying that the agent got it wrong. The card wasn’t stolen and it wasn’t outright fraud because there’s no imposter. It could be something along the lines of:
- Agent misunderstood the instructions and buying the wrong item
- The consumer asked for something cheap and got something expensive
- Shopper claims the agent went beyond what they authorized
- The agent did exactly what it was told, but the shopper claims it went rogue anyway (basically friendly fraud with a new excuse)
What’s even messier about this problem is that the cardholder essentially decides how the dispute gets framed. Meaning if they feel like the agent overstepped the boundaries, they can tell their bank “I didn’t authorize this” which is a whole different meaning than “this isn’t what I ordered.”
The first comes in as a fraud dispute, and the latter is a customer dispute. Even though the facts underneath the scenario are identical.
Which brings me back to the main point that the network frameworks still don’t have a clean answer for who absorbs the cost yet.
Federal rules don’t either. Regulation E, which governs consumer disputes on debit cards and electronic fund transfers treats a transaction as either authorized or unauthorized. There’s not a category for “I authorized my agent to buy something, but not this.”
Why the Cardholder Will Usually Win a Gray-Area Chargeback
Until the rules catch up to the technology, my expectation is that the cardholder will win any close call.
There’s no official positioning from governing bodies on this yet. Just my opinion, but I think it’s fairly substantiated based on historical context.
That’s how disputes have always worked with or without AI involvement. The issuer’s relationship is with its cardholder, and when the dispute comes down to the customer’s word against a merchant with little to counter, the bank gives the benefit of the doubt to the customer.
And agent purchases make it harder for merchants to fight these chargebacks in one specific way.
On a normal online order, you can point to the customer’s own activity on your website. But with an agent, the customer may have never touched your site at all.
Even a dispute you win will cost something. Funds get pulled while the case is open and your processor will hit you with a chargeback fee on top of it.
Data Points That Can Help Merchants Fight Against AI Agent Chargebacks
The networks have spent the last few years giving merchants better ways to push back against friendly fraud. And both of the main programs run on the same core idea of data that ties the cardholder to the purchase:
- Visa Compelling Evidence 3.0: Allows merchants to use two prior undisputed transactions that share key data points with the disputed one.
- Mastercard’s First Party Trust Program: Gives merchants a structured way to share transaction data with Mastercard and the issuer, and it doesn’t require a prior history with the cardholder.
Both of these are built for fraud claims, and CE 3.0 specifically covers reason code 10.4 for card-absent fraud. That makes them particularly useful when any agent dispute comes in with a fraud framing, including those false “my agent went rogue” claims.
When the same complaint comes in as “not what I ordered,” it’s a customer dispute. So winning those still depends on standard representment: what was ordered, what was delivered, and proof the two match.
There’s still an open question about how well CE 3.0’s data points hold up when an agent placed the order. But it’s one of the only current defenses at your disposal right now, and worth trying if you have the right historical data.
What Merchants Can Do While The Rules Get Written
You can’t flip a switch or turn on a setting to protect yourself from agentic commerce disputes. And I honestly don’t know when that day is going to come.
But in the meantime, you can do a few things that should still help:
- If you sell online, confirm your processor or gateway supports CE 3.0 and First Party Trust data submissions.
- Keep the order, fulfillment, and delivery records detailed enough to win a “not as described” dispute on their own.
- Check what you’re paying per chargeback, and push back against your processor if the fee is high.
- Watch your statement for any new fraud or agent-detection services you didn’t sign up for.
Processors are already building tools to help identify agent transitions and package dispute evidence. Some may eventually be worth paying for if the cost outweighs the potential losses. But these should only show up on your statement if you’ve agreed to them at a reasonable price for relevant transactions.
Be wary of any “free trials” being offered by your processor on a service that automatically converts to a paid service.
Card networks will eventually write rules for agent disputes. But until they do, you’re working under outdated rules that can work against you if you’re not prepared.
