
5 minutes
Agentic commerce liability is still being written
Visa, Mastercard and American Express have all launched frameworks for agent transactions, but who bears the loss in a dispute remains largely undecided.
Reshmi Suresh
Head of Agentic Commerce
Reshmi Suresh leads agentic commerce at Worldpay, now Global Payments, working with merchants to build fraud, identity and credential management capability for AI-driven purchases.
Key points
- Fraud models built to ask "are you trustworthy?" don't work when an agent, not a shopper, is the one transacting. The question has moved to authorization and intent.
- Visa, Mastercard and American Express have all launched agentic transaction frameworks, and EMVCo is now working on how its global specifications can support agentic payments through a dedicated task force. But liability allocation between merchant, issuer and agent platform remains largely unresolved once a dispute moves past straightforward fraud.
- Our Ravelin-powered agent detection identifies agent transactions today, with scoring and dispute evidence capabilities expected to become increasingly important as agentic commerce matures.
Every new payment method opens a short window where fraud outpaces the controls built to catch it. Agentic commerce's window is open right now, and the rules determining who pays for it are already being written.
Payments fraud has spent fifteen years answering one question: Are you trustworthy? Device metadata, behavioral biometrics, typing speed, mouse movement – all of it built to catch a human pretending to be someone else.
Agentic commerce asks a different question: Did the human actually authorize this specific purchase? The agent is now the customer, delegated by a shopper who never clicked, typed or showed up. The signals that powered older fraud models are becoming less effective or disappearing altogether. That's more consequential than it sounds. Merchants have spent a decade and a half building infrastructure to keep bots out; now the bot is the shopper, and the tooling built to block it doesn't yet know the difference.
The trust gap, in numbers
Worldpay's Agentic Commerce Report found 45% of consumers were ready to let an AI agent complete a purchase on their behalf, rising to 54% among Gen Z. At the same time, 95% reported at least one concern about agentic commerce, and 50% said fraud protections in place would make them trust it more. The gap between those two numbers – comfort and concern sitting side by side – is the whole story.
Where liability stands today
Visa's Intelligent Commerce Connect launched in April 2026, giving agent platforms a single integration point for onboarding, verification and token issuance across major agent protocols. For merchants, the practical effect is accepting agent-initiated payments through their existing Visa acceptance once an agent completes that process. It's currently in pilot with a handful of partners, with broader rollout planned through the year.
Mastercard's Agent Pay Acceptance Framework works the same way in practice, already integrated into some processor platforms and letting merchants accept agent-initiated payments through existing card agreements. American Express followed in April with its ACE developer kit and Amex Agent Purchase Protection, a commitment to back card member purchases made by registered agents.
EMVCo, the body that maintains the global EMV specifications underlying card payments, has also started work in this space, standing up a dedicated task force to explore how its specifications could eventually support agentic payments.
No liability shift exists yet. As more transaction data reaches the schemes, the task force's work points toward a future where liability frameworks could be rebuilt for this environment so no single party carries undue burden – and that's the outcome we're advocating for on behalf of merchants today.
Across all of this, the fraud case is reasonably well handled: When an agent authenticates properly and a token is issued correctly, liability generally follows existing authenticated tokenized-transaction rules, with the issuer carrying fraud risk and the cardholder's chargeback rights intact.
"Where it gets murkier is everything short of outright fraud."
Where it gets murkier is everything short of outright fraud. A shopper who claims their agent misunderstood an instruction, bought the wrong item or acted outside what they authorized is making a dispute claim, not a fraud claim. Today's frameworks don't yet have a clean answer for who absorbs that. Legal analysts tracking this space describe the allocation of that risk among issuer, acquirer, agent platform and merchant as still being negotiated in real time, with network rules setting a baseline but leaving real gaps for contractual terms, and eventually case law, to fill in.
Regulation hasn't caught up either. U.S. federal law built around Regulation E – the rule that regulates consumers’ right to dispute erroneous electronic fund transfers – still assumes a binary: You either authorized a transaction or you didn't. There's no framework yet for "I asked my agent to buy something inexpensive, and it bought something expensive instead."
How this plays out for non-card payment methods – open banking transfers, for example – is its own open question, and one this piece doesn't attempt to answer.
Europe has a different version of the same problem. PSD2 and Strong Customer Authentication were built to protect consumers, but as written they can block an agentic transaction from completing at all. The question isn't whether to weaken those protections – it's how to keep consumers protected without stalling the purchase. That's a problem tech providers are positioned to solve by building interoperability that abstracts the authentication complexity away from the transaction; regulatory clarification may follow, but isn't guaranteed. We're already doing this work with major agent platforms today.
How merchants get exposed without a plan
Even where fraud liability is reasonably clear, merchants can still be exposed in ways the current frameworks don't fully address. Amex's purchase protection commitment, for instance, covers the card member – it doesn't resolve what the merchant absorbs if the underlying dispute is about agent behavior rather than fraud.
- A dispute with no audit trail. Without a signed mandate proving what the shopper authorized, a disagreement between agent and shopper becomes a coin flip, and issuers tend to side with the cardholder.
- A false "my agent went rogue" claim. Friendly fraud with a new excuse. Without evidence tying the agent's action to a specific authorized instruction, merchants have no way to challenge it.
- A "this isn't what I wanted" chargeback. The agent buys something the shopper doesn't like, it isn't returnable and the shopper disputes the charge instead. Merchants can often win these – but fighting each one individually is its own cost.
- Good bot, bad bot confusion. Fraud tooling that can't distinguish a verified shopping agent from a malicious script either blocks legitimate revenue or lets bad actors through.
What closes the gap
Three capabilities matter here, and they're related, though not the same thing.
Agent identity and verification – knowing which agent placed an order and attributing it to a specific source, with reputation scoring by agent ID as a natural next step as more transaction history accumulates.
Intent verification – a record, ideally cryptographic, of what the shopper asked the agent to do, which becomes the evidence that matters most when a dispute happens. Verifiable Intent and protocols like AP2 point toward what that record could look like. We're working with the platforms building them to collect that data and pass it through the payment flow to merchants.
Credential management – not just tokenizing payment details, but restricting how they're used and making sure credentials handed to an agent are transmitted securely. Handing an agent a stored credential without those controls is closer to handing it an open pair of scissors than a normal checkout flow.
The goal across all three isn't blocking bots. It's attributing them – identifying and scoring each agent before a transaction reaches the gateway, so merchants can set their own rules (a spend cap that triggers a human step-up, for example) and enforce them at the infrastructure layer.
Trustworthy isn't the same as useful
Verifying that an agent is legitimate answers a different question than whether it's a good channel for your business. An agent can be entirely trustworthy and still be a poor fit if it returns a disproportionate share of what it buys, or only ever purchases one item at a time in a way that erodes per-order profitability. The question that matters most for a merchant isn't "can I trust this agent?" – it's "does this agent net positive once returns and channel cost are accounted for?"
"The question that matters most for a merchant isn't 'can I trust this agent?' – it's 'does this agent net positive once returns and channel cost are accounted for?'"
That's what an agent reputation score is for – average order size, return rate, chargeback rate and more, tracked by agent ID. Because we sit across many merchants rather than one storefront, we can see how the same agent behaves everywhere it shops, not just where it happens to be transacting right now.
What's still unsolved
Three domains remain genuinely open. Liability and dispute resolution doesn’t have a contract yet. Google’s AP2 and Mastercard’s Verifiable Intent protocols could supply the communication layer that a contract eventually gets built on, but only the card networks can close the liability gap at scale. The regulatory gap around Reg E remains unresolved. And the governance question – what an agent is and isn't allowed to do on a shopper's behalf – is being worked out now through forums including EMVCo's Agentic Payments Task Force and policymaker roundtables.
None of this gets solved by picking a side on which protocol wins. It gets solved by merchants and their PSPs building the fraud, identity and evidence layer underneath all of them.
Agentic commerce liability FAQ
Who is liable when an AI agent makes an unauthorized purchase?
Does Reg E cover AI agent purchases?
How can merchants verify an AI shopping agent is legitimate?
What is "know your agent" (KYA)?
Related insights

