AI Agent Chargebacks: Liability Risks for Merchants
- AI agent chargebacks are card disputes raised against purchases an autonomous AI agent placed on a consumer’s behalf. Merchants absorb the loss in almost every configuration live today, and four mechanisms stack to produce that outcome.
- The merchant stays the merchant of record. OpenAI’s Delegated Payment Spec states that OpenAI is not the merchant of record and that settlement, refunds, chargebacks and compliance remain with the merchant and its payment service provider.
- The usual evidence disappears. Device fingerprint, IP address and navigation path describe the agent’s server rather than the cardholder, removing most of what wins a representment.
- Only one network has committed to absorb agent error. American Express announced Agent Purchase Protection on 14 April 2026, and the commitment is written in future tense with eligibility conditions attached.
- Every dispute also costs you ratio headroom. Agent-initiated disputes count in Visa’s monitoring metric like any other, and the merchant threshold tightened from 2.2% to 1.5% on 1 April 2026.
- Merchants considering stablecoin rails as an escape route should read the section on settlement finality, because removing the chargeback removes recourse for both sides.
What Are AI Agent Chargebacks?
An AI agent chargeback is an ordinary card dispute with an unusual origin: the transaction being contested was placed by software acting on delegated authority rather than by a person filling in a checkout form. Agentic commerce, to define the term precisely, describes purchases where an autonomous AI agent handles discovery, evaluation and payment after a human sets a goal and some constraints. A consumer says “book me a quiet hotel under 250 dollars near the venue” and the agent does everything that follows.
How Do Agent Disputes Differ From Ordinary Friendly Fraud?
The distinction that matters sits in what the consumer has to claim. Friendly fraud, meaning a dispute filed by a legitimate cardholder against a legitimate purchase, traditionally requires the consumer to assert something untrue, usually that they never made the purchase. Agentic commerce removes that requirement, because a consumer can accurately say they authorised an agent, accurately say they never chose this item, and leave the merchant to prove a negative.
Chargebacks911 has framed the underlying mismatch well, noting that the dispute system in use today was built in the 1970s, long before autonomous purchasing was a consideration. Reason codes were designed around a binary question of whether a cardholder authorised a transaction. Agentic commerce produces a third state the binary cannot express: transactions authorised in general, executed correctly against the instruction given, and still wrong.
The Three Failure Modes Merchants Will Actually See
Sorting the failure modes matters because they carry different defences. Torys LLP draws the most useful line, separating unauthorised activity, meaning fraud or agents acting well beyond their instructions, from unintended activity, meaning transactions a human did not want even though the agent behaved reasonably.
The first mode is credential compromise, where a fraudster hijacks or spoofs an agent and the merchant receives a valid token attached to a stolen identity. The second is scope departure, where a legitimate agent exceeds the boundaries its principal set. The third is intent mismatch, where the agent stays inside every stated boundary and still buys the wrong thing, which existing reason codes handle worst.

Why Merchants Carry AI Agent Chargeback Liability by Default
Liability lands on the merchant because every major agentic protocol preserves the merchant of record designation, and merchant of record is where chargeback liability attaches. That is written into the specifications in plain language.
The Merchant of Record Rule, Written Into the Protocols
The Agentic Commerce Protocol, co-developed by OpenAI and Stripe under an Apache 2.0 licence, states the position more directly than any other published document. Its Delegated Payment Spec says that OpenAI is not the merchant of record and that settlement, refunds, chargebacks and compliance remain with the merchant and their payment service provider. OpenAI’s production guidance repeats the point, telling merchants their platform handles refunds and chargebacks because they accepted payment directly as merchant of record.
Stripe presents the same arrangement as a feature, and the framing is fair as far as it goes.
Merchants keep the customer relationship, control fulfilment, appear on the cardholder statement under their own name, and can accept or decline each order on their own risk signals. Google’s Universal Commerce Protocol takes the same approach, and Worldpay’s agentic commerce lead has summarised the state of play bluntly: the rules have not changed specifically for agents, so existing liability allocation applies as it always has.
What Target’S Terms Tell You About Liability Allocation
Large retailers have already started answering the question contractually rather than waiting for networks or regulators. Target updated its terms and conditions ahead of its Google Gemini integration to treat purchases made by authorised AI shopping agents as transactions authorised by the customer, which means shoppers remain responsible even where the agent buys the wrong item or acts on a wrong price. The company also states that it cannot guarantee an agent will act exactly as the customer intends.
That move is instructive for two reasons. It shows liability allocation is negotiable at the terms-of-service layer well before any scheme rule arrives, and it shows the limits of the tactic, since a merchant legally insulated from an agent’s error still absorbs the experience damage and the support cost. There is a legal ceiling too. In Moffatt v. Air Canada, the British Columbia Civil Resolution Tribunal held the airline responsible for representations its chatbot made and rejected the argument that the chatbot was a separate legal entity.
The Evidence Gap in Agentic Commerce Disputes
Winning a representment depends on evidence that agentic checkout largely destroys, which is the practical reason agent disputes are harder to defend than their volume alone suggests.
Signals That Disappear at Agentic Checkout
A merchant defending a normal card-not-present dispute submits some combination of IP address, device fingerprint, browsing path, time on site, order history and delivery confirmation. Issuers expect a clean line connecting a specific human to a specific decision, and agent-initiated orders break that line at several points at once.
| Evidence type | Human checkout | Agentic checkout |
|---|---|---|
| Device fingerprint | Buyer’s phone or laptop | Agent’s server or MCP host |
| IP address | Buyer’s home or mobile network | Agent platform infrastructure |
| Session behaviour | Human browsing, scrolling, hesitation | Software reading a structured product feed |
| Navigation path | Pages viewed before purchase | Direct API call to checkout |
| Proof of intent | Click on a specific product at a specific price | Open-ended instruction given earlier |
| Delivery confirmation | Unchanged | Unchanged |
Table 1: What a merchant can still submit when an agent checks out.
Only the last row survives intact, which is why fulfilment evidence carries disproportionate weight in agentic disputes. Everything above it either describes the wrong party or no longer exists.
The Mandate Metadata Replacing Them
Protocol designers have recognised the gap and are building a replacement evidence layer around delegation records. Checkout.com argues that mandate logs, orchestration traces and agent identifiers let merchants prove what was authorised, by whom and under what conditions, and that this could eventually push responsibility upstream toward platforms whose agents misread instructions.
Google’s Universal Commerce Protocol shows what that looks like concretely, requiring cryptographic proof of user consent for each transaction, with the merchant embedding a mandate documenting terms such as price and line items, signed at confirmation using a key from the assistant or the user’s wallet. Merchants should capture these fields now, because the shift depends on network dispute rules recognising the new evidence, and those rules have yet to arrive.
What Visa, Mastercard and Amex Have Actually Committed To
Reading the ecosystem accurately requires separating three problems that vendor marketing blurs together. Agent recognition answers whether the entity at checkout is a legitimate shopping agent, credential scoping answers how much it may spend and where, and dispute liability answers who absorbs the loss. The first two are largely solved and the third is mostly open.
Agent Recognition Versus Dispute Liability
The table below maps what each framework does against where the loss sits.
| Framework | Launched | What it does | Where dispute liability sits |
|---|---|---|---|
| Visa Trusted Agent Protocol | 14 October 2025, with Cloudflare | Cryptographic agent recognition via HTTP Message Signatures, distinguishing shopping agents from scrapers | No published agent-specific dispute rule |
| Visa Intelligent Commerce | April 2025, extended by Intelligent Commerce Connect on 8 April 2026 | Tokenised credentials, spend controls, and acceptance across TAP, MPP, ACP and UCP | Existing card dispute rules apply |
| Mastercard Agent Pay | 29 April 2025, with Microsoft, IBM and Braintree | Agentic Tokens scoped to an agent, merchant scope and consent policy, revocable in real time | Existing chargeback rights apply unchanged |
| Mastercard Agent Pay for Machines | 10 June 2026 | Machine-speed microtransactions with 30-plus partners including Coinbase, Stripe and BVNK | Partner-supplied evidence layer, no scheme liability shift |
| American Express ACE Developer Kit | 14 April 2026 | Agent registration, account enablement, intent intelligence, payment credentials, cart context | Agent Purchase Protection covers Card Members for agent error, conditionally |
| Agentic Commerce Protocol | September 2025, Apache 2.0 | Agent checkout, product feed, delegated payment via scoped single-use tokens | Explicitly the merchant and its PSP |
| Google Universal Commerce Protocol | 11 January 2026 at NRF | Intent-based discovery and checkout with Walmart, Target, Shopify, Etsy and 20-plus partners | Merchant remains merchant of record |
Table 2: Agentic commerce frameworks and where the dispute loss lands.
Two patterns run through that table. Recognition and scoping arrived roughly a year before anyone addressed disputes, which tells you which problem the industry found tractable. American Express is the sole outlier, and its closed loop explains why, because acting as issuer, network and acquirer at once lets it absorb agent error without renegotiating with anybody.
Reading the Amex Commitment Closely
Procurement teams should treat the Amex protection as narrower than the headlines suggest. The announcement uses future tense, saying that in the future, if a Card Member authorises an AI agent and that agent sends American Express the customer’s authenticated purchase intent, the company will protect eligible customers from charges related to agent error. Eligibility depends on using a registered agent, meeting account conditions, and reporting within required time frames.
The sequencing matters more than the caveats. American Express confirmed that its Account Enablement, Intent Intelligence and Payment Credentials specifications were available on 14 April 2026, with Agent Registration and Cart Context still under development. Protection that depends on registered agents cannot fully operate until agent registration ships.
Mastercard occupies a middle position worth watching. Existing chargeback rights apply to agent-initiated transactions, preserving consumer protection without moving the loss, and Rivero reports that Mastercard is weighing scheme-carried liability for certified agents, conditional on proving the agent departed from stored intent. Treat that as direction of travel rather than a rule you can plan against. EMVCo is separately working on agentic payments through a dedicated task force.
How Agent Disputes Hit Your Monitoring Ratio
Losing the transaction value is the visible cost of an agent chargeback and rarely the expensive one. Every dispute feeds card network monitoring programmes carrying fees, reserves and, at the extreme, loss of processing access. Agent-initiated disputes count in those ratios exactly like any other, and the thresholds moved sharply in 2026.
The April 2026 Threshold Change
Visa’s Acquirer Monitoring Program, known as VAMP, consolidated five earlier programmes into one metric combining TC40 fraud reports and TC15 disputes against settled card-not-present transactions. On 1 April 2026 the merchant Excessive threshold fell from 2.2% to 1.5% across the United States, Canada, the European Union and Asia Pacific, a 32% tightening in one step. Merchants enter monitoring only on breaching both the ratio and a floor of 1,500 combined events per month, and industry sources put the Excessive Merchant fee at 8 dollars per disputed transaction.
The arithmetic turns uncomfortable quickly. A merchant running 200,000 monthly transactions at a 1.8% combined ratio was compliant in March 2026 and sat 20% above the Excessive line in April, exposed to roughly 28,800 dollars in monthly enforcement fees before counting chargeback losses. Adding a new dispute-generating channel to a business already near that line carries consequences well beyond the disputed orders themselves.

Two structural details make agentic volume particularly awkward under VAMP. The ratio is count-based rather than value-based, so a disputed 5 dollar agent microtransaction weighs exactly as much as a disputed 5,000 dollar order, which matters for merchants selling API access or digital goods. A single fraud chargeback can also generate both a TC40 report and a TC15 dispute, landing twice in the numerator. Mastercard runs a parallel Excessive Chargeback Merchant tier triggering at a 1.5% ratio combined with 100 chargebacks in a month.
Levers That Work Regardless of Liability
Merchants have meaningful control here even while liability stays open. Disputes resolved through Rapid Dispute Resolution or the Cardholder Dispute Resolution Network before formal filing drop out of the VAMP calculation entirely, converting a ratio problem into a refund cost. Compelling Evidence 3.0, submitted through Order Insight and accepted by the issuer, removes qualifying TC40 fraud signals after the fact.
Agentic Commerce Liability Rules by Jurisdiction
Regulators have moved faster than the “nobody is looking at this” framing suggests, though none has resolved who pays for an agent’s mistake. The direction is consistent everywhere: deploying autonomous software does not dilute the deploying organisation’s accountability.
| Jurisdiction | Position as of August 2026 | Practical effect for merchants |
|---|---|---|
| United States | No federal rule addresses agent-initiated purchase liability; Regulation E permits authorisation by “card, code, or other means” | Cardholder dispute rights persist; the Center for Data Innovation has urged the CFPB to update Regulation E |
| United Kingdom | CMA published “Agentic AI and consumers” plus business guidance on 9 March 2026 | Businesses are responsible for an AI agent as for an employee, with DMCC Act penalties up to 10% of global turnover |
| European Union, payments | PSD3 and PSR agreed politically on 27 November 2025, final compromise texts published 23 April 2026 | No provisions specific to agent-initiated payments; PSD2 interpretation governs meanwhile |
| European Union, AI | The EU AI Act predates widespread agentic purchasing | Risk classification and transparency obligations attach to deployers, with no payment liability allocation |
Table 3: Where the three major jurisdictions stand on agent-initiated purchase liability.
United States
American merchants operate with the least regulatory clarity of the three jurisdictions. Regulation E permits a consumer to authorise a payment by “card, code, or other means,” which plausibly covers sharing credentials with an agent. The Center for Data Innovation has argued that as written the rule could leave consumers without dispute rights when contesting agentic purchases, and has called on the CFPB to update it. Nothing has changed so far, so existing dispute rights and existing liability allocation both continue to apply.
United Kingdom
British merchants have the clearest language to work from. The CMA’s guidance, published on 9 March 2026 alongside its research paper, tells businesses they are responsible for what an AI agent does in the same way they are responsible for an employee, even where a third party designed or supplied the agent. Merchants deploying their own shopping or service agents should read that as removing the “our vendor built it” defense, with DMCC Act penalties reaching 10% of global turnover.
European Union
European merchants face a restructuring that arrives without answering the agentic question. PSD3 and the Payment Services Regulation reached political agreement on 27 November 2025, with final compromise texts published on 23 April 2026, the PSR applying 20 days after publication and PSD3 requiring transposition within roughly 18 to 21 months. The package narrows the commercial agent exemption some platforms use to avoid payment institution licensing, adding a requirement that the agent genuinely negotiate for one side with a real margin to negotiate. On AI-initiated payment liability the drafts are silent, leaving PSD2 and its strong customer authentication regime governing a technology that strains the assumption of a human approving at the moment of payment.
A Claim to Treat With Caution
One assertion circulating in trade coverage deserves scepticism. Several secondary sources reference a CFPB advisory from January 2026 on autonomous-agent purchases under Regulation Z. That document does not appear in the CFPB’s published guidance listings, and the Center for Data Innovation was still urging the CFPB to update Regulation E in March 2026, which sits awkwardly with the question having been settled two months earlier. Merchants should not build a compliance position on it.
Do Stablecoin Rails Solve AI Agent Chargebacks?
Stablecoin settlement offers an apparently clean answer to chargeback exposure, and the mechanism deserves precise description before any merchant treats it as an escape route. The honest summary is that it removes the problem and the safety net together.
Why Onchain Settlement Has No Reverse Gear
A card payment is a pull transaction, where the merchant pulls funds from the cardholder’s account, and that pull can be reversed through the dispute process. A stablecoin transfer is a push transaction, where the payer initiates and settlement is final. Once an onchain transfer confirms, no issuer, network or processor has the technical ability to reverse it, which makes the absence of chargebacks a property of the protocol rather than a policy some company could revoke.
This is why the fastest-growing agent payment rail sits outside the card system. The x402 protocol, built by Coinbase and contributed to the Linux Foundation in April 2026, revives the dormant HTTP 402 status code: a server answers with a 402 response and a price, the agent pays in stablecoins over HTTP, and the server returns the resource. Coinbase reported roughly 165 million transactions and about 50 million dollars in cumulative volume across 69,000 active agents by April 2026, averaging around 30 cents per payment. Visa’s stablecoin settlement programme hit a 7 billion dollar annualised run rate in the same month.
What Merchants Give up With Finality
The costs of finality run in both directions and deserve honest accounting. Buyer recourse disappears, so a consumer whose agent overspends or pays for something that never arrives depends on the recipient cooperating or on a court order. Refunds survive as a business decision, since a merchant can always send a new transfer back, which makes the refund a voluntary act rather than an enforceable right.
Regulatory exposure also stays live, which merchants sometimes miss. The Electronic Fund Transfer Act and Regulation E may partially apply where crypto rails sit beneath a consumer-facing fiat interface, and state money transmitter laws can impose error-resolution and refund obligations on wallet providers, processors and merchants. Ecosystem designers are rebuilding recourse through reputation systems, escrow-first designs and smart-contract-mediated refunds, all early enough that relying on them means relying on infrastructure untested at volume or in court.
The Split Stack: Cards for Retail, Stablecoins for Machines
The market has drawn a sensible line and merchants should expect it to hold. Card rails carry interchange of roughly 1.5 to 3.5% plus per-transaction fees, uneconomic for a five-cent agent-to-agent API call and appropriate for a 300 dollar purchase a human may want to dispute. Stablecoin rails clear in seconds at sub-cent cost with no acquirer, suiting machine-to-machine commerce and cross-border business payments.

Merchants selling to both audiences should expect to run both rails and price the difference into each. A digital goods business drowning in friendly fraud gains genuinely from finality, while a consumer retailer moving to irreversible settlement trades a dispute problem for a customer trust problem.
A Merchant Playbook for AI Agent Chargeback Risk
Practical preparation matters more than protocol allegiance while liability stays unsettled, because the controls that reduce exposure are the same across frameworks.
Evidence to Capture Now
Start logging delegation data before you need it in a dispute file. Store agent identity, mandate scope, consent timestamp, the original consumer instruction, and any spend caps attached to the credential. Classify agent traffic as its own risk category, weighting account age, velocity and shipping consistency more heavily to compensate for missing behavioural context. Treat a valid token as weak evidence of intent, because a scoped credential proves an agent was allowed to spend and proves nothing about whether this purchase was the right one.
Contract Terms to Negotiate
Settle the commercial questions before enabling agentic checkout rather than after the first dispute. Retail TouchPoints argues that merchants should demand clarity about who the purchaser is in an AI-mediated transaction and set contractual terms on responsibility for agent-driven purchases before adoption becomes widespread. Ask processors and agent platforms for prompt logs and transaction records per agentic order, and review your terms of service against Target’s approach, keeping the Air Canada ruling in mind as a limit on how far disclaimers carry.
Operational Controls
Make correction cheaper than disputing, which is the highest-leverage change available. Include cancellation links in confirmation emails, use a recognisable billing descriptor, and reference the agent-led flow in post-purchase communication so a confused customer contacts you rather than their bank. Deploy pre-dispute tooling before agentic volume scales, because it protects your monitoring position independently of who ultimately bears the loss.
Frequently Asked Questions (FAQ)
Who is liable for a chargeback on an AI agent purchase? +
The merchant bears it in almost every current configuration, because every major protocol keeps the merchant as merchant of record and chargeback liability attaches there. American Express is the single published exception, having committed to protect Card Members from registered agent error, subject to eligibility conditions.
Have Visa or Mastercard published agent-specific chargeback rules? +
Neither network has published a binding dispute rule specific to agent-initiated transactions. Mastercard has confirmed existing chargeback rights apply unchanged. Both have shipped agent recognition and credential-scoping infrastructure, which addresses a different problem from dispute liability.
Can a consumer dispute a purchase their own AI agent made? +
Yes, and no jurisdiction has removed that right. Regulation E and Regulation Z continue to govern dispute rights in the United States, and the CMA has confirmed UK consumer law applies identically whether a human or an AI agent is involved.
Can merchants shift liability to the customer in their terms of service? +
Some are trying. Target treats purchases by authorised agents as transactions authorised by the customer. The approach has limits, since the Moffatt v. Air Canada ruling held a company responsible for its chatbot's representations and rejected treating the chatbot as a separate legal entity.
Do stablecoin payments eliminate chargeback risk? +
They eliminate chargebacks structurally, because a confirmed on-chain transfer cannot be reversed by any third party. They also eliminate buyer recourse, move dispute resolution to reputation systems or escrow, and leave open questions under Regulation E and state money transmitter law.
How do agent disputes affect chargeback monitoring ratios? +
They count exactly like any other dispute. Visa's VAMP merchant Excessive threshold fell to 1.5 percent on 1 April 2026, and the ratio is count-based, so low-value agent transactions carry the same weight as large orders.
What evidence should merchants collect on agent-initiated orders? +
Merchants should log agent identity, mandate scope, consent timestamp, the original consumer instruction, credential limits and fulfilment evidence. Device fingerprint and browsing path describe the agent's infrastructure rather than the buyer.