AI Agent Chargeback Liability: Who Pays When Bots Buy?

AI agents are starting to buy on customers' cards, and when those purchases get disputed, the merchant eats the loss by default. Here is who pays, what the card networks actually say, and the consent evidence subscription merchants should start capturing today.

Your next customer is not always a person. Sometimes it is an AI agent holding a scoped payment token, a delegated mandate, and instructions a human typed hours earlier. That human later sees the charge on a statement and files a dispute. At that point, the oldest question in payments (was this authorized?) no longer has a clean answer.

The short answer is that the merchant pays. As of August 2026, no card network has published an agent-specific dispute rule. Every live agentic checkout protocol leaves the seller as merchant of record. Unless you capture proof of the consumer's mandate to the agent, an agent-initiated dispute is your loss by default.

What is an AI agent chargeback and why is it a new risk?

An AI agent chargeback is a dispute on a purchase that an autonomous agent completed on a consumer's behalf. It creates a new risk because authorization becomes ambiguous. The consumer authorized the agent. That blanket permission does not automatically cover every individual transaction the agent makes. No one designed traditional dispute frameworks for that gap.

Early data suggests the gap is expensive. Disputes on agent-initiated transactions run at about 2.4 times the rate of comparable human-initiated card-not-present orders. The mix also differs: agents draw fewer classic fraud claims and more 'did not authorize' and 'not as described' claims. That pattern looks like friendly fraud, with one structural difference. The cardholder can claim they did not authorize the specific purchase without lying, because they genuinely did not. They authorized the agent.

The volume is arriving faster than the rules. Visa reported a 4,700% one-year surge in AI-driven traffic to US retail sites when it launched the Trusted Agent Protocol. Visa also says 47% of US shoppers already use AI for at least one shopping task. It predicts millions of consumers will complete purchases through agents by the 2026 holiday season. The dispute wave follows one statement cycle behind.

Flow from consumer delegation to agent purchase to unrecognized charge to unauthorized dispute, with the merchant absorbing the loss by default.
How an agent purchase becomes a dispute

Who is liable when an AI agent makes an unauthorized purchase?

By default, the merchant is liable. No rule assigns AI-agent chargeback fault to the AI provider. The merchant loses the revenue, pays the chargeback fees, and absorbs the operational cost. At least three parties are plausibly responsible: the consumer, the AI provider, and the merchant. Today's rules give the loss a single destination.

The clearest published answer points the same way. OpenAI's Agentic Commerce Protocol payment spec (ACP), the specification behind Instant Checkout in ChatGPT, states that OpenAI is not the merchant of record. Settlement, refunds, chargebacks, and compliance remain with the merchant and its payment service provider (PSP). Agent orders land in your normal dispute queue. Your existing acquiring agreement governs them.

The default is starting to crack at the edges. Under Mastercard's agentic token model, the issuer carries fraud liability when the token is validly issued and the transaction honors the consumer's policy at authorization. American Express announced Agent Purchase Protection in April 2026. For registered agents with authenticated purchase intent, Amex says it will stand behind the transaction and absorb agent errors rather than fight over them. Both moves are conditional carve-outs, not a new regime.

Regulators have not filled the gap either. As of 2026, no jurisdiction has enacted liability rules specific to autonomous AI purchasing. The closest existing anchors cut in the merchant's favor. Regulation E excludes from 'unauthorized' any transfer made by someone the consumer furnished the access device to. Regulation Z's 'unauthorized use' test fails when the user had actual, implied, or apparent authority. A consumer who deployed an agent arguably granted at least apparent authority. That argument only works if you can prove the delegation.

Liability by rail: ACP leaves chargebacks with merchants, Mastercard shifts to issuers when token policy is honored, Amex covers agent error.
Who eats the dispute, by rail

How do card network rules classify agent-initiated transactions?

Mostly, they do not, at least not yet. As of August 2026, no card network has published a binding chargeback rule for disputes on agent-initiated transactions. Visa and Mastercard shipped scoped-credential rails for AI agents. The networks still process and dispute agent purchases under ordinary card-not-present rules, with no separate agentic dispute category.

The structural problem is classification. Network rules sort every transaction into cardholder-initiated (CIT) or merchant-initiated (MIT). An agent purchase fits neither category: the cardholder was not present at purchase time, and the merchant did not initiate it. Visa updated its Core Rules to formally recognize agentic transactions. The rules condition that recognition on identity verification under Visa Intelligent Commerce specs and use of the provisioned token. Mastercard's public Transaction Processing Rules, by contrast, still contain no agentic terminology. Its framework lives in product programs like Agent Pay rather than in the operating rules that bind merchants.

Reason codes have the same gap. 'Merchandise not as described' does not capture 'agent exceeded mandate.' Issuers have no workflow that distinguishes consumer fraud, agent error, and scope disputes. So issuers squeeze agent disputes into existing chargeback reason codes built for humans. Visa 10.4 covers unauthorized fraud. Code 13.2 applies when the cardholder withdrew recurring permission. Code 13.5 applies when the cardholder claims they never agreed at all. Meanwhile, the monitoring programs do not care who initiated the transaction. Visa's VAMP (the Visa Acquirer Monitoring Program) and Mastercard's ECM (Excessive Chargeback Merchant) thresholds apply identically whether a human or an agent bought. Agent chargebacks burn the same compliance budget.

Why are subscription merchants most exposed to agentic disputes?

The reason is that subscription billing already runs on delegated, forgettable consent. Visa's own subscription-rules bulletin documents the root exposure: cardholders forget they consented to future billing at enrollment. An agent that enrolls, renews, or switches subscriptions on a customer's behalf stacks a second layer of forgettable delegation on top of the first.

The economics compound the problem. The Mastercard-commissioned Datos Insights study puts the average subscription chargeback at $69, the lowest ticket of any industry. Subscription businesses lose on volume, and every dispute costs more to fight relative to its value. The same study found issuers classify 72% of disputes as fraudulent, versus only 45% for merchants. That coding gap is exactly how 'I don't recognize this subscription charge' becomes an unauthorized-transaction fraud chargeback. The baseline is already rising. Forecasts put global chargeback volume at 324 million disputes in 2028, up from 261 million in 2025. That growth excludes any agent-specific surge.

Agents are also becoming subscription managers, not just shoppers. Shopping agents can now compare subscription value across providers, flag underused services, and initiate cancellations or switches autonomously. Agent-driven cancellation rates run 2.3 times higher than manual rates. Projections put agent-managed subscriptions at 34% by 2027. The core failure mode is the 'forgotten agent purchase': a customer sets an agent loose, forgets it, then disputes the charges it dutifully made. On your side of the network, those claims are indistinguishable from first-party fraud. Visa already pegs first-party fraud at about 20% of fraudulent disputes globally, rising to 30% for high-volume online merchants.

Four numbers framing agent-era risk: 2.4x dispute rate, 4,700% AI traffic surge, $69 average subscription chargeback, 1.5% VAMP threshold.
The exposure in four numbers

What evidence proves an AI agent purchase was authorized?

Mandate evidence is a record of what the consumer permitted the agent to do. Capture it at authorization time and store it with the transaction. The playbook is to log the mandate, not just the transaction. Log the agent identity, the intent signal, the token limits in force, and the recognition result. Retain those records for the full dispute window.

Mandate capture matters because everything else disappears. An agent transaction has no human click trail and no behavioral session data from the cardholder. The device fingerprint belongs to the agent's server, not the buyer's device. That breaks the strongest existing weapon against unauthorized-fraud disputes. Visa Compelling Evidence 3.0 requires two prior undisputed transactions, 120 to 365 days old, where the matching elements must include IP address or device ID. An agent transacts from its own infrastructure. So the exact match that shifts liability back to the issuer can fail precisely when you need it. Build your representment packages around delegation proof instead.

ArtifactWhat it provesWhy it wins
Delegated authority proofThe consumer granted the agent purchasing permissionDefeats 'I never authorized the agent'
Parameter recordsThe charge sat inside the limits the customer setConverts 'unauthorized' into 'authorized within scope'
Agent identity and session logWhich agent, version, and platform transactedAnchors attribution when device data points at a server
Notification timestampsThe customer was told and could cancel before fulfillmentDefeats the forgotten-agent dispute

Retain all four for the full dispute window on every agent-initiated order.

The protocols are starting to hand you these artifacts in machine-readable form. ACP delegated payment tokens carry an allowance object. The object records reason, max amount, currency, expiry, and the checkout session the token is tied to. Visa's Trusted Agent Protocol passes Agent Intent and Consumer Recognition signals on every request, plus a cryptographic signature with timestamps and a unique session identifier. Google's Agent Payments Protocol (AP2), announced with 60-plus organizations including Mastercard and American Express, makes signed Mandates the core primitive. Mandates are tamper-proof digital contracts that record the user's instructions, split into an Intent Mandate and a Cart Mandate. In network protocols, the original mandate record often sits on the issuer side. Keep your own parallel consent records, or you argue from evidentiary weakness.

How do 3-D Secure and tokenization apply to agentic checkout?

Rely on it cautiously. The 3-D Secure (3DS) liability shift moves fraud chargebacks to the issuer only when the cardholder authenticates. An autonomous agent cannot complete a challenge built for humans. Today, card networks classify agent traffic as ordinary card-not-present volume with no liability shift. So 3DS does not rescue merchants from agent disputes yet.

Even where 3-D Secure runs, subscription merchants should read the fine print. The shift covers fraud disputes only. It does not cover service, non-delivery, or not-as-described claims, which is exactly the territory where many agent-error disputes will land. Data-only flows carry no shift at all. On recurring merchant-initiated charges after the initial authentication, fraud liability stays with the merchant. The industry is retrofitting the specs rather than replacing them. EMVCo, the standards body behind card payment specifications, formally announced in November 2025 that it is adapting the EMV 3DS and tokenization specifications for agentic payments.

Tokenization is further along, and it is where consent becomes machine-readable. Visa Intelligent Commerce replaces the primary account number (PAN) with tokenized credentials seated inside the agent. Consumer-set spending limits govern those credentials. The program shares real-time commerce signals with Visa and explicitly ties them to dispute management. Mastercard's Agentic Tokens ride the same rails as contactless and card-on-file payments: the Mastercard Digital Enablement Service (MDES). Each token binds to a named agent and a revocable consent policy. Stripe's Shared Payment Tokens, the primitive behind ChatGPT checkout, are scoped per merchant and per basket. A token cannot cover a different seller or amount. Each of these is a consent boundary you can cite in a dispute response.

How can merchants prevent AI agent chargebacks today?

Treat agent orders as a distinct traffic class with their own evidence pipeline. Tag and track agent purchases so you can monitor their dispute performance independently. Adopt supported protocols so transactions arrive with authorization records. Log the mandate on every order. Give customers immediate confirmation with a cancellation window before fulfillment or renewal.

  • Identify agent traffic: adopt the Trusted Agent Protocol or an equivalent so credentialed agents are distinguishable from anonymous bots at checkout
  • Log the mandate on every agent order: agent identity, intent signal, token limits in force, and recognition result
  • Store protocol artifacts verbatim: ACP allowance fields, AP2 mandates, and TAP signatures, retained for the full dispute window
  • Send an immediate purchase notification with a cancel or modify window before fulfillment or renewal
  • Keep Visa subscription compliance tight: express consent at enrollment, plus a reminder with a cancellation link at least 7 days before a trial converts or billing terms change
  • Preserve CE3.0 eligibility where you can: capture user ID, IP address, shipping address, and any device data so prior-transaction matching still works on human orders
  • Deflect pre-dispute: order-detail sharing through Verifi Order Insight can stop a dispute from being filed at all, and it works across all reason codes, not just fraud

What changes as agentic commerce standards mature?

Expect the evidence to move into the rails themselves. EMVCo's 2026 workplan includes a Digital Payment Credentials schema for standardized credential provisioning, request, and verification. Mastercard announced Agent Pay for Machines in June 2026 with 30-plus partners. It bakes in programmatically enforced authorization rules and a purpose-built evidence layer for agent authorization, chargebacks, and liability review. The Mastercard and Google open standard promises cryptographic proof of what the consumer actually authorized. Amex has already created a third liability bucket, agent error, alongside merchant error and cardholder fraud. Until dispute rules catch up with the credential rails, the merchants who win will be the ones with consent records better than the issuer's.

Frequently Asked Questions

Who is liable when an AI agent makes an unauthorized purchase?

The merchant, by default. No card network rule assigns fault to the AI provider, and under every live protocol, including OpenAI's Agentic Commerce Protocol, the seller remains merchant of record. The merchant loses the revenue, pays the chargeback fees, and absorbs the operational cost unless it can prove the consumer's mandate to the agent.

Can a customer dispute a purchase their own AI agent made?

Yes. Consumer dispute rights apply to agent-initiated charges, and Visa's Zero Liability policy generally covers AI-agent purchases like any other, so an unauthorized claim becomes the merchant's or issuer's loss, never the cardholder's. Regulation E's exclusion for furnished access devices helps merchants argue the purchase was authorized, but only if they can prove the delegation.

Do Visa and Mastercard have chargeback rules for AI agent transactions?

Not yet. As of August 2026, neither network has published a binding dispute rule specific to agent-initiated transactions. Both have shipped credential rails (Visa Intelligent Commerce and the Trusted Agent Protocol, Mastercard Agent Pay), but agent disputes still default into the existing reason-code system that was built for human purchases.

What evidence do merchants need to win an AI agent chargeback?

Mandate evidence: proof of what the consumer authorized the agent to do. Capture agent identity, the permissions and limits the customer granted, token constraints like max amount and expiry, and notification timestamps showing the customer could cancel. Without these, the standard evidence stack of click trails and device fingerprints points at the agent's server, not your customer.

Does the 3-D Secure liability shift apply to AI agent purchases?

No, not today. Card networks classify agent traffic as ordinary card-not-present volume with no liability shift, and classic 3DS challenges assume a human is present, which autonomous agents cannot complete. EMVCo is adapting the 3DS and tokenization specs for agentic payments, but until that lands, fraud liability on agent orders stays with the merchant.