GuideJune 2026 · 9 min read

Agentic Commerce Chargebacks: Who Is Liable When AI Buys?

OG
Olga Gavrina · Founder, ChargeMate · Certified Chargeback Expert · June 2026

Quick answer

Agentic commerce — where AI assistants complete purchases on customers' behalf — is creating a new wave of chargebacks. Customers dispute charges they don't recognise, even when their AI agent made a legitimate purchase. Chargeback volume is projected to grow 24% by 2028, and agentic commerce is a key driver merchants are not prepared for.

Adobe Analytics recorded a 4,700% year-over-year jump in AI-driven traffic to US retail sites between 2024 and 2025. When AI agents shop, traditional fraud evidence breaks down — device fingerprints, IP geolocation, and behavioural biometrics all fail. Merchants are left holding liability for disputes they cannot prove were authorised.

What Is Agentic Commerce?

Agentic commerce describes AI agents — ChatGPT plugins, Google Gemini shopping actions, Apple Intelligence purchase flows, and third-party autonomous shopping bots — that complete purchases without the human reviewing each transaction. The customer delegates buying authority once ("buy me the cheapest flight under $400") and the agent executes autonomously.

The problem for merchants is temporal: the customer authorised the agent, the agent made a legitimate purchase, but weeks later the customer sees a charge they don't immediately recognise and files a dispute. From the card network's perspective, it looks like a standard "unrecognised transaction" claim.

The scale of the problem

  • 4,700% — YoY jump in AI traffic to US retail (Adobe Analytics, 2024–2025)
  • 24% — Projected growth in global chargeback volume by 2028
  • 261M → 324M — Chargebacks projected to rise from 261 million (2025) to 324 million (2028)
  • $0 — Card scheme rules currently addressing AI agent liability

The 4 Dispute Patterns From Agentic Commerce

1. Purchases customers cannot recall

The most common pattern. The customer authorised the agent weeks or months ago, the agent completed a legitimate purchase, but the customer sees the statement entry and doesn't connect it to their agent. They call their bank and dispute it as an unrecognised transaction — a legitimate chargeback from the bank's view.

2. Delegated mistakes

The agent bought the wrong item — wrong size, wrong colour, wrong delivery date. Instead of contacting the merchant for a return, the customer disputes the charge. This is misuse of the chargeback system, but it's happening at scale. The agent's mistake becomes the merchant's liability.

3. Fraudsters mimicking agents

Criminals are already using "my AI agent made this purchase without my knowledge" as cover for first-party fraud. It's the new "I didn't receive this" — a claim that's hard to disprove and card networks haven't yet developed specific rules to address.

4. Legacy fraud tools failing

When agents shop, they trigger every fraud signal merchants have built defences around: cloud IP addresses, no browser fingerprint, no human interaction pattern, high velocity from a single IP. Existing fraud prevention tools either block legitimate agent purchases entirely or fail to catch actual fraud dressed as agent activity.

Who Is Liable — Customer, Agent Platform, or Merchant?

Current card scheme rules (Visa, Mastercard, Amex) do not address AI agent purchases. There is no defined liability framework for agentic commerce as of mid-2026. The practical legal position today:

  • The merchant bears liability — because the "cardholder" (the human) files the dispute, and the merchant cannot prove to the card network that the human authorised the agent.
  • The agent platform bears no scheme liability — they are not a party to the card transaction. Their terms of service may create civil liability to the merchant, but that requires separate legal action.
  • The customer faces no direct consequence — card schemes protect cardholders, not merchants. Even if the customer authorised the agent, they can still dispute successfully under current rules.

Visa has announced work on agent authentication standards — a framework for verifying that a human authorised a specific agent to make a specific purchase. Mastercard has similar working groups. Nothing is live yet. Until standards exist, merchants are exposed.

Traditional Fraud Evidence That No Longer Works

The evidence types that win most card-not-present chargebacks today are useless or counterproductive against agentic commerce disputes:

Evidence typeWhy it fails with agents
Device fingerprintAgents run on cloud servers, not the cardholder's phone or laptop. No fingerprint match is possible.
IP geolocationAgents use data-centre IP addresses in any geography. Geolocation shows a cloud provider, not the customer's home.
Behavioural biometricsNo human interaction to analyse. Keystroke dynamics, mouse movement, typing patterns — all absent.
3DS authenticationSome agents handle 3DS automatically, generating a successful authentication without human review. 3DS pass ≠ human authorisation.

What Evidence Merchants Need Now

Until card network standards catch up, merchants must build a new evidence trail specifically for agent-initiated orders:

  • Agent authorisation logs — timestamped records showing the customer granted buying permission to the agent, ideally with the scope of authority (dollar limits, categories).
  • Delegation records from the agent platform — documentation from the AI service provider confirming the customer's account initiated the purchase action.
  • Purchase confirmation emails — sent to the customer's email at the time of purchase and not disputed or bounced. The customer's silence = acknowledgement.
  • Order confirmation with customer's email acknowledgment — a reply, click, or read receipt from the customer after purchase shows awareness.
  • Prior purchase history via CE 3.0 — evidence of the customer having previously made similar purchases through the same agent without dispute establishes a pattern of accepted behaviour.

How to Protect Yourself Today

Practical steps merchants can take before card network standards arrive:

Require human confirmation for high-value agent purchases

Build a confirmation step — email the customer before shipping for orders above a threshold (e.g. $150+). The customer's click or reply is your best evidence of conscious human authorisation. It also catches agent mistakes before they become disputes.

Integrate with emerging agent authentication standards

Monitor Visa and Mastercard announcements on agent authentication. Early adopters of new protocols will gain liability shift — similar to how early 3DS adoption shifted liability before it became standard. Sign up for scheme merchant bulletins.

Document agent-initiated orders separately

Tag orders that arrive via agent-specific APIs or known agent User-Agents in your order management system. This lets you pull agent-specific dispute reports and build targeted evidence packages rather than treating them like standard CNP orders.

Consider 3DS for new agent accounts

For first-time purchases from a new agent account (customer + agent combination not seen before), trigger 3DS. Even if the agent handles it automatically, you get a liability shift on that transaction and a timestamped authentication event to include as evidence.

Frequently Asked Questions

What is agentic commerce?+
AI agents (ChatGPT plugins, Google Gemini, Apple Intelligence, autonomous shopping bots) that complete purchases on behalf of customers without the human reviewing each transaction. The customer delegates buying authority once, and the agent executes autonomously.
Who is responsible for chargebacks from AI agent purchases?+
Under current card scheme rules, the merchant bears liability. The cardholder (the human) disputes the charge, and merchants cannot yet prove the human authorised the agent. Card networks are developing agent authentication standards but nothing is live as of mid-2026.
What evidence do I need to win an agentic commerce chargeback?+
Agent authorisation logs showing the customer granted buying permission, delegation records from the agent platform, purchase confirmation emails sent to the customer, order confirmations with customer acknowledgment, and prior purchase history via CE 3.0. Traditional evidence (device fingerprint, IP geolocation) does not apply.
How is agentic commerce different from regular card-not-present fraud?+
In regular CNP fraud, a fraudster uses stolen card details. In agentic commerce disputes, the purchase may be entirely legitimate — a real customer's AI agent made a real purchase. The dispute arises because the customer does not recognise the charge or made a delegated mistake. Traditional fraud signals don't apply because there is no human interacting in real time.
Is my existing fraud detection ready for AI agents?+
Almost certainly not. Device fingerprinting fails because agents run on cloud servers. IP geolocation is meaningless for cloud IPs. Behavioural biometrics cannot capture an interaction with no human. Some agents handle 3DS, creating false security. Merchants need new evidence types: agent authorisation logs, delegation records, and email confirmation trails.

ChargeMate builds dispute responses for any chargeback type, including agent-driven disputes. $10/case.

See outsourcing plans →