Agentic Commerce Chargebacks: Who Is Liable When AI Buys?
Quick answer
Agentic commerce — where AI assistants complete purchases on customers' behalf — is creating a new wave of chargebacks. Customers dispute charges they don't recognise, even when their AI agent made a legitimate purchase. Chargeback volume is projected to grow 24% by 2028, and agentic commerce is a key driver merchants are not prepared for.
Adobe Analytics recorded a 4,700% year-over-year jump in AI-driven traffic to US retail sites between 2024 and 2025. When AI agents shop, traditional fraud evidence breaks down — device fingerprints, IP geolocation, and behavioural biometrics all fail. Merchants are left holding liability for disputes they cannot prove were authorised.
What Is Agentic Commerce?
Agentic commerce describes AI agents — ChatGPT plugins, Google Gemini shopping actions, Apple Intelligence purchase flows, and third-party autonomous shopping bots — that complete purchases without the human reviewing each transaction. The customer delegates buying authority once ("buy me the cheapest flight under $400") and the agent executes autonomously.
The problem for merchants is temporal: the customer authorised the agent, the agent made a legitimate purchase, but weeks later the customer sees a charge they don't immediately recognise and files a dispute. From the card network's perspective, it looks like a standard "unrecognised transaction" claim.
The scale of the problem
- 4,700% — YoY jump in AI traffic to US retail (Adobe Analytics, 2024–2025)
- 24% — Projected growth in global chargeback volume by 2028
- 261M → 324M — Chargebacks projected to rise from 261 million (2025) to 324 million (2028)
- $0 — Card scheme rules currently addressing AI agent liability
The 4 Dispute Patterns From Agentic Commerce
1. Purchases customers cannot recall
The most common pattern. The customer authorised the agent weeks or months ago, the agent completed a legitimate purchase, but the customer sees the statement entry and doesn't connect it to their agent. They call their bank and dispute it as an unrecognised transaction — a legitimate chargeback from the bank's view.
2. Delegated mistakes
The agent bought the wrong item — wrong size, wrong colour, wrong delivery date. Instead of contacting the merchant for a return, the customer disputes the charge. This is misuse of the chargeback system, but it's happening at scale. The agent's mistake becomes the merchant's liability.
3. Fraudsters mimicking agents
Criminals are already using "my AI agent made this purchase without my knowledge" as cover for first-party fraud. It's the new "I didn't receive this" — a claim that's hard to disprove and card networks haven't yet developed specific rules to address.
4. Legacy fraud tools failing
When agents shop, they trigger every fraud signal merchants have built defences around: cloud IP addresses, no browser fingerprint, no human interaction pattern, high velocity from a single IP. Existing fraud prevention tools either block legitimate agent purchases entirely or fail to catch actual fraud dressed as agent activity.
Who Is Liable — Customer, Agent Platform, or Merchant?
Current card scheme rules (Visa, Mastercard, Amex) do not address AI agent purchases. There is no defined liability framework for agentic commerce as of mid-2026. The practical legal position today:
- The merchant bears liability — because the "cardholder" (the human) files the dispute, and the merchant cannot prove to the card network that the human authorised the agent.
- The agent platform bears no scheme liability — they are not a party to the card transaction. Their terms of service may create civil liability to the merchant, but that requires separate legal action.
- The customer faces no direct consequence — card schemes protect cardholders, not merchants. Even if the customer authorised the agent, they can still dispute successfully under current rules.
Visa has announced work on agent authentication standards — a framework for verifying that a human authorised a specific agent to make a specific purchase. Mastercard has similar working groups. Nothing is live yet. Until standards exist, merchants are exposed.
Traditional Fraud Evidence That No Longer Works
The evidence types that win most card-not-present chargebacks today are useless or counterproductive against agentic commerce disputes:
| Evidence type | Why it fails with agents |
|---|---|
| Device fingerprint | Agents run on cloud servers, not the cardholder's phone or laptop. No fingerprint match is possible. |
| IP geolocation | Agents use data-centre IP addresses in any geography. Geolocation shows a cloud provider, not the customer's home. |
| Behavioural biometrics | No human interaction to analyse. Keystroke dynamics, mouse movement, typing patterns — all absent. |
| 3DS authentication | Some agents handle 3DS automatically, generating a successful authentication without human review. 3DS pass ≠ human authorisation. |
What Evidence Merchants Need Now
Until card network standards catch up, merchants must build a new evidence trail specifically for agent-initiated orders:
- Agent authorisation logs — timestamped records showing the customer granted buying permission to the agent, ideally with the scope of authority (dollar limits, categories).
- Delegation records from the agent platform — documentation from the AI service provider confirming the customer's account initiated the purchase action.
- Purchase confirmation emails — sent to the customer's email at the time of purchase and not disputed or bounced. The customer's silence = acknowledgement.
- Order confirmation with customer's email acknowledgment — a reply, click, or read receipt from the customer after purchase shows awareness.
- Prior purchase history via CE 3.0 — evidence of the customer having previously made similar purchases through the same agent without dispute establishes a pattern of accepted behaviour.
How to Protect Yourself Today
Practical steps merchants can take before card network standards arrive:
Require human confirmation for high-value agent purchases
Build a confirmation step — email the customer before shipping for orders above a threshold (e.g. $150+). The customer's click or reply is your best evidence of conscious human authorisation. It also catches agent mistakes before they become disputes.
Integrate with emerging agent authentication standards
Monitor Visa and Mastercard announcements on agent authentication. Early adopters of new protocols will gain liability shift — similar to how early 3DS adoption shifted liability before it became standard. Sign up for scheme merchant bulletins.
Document agent-initiated orders separately
Tag orders that arrive via agent-specific APIs or known agent User-Agents in your order management system. This lets you pull agent-specific dispute reports and build targeted evidence packages rather than treating them like standard CNP orders.
Consider 3DS for new agent accounts
For first-time purchases from a new agent account (customer + agent combination not seen before), trigger 3DS. Even if the agent handles it automatically, you get a liability shift on that transaction and a timestamped authentication event to include as evidence.
Frequently Asked Questions
What is agentic commerce?+
Who is responsible for chargebacks from AI agent purchases?+
What evidence do I need to win an agentic commerce chargeback?+
How is agentic commerce different from regular card-not-present fraud?+
Is my existing fraud detection ready for AI agents?+
ChargeMate builds dispute responses for any chargeback type, including agent-driven disputes. $10/case.
See outsourcing plans →