The Agent Liability Gap: Banks Have Principles, Merchants Have Disputes
SEO title: Agentic Commerce Liability: The Evidence Gap Merchants Must Solve Meta description: Agentic commerce liability is moving faster than dispute rules. Learn why merchants need delegated authority, evidence trails and agent-aware payment controls. Suggested slug:agentic-commerce-liability-dispute-evidence-gap Primary keyword: agentic commerce liability Secondary keywords: agentic payments, agent payment fraud, chargeback evidence, delegated authority, Know Your Agent, AI payment routing, AI fraud detection payments, payment success rate
Agentic commerce has moved from pilot to live checkout. The liability framework has not.
That is the central risk for 2026–2027. The immediate problem is not necessarily that AI agents will commit more fraud than humans. It is that merchants may be unable to prove what happened when an agent placed an order on a customer’s behalf.
Could the merchant prove the customer delegated authority? Could it show the purchase stayed within the approved price, product, quantity or delivery parameters? Could it identify the agent, record the customer’s confirmation and demonstrate when the notification was sent?
If the answer is no, the merchant enters a dispute process designed for human cardholders and conventional fraud. Agentic commerce liability is therefore becoming an evidence problem before it becomes a fraud-rate problem.
The short answer
Agent-initiated transactions should be treated as a distinct acceptance channel.
Merchants need dedicated logs, evidence retention, refund rules and fraud controls for transactions initiated by software. The minimum record should connect the customer’s instruction to the agent identity, the purchase parameters, the final transaction and the post-purchase notification.
Without that chain, an authorised agent that exceeds its mandate may look indistinguishable from an unauthorised transaction.
The scale is arriving quickly. The Business Research Company forecasts the global AI agents market will grow from USD 12.1 billion in 2026 to USD 53.2 billion by 2030, at a 44.9% compound annual growth rate. This is a forecast, not a reported outcome, but it illustrates why merchants cannot wait for perfect regulation.
What the six banks actually agreed
On 22 September 2026, ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group and NatWest Group published Building Trust in Agentic Commerce.
The paper is voluntary and non-binding. It is not a liability rule, chargeback framework or technical standard. However, it is important because it identifies the precise gaps that merchants are already experiencing.
The six banks proposed five principles:
Transparency: parties should know when an AI agent is involved and on whose behalf it is acting.
Safety: participants should manage fraud, scams, authentication and disputes across the whole value chain.
Privacy and data: customer and merchant consent should govern how agent data is created, stored, accessed and shared.
Choice: consumers and merchants should not face unreasonable platform or payment restrictions.
Interoperability: agents, merchants, payment providers and networks should be able to connect safely.
The paper flags uncertainty over who is liable when an agent exceeds the authority granted by a customer. It also calls for auditable records covering consumer instructions, authentication, intent, transaction decisions, outcomes and interventions.
As Commonwealth Bank of Australia Executive General Manager Payments Ethan Teas said, “Building trust from the outset will be critical.” Bank of America’s Mark Monaco similarly identified identity, authorisation, fraud prevention, liability management and customer protection as essential to confidence.
The banks have promised a follow-up paper addressing implementation through protocols, standards and policies. That is necessary, but merchants cannot defer operational controls until the next paper arrives.
Why the payment rail changes the recovery path
The same agent action can create very different recovery options depending on the payment rail.
Card schemes have established unauthorised-charge and dispute processes. Yet it remains unsettled how those processes apply when a customer authorised an agent but the agent exceeded its instructions. An agent-initiated dispute currently has no dedicated chargeback reason code. It is generally filed under existing categories such as Visa 10.4 for fraud in a card-absent environment or Visa 13.3 for goods or services not as described.
There is no industry-wide agent-specific chargeback rate and no binding network rule that consistently allocates liability when delegated authority is exceeded.
The position is even more consequential on instant account-to-account rails. FedNow and RTP transactions are generally irrevocable, and the receiving bank is not obliged to return funds. That shifts the risk decision to the front of the transaction. The issuer, acquirer, merchant or orchestration layer must determine whether the agent and the instruction are legitimate before settlement.
ISO 20022 can carry richer payment data, but the agent’s full context often sits outside the payment message. A transaction may contain a reference or token without preserving the customer’s original instruction, the agent’s decision path or the exact purchase scope.

The evidence gap
A defensible agentic payment needs more than a successful authorisation response. It needs a connected evidence record covering:
Delegated authority: what the customer asked the agent to do, when the authority was granted and whether it was revocable.
Purchase parameters: approved products, price range, quantity, merchant category, delivery location, subscription terms and expiry.
Scope compliance: whether the agent stayed within those parameters or triggered an escalation when it did not.
Agent identifiers: the agent provider, agent instance, token or directory reference and authentication method.
Notification timestamps: when the customer was shown the order, price, terms, authentication event and confirmation or cancellation option.
Outcome records: the final order, fulfilment, refunds, customer communications and any intervention by a human or risk system.
This is chargeback evidence for an environment where the buyer may not have been present at checkout.
The industry is responding. Visa is developing Agent Score, an agent directory and a token assurance framework, alongside an OpenAI partnership. Mastercard’s Agent Pay includes more than 30 participants and a verifiable intent capability developed with Google. American Express has introduced Agent Purchase Protection, and Visa, Mastercard and Ant International are working on cross-network Know Your Agent interoperability.
These initiatives may improve trust and identity. They do not remove the merchant’s responsibility to retain evidence about the order it accepted.
What Shopify’s checkout opening means for merchants
On 28 September 2026, Shopify began allowing AI agents to read, update and submit checkout on behalf of buyers across eligible merchant sites. Agents can use saved payment and shipping details through Shop Pay, with buyer authorisation. The capability is built around WebMCP and the Universal Commerce Protocol.
Shopify had already enabled agents to search products, browse catalogues and add items to carts. The checkout change moves the agent from recommendation to execution. Shopify has reported roughly one million merchants on agentic sales channels.
For merchants, this means agent traffic should no longer be grouped into a generic “online” channel. It has a distinct operating profile:
The customer may not interact with the merchant’s checkout interface.
The agent may update delivery, discount or payment information.
The order may be submitted at machine speed.
The agent may retry or initiate multiple related purchases.
The merchant may receive a dispute without a clear agent marker in its existing systems.
Shopify’s Q2 2026 transaction and loan losses rose to USD 141 million from USD 80 million a year earlier. The increase was attributed primarily to scaling payments and lending volumes, particularly Shopify Capital, and is not evidence that agents caused the losses. It is nevertheless a structural warning: when agent sales carry no new fees, incremental risk can scale without a corresponding revenue line.
Merchant checklist for agent-initiated transactions
Create a separate channel flag for agent-initiated orders across the gateway, order management, fulfilment and dispute systems.
Capture the agent identity and preserve the relationship between the agent, principal, token, merchant and transaction.
Store the customer mandate in a tamper-evident format, including scope, limits, expiry and revocation status.
Compare the final order with the mandate before authorisation and escalate any price, product, quantity or delivery exception.
Record the customer-facing confirmation including the exact basket, terms, total amount and timestamp.
Retain post-purchase notifications and evidence that the customer could review, cancel or seek support.
Define an agent-specific refund policy for wrong-item, duplicate, subscription and out-of-scope transactions.
Map disputes to existing reason codes while adding agent evidence to representment files.
Monitor agent cohorts separately for approval rates, refunds, returns, disputes and repeat attempts.
Test recovery paths by rail because card disputes, instant payments and wallets do not provide the same remedies.
Operational controls and AI payment routing
A merchant should not choose between growth and control. It should route transactions according to context.
That requires AI payment routing that can reason over more than card number, device and IP address. The decision layer should consider the agent identifier, delegated authority, purchase scope, merchant risk, customer history, token assurance, fulfilment risk and the reversibility of the rail.
This is also where AI fraud detection payments must mature. A legitimate agent may generate high-frequency catalogue requests and almost no human browsing signals. Treating every agent as a bot will create false declines and damage payment success rate. Conversely, approving every authenticated agent without checking scope creates an evidence and loss problem.
Quantum Payments’ unified commerce and modular payment platform is designed around orchestration across channels, methods and operational workflows. Its relevance to agentic payments is not simply accepting another transaction type. It is connecting checkout, tokenisation, risk, refunds, reconciliation and business intelligence so merchants can govern the entire transaction lifecycle.
That complements Quantum Payments’ analysis of false declines and AI fraud detection and the frictionless paradox between authentication and payment success rate.

The strategic read
The next competitive advantage in agentic commerce will not belong only to the platform with the best agent interface. It will belong to the merchant that can prove what the agent was authorised to do.
Banks and networks are building principles, protocols, tokens and directories. Merchants are receiving orders now. The operational gap between those two realities is the agent liability gap.
The correct posture is to treat agent-initiated transactions as a new acceptance channel with its own identity, controls, evidence and economics. Merchants that build that layer early can support agentic sales without surrendering dispute defensibility or customer trust.
FAQ
What is agentic commerce liability?
Agentic commerce liability is the question of which party bears the loss when an AI agent makes a purchase, especially when it acts outside the authority delegated by the customer.
Do agent-initiated payments have dedicated chargeback codes?
No. Agent-initiated disputes currently use existing codes, including Visa 10.4 for card-absent fraud and Visa 13.3 for not-as-described claims. There is no industry-wide agent-specific chargeback code or binding liability rule.
What evidence should merchants retain?
Merchants should retain the customer mandate, agent identifier, purchase parameters, authentication event, scope-compliance result, final order, notification timestamps, fulfilment records and refund or dispute history.
Why are instant payments more difficult to recover?
FedNow and RTP payments are generally irrevocable, and the receiving bank is not obliged to return funds. That makes pre-transaction agent verification and AI payment routing particularly important.
What is Know Your Agent?
Know Your Agent is an emerging framework for identifying and verifying AI agents across payment networks, merchants, platforms and wallets. It is intended to complement, not replace, merchant-level evidence and risk controls.
Authoritative sources
.png)