Agentic Payments Expose Liability Gap as Card Network Rules Lag Behind AI Automation
AI agents are completing purchases autonomously using stored credentials, but card network dispute and chargeback frameworks were written for human-authorised transactions — leaving liability for agent-initiated payments legally unresolved. Legal commentary from Goodwin Procter and Astraea Counsel confirms no clear rule yet determines who bears the loss when an AI tool acts beyond its mandate.

As agentic commerce scales, the absence of agent-specific dispute rules from card networks creates unresolved loss-allocation risk for merchants, issuers and acquirers operating by analogy with frameworks never designed for autonomous software transactions.
When Bots Buy: The Liability Gap at the Heart of Agentic Payments
AI agents are booking flights, renewing subscriptions and completing purchases — autonomously, without asking for human sign-off on each transaction. The payments infrastructure those agents are using was not designed with them in mind, and the resulting legal vacuum is now a practical problem for every party in the transaction chain.
The core tension is structural. Card networks have not published rules specific to agent-initiated transactions, which means the frameworks that govern disputes, chargebacks and liability were written for a world in which a human being — or at least a clearly delegated human instruction — stood behind every card-present or card-not-present payment. They did not anticipate a software process acting repeatedly, at scale, on a stored credential.
Who Bears the Loss?
In the absence of agent-specific dispute rules from any card network, the default position — consistent with how existing chargeback frameworks operate — is that the merchant of record carries the loss when a disputed transaction cannot be defended. That outcome may be commercially tolerable in isolated cases, but it becomes structurally significant as agentic commerce scales.
The deeper difficulty lies one step upstream. Legal commentary reviewed for this article, including analysis published by Goodwin Procter via Mondaq and by Astraea Counsel, identifies a foundational ambiguity: a consumer's decision to authorise an AI agent does not automatically constitute authorisation of every individual transaction that agent subsequently executes. Whether a specific purchase counts as "authorised" under existing payment frameworks is, in the current absence of clear rules, genuinely open.
The consent a user gives to an AI agent at set-up may not, in regulatory terms, extend to each autonomous transaction the agent makes — leaving the boundaries of "authorisation" legally unresolved.
That ambiguity matters in both directions. A consumer disputing a transaction their agent made — perhaps because the agent acted beyond its intended scope, or simply made a choice the consumer would not have made — can plausibly argue the transaction was not individually authorised. Whether that argument succeeds under existing consumer payment rules is not settled.
The Mandate Problem
The scenario that troubles issuers most is the one in which an AI agent exceeds the boundaries of what the consumer intended. Commentary from Goodwin Procter and Astraea Counsel makes the point directly: there is no clear legal rule determining who bears the loss when an AI tool acts beyond its mandate. That gap is particularly acute for card issuers considering making credentials available to third-party AI tools — if the agent oversteps and a dispute results, the loss allocation is unresolved.
Agency-law principles, discussed in National Law Review commentary, add a further dimension. How concepts of authorisation and delegated action apply when the "agent" is software rather than a person, and when that software acts across many transactions rather than one, is not addressed by existing rules.
Issuers and acquirers currently navigating this environment are doing so by analogy — drawing on frameworks that may have partial relevance rather than frameworks designed for the purpose. That is a workaround rather than a solution, and its adequacy as a risk-management approach depends on whether regulators and card networks treat agentic transactions as functionally equivalent to existing categories.
Why the Gap Matters Now
The practical stakes are asymmetric. Merchants sitting as the default loss-bearer have limited ability to verify whether a transaction was within the agent's scope at the point of sale. Issuers extending credentials to AI tools face residual exposure if those tools act beyond their mandate. Consumers who dispute agent-initiated transactions may find that the very convenience of agentic payments — no per-transaction approval — weakens the clarity of their own authorisation chain.
No card network has yet published rules that address these questions directly. Until that changes, every party processing agent-initiated transactions is operating in a framework built for a different era of payments — and bearing whatever risks that mismatch creates.
The Fin Desk Newsroom publishes verified reporting on the developments shaping fintech, payments and modern financial infrastructure.
Related Stories

AI agents enter cross-border payments but cannot fix the structural flaws beneath
AI agents are being integrated into cross-border payment pre-processing workflows, including counterparty verification and sanctions screening, but primary research from the BIS, Federal Reserve and SWIFT consistently identifies structural, compliance and data-quality failures that technology acceleration alone cannot resolve.

Basware Acquires Fraud Prevention Platform Trustpair in Undisclosed Deal
Basware, an invoice lifecycle management firm, has completed its acquisition of Trustpair, a payment fraud prevention platform, in a deal whose financial terms were not disclosed. The combination targets AI-powered payment fraud and supplier impersonation risks within enterprise accounts-payable workflows.

Global Payments posts 12% adj. EPS growth in Q4 2024, launches $250m buyback amid Worldpay deal
Global Payments reported Q4 2024 adjusted EPS of $2.95, up 12% on a constant-currency basis, alongside a $250 million accelerated share repurchase and an upward revision to its transformation programme target of $600 million in operating income benefit. The results were released as the company moved to complete its acquisition of Worldpay.

Worldline Connects AI Agents to Payment Ecosystem Under Agentic Commerce Push
Worldline announced on 15 January 2026 that it is introducing capabilities to connect AI agents to its global payment ecosystem, framing the move as infrastructure for merchants to experiment with agentic commerce. The France-headquartered payments group is one of several companies announcing agentic payment initiatives within a short window, alongside IDEMIA Secure Transactions and WSPN.
The essential developments in modern finance
The essential developments across fintech, payments and modern finance — delivered to your inbox.
Free. No spam. Unsubscribe anytime.