Imagine a customer telling an AI assistant to find a hotel near a conference, keep the room under $350 a night, make sure breakfast is included, and only book something that can be cancelled without a penalty.
The agent searches dozens of properties, compares rates, evaluates location and amenities, selects a hotel, chooses a room, and completes the purchase using the customer's authorized payment credential. The customer never visits the hotel's website and never presses the final "buy" button because the entire point of the agent was to avoid doing all of that manually.
Two days later, the customer discovers that the room is nonrefundable.
The hotel says the reservation was valid. The payment credential was legitimate. The AI agent was authorized to transact. The customer says the agent ignored the instructions and disputes the charge.
So who gets the chargeback when the customer blames the robot?
That question sounds a little ridiculous today, but it gets directly to one of the most important payments problems created by agentic commerce. The industry isn't simply introducing a new checkout interface. It is inserting a decision-making system between the person who owns the payment credential and the merchant receiving the transaction.
For decades, digital payments have largely been designed around establishing whether the person using a credential was authorized to use it. Agentic commerce adds another layer because the consumer may authorize the agent without explicitly selecting the merchant, product, timing, or exact transaction that ultimately appears on the statement.
The payments industry may therefore need to prove something more complicated than identity. It may need to prove intent.
Authorization Is Becoming Delegation
In a traditional ecommerce transaction, the customer usually participates directly in the purchase. They search for the product, place it in a cart, review the total, select a payment method, and complete checkout. The industry has spent decades building authentication, fraud controls, tokenization, device intelligence, and dispute processes around that basic model.
Agentic commerce changes the sequence because the consumer can delegate some of those decisions to software. The customer may provide a broad instruction such as "buy more dog food when we're almost out," "book the least expensive nonstop flight that gets me there before noon," or "replace my running shoes when this model falls below $120."
The consumer is still the economic actor behind the transaction, but the consumer may not be present when the final merchant, product, price, or timing is selected. That distinction matters because authorization is no longer just a moment at checkout. It becomes a set of boundaries within which the agent is allowed to act.
How much can the agent spend? Which merchants can it use? Can it substitute products? Can it accept a nonrefundable rate? Can it use loyalty points? Can it select expedited shipping? Can it purchase from a marketplace seller instead of the brand itself?
Those details sound like product-design questions until a transaction is disputed. At that point, they become evidence.
A Valid Credential Doesn't Answer the Whole Question
Consider a merchant that receives an agent-initiated transaction using a legitimate tokenized payment credential. The credential belongs to the customer, the agent is recognized as an authorized agent, and the transaction passes the merchant's fraud controls.
That tells the merchant quite a bit, but it may not answer the question that becomes important later: did the purchase actually comply with the authority the customer delegated to the agent?
There is a meaningful difference between "this customer authorized this AI agent to make purchases" and "this customer authorized this AI agent to make this purchase under these conditions." The first statement establishes a relationship between the consumer and the agent. The second connects the consumer's instructions to the specific transaction.
Mastercard is already working directly on this problem through Verifiable Intent, an open, standards-based trust layer developed with Google. Mastercard describes it as a way to create a tamper-resistant record connecting the authenticated user, the consumer's specific instructions, and the interaction between the agent and merchant that results in a purchase. Mastercard has also said that the resulting audit trail can be used when a dispute occurs.
Visa is approaching the same broader trust problem through Visa Intelligent Commerce, which is designed to support AI-initiated transactions using payment credentials, controls, authentication, protections, and trusted-agent infrastructure. Visa's September 2026 consumer research also illustrates why the trust layer matters: while 72% of surveyed U.S. consumers had used an AI assistant, only 23% said they trusted generative AI to handle payment transactions on their behalf.
Consumers may become more comfortable with agentic commerce over time, but the payments infrastructure has to work when confidence breaks down, not only when everything goes correctly.
The Dispute Is Going to Need a Better Audit Trail
Today's payment disputes already depend heavily on evidence. Merchants may provide transaction records, authentication information, delivery confirmation, customer communications, recurring-payment disclosures, device information, and other documentation depending on the dispute and payment environment.
Agentic transactions potentially create another category of evidence: the delegation itself.
What did the consumer tell the agent?
What restrictions were active when the purchase occurred?
Did the consumer approve the final cart, or was the agent permitted to act autonomously?
Did the agent stay within the spending limit?
Was the merchant an approved merchant?
Were substitutions permitted?
Did the agent accurately transmit the customer's requirements to the merchant?
Was additional confirmation required because the transaction fell outside normal parameters?
The answers could determine whether a disputed transaction represents fraud, an agent error, a merchant issue, a misunderstanding by the consumer, or a perfectly valid purchase that the customer simply regrets.
Those are very different problems, even if they all begin with the same sentence: "I didn't buy this. My AI did."
Fraud and Disputes Are Not the Same Problem
The payments industry will also need to be careful not to collapse every bad agentic outcome into fraud.
A malicious actor stealing credentials and directing an unauthorized agent to transact is a fraud problem. An authorized agent exceeding its permitted spending limit is an authorization and control problem. An agent selecting a nonrefundable hotel when the consumer explicitly required a refundable rate may be an execution problem. A consumer receiving exactly what was requested and later changing their mind may be a customer-service or dispute-abuse problem.
Merchants, issuers, networks, and agent platforms will need enough information to distinguish among those scenarios. Otherwise, legitimate agentic transactions could become unnecessarily expensive for merchants, while consumers could lose confidence because nobody can explain why an automated purchase happened.
This is one reason a strong audit trail is more than a compliance feature. It is part of the economic infrastructure that could make agentic commerce sustainable.
Merchants Should Care Before the Volume Arrives
It would be easy for merchants to treat this as a future network problem and wait until agentic transactions represent meaningful volume. That would repeat a familiar payments mistake: allowing a new payment behavior to reach production before deciding who owns the operational consequences.
Merchants should understand how they will identify trusted agents, what transaction data will accompany agent-initiated purchases, what proof of consumer authorization will be available, and how that information will be retained for future disputes. Fraud teams need to understand how legitimate automated activity differs from malicious bots. Customer-service teams need to know what they can tell a consumer who says an agent made the wrong decision. Chargeback teams need to know what evidence exists and how quickly it can be retrieved.
Product teams also need to think carefully about how much autonomy they are willing to accept. A merchant may be comfortable allowing an agent to purchase a $30 household item without additional confirmation while requiring stronger verification for a $3,000 transaction, a nonrefundable reservation, or a product with unusual fulfillment requirements.
Agentic commerce will not eliminate merchant rules. It may make those rules more important because software can execute transactions faster and at a scale that humans cannot.
Issuers Have a Different Version of the Same Problem
Issuers will face their own questions because an agentic transaction can be legitimate even when the cardholder was not actively participating at the moment of purchase.
Traditional fraud signals may need additional context. An automated transaction should not automatically look suspicious merely because it occurred without familiar human browsing behavior. At the same time, recognizing an authorized agent cannot become a blanket approval signal because an authorized agent could still act outside the consumer's intended boundaries or become compromised.
The issuer therefore needs to understand not only whether the credential is valid, but whether the transaction fits the authority associated with the agent. Spending limits, merchant restrictions, authentication requirements, transaction context, and verifiable evidence of intent can become part of that decision.
This is where agentic commerce starts looking less like a new shopping feature and more like a new payments architecture.
The Customer Still Needs Recourse
None of this should be interpreted to mean consumers should lose the ability to dispute transactions simply because an AI agent was involved. The opposite is more likely to be necessary.
Consumers will need confidence that delegating a purchase does not mean surrendering control. Mastercard explicitly frames Verifiable Intent around clarity, accountability, and recourse when an agent acts on someone's behalf, while Visa's work similarly emphasizes consumer-controlled and permissioned commerce.
The challenge is making recourse work without turning every disagreement between a consumer and an AI agent into merchant liability.
If agentic commerce grows, the ecosystem will need rules and evidence capable of separating unauthorized transactions from authorized transactions, and agent mistakes from merchant mistakes. It will also need a practical way to determine when a consumer's instruction was ambiguous enough that responsibility cannot be reduced to a simple yes-or-no authorization question.
Payments has always been full of edge cases. AI agents are going to manufacture new ones at machine speed.
The Real Product Is Proof
The flashy part of agentic commerce is the idea that an AI assistant can find something, negotiate or compare options, and buy it without requiring the consumer to work through a traditional checkout flow.
The less glamorous part is what makes that experience commercially viable: credentials, permissions, authentication, transaction controls, fraud management, recordkeeping, dispute evidence, and recourse.
In other words, the hard part is still payments.
The winners in agentic commerce will not simply be the companies that make AI agents capable of spending money. They will be the companies that can prove why the money was spent, what the consumer authorized, whether the agent stayed within those instructions, and what should happen when something goes wrong.
Because eventually a customer is going to look at a transaction and say, "I didn't buy that. The robot did."
When that happens, the most important question will not be whether the robot can pay.
It will be whether everyone can prove what the robot was allowed to do.
Sources
- Mastercard, "When AI starts buying for you, trust becomes the product," March 5, 2026: https://www.mastercard.com/us/en/news-and-trends/stories/2026/verifiable-intent.html
- Mastercard, "Mastercard gives merchants a simpler way to build, connect and scale AI-powered shopping experiences," September 9, 2026: https://www.mastercard.com/us/en/news-and-trends/press/2026/september/mastercard-gives-merchants-a-simpler-way-to-build--connect-and-s.html
- Visa, "New Visa Research Finds Consumer Trust is Accelerating the Path to Agentic Commerce," September 9, 2026: https://usa.visa.com/about-visa/newsroom/press-releases.releaseId.22736.html
- Visa Intelligent Commerce: https://www.visa.com/en-us/solutions/intelligent-commerce