NEWNow shipping: ACP Β· Google UCP Β· Retail MCP integrations
MnT Future
Agentic Commerce

Who Eats the Chargeback When an AI Agent Buys From You?

CEO UdhayaseelanΒ·Β·5 min read
Who Eats the Chargeback When an AI Agent Buys From You?

A funded D2C brand getting ready to switch on agent checkout β€” routing through Google's UCP, or accepting a purchase initiated by a shopping assistant like ChatGPT β€” usually gets the engineering questions answered first. Product feed hygiene. Inventory sync. Which merchant-of-record flag to set. The question that isn't getting answered, because almost nobody outside a payments-compliance team is asking it yet, is simpler and far more expensive: when the agent gets it wrong β€” buys the wrong size, double-buys, or gets spoofed by a bad actor posing as an authorized agent β€” who actually eats the chargeback?

Two payment networks launched agent checkout. Neither one named who's liable.

Visa introduced its Trusted Agent Protocol on October 14, 2025, and Mastercard unveiled Agent Pay on April 29, 2025. Both are real, shipping infrastructure β€” Visa's protocol issues cryptographically verifiable records of which agent acted and when; Mastercard's Agentic Tokens extend its existing tokenization stack so a consumer can scope exactly what an agent is allowed to spend. Both press releases talk about verification, authentication, and fraud prevention. Neither one specifies how a loss gets allocated after the fact β€” between the cardholder, the merchant, and the agent platform β€” when a dispute actually happens.

That's not a gap this piece is speculating into existence. Rivero, a payments-dispute technology company, published an analysis in December 2025 noting that because no new liability framework accompanies these protocols, agent-initiated disputes currently fall under the existing card-not-present rulebook β€” and dispute teams are already hitting cases that sit "uncomfortably between fraud and non-fraud categories." Fenwick, reviewing the regulatory picture in 2026, put the open question even more bluntly: when an agentic payment goes wrong, is it the user, the AI developer, the bank or processor, or the merchant who's responsible? Nobody has answered that yet, in rule or in law.

Why "authorized" doesn't mean what it used to

Under Regulation E, a disputed transaction is either authorized or it isn't β€” a binary built for a human tapping "confirm." An AI agent complicates that binary in a way the framework was never built for: the agent can act entirely within the technical permissions a shopper granted it, and still buy something the shopper never actually intended. Fenwick's analysis flags this directly β€” it's currently unresolved whether letting an agent hold your payment credentials even satisfies Regulation E's authorization standard in the first place. Until that's settled, a merchant accepting agent-initiated payments is operating inside a dispute process built for a different kind of transaction, and standard card-not-present liability rules β€” which frequently land on the merchant β€” are the default in the meantime.

To be direct about what's still unknown: nobody in this space β€” not Visa, not Mastercard, not the law firms writing about it β€” is claiming to have a finished answer. That's the honest state of the market right now, and it cuts against both an alarmist read ("agent checkout is unsafe, don't touch it") and a dismissive one ("the card networks have this handled"). Neither is accurate. The accurate version is narrower and more useful: the risk is real, it's currently unpriced, and it's a solvable operational question if you ask it early instead of discovering it mid-dispute.

The volume argument for solving this now, not later

McKinsey's October 2025 research put US agentic commerce revenue on a path to roughly $1 trillion by 2030, with a global estimate as high as $5 trillion. That's not a reason to slow down on agent-readiness β€” it's the reason the liability question can't stay parked. The brands moving first on UCP and ACP integration are also the ones who'll generate the first meaningful volume of agent-initiated disputes, well before the card networks or regulators have finished defining who owns them.

What agent-readiness actually has to include

Most agent-readiness conversations stop at the protocol layer: is the store discoverable, is the product feed structured, does checkout support UCP or ACP. That's necessary and it's not sufficient. The fraud-and-dispute layer sits underneath it, and it's a payments-operations question, not a code question β€” which is exactly why it gets skipped by teams that only think in terms of API integration. It's part of what we check across every AI & Agents engagement we run: not just whether an agent can transact with your store, but what happens contractually and financially the first time one of those transactions gets disputed.

That's the same shape of blind spot our AI Cleanup Lab keeps finding one layer down the stack in vibe-coded storefronts: the technology works in the pilot, and the gap only shows up the first time a real dispute β€” or a real exploit β€” has to be resolved and nobody agreed in advance whose job that was.

In practice, that means asking your payment service provider three things before agent checkout goes live: how they currently classify agent-initiated transactions under existing card-not-present rules; whether adopting Visa's Trusted Agent Protocol or Mastercard's Agentic Tokens changes your liability exposure in writing, not in a press release; and who β€” cardholder, your business, or the agent platform β€” is named as responsible in the specific integration you're using, whether that's a direct UCP integration, an ACP-based flow, or a third-party checkout agent.

None of that shows up in a feed-hygiene audit. All of it shows up in your first serious chargeback dispute if it isn't answered first.

Direct answer: Visa and Mastercard's 2025 launch announcements for agent checkout (Trusted Agent Protocol and Agent Pay) verify and tokenize AI agent transactions but do not specify who bears fraud liability. Payments-dispute specialists and legal analysts confirm this allocation β€” cardholder, merchant, or agent platform β€” remains unresolved industry-wide, so merchants accepting agent-initiated payments should confirm liability terms directly with their PSP before enabling it.

Agent-ready commerce is coming whether or not the liability rulebook is finished β€” the brands who ask this question before they flip the switch are the ones who won't be finding the answer out during a dispute. If you're evaluating UCP, ACP, or Retail MCP integration for your store, we run a free agent-readiness audit that covers this layer along with feed structure and protocol readiness.

Next step

Tell us what you're building. We'll show you how we'd build it.

A free strategy session with a senior consultant: data model, APIs, and a scalability plan. Or a free agent-readiness audit of your store.