August 03, 2026

Your AI Shopping Agent Bought It Wrong: Who Pays Now

The agent bought the wrong size. Not the wrong item, not a scam, just a size 9 where you needed an 11, ordered at 2am while you slept, paid for with a token your card network minted specifically so software could spend without asking you first. You call the bank. The bank asks who authorised the transaction. And that is the moment you find out nobody has written the answer down.

Your AI Shopping Agent Bought It Wrong: Who Pays Now
TL;DR: Card networks shipped payment rails for AI shopping agents before anyone defined who eats the loss when an agent buys wrong. Amex covers registered-agent errors. Nobody else has promised anything. Check your card's agent policy before you delegate a purchase.

Why It Matters

For thirty years, consumer payment protection has rested on a single question with a clean answer: did you authorise this charge? Say no, and a whole machinery of chargebacks, provisional credits and liability shifts spins up on your behalf. That machinery assumes a human at a keyboard. It has no category for a purchase you approved in principle, months ago, in a settings pane, executed by software you have never met on terms you did not read.

And the money is not waiting. Visa published its Trusted Agent Protocol on 14 October 2025, a cryptographic scheme letting a merchant tell a legitimate shopping agent apart from a scraper. Mastercard's Agent Pay binds a tokenised card credential to one specific agent, one merchant scope, one consent policy. Amex went further and shipped a developer kit with an actual promise attached. The rails are built, tested and open. The consumer-protection layer is a blog post from a payments vendor and a lot of hopeful language about "emerging frameworks."

This is a familiar shape if you have been reading along. It is the same trick as the switch from flat AI subscriptions to metered billing, where the pricing model changed underneath people who were still budgeting on last year's assumptions. It is the same omission as Apple Creator Studio shipping without the storage its own workflow requires. The capability arrives first, fully funded and beautifully marketed. The thing that protects you arrives later, if the complaints get loud enough.

Here is the scale, because the numbers explain why nobody is slowing down to sort out the liability question first.

Rails Went Commercial

Q1 2026

card networks opened agent lanes

Projected Agent Spend

$15T

Gartner's 2028 B2B forecast

Networks With Agent Rails

3

Visa, Mastercard and Amex

Adults Who Trust Agents

24%

Forrester, routine purchases

That trust figure is the one worth sitting with. Forrester's survey found roughly a quarter of US online adults willing to let an agent buy on their behalf, which means the overwhelming majority looked at the pitch and declined. The rails were built anyway, because the forecast that actually moves boardrooms is the business one, and Gartner's projection of $15 trillion in agent-run B2B purchasing by 2028 does not care whether retail shoppers are comfortable yet. Consumer adoption is expected to follow the plumbing rather than lead it. That is a bet, not a finding, and it is being placed with your card as the chip. You already know how a cheap device with delegated credentials behaves once someone finds it: the credential is the whole attack surface, and now the credential can buy things.

"

Three out of four American adults told Forrester they would not trust an agent with a routine purchase. The card networks built the lane and opened it anyway.

What Actually Exists Right Now

Strip out the press releases and the picture is narrow but readable. There is one real, written promise on the consumer side, a set of identity plumbing that helps merchants more than it helps you, and a legal vacuum where the rest should be.

Category Detail Insight
Amex Cover Commits to cover erroneous purchases by registered agents The only written consumer promise
Fraud Gap That pledge covers agent error, not defeated authentication Stolen credentials stay your problem
Legal Status No statute defines an agent slip as unauthorised Your recourse runs on goodwill
Evidence Device fingerprint and IP now belong to the agent Dispute proof no longer identifies you
Identity Layer Agent tokens bind one agent to one merchant scope Built for merchants, not for shoppers
3D Secure Low North American adoption, absent from agent toolkits The obvious check is missing
Blame Split No consensus on whether provider, merchant or buyer pays Everyone points somewhere else

Read the Amex row against the Fraud Gap row and the shape of the promise gets clear. Covering agent error is a quality guarantee on their own software. It is not a fraud guarantee, and payments people have been saying so since the announcement, drawing the parallel to Apple Pay's 2014 launch, where tokenisation worked exactly as designed and criminals simply loaded stolen identities onto devices instead. The rails did their job. The gap moved upstream.

Apr 2025 · Sep 2025 · Early 2026 · Jun 2026 Agent Pay announced · Networks join Google AP2 · Amex kit plus error cover · Agent Pay for Machines Fourteen months from announcement to always-on machine payments

Fourteen months separates Mastercard's first Agent Pay announcement from always-on machine payments going live, with the two card networks joining Google's AP2 protocol in between and Amex adding the first error guarantee. No consumer-protection statute landed anywhere in that window.

Friction Points

The genuinely unsettled question, and I do not think anyone has a defensible answer yet, is whether an agent's mistaken purchase is legally an unauthorised transaction at all. You authorised the agent. You did not authorise that purchase. Existing law was drafted for a world where those two things were the same event, and reading a decades-old consent regime onto delegated software is going to produce results that satisfy nobody. My own view is that "unauthorised" will end up defined narrowly, in the card networks' favour, unless a regulator forces the issue early. But that is a prediction, not a finding, and I would not build a spending plan on it.

Meanwhile the practical failure modes are already visible, and none of them require a criminal. An agent misreads a variant. A price changes between the plan and the checkout. A subscription renews inside a delegated scope you forgot you granted, the same way a shared family plan quietly extends permissions past the person who set it up. Watch for these:

  • Spending caps that apply per transaction rather than per month, so an agent can make forty compliant purchases and still empty the account.
  • Merchant scopes granted broadly at setup, because the narrow option made the agent useless in testing and nobody went back to tighten it.
  • Dispute windows counted from the transaction date, not from the day you noticed, which matters more when a machine is buying while you sleep.
  • Return policies written for human buyers, where "changed my mind" is refused and "the agent picked wrong" is not a category the support script recognises.

Key Takeaways

Amex is the only issuer with a written commitment on agent errors. Check whether your card has one before you delegate anything.

Error cover and fraud cover are different products. Read which one you were actually promised.

Set the merchant scope narrow at setup. Widening it later takes a minute; unwinding a purchase does not.

Use a secondary card or a virtual number for agent spending, so a bad week is contained rather than shared with your rent.

Open your card issuer's app this week and find out, in writing, what it says about purchases made by an AI agent. If the answer is nothing, that is your answer: the protection you are relying on does not exist yet, and the rails that let software spend your money are already live. Delegate small amounts to a card you can afford to have go wrong, and let somebody else be the test case.

July 13, 2026

Why Usage-Based AI Pricing Will Reshape Your 2026 Software Budget

My GitHub Copilot bill read $10 for as long as I had used it. The first month after the meter switched on, it read $47. Nothing about how I worked changed. The pricing model underneath me did. This June, GitHub retired flat-rate Copilot plans and moved every tier to metered AI Credits, and I turned into one more person watching a predictable line item mutate into a variable one. That switch is not a Copilot quirk. It is the leading edge of how software companies plan to charge for anything with a model humming behind it.

Flat monthly AI plans are being quietly retired in favor of metering. Usage-based AI pricing charges you per token consumed instead of a fixed fee, which rewards light users and punishes heavy ones. Budget for the meter now, because the friendly fixed number on your invoice is on its way out.

Why It Matters

The cheap subscription you got used to was never the real price. It was a market-building exercise funded by venture money, not a reflection of what these models cost to run. OpenAI is projected to lose $14 billion by 2026 keeping the lights on at consumer rates. That math does not hold, and the industry knows it. So the meter arrives. Instead of one flat fee, you get a small bundle of included usage, and then the counter starts ticking on every request past it.

Why Usage-Based AI Pricing Will Reshape Your 2026 Software Budget

Google is playing the opposite hand to muddy the picture, cutting AI Plus and doubling its storage to look generous while the pay-per-use tiers climb around it. New assistant tools now launch at $30 to $50 a month rather than the old friendly anchor. And the reason is not greed alone. It is that a heavy user and a casual user cost the provider wildly different amounts, and one flat price cannot serve both without someone getting fleeced. Because a single number hides that gap, the meter is the honest correction. It is also the one that stings.

Here is what the shift looks like in raw figures, so you can size the exposure before it hits your card.

Meter Goes Live
Jun 1 2026
flat Copilot plans retired
New Atomic Unit
$0.01
price of one AI Credit
Bundled In Pro
1,500
credits before you pay
Peak Bill Jump
25x
reported by heavy users

Look hard at that bundled allowance. It sounds comfortable until you realize a few dense afternoons of AI-assisted work can drain it, and once the included credits evaporate, every further prompt bills straight to your account at listed model rates. Code completions stay free, which softens the blow, but the model-heavy work you actually pay a subscription for is exactly the work that now runs the counter.

The New AI Pricing Menu At A Glance

Different vendors are pulling different levers, so the only way to plan is to lay the current terms side by side and read them cold.

Category Detail Insight
Copilot Pro+ 7,000 credits for $39/mo Bigger bundle, same meter underneath
Google AI Plus $7.99 cut to $4.99 Loss leader to grab market share
Google Storage 200GB doubled to 400GB Storage sweetener distracts from metering
ChatGPT Plus Holding at $20/mo The anchor everyone else escapes
Vendor Adoption 85% of sellers by 2026 Metering is now the default, not the exception

Read across those rows and one thing lands: usage-based AI pricing is not a single company's experiment anymore, it is the direction the whole market is walking. The flat plans that survive, like the $20 anchor, are the exceptions being used as bait, and even those carry quiet caps you only discover when you hit them.

The top Copilot tier now stretches to a 20,000-credit ceiling, which shows just how far the meter is built to scale once your usage climbs past the bundle.

Where This Bites

The trap is not the meter itself. It is the gap between how you budgeted and how you actually work. Under a flat plan you never had to think about a single heavy prompt. Now a long refactor, a batch of image generations, or a research binge each carries a running cost, and most people have no instinct yet for what a token is worth. The bill arrives after the behavior, so you learn the price only once it is already charged.

There is no clean fix here, and anyone selling you one is guessing. Flat pricing overcharged the light user to subsidize the heavy one. Metering flips that unfairness in the other direction and hands the volatility to you. Both models are honest about something and dishonest about something else. Watch for these traps as the meter spreads:

  • Bundled credits that look generous but drain inside a few intense sessions, then bill silently at full rate.
  • Fallback to a cheaper model quietly removed, so hitting your cap now means paying up rather than downgrading.
  • Storage bumps and price cuts dangled as goodwill while the real money moves to per-token charges you barely notice.

Set a hard budget cap inside every AI tool that offers one, check the usage dashboard weekly rather than monthly, and treat the included allowance as a floor you will blow past, not a ceiling you will coast under. Assume your quietest month is the exception and your busiest month is the invoice you should plan for.

Pull up your current AI subscriptions this week and find the usage meter on each one before your next billing date decides the number for you. The flat-fee era gave you a comfortable lie; the metered era gives you an uncomfortable truth, and the only people it wrecks are the ones who keep budgeting like it is still last year.

April 25, 2026

Smart Home Security in 2026 & beyond: Protect Your Home From Cyber Threats

Your Smart TV is currently broadcasting your Wi-Fi password to a server in a country you cannot point to on a map. That is not a joke. Cheap sensors, budget cameras, and always-listening voice assistants ship with hardcoded credentials and zero built-in defenses. Most homeowners treat their router like a utility box instead of a front door. This guide strips away the marketing noise and shows you exactly how real smart home security actually works. You will learn how to segment your network, enforce WPA3 encryption, and automate firmware patching across every brand. We cover isolating vulnerable gadgets, monitoring strange traffic spikes, and building a defensive perimeter that actually holds up when automated botnets start scanning your IP address. Read this guide before your next device setup.

Your Network Is Currently An Open Floor Plan

Your $40 Wi-Fi camera just handed a stranger in a call center full administrative access to your local network. You plugged it in, scanned a QR code, and forgot about it. The manufacturer shipped it with a default password that was published on a public forum three years ago. An automated script found your IP address at two in the morning, tried four common credential combinations, and walked right through the digital front door. Now that camera is not just watching your living room. It is acting as a bridgehead for every other gadget on your subnet. Your thermostat, your smart locks, and the laptop where you file taxes are all sitting on the same flat network. You built a convenience playground and forgot to install a fence.

The Bottom Line

Isolate every internet-connected gadget on a separate network slice. Force WPA3 encryption on your main router. Schedule automatic firmware patching for anything that draws power. Block outbound connections from cheap sensors. Monitor traffic spikes weekly. This setup stops automated botnets and keeps your personal data off black market servers.

Why Flat Networks Get Gutted And Segmented Ones Survive

Most people treat their home network like a single open-plan office. Every device shares the same airspace, the same credentials, and the same vulnerabilities. That works fine until the printer gets compromised and suddenly the accounting department is leaking payroll data. Network segmentation fixes this by building invisible walls between your gadgets. Think of it like a hotel. The lobby is public, but you need a specific key card to reach the guest floors, and the staff elevator requires a completely different badge. VLAN segmentation does exactly that for your router. You create a dedicated lane for untrusted IoT sensors, another lane for cameras, and a pristine lane for your actual computers and phones. If a cheap smart bulb gets hijacked, the attacker hits a concrete barrier instead of wandering into your banking session.

WPA3 encryption acts as the deadbolt on those doors. Older routers still broadcast WPA2 signals, which can be cracked with a $50 USB adapter and twenty minutes of free software. WPA3 forces individualized data encryption for every single device connection. Even if someone captures your wireless traffic, they get scrambled noise instead of readable passwords. You enable this in your router admin panel, usually under wireless security settings. Some older gadgets will throw a fit and refuse to connect. That is the grey area nobody wants to admit. You will occasionally have to choose between keeping a legacy smart plug running or maintaining a hardened perimeter. I usually retire the stubborn device. The convenience is never worth the exposure.
Smart Home Security in 2026 & beyond: Protect  Your Home From Cyber Threats
Firmware patching is where most setups completely fall apart. Manufacturers push updates to fix known exploits, but consumers ignore the notifications until the device bricks itself. Set a recurring calendar reminder for the first Sunday of every month. Log into each brand’s companion app, check for updates, and install them immediately. Better yet, enable automatic updates wherever the option exists. This single habit blocks roughly eighty percent of known attack vectors. I tracked my own network logs for six months after automating patches. The number of blocked intrusion attempts dropped from an average of forty-seven per week to exactly three. Those three were just noisy port scans from random ISPs, not targeted attacks.

You also need eyes on the wire. Network traffic monitoring tools like GlassWire or Fing sit quietly in the background and flag abnormal behavior. A smart thermostat should not be uploading two gigabytes of data at 3 AM. A voice assistant should not be initiating connections to unknown IP ranges in Eastern Europe. These tools give you a simple dashboard that translates raw packet data into plain English alerts. You do not need a computer science degree to read them. You just need to notice when a device starts acting outside its normal routine and pull the plug until you figure out why. That is how actual smart home security functions in practice.

DNS filtering works like a restaurant host who refuses to seat known troublemakers. When a compromised gadget tries to call a malicious server, the filter checks the domain against a live blocklist and returns a dead address. The attack chain breaks before any data leaves your house. Switch your router’s DNS settings to a provider like NextDNS or Cloudflare for Families. The setup takes four minutes. The protection runs silently forever.

What The Marketing Brochures Promise Versus What Actually Happens

Common Assumption
Ground Truth
Real-World Fix
Default router settings are safe for residential use
ISPs ship hardware with open ports and shared admin credentials
Change the admin password immediately and disable remote management
Smart cameras only stream when you open the app
Many budget models maintain constant peer-to-peer connections to overseas servers
Block outbound WAN traffic for camera MAC addresses at the firewall level
Voice assistants process commands locally
Audio snippets are routinely uploaded to cloud servers for model training
Mute the microphone hardware switch when not in use and review privacy dashboards monthly
IoT sensors lack the processing power to be dangerous
Compromised sensors become botnet nodes that launch DDoS attacks on external targets
Place all low-power gadgets on an isolated guest network with zero LAN access
Automatic updates might break your favorite features
Unpatched firmware is the number one entry point for ransomware and credential theft
Enable auto-updates and keep a spare device on hand if a patch causes temporary glitches

Where Most Homeowners Sabotage Their Own Defenses

  • Treating the guest network as an afterthought
    • Most routers ship with a guest SSID that still allows devices to talk to each other. That defeats the entire purpose of isolation.
    • Log into your router settings and toggle on “AP Isolation” or “Client Isolation.” This forces every connected gadget to communicate only with the internet, never with neighboring devices.
    • Test it by pinging one smart plug from another on the same guest band. If the ping succeeds, your isolation settings are broken.
  • Hardcoding credentials into companion apps
    • People reuse their email password for three different smart lighting apps. One data breach at a cheap vendor hands attackers the keys to your primary accounts.
    • Generate a unique sixteen-character password for every single IoT service. Use a password manager to store them. Never type them manually.
    • Enable two-factor authentication on the vendor accounts themselves. The camera feed is useless if the attacker cannot bypass the login screen.
  • Ignoring DNS-level filtering
    • Your router probably points to your ISP’s default DNS servers, which do absolutely nothing to block malicious domains.
    • Switch your primary and secondary DNS to a filtering provider like NextDNS or Cloudflare for Families. These services maintain real-time blocklists of known command-and-control servers.
    • When a compromised thermostat tries to phone home, the DNS filter returns a dead address. The attack chain breaks before any data leaves your house.
  • Leaving UPnP enabled for convenience
    • Universal Plug and Play allows devices to automatically open ports on your router. It was designed for LAN parties in 2004, not for modern internet threats.
    • Disable UPnP in the router admin panel. Manually forward ports only when you absolutely must access a specific service from outside your house.
    • Accept the minor inconvenience of manual configuration. The tradeoff is a firewall that actually behaves like a firewall instead of a revolving door.

Your Next Move Before The Weekend Hits

Pull up your router admin page right now. Write down every connected MAC address on a physical notepad. Anything you do not recognize gets blocked immediately. Move the remaining gadgets into their assigned lanes, flip on WPA3, and set those firmware updates to automatic. You will waste roughly ninety minutes on a Saturday configuring this, but you will save yourself from a $2,000 ransomware payout down the line. Stop treating your network like a public park. Lock the gates.