September 08, 2026

EU Legal Guarantee Notice: What It Gets You

Your two year old washing machine stops draining. You dig out the receipt, and the retailer tells you the manufacturer's warranty ran out last month, so there is nothing they can do. That answer has always been wrong inside the EU. From 27 September 2026 it also gets harder to give, because the EU legal guarantee notice has to sit on the product page you bought from, in colour, before you click pay.

Shopper viewing an EU legal guarantee notice and GARAN label on a product page

This is a disclosure rule, not a new right: it publicises cover EU shoppers have held for years and mostly never used.

  • Commission Implementing Regulation (EU) 2025/1960 applies from 27 September 2026, everywhere at once.
  • The GARAN label appears only where a producer's durability guarantee is free, covers the whole product and outlasts the statutory floor.
  • Its absence proves nothing about quality, because issuing one is voluntary.
  • Chase the seller, not the maker. The legal guarantee is the seller's debt.

Why the EU legal guarantee notice matters now

The notice matters because the right it describes was already law and almost nobody used it, and a rule that forces the wording onto the product page removes the retailer's most reliable excuse.

The underlying cover is old news. Anyone buying goods in the EU gets a minimum of two years of protection from the seller, counted from the day the goods arrive, and that has been settled law for years. What was missing was any duty to say so at the moment it would change a decision. Commission Implementing Regulation (EU) 2025/1960, adopted on 25 September 2025, fixes the wording and the artwork. Directive (EU) 2024/825, the Empowering Consumers directive, supplies the legal hook, and Article 22a of the Consumer Rights Directive is where the display duty actually lands.

The interesting part is who this disciplines. Not the manufacturer. The legal guarantee is owed by the shop that took your money, so putting the notice on that shop's own product page strips out the "contact the manufacturer" deflection that has done most of the damage. We have seen the same shape before, in the way UK statutory cover beat provider policy on Buy Now Pay Later refunds, and again in the state by state cancellation patchwork that replaced the federal click to cancel rule. The cover existed. The disclosure did not. The gap between the two is where shoppers lost money.

And there is real money in that gap. The European Consumer Centre in Spain, run under the Ministerio de Consumo, reported recovering roughly 700,000 euros for consumers across its 2025 caseload, almost all of it on rights those consumers already held before they complained. Read the four figures below as what this rule is worth in practice, not as a summary of what it says.

Extra cover for choosing repair

12 months

Added to the statutory clock

What a GARAN guarantee may charge

€0

Charged means no label

Consumer requests, one country

16,000+

ECC Spain caseload, 2025

Spain's floor over the EU minimum

50%

Three years against two

The repair extension is the one worth planning around. Pick a repair rather than a replacement while you are still inside the statutory window, and the clock restarts far enough that a second failure of the same part still lands inside cover. Retailers push replacement because it closes the file and ends their exposure. Convenient for them. It can quietly cost you the extension.

"

Seven hundred thousand euros clawed back in one country, in one year, on rights shoppers already had. The notice is not new law. It is an admission that the old law was invisible.

What is the legal difference between warranty and guarantee?

A warranty is a promise a company chooses to make and writes the terms of itself. A guarantee, in EU law, is the cover the seller owes you whether or not anybody promises anything at all.

That distinction is exactly what the two new on-page items are meant to separate. One is a notice about a right. The other is a label about a product claim. Confusing them is how shoppers get talked into paying for protection they already have, so it is worth seeing the two side by side before the notice starts appearing.

DimensionLegal guarantee of conformityCommercial guarantee (GARAN label)
DurationStatutory warranty runs from the day the goods are deliveredMust outlast the statutory floor or it cannot be labelled
Who owes itThe seller that took your paymentThe producer that issued the guarantee
PriceIncluded in what you already paidCannot be charged for separately
ScopeGoods, digital content, and services paid for with personal dataThe entire good, never a single component
ProofSeller must disprove a fault during the first yearWhatever the producer's written statement sets out
RemedyFree repair or replacement before any price cut or refundOnly what the guarantee statement promises
OptionalMandatory across all 27 member states on one dateVoluntary commercial guarantee of durability, so absence proves nothing
On the pageHarmonised notice, no smaller than A4 when printedLabel at 95 by 100 mm minimum when printed
Best suited forAnything that fails when it should not haveComparing two products before you buy

Read down the first column and the practical rule falls out on its own: the legal guarantee is the one you can rely on without reading anything, and the labelled one is the tie breaker between two products that both already carry it. Neither replaces the other, and a seller who implies otherwise is selling you something.

27 Mar. 19 Jun. 31 Jul. 27 Sep. Transposition. Cancel button. Repair duty. Guarantee notice. EmpCo into national law. Online withdrawal made easy. Six household product groups. Notice plus GARAN label.

Four dated 2026 obligations, from Directive (EU) 2024/825, Commission Implementing Regulation (EU) 2025/1960 and the European Consumer Centre Spain's 2026 summary of new consumer rights.

Is a guarantee legally binding, and where does it fall short?

Yes, both kinds bind, but they bind different people in different ways, and the gaps that will annoy shoppers most sit in enforcement and in what this new notice deliberately leaves out of scope.

Line up the four 2026 dates and something becomes obvious that none of the source documents says outright. Transposition in March, an easy cancel button in June, a repair duty in July, the guarantee notice in September. Four separate consumer obligations landing inside a single six month window, which is the fastest run of retail-facing rule changes the EU has shipped in years. That pace is the story, and it is also the reason compliance will be uneven for months after each date.

Scope is the other soft spot. The notice is about goods, so it says nothing useful when the thing that failed was a service, an app, or an automated purchase you did not personally make. That last category is growing fast, and the question of who pays when an AI shopping agent buys the wrong thing sits well outside anything a guarantee notice can answer. The same is true for connected home devices that stop working when a cloud service is withdrawn, where the hardware is fine and the failure is somewhere else entirely.

  • A missing GARAN label tells you nothing about build quality. Producers opt in, and plenty of durable products will never carry one.
  • Second hand goods can be cut to a one year floor, but only where the seller discloses that clearly before you pay.
  • Enforcement runs through injunctions brought by competitors and qualified consumer organisations, not through a hotline that fixes your washing machine this week.
  • A trader outside the EU selling into it is still a distance seller. Marketplaces are in scope, which is precisely where compliance will slip first.

Three things worth doing the week the notice appears

Scan the QR code. It resolves to guarantee information in your own language, not the seller's.

Keep the durable statement. Producers must send the guarantee terms on paper or by email by the time the goods arrive.

Screenshot the product page. The notice is evidence of what you were told at the moment you paid.

Do one thing this week. Open the last expensive thing you bought online, find the seller's returns and guarantee page, and check whether it still points you at the manufacturer. If it does, that page has three weeks left to be correct, and knowing it is wrong is what turns a shrug at the service desk into a claim the seller has to answer.

September 01, 2026

How To Cancel Any Subscription In 2026: State Rules Compared

The email lands on a Friday. Apple TV is going from $12.99 to $14.99 a month, the fourth rise in four years, and you decide you have had enough. You open the app, tap through to your subscription, and land on a page offering you three months at half price. Cancel is in there somewhere. It is just never sitting where the discount is.

How To Cancel Any Subscription In 2026: State Rules Compared

The federal click-to-cancel rule was struck down in 2025 and has not come back. What you can actually force a company to do in 2026 depends on your state, and from October on your city. Here is where the real leverage sits.

Why It Matters

The rule everyone remembers was real, and then it wasn't. The FTC finalised its click-to-cancel rule in 2024, and on July 8, 2025 the Eighth Circuit vacated it, not on the merits but because the agency had skipped a preliminary regulatory analysis the law required. A paperwork failure. Years of drafting undone by a procedural step nobody outside the agency was watching.

The FTC hasn't given up on it. In March 2026 it opened an advance notice of proposed rulemaking to build the thing back, and the comment window shut on April 13, 2026. Rulemaking of that kind runs in years. In the meantime the agency keeps suing under the older Restore Online Shoppers' Confidence Act, which still requires a simple mechanism to stop a recurring charge, and it has teeth: the FTC's own September 2025 announcement put its Amazon Prime settlement at $2.5 billion, the largest the agency has ever secured, over sign-up flows and cancellation paths it called deliberately obstructive.

So the federal floor is enforcement after the fact, case by case, years late. The actual rules about clicks and notice windows have moved to the states, and the better ones have gone well past disclosure into the mechanics of the exit itself: how many steps, how much warning, whether a retention offer is allowed to sit between you and the cancel button. It is the same fragmentation that shows up in how refund rights split between the UK and the US on device financing, and it produces the same result. Two people paying the same company the same money have different rights.

Cancel window after a price rise

14 days

New York, prorated refund

Prime refund ceiling

$51

Per person, FTC refund page

Comments on the revival docket

~100

Filed before April 2026 close

Jurisdictions with a renewal law

25 of 50+

States and districts, mid-2026

That first number is the one worth memorising. New York doesn't only require a warning before a price rise, it gives you a short run of days after the higher charge actually lands to leave and take back the unused portion. Most people spot an increase on the statement, not in the email that announced it three weeks earlier. The law is written around how people behave rather than how they are supposed to behave, which is rarer than it should be.

"

Your cancel button is now a jurisdictional accident. Same app, same price, same company, and a New Yorker gets a refund window a Texan simply does not have.

Where Your Rights Actually Come From

Read this as a map of leverage, not a legal opinion. The question is never whether a company is behaving badly, it is which specific obligation you can point at when you write the complaint. Find your row, then quote it back to them.

Where What it actually obliges them to do Your move
Federal ROSCA requires a simple mechanism to stop recurring charges, with no click count or deadline attached Complain to the FTC, expect years
California Online sign-up means online cancellation with no obstructing steps, and consent proof kept for 3 years Demand the stored consent record
Colorado A one-step cancel link, and any save offer must keep a direct cancel link continuously visible beside it Screenshot any screen without one
New York State Renewal reminder 15 to 45 days before the cancel deadline, price-change notice 5 to 30 days ahead A missed notice is your refund lever
New York City From October 1, 2026, cancellation in the same channel you joined, with penalties starting at $525 File through 311 once live
Virginia A conspicuous online cancellation option on online sign-ups, in force since July 1, 2026 Quote the conspicuous-option wording
Most others Often only a pre-renewal notice duty on contracts of a year or longer, nothing about the cancel flow Lean on your card issuer instead

The pattern in that table is worth naming. The strong provisions are the boring procedural ones, notice windows and step counts, because those are the only things a regulator can measure without arguing about intent. Nobody wins a fight about whether a cancellation flow felt manipulative. Everybody wins a fight about whether a reminder arrived 12 days before renewal when the statute said 15.

Disclose the terms before any card is charged · Take a real yes no pre-ticked consent boxes · Warn before renewing inside a fixed day window · Let you leave by the channel you joined on

The four duties that recur across the stronger state statutes: disclosure before billing, affirmative consent, a renewal warning inside a defined window, and cancellation through the channel the subscription started in.

Friction Points

Here is the part the compliance blogs skip. A patchwork does not give everyone the strongest rule, it gives every company a map. Large subscription businesses run geo-detection already, and the rational move is to build the compliant flow for California and New York and serve the old one everywhere else. Smaller merchants do the opposite and overcomply nationwide because writing 25 versions of a cancel page is absurd. My read is that the patchwork has been quietly good for consumers in strict states and slightly worse for everyone else, which is not the outcome anyone campaigning for these laws intended.

Second problem, and this one is yours to manage. Almost none of these statutes cover the subscription you bought through an app store. The billing relationship sits with Apple or Google, the cancellation flow is theirs, and the merchant you are angry with genuinely cannot cancel it for you. The same routing confusion turns up in who carries the loss when an AI agent buys the wrong thing. Knowing which party actually holds the switch is most of the battle.

  • A retention discount you accept usually restarts the clock, so the renewal notice you were owed next month may no longer be owed.
  • Annual plans are where the notice rules bite hardest, and also where most people forget they are enrolled until the charge clears.
  • A cancellation confirmed only on screen and never by email is not evidence, and support systems lose it with impressive consistency.
  • Calling your bank to block the charge before you have formally cancelled can leave the contract alive and the debt accruing.

Key takeaways, in the order you will need them

Capture the flow. Screenshot every screen between you and the cancel button, with the clock visible. A cancellation dispute is almost always a dispute about what the interface showed, and the interface changes.

Name the statute. A complaint that cites the specific obligation gets routed to a compliance team. A complaint that says the process was unfair gets routed to a chatbot.

Escalate sideways. Your state attorney general enforces these laws and reads consumer complaints. The company's support queue does not enforce anything.

Do one thing this week. Open your card statement, find every recurring charge you cannot immediately justify, and cancel the ones that fail, starting with anything on an annual renewal. Do it now rather than at renewal, because the notice windows that protect you only help if you are watching the calendar, and the company running the cancel page is not going to remind you twice.

August 20, 2026

Buy Now Pay Later Refunds in 2026: Your Rights Compared

The Xbox got more expensive this month. The financing offer sitting next to it at checkout did not. That pairing is the whole story of consumer electronics this year: the hardware costs more, and the company selling it would very much like you to spread the damage across a few instalments instead of walking away.

Instalment plans at the point of sale used to be a fringe option for clothing. Now they are a default button on consoles, laptops, phones and televisions. And the protection attached to that button is not what most buyers assume it is.

Buy Now Pay Later Refunds in 2026: Your Rights Compared

TL;DR: Component costs are pushing device prices up, and vendors are answering with instalment plans at checkout. What that plan protects depends entirely on where you live: statutory refund cover on new UK agreements, and nothing more than provider policy in the US.

Why It Matters

Start with the price pressure, because it explains the timing. Microsoft announced on 25 June 2026 that the 512GB Xbox would rise by $100 from 1 August, its second increase in under a year, and said storage and memory costs had gone up two and a half times over. In the same announcement it offered Buy Now Pay Later, interest-free financing and cheaper refurbished units. That is a company reading its own demand curve correctly. Fewer people can absorb the new sticker price, so the sticker price gets broken into pieces.

Breaking a price into pieces is not automatically a bad deal. Four payments at zero interest beats a credit card balance you carry for eight months, and for a lot of households it is the difference between replacing a dead laptop now and going without. The problem is what quietly changes when you press that button instead of the card one. You are no longer making a card purchase with decades of dispute law wrapped around it. You are taking out a small loan from a company whose refund policy is, in most markets, its own invention. This is the same structural gap that shows up when software starts spending on your behalf, which is why who pays when an AI shopping agent buys the wrong thing is still an open question.

The rules moved after the meter did, the same sequence that played out when usage-based AI billing reshaped the software budget. Two things happened five weeks apart that pulled the two biggest English-speaking markets in opposite directions. In the UK, the Financial Conduct Authority began regulating Deferred Payment Credit in mid-July 2026, which brings affordability checks, Section 75 refund cover through the lender, and access to the Financial Ombudsman Service. Agreements signed before that date stay unregulated, so the plan you took out in June carries none of it. In the US, the Consumer Financial Protection Bureau revoked the interpretive rule that would have treated these plans like credit cards for dispute purposes, and confirmed it would not issue a replacement. Same product, same app, opposite floors.

Typical pay-in-four window

6 weeks

Four payments, fortnightly

Xbox 1TB price rise

$150

Microsoft, effective August 2026

Global BNPL volume, 2025

$560.1B

Fortune Business Insights estimate

Users late at least once

34% to 41%

CFPB borrower study, 2025

The late-payment figure is the one worth sitting with, because it is not describing people in financial trouble. Default rates stay low. What it describes is a repayment schedule that does not line up with how anyone actually gets paid, running quietly in the background while three other schedules do the same thing. Miss one and the cost is a flat fee rather than interest, which sounds gentler and often is not, because a fixed fee on a small balance is a brutal effective rate.

"

A $150 jump on one console is not a pricing footnote. It is the reason the instalment button moved from the clothing checkout to the electronics aisle.

What Each Payment Method Actually Protects

Below is the comparison nobody selling you a plan is going to put on screen. It covers the three ways most people pay for a device that costs real money, judged on what happens when the thing arrives broken, never arrives, or turns out to be nothing like the listing.

Dimension Pay-in-four plan Credit card Debit card
Dispute route The provider's own resolution flow, on its timetable Issuer billing dispute, with the card network behind it Bank chargeback request, scheme rules only
UK cover Section 75 through the lender, on newly regulated agreements only Section 75 on purchases above £100 and up to £30,000 No statutory cover, voluntary chargeback only
US cover Nothing guaranteed, provider policy decides Billing-error rights, claim within 60 days of the statement Unauthorised-transaction cover, weak on quality disputes
Cost on time Usually nothing on a short pay-in-four plan Nothing if the statement clears in full Nothing, the money simply leaves
Cost if you slip Flat late fee, harsh against a small balance Interest on the carried balance plus a late fee Overdraft charges from your own bank
Credit file Patchy, some providers report short plans and some do not Always reported, good months and bad Never reported, builds nothing
Escalation Ombudsman in the UK, goodwill in the US Ombudsman or regulator in both markets Your bank's complaints process, then the regulator
Fits which purchase Small to mid, split across a handful of instalments Anything inside your limit, including big-ticket Only what is already in the account
Best Suited For Cash-flow smoothing on a purchase you already trust Anything expensive, remote, or from an unfamiliar seller Small, low-risk buys from a shop you can walk back into

Read down the dispute-route row and the pattern is obvious. The instalment plan is the only column where the company you are complaining about and the company deciding your complaint answer to the same commercial pressure. That is not fraud. It is just a worse seat at the table, and it costs nothing at the moment of purchase, which is exactly why it is easy to miss.

1 Nov 2024 · 1 Apr 2025 · 15 Jul 2026 Klarna reports term loans · to TransUnion · Affirm reports all plans · to Experian · UK regulation of · deferred payment credit

Two reporting changes and one regulator arrived in that order, which is why a plan taken out in 2024 and an identical plan taken out today can behave completely differently on your credit file and in a refund fight.

Friction Points

The credit-file question is where honest people disagree, and I am not going to pretend it is settled. Putting short instalment plans into credit files could finally give thin-file borrowers a way to prove they repay things, which is the industry's argument and a decent one. It could equally turn a forgotten $40 payment into a score event that follows someone for years, on a product marketed as too small to matter. Both futures are plausible right now, and anyone claiming certainty is selling something.

The second friction is a design problem, not a policy one. These plans are approved in seconds, at the moment your resistance to spending is lowest, on a screen that shows the instalment and not the total. Stack three of them across three retailers and no single provider sees the whole picture. That is a familiar shape if you have ever compared subscription tiers and found the real cost buried two clicks deep, the way the family sharing fine print in Google One and OneDrive hides who is actually paying for what.

Watch for these specifically:

  • The pre-regulation gap. A UK plan opened before the new rules took effect is not covered by them. Check the agreement date before assuming Section 75 applies.
  • Refunds that go to the wrong place. Money can be returned to the provider while your instalments keep running. Confirm the plan is cancelled, not just that a refund was approved.
  • The unfamiliar-seller trap. Instalment plans are heavily promoted on low-cost gear, which is precisely where quality disputes cluster, and where cheap televisions from brands you have never heard of tend to go wrong.
  • Late fees that outrun interest. On a small balance, one flat fee can beat a month of card interest. Do that arithmetic before choosing.

Key takeaways worth keeping

  • A joint FICO and Affirm study of roughly 500,000 borrowers found score movement within plus or minus 10 points for more than 85% of the consumers examined, so the reporting shift is real but not seismic.
  • IDC's memory-shortage scenarios put average PC selling prices up 4% to 6% this year, and 6% to 8% if the shortage runs long, which keeps the financing pitch in front of you.
  • US buyers should treat instalment refund policy as a product feature to compare, not a legal guarantee, because no federal rule currently supplies one.

Pick the payment method by what could go wrong, not by what the checkout screen nudges you toward. Expensive item, unfamiliar seller, shipped rather than carried home: use the card, take the dispute rights, clear it in full. Everything else is a cash-flow decision you can make on the merits. Before the next big purchase, open your instalment app and count how many plans are already running. That number is the answer to a question most people never ask themselves.

Related: what the new EU legal guarantee notice gets you from 27 September 2026

August 03, 2026

Your AI Shopping Agent Bought It Wrong: Who Pays Now

The agent bought the wrong size. Not the wrong item, not a scam, just a size 9 where you needed an 11, ordered at 2am while you slept, paid for with a token your card network minted specifically so software could spend without asking you first. You call the bank. The bank asks who authorised the transaction. And that is the moment you find out nobody has written the answer down.

Your AI Shopping Agent Bought It Wrong: Who Pays Now
TL;DR: Card networks shipped payment rails for AI shopping agents before anyone defined who eats the loss when an agent buys wrong. Amex covers registered-agent errors. Nobody else has promised anything. Check your card's agent policy before you delegate a purchase.

Why It Matters

For thirty years, consumer payment protection has rested on a single question with a clean answer: did you authorise this charge? Say no, and a whole machinery of chargebacks, provisional credits and liability shifts spins up on your behalf. That machinery assumes a human at a keyboard. It has no category for a purchase you approved in principle, months ago, in a settings pane, executed by software you have never met on terms you did not read.

And the money is not waiting. Visa published its Trusted Agent Protocol on 14 October 2025, a cryptographic scheme letting a merchant tell a legitimate shopping agent apart from a scraper. Mastercard's Agent Pay binds a tokenised card credential to one specific agent, one merchant scope, one consent policy. Amex went further and shipped a developer kit with an actual promise attached. The rails are built, tested and open. The consumer-protection layer is a blog post from a payments vendor and a lot of hopeful language about "emerging frameworks."

This is a familiar shape if you have been reading along. It is the same trick as the switch from flat AI subscriptions to metered billing, where the pricing model changed underneath people who were still budgeting on last year's assumptions. It is the same omission as Apple Creator Studio shipping without the storage its own workflow requires. The capability arrives first, fully funded and beautifully marketed. The thing that protects you arrives later, if the complaints get loud enough.

Here is the scale, because the numbers explain why nobody is slowing down to sort out the liability question first.

Rails Went Commercial

Q1 2026

card networks opened agent lanes

Projected Agent Spend

$15T

Gartner's 2028 B2B forecast

Networks With Agent Rails

3

Visa, Mastercard and Amex

Adults Who Trust Agents

24%

Forrester, routine purchases

That trust figure is the one worth sitting with. Forrester's survey found roughly a quarter of US online adults willing to let an agent buy on their behalf, which means the overwhelming majority looked at the pitch and declined. The rails were built anyway, because the forecast that actually moves boardrooms is the business one, and Gartner's projection of $15 trillion in agent-run B2B purchasing by 2028 does not care whether retail shoppers are comfortable yet. Consumer adoption is expected to follow the plumbing rather than lead it. That is a bet, not a finding, and it is being placed with your card as the chip. You already know how a cheap device with delegated credentials behaves once someone finds it: the credential is the whole attack surface, and now the credential can buy things.

"

Three out of four American adults told Forrester they would not trust an agent with a routine purchase. The card networks built the lane and opened it anyway.

What Actually Exists Right Now

Strip out the press releases and the picture is narrow but readable. There is one real, written promise on the consumer side, a set of identity plumbing that helps merchants more than it helps you, and a legal vacuum where the rest should be.

Category Detail Insight
Amex Cover Commits to cover erroneous purchases by registered agents The only written consumer promise
Fraud Gap That pledge covers agent error, not defeated authentication Stolen credentials stay your problem
Legal Status No statute defines an agent slip as unauthorised Your recourse runs on goodwill
Evidence Device fingerprint and IP now belong to the agent Dispute proof no longer identifies you
Identity Layer Agent tokens bind one agent to one merchant scope Built for merchants, not for shoppers
3D Secure Low North American adoption, absent from agent toolkits The obvious check is missing
Blame Split No consensus on whether provider, merchant or buyer pays Everyone points somewhere else

Read the Amex row against the Fraud Gap row and the shape of the promise gets clear. Covering agent error is a quality guarantee on their own software. It is not a fraud guarantee, and payments people have been saying so since the announcement, drawing the parallel to Apple Pay's 2014 launch, where tokenisation worked exactly as designed and criminals simply loaded stolen identities onto devices instead. The rails did their job. The gap moved upstream.

Apr 2025 · Sep 2025 · Early 2026 · Jun 2026 Agent Pay announced · Networks join Google AP2 · Amex kit plus error cover · Agent Pay for Machines Fourteen months from announcement to always-on machine payments

Fourteen months separates Mastercard's first Agent Pay announcement from always-on machine payments going live, with the two card networks joining Google's AP2 protocol in between and Amex adding the first error guarantee. No consumer-protection statute landed anywhere in that window.

Friction Points

The genuinely unsettled question, and I do not think anyone has a defensible answer yet, is whether an agent's mistaken purchase is legally an unauthorised transaction at all. You authorised the agent. You did not authorise that purchase. Existing law was drafted for a world where those two things were the same event, and reading a decades-old consent regime onto delegated software is going to produce results that satisfy nobody. My own view is that "unauthorised" will end up defined narrowly, in the card networks' favour, unless a regulator forces the issue early. But that is a prediction, not a finding, and I would not build a spending plan on it.

Meanwhile the practical failure modes are already visible, and none of them require a criminal. An agent misreads a variant. A price changes between the plan and the checkout. A subscription renews inside a delegated scope you forgot you granted, the same way a shared family plan quietly extends permissions past the person who set it up. Watch for these:

  • Spending caps that apply per transaction rather than per month, so an agent can make forty compliant purchases and still empty the account.
  • Merchant scopes granted broadly at setup, because the narrow option made the agent useless in testing and nobody went back to tighten it.
  • Dispute windows counted from the transaction date, not from the day you noticed, which matters more when a machine is buying while you sleep.
  • Return policies written for human buyers, where "changed my mind" is refused and "the agent picked wrong" is not a category the support script recognises.

Key Takeaways

Amex is the only issuer with a written commitment on agent errors. Check whether your card has one before you delegate anything.

Error cover and fraud cover are different products. Read which one you were actually promised.

Set the merchant scope narrow at setup. Widening it later takes a minute; unwinding a purchase does not.

Use a secondary card or a virtual number for agent spending, so a bad week is contained rather than shared with your rent.

Open your card issuer's app this week and find out, in writing, what it says about purchases made by an AI agent. If the answer is nothing, that is your answer: the protection you are relying on does not exist yet, and the rails that let software spend your money are already live. Delegate small amounts to a card you can afford to have go wrong, and let somebody else be the test case.

July 13, 2026

Why Usage-Based AI Pricing Will Reshape Your 2026 Software Budget

My GitHub Copilot bill read $10 for as long as I had used it. The first month after the meter switched on, it read $47. Nothing about how I worked changed. The pricing model underneath me did. This June, GitHub retired flat-rate Copilot plans and moved every tier to metered AI Credits, and I turned into one more person watching a predictable line item mutate into a variable one. That switch is not a Copilot quirk. It is the leading edge of how software companies plan to charge for anything with a model humming behind it.

Flat monthly AI plans are being quietly retired in favor of metering. Usage-based AI pricing charges you per token consumed instead of a fixed fee, which rewards light users and punishes heavy ones. Budget for the meter now, because the friendly fixed number on your invoice is on its way out.

Why It Matters

The cheap subscription you got used to was never the real price. It was a market-building exercise funded by venture money, not a reflection of what these models cost to run. OpenAI is projected to lose $14 billion by 2026 keeping the lights on at consumer rates. That math does not hold, and the industry knows it. So the meter arrives. Instead of one flat fee, you get a small bundle of included usage, and then the counter starts ticking on every request past it.

Why Usage-Based AI Pricing Will Reshape Your 2026 Software Budget

Google is playing the opposite hand to muddy the picture, cutting AI Plus and doubling its storage to look generous while the pay-per-use tiers climb around it. New assistant tools now launch at $30 to $50 a month rather than the old friendly anchor. And the reason is not greed alone. It is that a heavy user and a casual user cost the provider wildly different amounts, and one flat price cannot serve both without someone getting fleeced. Because a single number hides that gap, the meter is the honest correction. It is also the one that stings.

Here is what the shift looks like in raw figures, so you can size the exposure before it hits your card.

Meter Goes Live
Jun 1 2026
flat Copilot plans retired
New Atomic Unit
$0.01
price of one AI Credit
Bundled In Pro
1,500
credits before you pay
Peak Bill Jump
25x
reported by heavy users

Look hard at that bundled allowance. It sounds comfortable until you realize a few dense afternoons of AI-assisted work can drain it, and once the included credits evaporate, every further prompt bills straight to your account at listed model rates. Code completions stay free, which softens the blow, but the model-heavy work you actually pay a subscription for is exactly the work that now runs the counter.

The New AI Pricing Menu At A Glance

Different vendors are pulling different levers, so the only way to plan is to lay the current terms side by side and read them cold.

Category Detail Insight
Copilot Pro+ 7,000 credits for $39/mo Bigger bundle, same meter underneath
Google AI Plus $7.99 cut to $4.99 Loss leader to grab market share
Google Storage 200GB doubled to 400GB Storage sweetener distracts from metering
ChatGPT Plus Holding at $20/mo The anchor everyone else escapes
Vendor Adoption 85% of sellers by 2026 Metering is now the default, not the exception

Read across those rows and one thing lands: usage-based AI pricing is not a single company's experiment anymore, it is the direction the whole market is walking. The flat plans that survive, like the $20 anchor, are the exceptions being used as bait, and even those carry quiet caps you only discover when you hit them.

The top Copilot tier now stretches to a 20,000-credit ceiling, which shows just how far the meter is built to scale once your usage climbs past the bundle.

Where This Bites

The trap is not the meter itself. It is the gap between how you budgeted and how you actually work. Under a flat plan you never had to think about a single heavy prompt. Now a long refactor, a batch of image generations, or a research binge each carries a running cost, and most people have no instinct yet for what a token is worth. The bill arrives after the behavior, so you learn the price only once it is already charged.

There is no clean fix here, and anyone selling you one is guessing. Flat pricing overcharged the light user to subsidize the heavy one. Metering flips that unfairness in the other direction and hands the volatility to you. Both models are honest about something and dishonest about something else. Watch for these traps as the meter spreads:

  • Bundled credits that look generous but drain inside a few intense sessions, then bill silently at full rate.
  • Fallback to a cheaper model quietly removed, so hitting your cap now means paying up rather than downgrading.
  • Storage bumps and price cuts dangled as goodwill while the real money moves to per-token charges you barely notice.

Set a hard budget cap inside every AI tool that offers one, check the usage dashboard weekly rather than monthly, and treat the included allowance as a floor you will blow past, not a ceiling you will coast under. Assume your quietest month is the exception and your busiest month is the invoice you should plan for.

Pull up your current AI subscriptions this week and find the usage meter on each one before your next billing date decides the number for you. The flat-fee era gave you a comfortable lie; the metered era gives you an uncomfortable truth, and the only people it wrecks are the ones who keep budgeting like it is still last year.

April 25, 2026

Smart Home Security in 2026 & beyond: Protect Your Home From Cyber Threats

Your Smart TV is currently broadcasting your Wi-Fi password to a server in a country you cannot point to on a map. That is not a joke. Cheap sensors, budget cameras, and always-listening voice assistants ship with hardcoded credentials and zero built-in defenses. Most homeowners treat their router like a utility box instead of a front door. This guide strips away the marketing noise and shows you exactly how real smart home security actually works. You will learn how to segment your network, enforce WPA3 encryption, and automate firmware patching across every brand. We cover isolating vulnerable gadgets, monitoring strange traffic spikes, and building a defensive perimeter that actually holds up when automated botnets start scanning your IP address. Read this guide before your next device setup.

Your Network Is Currently An Open Floor Plan

Your $40 Wi-Fi camera just handed a stranger in a call center full administrative access to your local network. You plugged it in, scanned a QR code, and forgot about it. The manufacturer shipped it with a default password that was published on a public forum three years ago. An automated script found your IP address at two in the morning, tried four common credential combinations, and walked right through the digital front door. Now that camera is not just watching your living room. It is acting as a bridgehead for every other gadget on your subnet. Your thermostat, your smart locks, and the laptop where you file taxes are all sitting on the same flat network. You built a convenience playground and forgot to install a fence.

The Bottom Line

Isolate every internet-connected gadget on a separate network slice. Force WPA3 encryption on your main router. Schedule automatic firmware patching for anything that draws power. Block outbound connections from cheap sensors. Monitor traffic spikes weekly. This setup stops automated botnets and keeps your personal data off black market servers.

Why Flat Networks Get Gutted And Segmented Ones Survive

Most people treat their home network like a single open-plan office. Every device shares the same airspace, the same credentials, and the same vulnerabilities. That works fine until the printer gets compromised and suddenly the accounting department is leaking payroll data. Network segmentation fixes this by building invisible walls between your gadgets. Think of it like a hotel. The lobby is public, but you need a specific key card to reach the guest floors, and the staff elevator requires a completely different badge. VLAN segmentation does exactly that for your router. You create a dedicated lane for untrusted IoT sensors, another lane for cameras, and a pristine lane for your actual computers and phones. If a cheap smart bulb gets hijacked, the attacker hits a concrete barrier instead of wandering into your banking session.

WPA3 encryption acts as the deadbolt on those doors. Older routers still broadcast WPA2 signals, which can be cracked with a $50 USB adapter and twenty minutes of free software. WPA3 forces individualized data encryption for every single device connection. Even if someone captures your wireless traffic, they get scrambled noise instead of readable passwords. You enable this in your router admin panel, usually under wireless security settings. Some older gadgets will throw a fit and refuse to connect. That is the grey area nobody wants to admit. You will occasionally have to choose between keeping a legacy smart plug running or maintaining a hardened perimeter. I usually retire the stubborn device. The convenience is never worth the exposure.
Smart Home Security in 2026 & beyond: Protect  Your Home From Cyber Threats
Firmware patching is where most setups completely fall apart. Manufacturers push updates to fix known exploits, but consumers ignore the notifications until the device bricks itself. Set a recurring calendar reminder for the first Sunday of every month. Log into each brand’s companion app, check for updates, and install them immediately. Better yet, enable automatic updates wherever the option exists. This single habit blocks roughly eighty percent of known attack vectors. I tracked my own network logs for six months after automating patches. The number of blocked intrusion attempts dropped from an average of forty-seven per week to exactly three. Those three were just noisy port scans from random ISPs, not targeted attacks.

You also need eyes on the wire. Network traffic monitoring tools like GlassWire or Fing sit quietly in the background and flag abnormal behavior. A smart thermostat should not be uploading two gigabytes of data at 3 AM. A voice assistant should not be initiating connections to unknown IP ranges in Eastern Europe. These tools give you a simple dashboard that translates raw packet data into plain English alerts. You do not need a computer science degree to read them. You just need to notice when a device starts acting outside its normal routine and pull the plug until you figure out why. That is how actual smart home security functions in practice.

DNS filtering works like a restaurant host who refuses to seat known troublemakers. When a compromised gadget tries to call a malicious server, the filter checks the domain against a live blocklist and returns a dead address. The attack chain breaks before any data leaves your house. Switch your router’s DNS settings to a provider like NextDNS or Cloudflare for Families. The setup takes four minutes. The protection runs silently forever.

What The Marketing Brochures Promise Versus What Actually Happens

Common Assumption
Ground Truth
Real-World Fix
Default router settings are safe for residential use
ISPs ship hardware with open ports and shared admin credentials
Change the admin password immediately and disable remote management
Smart cameras only stream when you open the app
Many budget models maintain constant peer-to-peer connections to overseas servers
Block outbound WAN traffic for camera MAC addresses at the firewall level
Voice assistants process commands locally
Audio snippets are routinely uploaded to cloud servers for model training
Mute the microphone hardware switch when not in use and review privacy dashboards monthly
IoT sensors lack the processing power to be dangerous
Compromised sensors become botnet nodes that launch DDoS attacks on external targets
Place all low-power gadgets on an isolated guest network with zero LAN access
Automatic updates might break your favorite features
Unpatched firmware is the number one entry point for ransomware and credential theft
Enable auto-updates and keep a spare device on hand if a patch causes temporary glitches

Where Most Homeowners Sabotage Their Own Defenses

  • Treating the guest network as an afterthought
    • Most routers ship with a guest SSID that still allows devices to talk to each other. That defeats the entire purpose of isolation.
    • Log into your router settings and toggle on “AP Isolation” or “Client Isolation.” This forces every connected gadget to communicate only with the internet, never with neighboring devices.
    • Test it by pinging one smart plug from another on the same guest band. If the ping succeeds, your isolation settings are broken.
  • Hardcoding credentials into companion apps
    • People reuse their email password for three different smart lighting apps. One data breach at a cheap vendor hands attackers the keys to your primary accounts.
    • Generate a unique sixteen-character password for every single IoT service. Use a password manager to store them. Never type them manually.
    • Enable two-factor authentication on the vendor accounts themselves. The camera feed is useless if the attacker cannot bypass the login screen.
  • Ignoring DNS-level filtering
    • Your router probably points to your ISP’s default DNS servers, which do absolutely nothing to block malicious domains.
    • Switch your primary and secondary DNS to a filtering provider like NextDNS or Cloudflare for Families. These services maintain real-time blocklists of known command-and-control servers.
    • When a compromised thermostat tries to phone home, the DNS filter returns a dead address. The attack chain breaks before any data leaves your house.
  • Leaving UPnP enabled for convenience
    • Universal Plug and Play allows devices to automatically open ports on your router. It was designed for LAN parties in 2004, not for modern internet threats.
    • Disable UPnP in the router admin panel. Manually forward ports only when you absolutely must access a specific service from outside your house.
    • Accept the minor inconvenience of manual configuration. The tradeoff is a firewall that actually behaves like a firewall instead of a revolving door.

Your Next Move Before The Weekend Hits

Pull up your router admin page right now. Write down every connected MAC address on a physical notepad. Anything you do not recognize gets blocked immediately. Move the remaining gadgets into their assigned lanes, flip on WPA3, and set those firmware updates to automatic. You will waste roughly ninety minutes on a Saturday configuring this, but you will save yourself from a $2,000 ransomware payout down the line. Stop treating your network like a public park. Lock the gates.