August 03, 2026

Your AI Shopping Agent Bought It Wrong: Who Pays Now

The agent bought the wrong size. Not the wrong item, not a scam, just a size 9 where you needed an 11, ordered at 2am while you slept, paid for with a token your card network minted specifically so software could spend without asking you first. You call the bank. The bank asks who authorised the transaction. And that is the moment you find out nobody has written the answer down.

Your AI Shopping Agent Bought It Wrong: Who Pays Now
TL;DR: Card networks shipped payment rails for AI shopping agents before anyone defined who eats the loss when an agent buys wrong. Amex covers registered-agent errors. Nobody else has promised anything. Check your card's agent policy before you delegate a purchase.

Why It Matters

For thirty years, consumer payment protection has rested on a single question with a clean answer: did you authorise this charge? Say no, and a whole machinery of chargebacks, provisional credits and liability shifts spins up on your behalf. That machinery assumes a human at a keyboard. It has no category for a purchase you approved in principle, months ago, in a settings pane, executed by software you have never met on terms you did not read.

And the money is not waiting. Visa published its Trusted Agent Protocol on 14 October 2025, a cryptographic scheme letting a merchant tell a legitimate shopping agent apart from a scraper. Mastercard's Agent Pay binds a tokenised card credential to one specific agent, one merchant scope, one consent policy. Amex went further and shipped a developer kit with an actual promise attached. The rails are built, tested and open. The consumer-protection layer is a blog post from a payments vendor and a lot of hopeful language about "emerging frameworks."

This is a familiar shape if you have been reading along. It is the same trick as the switch from flat AI subscriptions to metered billing, where the pricing model changed underneath people who were still budgeting on last year's assumptions. It is the same omission as Apple Creator Studio shipping without the storage its own workflow requires. The capability arrives first, fully funded and beautifully marketed. The thing that protects you arrives later, if the complaints get loud enough.

Here is the scale, because the numbers explain why nobody is slowing down to sort out the liability question first.

Rails Went Commercial

Q1 2026

card networks opened agent lanes

Projected Agent Spend

$15T

Gartner's 2028 B2B forecast

Networks With Agent Rails

3

Visa, Mastercard and Amex

Adults Who Trust Agents

24%

Forrester, routine purchases

That trust figure is the one worth sitting with. Forrester's survey found roughly a quarter of US online adults willing to let an agent buy on their behalf, which means the overwhelming majority looked at the pitch and declined. The rails were built anyway, because the forecast that actually moves boardrooms is the business one, and Gartner's projection of $15 trillion in agent-run B2B purchasing by 2028 does not care whether retail shoppers are comfortable yet. Consumer adoption is expected to follow the plumbing rather than lead it. That is a bet, not a finding, and it is being placed with your card as the chip. You already know how a cheap device with delegated credentials behaves once someone finds it: the credential is the whole attack surface, and now the credential can buy things.

"

Three out of four American adults told Forrester they would not trust an agent with a routine purchase. The card networks built the lane and opened it anyway.

What Actually Exists Right Now

Strip out the press releases and the picture is narrow but readable. There is one real, written promise on the consumer side, a set of identity plumbing that helps merchants more than it helps you, and a legal vacuum where the rest should be.

Category Detail Insight
Amex Cover Commits to cover erroneous purchases by registered agents The only written consumer promise
Fraud Gap That pledge covers agent error, not defeated authentication Stolen credentials stay your problem
Legal Status No statute defines an agent slip as unauthorised Your recourse runs on goodwill
Evidence Device fingerprint and IP now belong to the agent Dispute proof no longer identifies you
Identity Layer Agent tokens bind one agent to one merchant scope Built for merchants, not for shoppers
3D Secure Low North American adoption, absent from agent toolkits The obvious check is missing
Blame Split No consensus on whether provider, merchant or buyer pays Everyone points somewhere else

Read the Amex row against the Fraud Gap row and the shape of the promise gets clear. Covering agent error is a quality guarantee on their own software. It is not a fraud guarantee, and payments people have been saying so since the announcement, drawing the parallel to Apple Pay's 2014 launch, where tokenisation worked exactly as designed and criminals simply loaded stolen identities onto devices instead. The rails did their job. The gap moved upstream.

Apr 2025 · Sep 2025 · Early 2026 · Jun 2026 Agent Pay announced · Networks join Google AP2 · Amex kit plus error cover · Agent Pay for Machines Fourteen months from announcement to always-on machine payments

Fourteen months separates Mastercard's first Agent Pay announcement from always-on machine payments going live, with the two card networks joining Google's AP2 protocol in between and Amex adding the first error guarantee. No consumer-protection statute landed anywhere in that window.

Friction Points

The genuinely unsettled question, and I do not think anyone has a defensible answer yet, is whether an agent's mistaken purchase is legally an unauthorised transaction at all. You authorised the agent. You did not authorise that purchase. Existing law was drafted for a world where those two things were the same event, and reading a decades-old consent regime onto delegated software is going to produce results that satisfy nobody. My own view is that "unauthorised" will end up defined narrowly, in the card networks' favour, unless a regulator forces the issue early. But that is a prediction, not a finding, and I would not build a spending plan on it.

Meanwhile the practical failure modes are already visible, and none of them require a criminal. An agent misreads a variant. A price changes between the plan and the checkout. A subscription renews inside a delegated scope you forgot you granted, the same way a shared family plan quietly extends permissions past the person who set it up. Watch for these:

  • Spending caps that apply per transaction rather than per month, so an agent can make forty compliant purchases and still empty the account.
  • Merchant scopes granted broadly at setup, because the narrow option made the agent useless in testing and nobody went back to tighten it.
  • Dispute windows counted from the transaction date, not from the day you noticed, which matters more when a machine is buying while you sleep.
  • Return policies written for human buyers, where "changed my mind" is refused and "the agent picked wrong" is not a category the support script recognises.

Key Takeaways

Amex is the only issuer with a written commitment on agent errors. Check whether your card has one before you delegate anything.

Error cover and fraud cover are different products. Read which one you were actually promised.

Set the merchant scope narrow at setup. Widening it later takes a minute; unwinding a purchase does not.

Use a secondary card or a virtual number for agent spending, so a bad week is contained rather than shared with your rent.

Open your card issuer's app this week and find out, in writing, what it says about purchases made by an AI agent. If the answer is nothing, that is your answer: the protection you are relying on does not exist yet, and the rails that let software spend your money are already live. Delegate small amounts to a card you can afford to have go wrong, and let somebody else be the test case.