Your merchants are preparing for buyers who never see the checkout page. An AI agent selects the product, submits the payment and completes the order while the cardholder is doing something else. The transaction settles normally. The problem surfaces weeks later, in a dispute.
The infrastructure for this is still being built and commercial models are still evolving. In March 2026, OpenAI shifted the emphasis of its shopping experience toward product discovery and merchant-owned checkout, saying the initial version of Instant Checkout did not offer the level of flexibility it aspires to provide. EMVCo published its draft agentic payments framework on September 1. The industry is defining these rails right now.
Notice what the rails define. Every major effort answers the same question: is this agent allowed to transact? None of them answers what happens when it transacts incorrectly.
The Authorization Layer Is Getting Solved
Three efforts in the past year have built out agent authorization, and they are converging quickly.
Visa published its Trusted Agent Protocol in October 2025 with Cloudflare and 12 launch partners. Agents present a cryptographically signed intent tied to the merchant domain and the operation being performed, with nonce and short-lived timestamps that stop a signature from being reused.
Mastercard announced Agentic Tokens in April 2025 as an extension of Mastercard Digital Enablement Service. The token binds a credential to a specific agent, a specific merchant scope and a specific consent policy, so an agent completes checkout without ever holding a card number.
EMVCo followed with a draft EMV Agentic Payments framework covering 3-D Secure, tokenization and secure remote commerce.
Read those together and the direction is clear. The networks are establishing agent identity, agent permission and agent scope before a transaction ever reaches your risk engine. Visa’s specification carries the consumer’s IP address and device data through with the agent transaction, which preserves signals your fraud tooling already depends on.
All of it settles whether an agent is permitted to buy. None of it settles what happens when the agent buys wrong.
The Dispute Nobody Has a Process For
Picture the dispute. An agent buys the wrong item, or the right item in the wrong size, or the right item from a merchant the cardholder never intended to use. The cardholder calls the issuer.
Now look at what your merchant has to work with. Chargeback defense rests on a record of human action: an IP address, a device fingerprint, a session log, accepted terms and a delivery confirmation. In an agent transaction, every one of those artifacts is still there. Not one of them addresses the claim.
Four statements are true at the same time:
- The agent clicked
- The agent accepted the terms
- The cardholder authorized the agent
- The cardholder did not authorize this purchase
Representment was built to prove the third statement. The dispute turns on the fourth.
Liability today sits with the merchant, and the documentation says so plainly. OpenAI’s production guidance states that the merchant selling the goods and taking payment is the merchant of record, that OpenAI and payment service providers are not, and that the platform handles refunds and chargebacks because it accepted the payment directly from the customer.
No jurisdiction has enacted rules assigning liability for autonomous agent purchases. Neither Visa nor Mastercard has published a dispute framework or a reason code that separates agent error from cardholder fraud. Until one exists, the loss lands on your merchants.
Why American Express Moved and the Others Have Not
One network has moved. On April 14, 2026, American Express launched its Agentic Commerce Experiences Developer Kit alongside Amex Agent Purchase Protection, a commitment to cover erroneous purchases made by AI agents. Wrong item, wrong size or color, wrong merchant.
Read the conditions closely. The agent must be registered with American Express, the authenticated purchase intent must reach American Express, and the cardholder must attempt a return with the merchant first where that is possible. The protection covers the cardholder. It does not transfer merchant liability, and it applies to a narrow slice of transactions.
The structural reason Amex got there first matters more than the product itself. American Express runs a closed loop, acting as issuer, network and acquirer in the same transaction, so absorbing agent error is an internal cost decision it makes on its own. Visa and Mastercard operate four-party models. The same guarantee requires thousands of issuers and acquirers to agree on who takes the loss, and that negotiation has not happened.
A single-network answer is not an industry answer. The gap will stay open across the overwhelming majority of your merchants’ volume while that negotiation runs.
What to Sort Out Now
Across the platforms we power, merchants asking about agent checkout are not yet asking about agent disputes. That ordering will reverse.
You do not need a finished agentic strategy this quarter. You do need answers to five questions:
- Whether agent-initiated transactions carry an identifying indicator through your gateway and processor, and whether that indicator reaches your reporting layer
- How your risk rules score a transaction carrying agent metadata your models have never seen, because an unfamiliar signal usually gets treated as a risky one
- Whether your merchants’ representment evidence holds up when the cardholder authorized an agent but not the purchase
- Whether your tokenization model supports credentials scoped to one agent and one merchant, rather than a stored card that works anywhere
- What refund guidance you give merchants, given that a fast refund usually costs less than defending a dispute you are unlikely to win
The fourth question deserves attention first. Scoped credentials are the difference between an agent that overspends on a single order and an agent holding standing access to a card on file.
The Controls Are Ones You Already Run
None of this argues for sitting out agentic commerce. Merchants will move toward platforms that support agent checkout, and the platforms that arrive first will take that business.
But “we support agent checkout” is a much smaller claim than “we know who is liable when an agent gets it wrong,” and your merchants will ask you the second question eventually.
Network tokenization narrows what a compromised credential is worth. Scoped tokens limit what a single agent is authorized to do. Event-driven transaction monitoring produces the audit trail a dispute needs. These are the same protections that made card-on-file recurring billing safe, pointed now at a buyer who is not a person.
Start with the question your risk team has not been asked yet. When the buyer is not human, what does your evidence actually prove?
None of these controls are theoretical. Network tokenization through the Customer Vault keeps a stored credential from being worth much on its own. Webhook-driven transaction events give you the audit trail a dispute needs. Our Fraud Defense Suite is built for the card-not-present risk that agent transactions intensify.
To find out more about how NMI helps you protect your merchants as agentic commerce takes shape, reach out to a member of our team today.

