In agentic payments the retailer carries the risk that nobody has regulated
Card schemes, acquirers and AI providers have presented credentials, protocols and interfaces for shopping agents within two weeks. The question of who pays the chargeback when an agent buys the wrong thing is expressly on the open list in every announcement.
Over the past two weeks the payments industry has built almost everything for shopping by AI agents: a credential, three protocols, a merchant interface, an acquirer connection and the first real purchase with a real card. What it has not built is the answer to the only question that decides about money in retail: who pays when the agent buys the wrong thing? This gap is neither an oversight nor a matter of time, it is a default setting. Where a rulebook does not expressly shift liability, in the card world it stays where it always lies — with the retailer. That is why agentic commerce in the autumn of 2026 is not yet a new sales channel but a risk transfer with a product name.
The facts of two weeks
On 9 September 2026 Ant International, Mastercard and Visa announced that they would work together on an interoperable know-your-agent framework, coordinated through BuildFin.ai, the platform convened by the Monetary Authority of Singapore. Each brings its own protocol: Visa's Trusted Agent Protocol, Mastercard's Verifiable Intent, Ant's Agentic Mobile Protocol. According to the reporting on the announcement, four points expressly remain open: liability, revocation of an agent's authorisation, data sharing and the handling of disputes.
On the same day Mastercard presented Agent Connect, a shared connection through which retailers, agents, platforms and payment service providers are meant to link up with a single integration. On 14 September Worldline switched on a payment handler for Google's Universal Commerce Protocol on its cross-border platform Global Collect. On 7 September Revolut and Visa processed the first card payment triggered by an AI agent in France, with a real card at a real retailer, authenticated via a Visa Payment Passkey instead of a PIN. And on 16 September the law firm Annerton publicly recalled that what counts for the supervisor is not what a provider calls its product but what it actually does: anyone who accesses an account and initiates a transfer may be operating a payment initiation service requiring authorisation.
Five reports, five components, one pattern. Identity: settled. Connection: settled. Authentication: settled. Authorisation: at least raised. Liability: open.
The best counter-argument, and why it does not hold
The strongest objection to my thesis is: standards always emerge in this order. First the technology, then the rules. That is how it was with 3-D Secure, and with strong customer authentication too, and at the end stood a liability shift that took the burden off the retailer. Anyone warning now is just missing the start and will be left without a connection in two years. On top of that comes the revenue argument: according to the PYMNTS survey of 16 September, 52 per cent of the wallet users surveyed consider it likely that they will link their wallet to an AI agent within two years. The figure is American and cannot be transferred to Germany, but the direction is not a matter of opinion.
The argument is right in its observation and wrong in its conclusion. With 3-D Secure there was a customer who either authenticated or did not; the dispute was about the evidence. With an agent the subject of the dispute is a different one: the customer authenticated, the agent was credentialed, the transaction ran cleanly on the technical side, and yet the wrong thing is in the basket. A verified agent is not an authorised purchase. For this case no rulebook so far has a dispute reason of its own, and as long as there is none, the case will be processed under whatever lies closest: goods not as described, or order not authorised. In both categories the retailer carries the burden of proof.
The second error lies in the word “wait”. I am not advising any retailer to lock agentic traffic out. I am advising him to count it before he scales it.
What this means for retailers in practice
Distinguishing an agent order from a direct order is not an IT project, it is a data field. Anyone who does not have it today will not be able to show in two years whether a risen chargeback rate is an agent problem or a retailer problem. That distinction is the only solid basis for negotiating with acquirer and card scheme. Without it you are negotiating about a feeling.
Three questions therefore belong in every conversation about an agent pilot, answered in writing. First: are agentic orders passed through flagged? Second: which transaction type is transmitted, and which liability shift applies to it? Third: under which authorisation, or under which exemption for technical service providers, does the agent's provider operate? Anyone who dodges the third question has answered it.
For choosing the pilot product range the logic is the reverse of marketing: do not start where the margin is biggest, but where an individual case hurts least — small baskets, standard items, returns processes that are practised anyway. High-priced goods, configurable ones and tight return windows are the last stage, not the first.
What I am calling for
I sell payment technology myself and earn from retailers adopting new channels. Precisely for that reason: from Visa and Mastercard I expect the know-your-agent framework not to be published without a dispute reason of its own for agentic purchases. A credential without a liability rule is half a standard, and the expensive half is the one missing.
From acquirers and payment network operators (Netzbetreiber), my own trade, I expect the flagging of agentic transactions to become standard issue and not a premium feature. A retailer has to be able to see in his statement which revenue came from which channel. That is not innovation, that is bookkeeping.
From the retail associations I expect them to ask this question before the first tender demands an agent connection as a matter of course. And from the European legislator I expect no special regulation for AI at the checkout but a clarification: whoever initiates a payment is subject to the duties of payment initiation, regardless of whether the software is marketed as an agent, a platform or an assistant. The functional approach already exists in supervisory law; it merely has to be applied visibly before business models have grown on top of it.
Agentic commerce will come, and it will bring revenue. But a channel in which the identity of the buyer is settled and the responsibility for his mistake is not, is not a finished product. Until a rulebook says who carries the loss, the retailer carries it — and he should know that before he agrees, not at the first chargeback.
Sources
- Business Wire: Ant International, Mastercard and Visa Initiate Collaboration on Know-Your-Agent Interoperability (09.09.2026)
- PayTechLaw / Annerton: Agentic Payments — Wann braucht der KI-Anbieter eine Lizenz? (16.09.2026)
- Finextra: Worldline to accept agentic AI payments (14.09.2026)
- The Paypers: Revolut and Visa complete France first agentic card payment (08.09.2026)
- PYMNTS: 47% of Shoppers Who Abandoned Their Carts Wanted a Digital Wallet Option (16.09.2026)