When an AI Agent Makes an Incorrect Purchase, Who’s Responsible? Amex Offers a Partial Answer
By Coby Montoya, Director of Market Intelligence at Riskified
Simple Subscribe
Subscribe Now!
As AI agents begin transacting on behalf of consumers, issuers must prepare for new answers to the question, “Who authorized this transaction?”. Because card issuers see their card members complete spending behaviors and patterns, they have an opportunity to determine whether or not the transaction is within the customers’ typical buying behavior.
The theoretical future of agentic commerce became tangible in 2025. With Apple integrating agent-like intelligence into Siri for hundreds of millions of users and Google embedding AI-driven shopping experiences directly into search, AI systems are beginning to act on behalf of consumers in increasingly autonomous ways.
What this means: This shift enables a more seamless, intent-driven commerce experience, but it also introduces a new and rapidly evolving class of risk. Every major evolution in shopping behavior, from ecommerce to mobile wallets, has expanded the surface area for fraud and abuse. Agentic commerce is following the same pattern, but the velocity and scale of AI systems compress that risk into a much shorter operational window.
The key question for the payments ecosystem: When an AI agent makes an incorrect purchase due to an error who ultimately bears responsibility?
The Amex Precedent
American Express has taken an early step toward addressing this question.
In early 2026, the company introduced an agentic commerce developer kit alongside a commitment to cover erroneous purchases made by registered AI agents operating on its network. The model is built on a controlled environment where verified agents are issued payment credentials and cardholders are authenticated before those agents are allowed to transact.
The objective is to establish a higher baseline of trust in order to reduce disputes and chargebacks while enabling consumers to transact more freely through AI intermediaries.
This is a controlled approach designed to increase trust and drive volume.
The good news: This reflects liability becoming an explicit design variable in agentic commerce. Amex is not alone in this shift. Mastercard and Visa have already introduced early infrastructure to support agent-based transactions.
The bad news: What’s missing from Amex’s press release is the word “fraud”. Amex states they will only provide credentials to verified agents and authenticate card members before allowing them to use agents, but what happens when a bad actor defeats the authentication control?
We can use the launch of Apple Pay as a case study. In 2014 when Apple Pay was announced, Apple claimed the new payment method would reduce fraud by limiting the exposure of card credentials. Card issuers like American Express developed digital tokens with domain restrictions that made stealing the payment token practically useless. But what Apple and Amex did not account for was bad actors provisioning stolen identity data onto a device. This led to rampant fraud during launch. Amex and other card networks will face the same challenge with agentic commerce offerings.
New Buying Channels Means New Attack Vectors
While Amex says their approach in verifying agents and authenticating card members will give merchants a stronger baseline of legitimacy, merchants should expect bad actors to probe new technologies as they did when mobile wallets like Apple Pay were launched.
The reality is that verifying buying agents and authenticating card members comes with the territory of launching new payment capabilities with or without AI. Amex’s press release shows that they are taking the right steps to lay the foundation for safe Agentic Commerce experiences by reducing the likelihood of errors that come with AI hallucinations and bugs, but it’s important not to conflate this effort with protection against fraud.
From Transactions to Identities
Card issuer fraud controls rely heavily on payment authorization data that often lacks identity context. Payment authorization messages were designed to answer the question “is this payment event authorized?” but does not answer the question “is this payment being made by the real card member?”. The exception to this is 3D Secure authenticated transactions where additional data like email, device and ip are sent to the issuer in a pre-auth message.
The challenge: 3D Secure has very low adoption in North America. To date, there have not been any references to 3D Secure being part of payment network agentic toolkits.
Read more: Your Customers Will Blame You When Their Shopping Bots Go Rogue
Solving the Identity Resolution Gap
The underlying challenge is identity.
Current merchant fraud payment solutions are built around cardholder identity and device signals. Issuers that consume this data via the merchant experience much lower fraud and false decline rates. This approach is no longer realistic with agentic models. Issuers must now account for a third entity: the agent itself.
What this means:If an issuer cannot distinguish between a verified AI agent acting on behalf of a user and a malicious or compromised bot, then every transaction carries elevated uncertainty. In that environment, liability coverage becomes a structural requirement rather than a strategic choice.
Closing this gap requires moving identity resolution into the transaction protocol itself. This includes establishing persistent agent identities, enabling cryptographic or token-based validation of agent authorization, linking user consent directly to agent actions, and maintaining real-time visibility into agent behavior.
Early approaches, such as controlled agent registries, point toward this direction. However, scaling these models across open ecosystems introduces significant complexity across issuers, networks, and platforms.
What Issuers Need to Do Now
The critical window for action is before agentic transaction volume reaches scale. The priority is upgrading the authorization stack.
1. Upgrade authorization logic
Issuer decisioning systems must evolve beyond user-centric signals. Agent identity, provenance, and behavioral context need to be incorporated into real-time authorization decisions.
2. Implement identity-centric infrastructure
Systems must verify both users and agents, and define the relationship between them. Without this, distinguishing legitimate automation from fraud will remain unreliable.
3. Redesign dispute frameworks
Agent-driven disputes do not fit existing categories. Issuers need workflows that reflect shared responsibility between users, agents, and merchants.
4. Align internal teams on agentic use cases
Fraud, product, and customer experience teams must operate under a shared framework for agentic commerce. Siloed ownership slows response and increases risk exposure.
5. Engage in emerging standards development
As networks define early frameworks for agentic commerce, issuers should participate in shaping standards around identity, authorization, and liability allocation.
Welcome to the New Agentic Era
Agentic commerce is driving a structural shift in how liability is assigned across the payments ecosystem. Fraud and dispute resolution, historically treated as downstream processes, are moving upstream into the design of authorization itself.
As AI agents initiate purchases at scale, the key question becomes whether the system correctly identified the type of actor initiating the transaction and whether that actor’s autonomy was appropriately constrained. That distinction will define the next era of payments infrastructure.
Institutions that treat agentic activity as a variation of digital commerce will face increasing ambiguity: too much friction when intervention is unnecessary, and insufficient protection when it is required.
Others will take a different approach. They will treat identity as a continuous relationship between user, agent, and issuer that is evaluated at authorization, rather than reconstructed after disputes occur. In this model, fraud prevention and customer experience converge into a single standard: whether the system correctly interpreted intent before funds moved.
This is the inflection point highlighted by the American Express announcement. The question of who absorbs losses when agents fail is not new. The question of who defines what constitutes failure is.
Once that determination moves into the authorization layer, liability is no longer something issuers manage after the fact. It becomes something they shape in real time through the systems they design and the rules they enforce at the moment of transaction.
Read next: How Amex is Using GenAI to Augment Human Service for the Platinum Card Customers
