# What happens when your AI agent buys the wrong thing: a merchant’s guide to agentic-commerce liability | RankShield

> When an agent misreads intent and orders wrong, the merchant usually eats the chargeback. A plain-English guide to authorization, identity, and provable approval in agent-driven checkout, with a readiness check.
>
> Source: https://rankshield.co/resources/agentic-commerce-merchant-liability-chargebacks/ · RankShield (the verifiable, quantum-safe AI security platform)

Resources   /   Small Business
# What happens when your AI agent buys the wrong thing: a merchant’s guide to agentic-commerce liability

When an agent misreads intent and orders wrong, the merchant usually eats the chargeback. A plain-English guide to authorization, identity, and provable approval in agent-driven checkout, with a readiness check.
    June 26, 2026   · 10 min read   · agentic commerce chargebacks            Jamie Kloncz  Founder & CEO, RankShield        Share
A shopper tells their AI assistant to “reorder the coffee,” and it buys the wrong roast, the wrong size, or three of them. The shopper disputes the charge. Guess who usually pays? In agentic commerce, where software agents place orders on a person’s behalf, the merchant is often left holding the chargeback when the agent gets it wrong ([Finextra](https://www.finextra.com/blogposting/31251/deep-dive-the-hidden-liability-of-agentic-commerce) 3 ). That is a real shift, because the buyer on the other end of your checkout is no longer always a human clicking a button. This guide is written for small-business owners who are starting to see agent traffic and want to understand the liability before it becomes a monthly line item. We will walk through the four risk buckets analysts use to frame agentic commerce, explain who typically owns the chargeback, look at an emerging bot-farm refund-abuse threat, compare human and agent checkout side by side, and lay out what you should require before you accept agent orders. This is general information, not legal or payments advice.
       Key takeaways
- In agent-driven checkout, the merchant often eats the chargeback when the agent buys the wrong thing; plan for it before it becomes a monthly cost.
- Sort every agent incident into authorization, identity, fraud, or discovery; the bucket tells you which control and which record would have prevented it.
- Dispute case volume is forecast to rise about 24% from 2025 to 2028, most of it card-not-present, exactly where agents operate (Checkout.com).
- Agents also raise the ceiling on abuse: friendly-fraud and bot-farm refund abuse can arrive at machine speed and scale, not human pace.
- Keep a verifiable, non-repudiable record of who approved what so you can prove an agent purchase was authorized rather than guess.

## What are the four risk buckets of agentic commerce?

When an agent shops for a person, the familiar assumptions behind checkout start to break. You are no longer verifying that a human saw the price, chose the item, and clicked buy. Instead, a piece of software interpreted an instruction and acted. Analysts who study this shift describe the risk in four buckets, and it helps to name them plainly before you decide how to handle agent traffic. Each bucket maps to a question you already care about as a merchant: did the buyer mean to buy this, is the buyer who they claim to be, is this a scam, and where did the agent even find you.

Thinking in buckets keeps the problem from feeling abstract. Most disputes you will see trace back to one of them: the agent misread intent (authorization), the agent could not prove whose behalf it acted on (identity), someone weaponized the agent (fraud), or the agent surfaced and transacted through a channel you never vetted (discovery). Sorting an incident into a bucket tells you which control would have prevented it, and which record you wish you had kept.

- Authorization: did the shopper actually approve this specific purchase, or did the agent guess at intent?
- Identity: can the agent prove whose behalf it is acting on, and that the person is real?
- Fraud: is the agent being used to run friendly fraud, refund abuse, or automated scams?
- Discovery: through what channel did the agent find your product, and can you trust it?

## Who is liable for the chargeback when an AI agent buys the wrong thing?

Here is the uncomfortable part. When an AI agent misinterprets a shopper’s intent and buys the wrong thing, the merchant is often left liable for the resulting chargeback. The shopper did not choose that item on your product page, the agent did, but the dispute still lands on your account, with your fees and your win-rate at stake. Card rules were written for a world where a human sat at checkout, so the default liability today frequently tilts toward the seller when an agent is in the loop and nobody can show that the person approved the order.

The volume trend makes this worth planning for now rather than later. Global dispute case volume is forecast to rise about 24% from 2025 to 2028, and most of that growth is card-not-present, exactly the environment agents operate in, per [Checkout.com](https://www.checkout.com/blog/chargebacks-in-agentic-commerce-how-merchants-can-stay-ahead) 2 . More agent traffic plus more disputes plus a liability default that leans toward you is a combination worth getting ahead of. The practical defense is evidence: a record of who approved what, tied to the order, that you can produce when a dispute arrives. That is where proving authorization stops being abstract and starts protecting your margin.
         DOWNLOADABLE INFOGRAPHIC
### The agentic-commerce accountability gap
      Sources: Checkout.com, Chargeback Gurus, Finextra. General information, not legal or payments advice. Free to share with attribution.
## Why are bot-farm refund-abuse attacks a threat merchants aren’t ready for?

Agentic commerce does not just raise honest mistakes, it raises the ceiling on abuse. Alongside the wrong-item chargebacks, agents introduce friendly-fraud and automated bot-farm refund-abuse risk, per [Chargeback Gurus](https://www.chargebackgurus.com/blog/agentic-commerce-chargebacks) 1 . The problem is scale. A human running a refund scam is limited by how fast they can type and how many accounts they can juggle. An agent, or a farm of them, can request refunds, dispute charges, and cycle through orders at machine speed, around the clock, in patterns designed to look like ordinary buyers.

For a small merchant, that changes the math on refund policy and monitoring. A refund rate that looked like noise at human pace can become a real leak at automated scale, and it can arrive suddenly rather than creeping up. You do not need to treat every agent as hostile, because most will be legitimate assistants running errands. But you do need a way to tell an authorized agent order apart from an automated abuse run, and a way to show, after the fact, which orders carried a genuine approval. Without that record, every disputed agent order looks the same, and the abusive ones hide in the crowd.

The defensive posture that works here is the same one that protects you on honest mistakes, which is why it is worth building once rather than twice. If every agent order carries a verifiable approval record, the authorized orders can prove themselves and the abusive ones stand out precisely because they cannot, so the crowd the bad orders were hiding in thins out on its own. Monitoring tuned for machine-speed patterns, sudden velocity, repeated refund requests, order-cycling, then does the rest, catching the automated runs by their behavior rather than by manual review that no small team can sustain at agent pace.

## How does agent checkout differ from human checkout?

The gap is easiest to see when you put the two flows next to each other. In a human checkout you inherit decades of card rules, a session and device trail, and a cardholder who approved the purchase directly. In an agent checkout, an intermediary approved on the shopper’s behalf, the proof of that approval is often missing entirely, and the liability default frequently swings to you. Read the accountability gap below: the middle column is what you are used to, and the right column is what you actually get when an agent checks out today.
      THE ACCOUNTABILITY GAP
### Human checkout vs. agent checkout

|  | Human checkout | Agent checkout |
| --- | --- | --- |
| Who approved the purchase | The cardholder, directly | An agent acting for them |
| Proof of approval you can show | Session, device, consent trail | Often none today |
| Chargeback liability default | Established card rules | Frequently the merchant |
| Refund / bot-farm abuse exposure | Human-paced | Automated, at scale |

## Is your store ready for agent-driven checkout?

Run the quick check below. It scores whether you could actually defend an agent order, by asking whether you can prove approval, verify the agent, spot machine-speed abuse, and support the emerging approval standards. The gaps it surfaces are the ones that turn into chargebacks and refund leaks.
         READINESS CHECK
### Can you defend an agent order?

- For an agent order, can you show the shopper approved that specific purchase?
- Can you confirm whose behalf an agent is acting on before you fulfill?
- Is your refund and dispute monitoring tuned for machine-speed abuse?
- Are you set up to support emerging approval standards (AP2, TAP, agent tokens)?
- Could you produce a non-repudiable approval record when a dispute arrives?

## What should a merchant require before accepting AI agent orders?

You do not have to solve agentic commerce single-handedly, and you should not wait for the whole industry to standardize before you protect yourself. Emerging standards are moving in your direction: Google’s Agent Payments Protocol (AP2), Visa’s Trusted Agent Protocol (TAP), and agent payment tokens are all being built to encode and prove a shopper’s approval, per [Checkout.com](https://www.checkout.com/blog/chargebacks-in-agentic-commerce-how-merchants-can-stay-ahead) 2 . Until those are universal, treat the checklist below as your minimum bar for accepting agent orders, because each item is really the same idea in different clothing, which is proof that the purchase was authorized.

The through-line is a verifiable record: an independently checkable trail of who approved what, tied to the order, that you can produce when a dispute or refund demand arrives. That is the honest value of a non-repudiable approval trail, not that it makes you win every dispute, but that it lets you prove an agent purchase was authorized instead of guessing. RankShield builds exactly that kind of verifiable record, so “the customer’s agent approved this” becomes something you can show rather than assert. See the payment-attestation angle on [agentic payment security](https://rankshield.co/agentic-payment-security/).

- A record of authorization: evidence the shopper approved this specific order, not just a standing relationship.
- Agent identity you can check: some way to confirm whose behalf the agent acted on before you fulfill.
- Support for emerging approval standards (AP2, TAP, agent payment tokens) as your platforms adopt them.
- Refund and dispute monitoring tuned for machine-speed, so an abuse run cannot hide inside normal traffic.

                FREQUENTLY ASKED
## Questions, answered.
            Jamie Kloncz  CEO, RankShield · online
If an AI agent orders the wrong item, who pays the chargeback?

Most often, the merchant. Card dispute rules were written for a human sitting at checkout, so when an agent interprets an instruction and orders wrong, the liability default frequently tilts toward the seller, especially when no one can show the shopper approved that specific purchase. The shopper chose to delegate, the agent chose the item, but the dispute lands on your account with your fees and win-rate at stake. The practical defense is a record of authorization tied to the order that you can produce when the dispute arrives. This is general information, not legal or payments advice.

What are the four risk buckets of agentic commerce?

Authorization (did the shopper actually approve this specific purchase, or did the agent guess at intent?), identity (can the agent prove whose behalf it acted on, and that the person is real?), fraud (is the agent being used for friendly fraud, refund abuse, or automated scams?), and discovery (through what channel did the agent find and transact with you, and can you trust it?). Sorting any agent incident into one of these buckets tells you which control would have prevented it and which record you wish you had kept.

Why are chargebacks expected to rise with agentic commerce?

Because agent traffic concentrates in exactly the environment where disputes already grow fastest. Global dispute case volume is forecast to rise about 24% from 2025 to 2028, most of it card-not-present, which is precisely how agents transact, per Checkout.com. Add a liability default that leans toward the merchant when an agent is in the loop, and rising agent volume compounds rising disputes. That is why building an approval-evidence habit now, before agent orders are a large share of your volume, is cheaper than reacting once they are.

What is bot-farm refund abuse, and why is it worse with agents?

It is refund and friendly-fraud abuse run by automated agents rather than individual people. A human scammer is limited by typing speed and how many accounts they can manage; a farm of agents can request refunds, dispute charges, and cycle through orders at machine speed, around the clock, in patterns designed to mimic ordinary buyers, per Chargeback Gurus. The danger is scale and suddenness: a refund rate that was noise at human pace can become a real leak overnight, and without a way to tell authorized agent orders from abuse runs, the bad ones hide in the crowd.

How do I prove an agent purchase was actually authorized?

Keep a verifiable, non-repudiable record of who approved what, tied to the specific order, that you can produce later and that a third party could check. That is stronger than a standing relationship or an internal note, because it evidences approval of this purchase rather than a general permission. Emerging standards, Google’s AP2, Visa’s TAP, and agent payment tokens, are being built to encode and prove exactly this, and until they are universal, a verifiable approval trail is the practical defense. It does not guarantee you win every dispute; it lets you prove authorization instead of guessing.

What should I require before accepting agent orders in my store?

At minimum: a record of authorization showing the shopper approved this specific order; a way to check the agent’s identity and whose behalf it acts on before you fulfill; readiness to support emerging approval standards (AP2, TAP, agent payment tokens) as your platforms adopt them; and refund and dispute monitoring tuned for machine-speed abuse so an automated run cannot hide in normal traffic. The unifying idea is an independently checkable proof of approval tied to the order, which is what turns “the customer’s agent approved this” from an assertion into evidence.

## References

- [Chargeback Gurus — Agentic commerce and chargebacks](https://www.chargebackgurus.com/blog/agentic-commerce-chargebacks)
- [Checkout.com — Chargebacks in agentic commerce](https://www.checkout.com/blog/chargebacks-in-agentic-commerce-how-merchants-can-stay-ahead)
- [Finextra — The hidden liability of agentic commerce](https://www.finextra.com/blogposting/31251/deep-dive-the-hidden-liability-of-agentic-commerce)

              WRITTEN BY
## [Jamie Kloncz](https://rankshield.co/author/jamie-kloncz/)

Founder & CEO, RankShield

Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.
    More from Jamie →
## Make every AI action provable.

RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.
   Explore the platform  →   Get started
## More from Resources
      Security   Cloudflare Blocks AI Crawlers by Default on September 15. What Site Owners Must Do   On September 15, 2026, Cloudflare changes how it treats AI crawlers for every site. Here is what could quietly cut your AI visibility, and the settings to check before then.      Quantum   AI Just Broke a Post-Quantum Algorithm. Here’s What It Actually Means   An AI model weakened a post-quantum algorithm in about 60 hours. Before you panic: it was not a standardized one, your encryption is not broken, and the real lesson is about speed.      Quantum   A Post-Quantum Migration Roadmap: Moving Your Business Off Vulnerable Crypto   NIST’s post-quantum standards are final and federal deadlines are set. Here is a staged roadmap to move your business off vulnerable cryptography in the right order.
