Is Agentic Commerce Safe? Fraud and Consumer Protection in AI-Driven Payments
Learn how agentic commerce handles fraud, chargebacks, and consumer protection, and what merchants must fix before AI agents pay.
AI-referred traffic to U.S. retail sites grew 393% year over year in Q1 2026, according to Adobe Analytics, and the payment rails underneath that traffic were designed for a human clicking "buy."
B2Bcentr tracks the agentic commerce stack for operators who have to make real decisions about it, translating protocol releases, network rule changes, and fraud data into practical guidance.
Agentic commerce means AI systems that browse, compare, decide, and pay on a consumer's behalf, which breaks the assumption sitting at the center of nearly every fraud control and dispute rule in payments: that a person made a specific choice at a specific moment.
This article breaks down the actual fraud exposure, how chargebacks behave when an agent is the buyer, where liability currently sits, what consumer protection law says in 2026, and what merchants and consumers should do right now.
Key Takeaways
- Agent-initiated disputes run roughly 2.4x higher than comparable human card-not-present transactions.
- Consumer chargeback rights survive delegation to an AI agent under current U.S. rules.
- Prompt injection is the dominant agentic attack vector, mapped across most OWASP agentic risk categories.
- Merchants keep fraud liability under most agentic protocols, including OpenAI's delegated payment spec.
- Only a minority of merchants can technically distinguish a legitimate agent from a bot.

The Agentic Commerce Market Has Outrun Its Safety Rails
The commercial pull is not theoretical. The global agentic commerce market was valued at USD 5.7 billion in 2025 and is projected to grow from USD 7.7 billion in 2026 to USD 65.5 billion by 2033, a 35.7% CAGR.
On the narrower definition of retail ecommerce actually transacted on AI platforms in the United States, the figure in circulation is roughly $20.6 billion for 2026, about 1.5% of US ecommerce and close to four times the 2025 level.
B2B is where the volume concentrates. Gartner's top strategic prediction for 2026 held that by 2028, 90% of all B2B purchases will be intermediated by AI agents, routing more than $15 trillion through automated, machine-to-machine exchanges.
Directionally, that reframes agentic commerce from a consumer novelty into procurement infrastructure, which is why the same questions now surface in B2B marketplace design and agentic prospecting workflows.
Merchant intent is running ahead of merchant capability. The Merchant Risk Council's 2026 Global eCommerce Payments and Fraud Report found 63% of merchants are actively exploring or planning to implement agentic AI payments, while 3.2% of total annual eCommerce revenue is lost to payment fraud globally.
In the UK the gap is starker: only 15% of the top 100 retailers say their payment systems are prepared for agent transactions, even though 49% are investing in agentic AI, and a Payments Association survey found 58% of UK online merchants believe agents have already reached their platforms while only 3% of transactions involve one today.
Consumer Trust Is the Real Constraint
Adoption data and trust data point in opposite directions. IBM's Institute for Business Value found in January 2026 that 45% of consumers already use AI for some part of the buying journey, yet Sift reports 74% of consumers say AI shopping agents increase their account takeover concerns and only 14% would let an agent shop on their behalf.
That gap is the commercial risk. A consumer who does not trust the mechanism will dispute aggressively when anything goes wrong, and disputes are where trust failures become balance sheet items.
How an AI-Driven Payment Actually Works
Four frameworks shipped between April and October 2025, each at a different layer of the stack.
Mastercard Agent Pay, announced April 29, 2025, lets verified AI agents transact using Agentic Tokens, an extension of the Mastercard Digital Enablement Service.
Agentic Tokens bind a tokenized card credential to a specific agent, a specific merchant scope, and a specific consent policy, so a model can complete checkout without ever holding the raw card number.
Visa announced Intelligent Commerce in 2025, anchored by the Trusted Agent Protocol, which issues each agent a cryptographic identity that merchants verify through Visa's endpoints to confirm the agent's identity and the user's authorization scope.
Both Trusted Agent Protocol and Agent Pay use Web Bot Auth as the agent authentication layer, allowing infrastructure providers such as Cloudflare to verify traffic from AI shopping agents registered with a payment network.
Above the networks sits the mandate layer. The Agent Payments Protocol (AP2), originally proposed by Google and donated to the FIDO Alliance in 2026, defines a vendor-neutral mandate format, and as of April 2026 payment service providers can mint AP2 Mandates that Mastercard's network treats as valid Verifiable Intent.
For a full comparison of how these interoperate, see our breakdown of AP2, ACP, x402, and MPP, and our primer on the Model Context Protocol that underpins much agent tooling.
The critical distinction: recognition and authorization are separate problems. The Trusted Agent Protocol answers whether the agent in front of you is real.
Tokenized credential suites answer what that agent is allowed to spend. A merchant needs both, and neither one answers what happens when the purchase is disputed.

The New Fraud Surface: Attack Vectors Built for Agents
Agentic fraud is not simply bot fraud at higher volume. The defining difference is intent ambiguity, because a legitimate agent and a malicious one can look nearly identical at the network layer.
Indirect prompt injection. This is the primary vector. OWASP's 2026 State of Agentic AI Security maps prompt injection to six of the ten categories in its Top 10 for Agentic Applications, and where the 2025 edition cataloged plausible threats, the 2026 edition catalogs CVEs, vendor advisories, and breach reports.
Palo Alto Networks Unit 42 documented a concrete retail scenario: a fraudulent deals aggregator site embeds a hidden instruction in its HTML, a shopping agent crawling for discounts ingests it, and the instruction reprograms the agent's memory to append an unauthorized gift card to the final cart payload before checkout, sent to the attacker's address.
If the user's interface shows only a total price, the addition may not surface until the bank statement arrives.
- Agent impersonation. Merchants that extend preferential treatment or relaxed friction to recognized crawlers create a trust relationship, and fraudsters build agents that present themselves as those crawlers to exploit it.
- Counterfeit storefronts targeting agents. Visa's analysis of the agentic commerce threat landscape documents agent-targeted counterfeit storefronts already in the wild.
- Machine-speed credential testing. Bad actors can exploit AI agents to make rapid purchases, test stolen payment credentials, or manipulate pricing algorithms, and the speed and scale at which agents operate makes these risks harder to catch in real time.
- Supply chain compromise. A backdoored version of LiteLLM, the language-model gateway for CrewAI, DSPy, Microsoft GraphRAG and dozens of other agent frameworks, sat on PyPI for three hours in March 2026 and was downloaded nearly 47,000 times, shipping an autonomous attack bot alongside it.
Anyone building agentic payments should treat this as a dependency governance problem, which connects directly to how you structure a resilient cybersecurity stack.
The defensive posture is not keeping up. Darwinium's survey of 500 fraud, risk and security executives across the US and UK found 64% of organizations defend only a fraction of the customer journey.
Why Chargebacks Break When a Bot Buys
Disputes are where agentic risk becomes measurable. Early data shows disputes on agent-initiated transactions running at roughly 2.4x the rate of comparable human-initiated card-not-present transactions, with a different composition: fewer fraud disputes, more "did not authorise" and "not as described" claims.
The reason is evidentiary. When a human buys something and files a chargeback, the merchant can point to order confirmations, shipping records, and IP addresses.
When an AI agent makes the purchase, the evidence trail changes, and the consumer may argue they never intended that specific purchase even though they authorized the agent to shop on their behalf.
Issuers are finding that the absence of a clean human-decision moment makes traditional dispute adjudication harder, not impossible.
This produces a durable new dispute claim: "I didn't authorize that, my agent did."
The volume backdrop was already bad before agents arrived. By 2026, U.S. chargeback volume is estimated to reach 146 million at a value of $15.3 billion, and global card-not-present fraud losses are estimated to reach $28.1 billion, a 40% increase from 2023.
First-party fraud is now the leading fraud type globally at 36% of all reported fraud in 2024, up from 15% in 2023. Datos Insights projects a 24% rise in global chargeback volume between 2025 and 2028, reaching 324 million disputes annually, and agentic commerce will initially accelerate that trend before authentication standards mature enough to stabilize it.
Who Pays? The Liability Map in 2026
There is no consensus. Darwinium's survey found that when an AI agent-driven transaction goes wrong, 39% say the AI provider should bear liability, 20% say the customer, only 14% say the merchant or platform, and 11% say the bank or payment processor.
What the documents actually say is less ambiguous, and less favorable to sellers. The Agentic Commerce Protocol's Delegated Payment Spec states that OpenAI is not the merchant of record, and that settlement, refunds, chargebacks and compliance remain with the merchant and their PSP.
That is the clearest published answer anyone has, and it points at the seller. Agentic payments do not remove the merchant's responsibility to manage fraud, absorb chargebacks, and handle regulatory consequences, and they often increase it.
Card network programs shift some of that. Under Mastercard Agent Pay, liability follows standard tokenized transaction rules: the issuer carries fraud liability when the token is validly issued and the policy is honored at authorization, and chargeback rights for the consumer remain intact.
The rulebooks are diverging: as of April 2026 Visa's Core Rules contain express provisions for agentic transactions requiring identity verification in accordance with Visa Intelligent Commerce specifications and use of the provisioned token, while Mastercard's public Transaction Processing Rules remain silent on agentic terminology, with movement appearing in product programs instead.
The practical read: liability protection is conditional on using the network program correctly. Accept agent traffic outside those rails and you own the loss.

Consumer Protection: What the Law Actually Says
Consumers have more protection than the discourse suggests.
The CFPB's January 2026 advisory on autonomous-agent purchases framed agent-initiated card transactions as squarely within the existing dispute-and-chargeback regime under Regulation Z, with one important addition: the consumer's right of recourse is not extinguished by the existence of an agent mandate, only narrowed where that mandate is appropriately scoped.
Chargeback rights were not revoked when a consumer handed their card to an AI, and for the vast majority of early agentic deployments, the scoping documentation that would narrow those rights does not exist.
Regulation E is the unresolved piece. Agentic commerce creates a category Reg E did not contemplate: a standing authorization granted to an agent to initiate transactions on a consumer's behalf, without transaction-specific consent.
The CFPB's August 2025 advance notice of proposed rulemaking on personal financial data rights is reconsidering who can serve as a "representative" acting on a consumer's behalf, and analysts argue the Bureau should clarify that consumer-authorized agents do not waive all error resolution rights.
Legislation is early. On June 29, 2026, Senator Mark Warner released a discussion draft of the AI AGENT Act, a proposed federal framework requiring covered platforms to permit authorized third-party AI agents to access the platform functionally "on the same terms as a user" through interoperable, non-discriminatory interfaces. It is not yet introduced.
In Europe, the EU AI Act's high-risk rules were delayed to December 2027, which matters for anyone already mapping disclosure duties, as covered in our analysis of EU AI Act Article 50.
Industry's position is that the existing framework mostly holds. Electronic Transactions Association CEO Jodie Kelley told the House Financial Services Committee in January 2026 that many existing principles including authorization, consent, liability, and auditability apply in the agentic context.
The Underrated Cost: False Declines
The most immediate financial damage may not be fraud at all. Without agent-identification standards, existing fraud detection treats agent-initiated transactions as bot attacks by default, triggering mass false declines at machine scale.
Every blocked legitimate agent is lost revenue plus a customer who learns your store does not work with their assistant. In 2026, the merchants who win agentic commerce will be the ones whose fraud stack can distinguish a legitimate agent from a bot attack.
Is Agentic Commerce Safe? A Direct Answer
Agentic commerce is conditionally safe in 2026. For consumers using major card rails, it is reasonably safe, because dispute and chargeback rights survive delegation and network tokenization keeps raw credentials away from agents.
For merchants, it is not yet safe by default, because liability concentrates on the seller while the evidence infrastructure needed to defend disputes is still being built. Merchants operating under ACP own the liability without the evidence infrastructure needed to defend against disputes, and the chargeback system built for human-initiated transactions breaks across multiple links when an AI agent is the shopper.
The safety of any given agentic transaction depends almost entirely on whether it ran through a credentialed, mandate-bearing rail or through an unverified browser agent.

Merchant Readiness Checklist
- Identify your agent traffic. Know which platforms your agentic sales arrive through and what your position is on merchant of record and chargeback liability for each.
- Adopt agent authentication. Support Web Bot Auth, Trusted Agent Protocol credentials, or Agentic Tokens so legitimate agents are recognized rather than blocked.
- Capture mandate metadata at authorization. Merchants are responding to agentic disputes by demanding richer mandate metadata at authorisation: agent identity, mandate scope, and consent timestamp.
- Harden against injection. Treat any content an agent reads on your site, including reviews and seller-supplied HTML, as untrusted input.
- Move fraud controls from checkpoint to continuous. The highest-leverage investment is shifting from point-in-time controls to continuous, end-to-end visibility, because AI-powered attackers and legitimate AI agents both operate across the entire lifecycle.
- Structure your catalog. Accurate machine-readable product data reduces "not as described" disputes, a discipline familiar from ecommerce personalization work.
What Consumers Should Do, and What Changes Next
Consumers should set hard spending caps and per-merchant scopes on any agent mandate, use a card rather than a bank debit rail where possible for stronger dispute rights, review agent order confirmations line by line for added items, and keep records of the instruction given to the agent.
Emerging frameworks such as Know Your Agent for identity validation and agent reputation scores for behavior validation are steps toward building consumer trust, but neither is universally deployed.
Between now and 2028, expect three shifts: convergence of network programs on the AP2 mandate envelope, a CFPB resolution on representative status under Section 1033, and the first litigated precedents on what constitutes valid evidence of consumer intent.
Those precedents are being set now, at low volume, and they will govern disputes at scale. Teams building agent capability internally should factor this into how they design agent skills and workflows.

Conclusion
B2Bcentr covers agentic commerce as an operational problem rather than a trend, which means tracking the specific rules, protocols, and loss data that determine whether an AI-driven payment costs you money.
Agentic commerce is growing far faster than the safety infrastructure around it, disputes on agent-initiated transactions are running well above human baselines, prompt injection has moved from research to documented attacks on retail agents, and liability currently lands hardest on merchants under the most widely adopted protocol.
Consumer protection has held up better than expected, with dispute rights surviving delegation, but the regulatory questions that matter most for scale remain open.
The merchants who treat agent authentication, mandate capture, and continuous fraud visibility as prerequisites rather than upgrades will be the ones who can accept this traffic profitably.
Read Next
- How to Make Your Checkout AI-Agent-Ready: The Merchant's Guide to Agentic Commerce
- Agent Payment Protocols Compared: AP2, ACP, x402 and MPP in 2026
- Does the EU AI Act Apply to Your AI SDR? Article 50 Explained (2026)
FAQs
1. Is agentic commerce safe for consumers in 2026?
Agentic commerce is reasonably safe for consumers in 2026 because chargeback and dispute rights survive delegation to an AI agent. The CFPB's January 2026 advisory confirmed the consumer's right of recourse is not extinguished by an agent mandate, only narrowed where that mandate is appropriately scoped. Risk rises sharply when consumers use unverified browser agents outside credentialed card rails.
2. Who is liable for fraud in an AI agent transaction?
Liability for fraud in an AI agent transaction usually falls on the merchant. The Agentic Commerce Protocol's Delegated Payment Spec states that OpenAI is not the merchant of record and that settlement, refunds, chargebacks and compliance remain with the merchant and their PSP. Under Mastercard Agent Pay, the issuer carries fraud liability when the token is validly issued and the policy is honored at authorization.
3. How often are AI agent purchases disputed?
AI agent purchases are disputed roughly 2.4 times more often than comparable human transactions. Early data shows agent-initiated disputes running at about 2.4x the rate of comparable human-initiated card-not-present transactions, with fewer fraud claims and more "did not authorise" and "not as described" claims.
4. What is the biggest security risk in AI-driven payments?
The biggest security risk in AI-driven payments is indirect prompt injection. OWASP's 2026 State of Agentic AI Security maps prompt injection to six of the ten categories in its Top 10 for Agentic Applications, and Unit 42 research documents agents being subverted by malicious instructions encountered while performing a task.
5. How can merchants prevent agentic commerce chargebacks
Merchants can prevent agentic commerce chargebacks by capturing mandate evidence at authorization and authenticating agents before checkout. Merchants accepting agent-initiated transactions are demanding richer mandate metadata at authorisation, including agent identity, mandate scope, and consent timestamp, alongside continuous, end-to-end visibility rather than point-in-time controls.
Disclaimer:
This content is provided for informational purposes only and does not constitute legal, financial, or compliance advice. Protocol versions, governance arrangements, and partner counts cited here reflect publicly announced milestones as of August 2026 and are moving quickly. Adoption figures come from vendor and foundation announcements with differing methodologies and should be treated as directional signals rather than guaranteed outcomes.