In February 2025 a Washington Post columnist asked OpenAI's Operator to find cheap eggs. It bought a dozen through Instacart for $31.43 and did not check back first.
Nobody has published what became of that charge. The card rules describe what such a charge normally sets off, and the sequence is worth following all the way down, because the money moves before anyone has decided anything: the cardholder disputes a purchase they say they did not intend, the issuing bank raises a chargeback, the amount comes back off the merchant within days, and only then does the merchant get to answer, with evidence it had to collect before it knew it would be needed, against a claim about intent that no field in the transaction records.
Who pays first
No card network has published a dispute reason for a purchase made by an agent. Visa's rulebook of 18 April 2026 runs its codes from 10.1 to 13.9 without one. It does define an Agentic Transaction, and it decides whose purchase that is:
A Cardholder is responsible for any actions taken by an Agentic Payment Provider as part of an Agentic Transaction as if the Cardholder initiated the Transaction.
A purchase inside the cardholder's instructions is the cardholder's own, then. Outside them it is different. The wrong item lands in the consumer-dispute codes 13.x, and there the merchant rebuts.
Mastercard's Chargeback Guide of 19 May 2026 contains none of the words. Not agentic, not Agent Pay, not Know Your Agent. Fraud claims run under 4837 and consumer disputes under 4853, and the developer guide says Mastercard and Visa have both confirmed that the existing frameworks apply.
American Express files an online fraud claim under F29, Card Not Present, and its merchant regulations of April 2026 carry no rule on agents at all.
Every dispute costs money before the merits are reached. Stripe charges €20 per dispute received. Braintree charges $15.
3-D Secure is no help. Its liability shift moves fraud losses to the issuer and stops there, and Amex says so for its own scheme: the shift does not reach disputes whose reason is something other than fraud, goods and services among them.
The three tests
Visa's Compelling Evidence 3.0 wants two earlier purchases on the same card, more than 120 days back and never reported as fraud, plus a matching device ID, fingerprint or IP address, plus one further matching element. From 24 October 2026 one line of that list mentions agents. It covers the login, and nothing else.
Mastercard's answer to a 4837 wants proof of cardholder authentication together with either other undisputed purchases or a registered device and IP address, which means a merchant facing a first-time guest checkout (no history on the card, no registered device, no earlier order to point at) has nothing on the list it can produce, and Amex sets the same kind of bar by asking for an undisputed purchase on the same card inside twelve months plus two of device ID, IP address and email address. A guest checkout fails both.
All three tests were built to show one thing: that the cardholder made the purchase. An agent purchase raises a second question. So far one document asks it, in guidance that carries no rule status:
you must prove not just that the transaction was authorized, but that the agent acted within the consumer's delegated authority.
The following page says what to keep for it, and the answer is the signed intent, held as non-repudiable evidence.
The standards
Google's AP2 says the most about disputes. Its mandates are signed records of what the user approved, and the specification says they can be brought together into a non-repudiable picture of the transaction. The next sentence puts retention and retrieval outside its scope.
The roles allowed to hold those records are the shopping agent, the merchant, the credential provider, the network and the payment processor. An independent archive is not among them.
Mastercard's Verifiable Intent chains three signatures, from the card issuer to the user to the agent, and describes the result as a self-contained evidence package that any dispute investigator can verify independently. The same document says the contribution is evidentiary only, and that it assigns no liability, specifies no chargeback codes and prescribes no arbitration.
Visa leaves the record with the agent provider, which has to keep an order confirmation available for at least 120 days. For the purposes of the rules that provider counts as the cardholder. So the record sits with the side the merchant is arguing against.
EMVCo proposed a shared layer in September 2026, Intent Services, through which payment participants would register, reference, retrieve and manage consumer-authorised intent before, during and after a transaction. The public text does not say who would run it, the framework itself is available only under EMVCo's terms of use, and the comment period closed on 30 September.
The Stripe and OpenAI protocol has no mandate at all. Disputes appear in it as a status the agent can read.
No ruling yet
I found no court decision, no regulator action and no ombudsman ruling on an agent purchase between a consumer and a merchant, platform or payment provider.
The one appellate opinion near the subject is Amazon v. Perplexity, and it is about computer access rather than payment. On 4 August 2026 the Ninth Circuit held that the agent is a tool and not a person for statutory purposes, and that the user is the one who accesses Amazon's computers.
Network figures for agent chargebacks are not published. Nobody outside could count them either, because no reason code marks them.
The European texts are quiet too. PSD2 and the final compromise text of the Payment Services Regulation contain no provision on AI agents. The European Banking Authority has scheduled a first targeted analysis of agentic AI in payments for its 2027 work programme.
So no judge has yet weighed a signed mandate against a cardholder who denies the purchase. The only allocation in force is Visa's clause, and that is a clause in a network rulebook.
The empty role
Each part of the process is written down somewhere. The networks list what a merchant must show, Mastercard names the signed intent as the thing to keep, AP2 and Verifiable Intent produce signed records for a dispute investigator, and Visa and EMVCo each describe a place where those records could live. None of these documents gives anyone outside the purchase the job of holding the mandate and producing it when the merchant answers a chargeback. AP2 puts retention and retrieval outside its scope, Verifiable Intent stops at evidence, Visa leaves the record with the agent provider, and EMVCo's registry has no named operator.
The merchant carries the first loss meanwhile. It pays €20 or $15 for every dispute it answers.
Two dates will move this. Visa's dispute rules change on 24 October 2026, which is when the agent login enters Compelling Evidence 3.0, and EMVCo's comment period on Intent Services closed on 30 September, so a framework text and a named operator could follow. I will read both against the four documents above and write down what changed.
Evidence
| Source | Date | What it carries |
|---|---|---|
| Washington Post | 2025-02-07 | Operator bought a dozen eggs through Instacart for $31.43 without checking back |
| Visa Core Rules §4.1.24.10, ID# 0031176 | 2026-04-18 | the cardholder is responsible for the agent provider's actions as if they had initiated the transaction |
| Visa Core Rules, dispute code list | 2026-04-18 | codes 10.1–10.5, 11.1–11.3, 12.2–12.7, 13.1–13.9, none for an agent purchase |
| Visa Core Rules §11.7.5.3, table 11-28 | effective 2026-10-24 | Compelling Evidence 3.0: two prior purchases over 120 days old, device ID, fingerprint or IP, one further element; one line covers an agent login |
| Visa Core Rules §4.1.24.8, ID# 0031174, and glossary ID# 0024372 | 2026-04-18 | agent provider keeps the order confirmation at least 120 days and counts as the cardholder |
| Mastercard Chargeback Guide, Merchant Edition | 2026-05-19 | 4837 fraud, 4853 consumer dispute; no occurrence of agentic, Agent Pay or Know Your Agent; evidence requirements p. 505 ff. |
| Mastercard Developer Guide, agentic commerce | 2026 | existing dispute frameworks apply; the merchant must prove the agent acted within delegated authority; keep the signed intent |
| Mastercard Verifiable Intent v0.1-draft, HEAD 356c29635f | 2026-02-18 | three chained signatures; evidentiary only, assigns no liability |
| American Express Merchant Regulations International | 2026-04 | F29 Card Not Present; no rule on agents; CE equivalent needs an undisputed purchase inside 12 months plus two of device ID, IP, email |
| American Express SafeKey Fraud Liability Shift | — | the shift does not reach non-fraud disputes |
| Stripe pricing, Braintree fee page | fetched 2026-10-05 | €20 and $15 per dispute received |
| Google AP2 v0.2, tag v0.2.0 | 2026-04-28 | mandates as signed records; retention and retrieval out of scope; five permitted holder roles, no independent archive |
| EMVCo press release, Intent Services | 2026-09-01 | register, reference, retrieve and manage consumer-authorised intent; no named operator; comment period closed 2026-09-30 |
| Stripe and OpenAI Agentic Commerce Protocol | 2025–2026 | no mandate; disputes appear as a status an agent can read |
| Amazon v. Perplexity, 9th Cir. No. 26-1444 | 2026-08-04 | the agent is a tool, not a person for statutory purposes; the user accesses the computers |
| PSD2, RTS SCA, Payment Services Regulation compromise text ST 8221/26 | full-text search 2026-10-05 | no provision on AI agents |
| EBA work programme EBA/REP/2026/18 | 2026-09 | first targeted analysis of agentic AI in payments scheduled for 2027 |
| chargeflow.io | 2026 | no published network figures for agent chargebacks |