Picture an agent built on Cloudflare’s new wallet infrastructure. It has a spending allowance, a list of approved merchants and a maximum transaction size, all set by the business that deployed it. It authenticates correctly, stays inside every limit, and renews a data subscription the business had already cancelled, because the merchant’s cancellation hadn’t yet propagated to the record the agent was reading from. The agent did exactly what it was authorised to do, and the result is still a purchase nobody wanted.
That scenario is hypothetical, but every part of the mechanism is real, and it recurs across every agentic-payment infrastructure launched in the past sixteen months.
Cloudflare Wallets, launched on 4 August 2026, lets an autonomous agent hold a stablecoin balance and pay merchants directly, with a “Virtual Wallet” for the agent capped at whatever allowance the account owner sets and a human review prompt that fires only “when something anomalous happens, such as unexpectedly fast spending.” The launch post has no section on disputes, refunds or liability for a transaction that clears every check and is still the wrong one.
Cloudflare isn’t the exception. Visa and Mastercard set the same pattern months earlier. All three have built the infrastructure to let a machine spend money, and built it fast. None has built the AI agent liability framework that decides who owns a bad decision inside that spending.
Agentic commerce is live, not experimental
Sixteen months separate the first agentic-payment launch from Cloudflare’s wallet, and the pace hasn’t slowed. The table below lines up the public record.
| Date | Launch | What it added |
| 29 April 2025 | Mastercard Agent Pay | Agentic Tokens built on Mastercard’s existing tokenisation; agents registered and verified through One Credential and on-device biometrics before they can act |
| 30 April 2025 | Visa Intelligent Commerce | Tokenised credentials letting agents browse, select and buy on a consumer’s behalf, inside limits the consumer sets |
| 14 October 2025 | Visa Trusted Agent Protocol, built with Cloudflare | Cryptographic signatures letting a merchant confirm which agent it is dealing with, and block impersonators |
| 18 December 2025 | Visa network milestone | Hundreds of agent-initiated transactions completed across Visa’s partner ecosystem |
| 10 June 2026 | Visa-OpenAI integration | Tokenised Visa credentials inside ChatGPT, with “real-time authorization and fraud monitoring” |
| 4 August 2026 | Cloudflare Wallets | Stablecoin-funded wallets for agents built on Cloudflare’s x402 payment standard |
Visa’s Jack Forestell, chief product and strategy officer, framed the initial launch plainly: “Now, with Visa Intelligent Commerce, AI agents can find, shop and buy for consumers based on their pre-selected preferences.” By December, Visa’s Rubail Birwadker was already describing the shift as settled rather than emerging: “This holiday season marks the end of an era. In 2026, AI agents won’t just assist your shopping, they will complete your purchases.”
The scale forecasts back that up: Deloitte’s agentic commerce guide projects that 25% of global e-commerce sales will be enabled by AI agents by 2030. Three of the world’s largest payment networks are competing hard to own the identity and authentication layer that makes it possible, and none has published a liability framework for the transaction that clears every check and is still wrong.
The legal hinge: authority decides, not intent
That silence is inherited from payment law written for a different problem, and the gap comes into focus in the actual statutory language both card rails run on.
The debit and bank-transfer rail runs on Regulation E. 12 CFR 1005.2(m) defines an unauthorised electronic fund transfer as one “initiated by a person other than the consumer without actual authority to initiate the transfer”, but a transfer initiated by someone “furnished the access device to the consumer’s account by the consumer” isn’t unauthorised, unless the consumer told the bank that person’s transfers were no longer permitted.
An agent a business deployed and gave a wallet to was furnished the access device by construction, so 15 USC 1693g’s liability ladder, which only engages once a transfer is unauthorised, never activates for an authorised-but-mistaken purchase.
The credit-card rail works the same way with one extra door. 12 CFR 1026.12(b) defines unauthorised use as use by someone “who does not have actual, implied, or apparent authority for such use”, capping cardholder liability at $50 under 15 USC 1643.
The billing-error process under 12 CFR 1026.13(a) adds a second door: a consumer can dispute a charge for goods “not accepted… or not delivered… as agreed.” That door was built for a merchant that fails to deliver. It was never built for a case where the merchant delivered exactly what was ordered, and the mistake sits one level up, in the agent’s own judgement about what to buy.
Both frameworks pre-date agentic commerce by decades and police one binary: the accountholder did this, or someone else did it without permission. An agent operating exactly as authorised and still getting the outcome wrong is neither side of that binary, because the rules assume a delegated party only errs by acting outside its mandate, not by executing it badly.
Why chargebacks can’t close the gap either
Card-network dispute processes run on the same authority-first logic as the statutes underneath them, which is why agentic commerce chargebacks currently have nowhere clean to go. The table below maps Regulation Z’s billing-error categories against an agent that bought the wrong thing while acting entirely within its mandate.
| Billing-error category (12 CFR 1026.13(a)) | Covers | Fits an authorised agent’s bad purchase? |
| Unauthorised charge | Use by someone without actual, implied or apparent authority | No, the agent had authority |
| Unidentified charge | The cardholder can’t identify what the charge was for | No, the item is identified, just unwanted |
| Not accepted or not delivered as agreed | The merchant failed to deliver what was ordered | No, the merchant delivered exactly what the agent ordered |
| Payment posting error | The payment was applied to the wrong account or amount | No, the charge posted correctly |
| Computational or accounting error | Arithmetic mistakes on the statement | No, no arithmetic error occurred |
Every category resolves to a merchant failure or a genuine authority failure. Reshmi Suresh, head of agentic commerce at Worldpay, put it directly in a July 2026 piece: “Where it gets murkier is everything short of outright fraud”, since once an agent authenticates properly, fraud liability follows existing rules, but for an agent that simply misjudged an instruction, “no liability shift exists yet.”
Her diagnosis matches the statute: “Reg E currently assumes binary authorization, a transaction was either authorized or it wasn’t, with no framework for disputes where an agent misinterpreted a shopper’s instruction.”
An authorised-but-wrong transaction isn’t a chargeback category any network rulebook or federal regulation defines. The entire dispute architecture asks one question: was this person allowed to do this. An agent operating inside its mandate always answers yes, whatever it actually bought.
An old legal idea meeting a new kind of scale
None of this is a wholly novel legal problem. Cornell Law School’s Legal Information Institute describes actual authority as power “expressly or impliedly conferred” by a principal on an agent, and under that doctrine “an agreement made by an agent is binding on the principal so long as the agreement was within the authority actually granted.” That is precisely why a business whose employee books the wrong flight is still on the hook for it. The law has never required a delegate to be infallible before the principal is bound.
What changes with an AI agent isn’t the legal principle, but the scale and speed at which it operates. A human assistant who misreads an instruction makes one mistake, reviewable within hours. An agent misjudging the same instruction can repeat it across every account it manages before anyone reviews anything. Agency law assumed a human available to notice quickly when something had gone wrong; agentic commerce keeps the authority structure and removes that noticing.
Where the loss actually lands today
Put the statutory analysis and industry commentary together and they point the same direction. Howard Xiao and Laura Furlong of VGS, writing for the Merchant Advisory Group in October 2025, reached the same conclusion from the commercial side that Regulation E and Regulation Z reach from the statutory side: “liability likely remains with the consumer as the agent acts as their authorised proxy”, and in a dispute, “merchants typically prevail since consumers authorised the agent, mirroring today’s framework.”
That isn’t several parties sharing an undefined risk. It is one default outcome, reached from two directions, that puts the loss on whoever deployed the agent. The merchant wins by default, because it delivered what was ordered; the agent platform that actually made the wrong call carries no liability unless it accepts some voluntarily. Xiao and Furlong flag that as the one place the market is already moving: platforms could differentiate by “offering purchase liability coverage” as a feature. Nobody has shipped that as standard yet.
Regulators see the shape of the gap, not yet a fix
The gap hasn’t gone unnoticed by the people who write the rules. Nikhil Rathi, chief executive of the UK’s Financial Conduct Authority, told a techUK audience on 24 June 2026 that agentic systems are moving from supporting financial decisions to systems that “coordinate and transact” on their own.
“Accountability for regulated activities and outcomes must remain clear.” Nikhil Rathi, chief executive, Financial Conduct Authority, techUK, 24 June 2026
That is a statement of principle, not a rule. The FCA hasn’t issued guidance on how consumer protection applies once the party making a purchasing decision is software. In the US, neither the Federal Trade Commission’s recent enforcement actions nor its published guidance address agent-initiated purchases directly, based on the FTC’s most recent releases at the time of writing. Two major regulators have flagged the concern; neither has published a rule for who absorbs the loss.
The case for treating this as solvable, not just a risk
None of this makes the identity and authentication work pointless. Knowing exactly which agent acted, and capping what it can spend, genuinely reduces how large a single bad decision can get. That is real risk management, not evidence that agentic commerce is unready for real money.
Two routes close the remaining gap, and neither requires new legislation. The first is a genuinely new dispute category, distinct from “unauthorised” and from “not delivered as agreed”, that lets an accountholder contest a transaction their agent had every right to make but never should have made. Card networks have created reason codes before, for subscription disputes that didn’t fit the older taxonomy, and Visa’s Trusted Agent Protocol already proposes passing “agent intent” data alongside payment information, so the evidence exists before the rulebook that would use it.
The second, available immediately with no rule change, is exactly what Xiao and Furlong point to: a contractual liability shift, the agent platform or issuer agreeing upfront to absorb losses from the agent’s own bad judgement, sold as a feature rather than mandated by a regulator. A platform that can say “if our agent gets it wrong, we cover it” removes the entire dispute question for its own customers, competitively, before any network or regulator forces the issue.
The risk of leaving it unresolved
The commercial cost of doing nothing isn’t small at the scale Deloitte and Visa are projecting. The party with the least visibility into how the agent reasoned, the consumer or business that deployed it, is also the party holding the loss, and that asymmetry grows as agents handle a larger share of everyday purchasing.
The reputational exposure sits with the platforms too. The first widely reported case of an agent making an expensive, defensible-looking mistake, with the accountholder discovering there is no dispute route because the transaction was, technically, authorised, will land just as trust in agentic commerce is supposed to be scaling. That failure would cost more than the bad purchase; it would cost the adoption curve every one of these companies is racing to build.
The verdict
Three major payments infrastructure launches in sixteen months have solved identity and authentication for AI purchasing agents to a high standard. None has solved, or even addressed, what happens when a properly authorised agent still buys the wrong thing. Existing US and UK payment law wasn’t built for this, and read literally it resolves the loss onto whoever deployed the agent by default, not because any regulator decided that was fair, but because no other category applies.
Where the edge actually is. The gap is a commercial opportunity for whichever party closes it first, not just a compliance risk. An issuer or platform that publishes a clear delegated-agent dispute policy, or simply offers purchase-liability coverage as standard, gains a real trust advantage over competitors still relying on “authorised means authorised” as their entire answer. The first mover isn’t waiting for a regulator; the tools to build the contract already exist.
Questions worth asking, grouped by who is asking them.
Deploying a purchasing agent: Does the platform say what happens if the agent buys the wrong thing inside its own spending limit, and is there a purchase-liability guarantee in writing, or only fraud protection?
Accepting agent-initiated payments: What evidence does the network capture about the agent’s actual instructions, and what does the current reason-code set let you contest or concede?
Building agentic-payment infrastructure: Has a liability position been published, or does silence on disputes function as a default nobody chose deliberately?
Until a new dispute category or a contractual liability shift exists, “authorised” and “right” will keep meaning different things inside the same transaction, and the person who turned the agent on will keep being the one left holding whichever purchase the rulebook can’t see.