When an AI agent can legitimately use your payment method, the hard question is no longer only “Was this really you?” It becomes “Did you authorize this agent to buy this specific thing, from this merchant, for this amount, at this time?”
| Core thesis: Agentic commerce turns payment authorization into a two-step problem: authenticating the user and proving the scope of delegated authority. The next wave of disputes may therefore center on valid credentials used outside a valid mandate—not stolen credentials alone. |
The Fraud Question Is Changing
For decades, consumer-payment fraud has been organized around identity and possession. Was the card stolen? Was the account taken over? Did the cardholder approve the transaction? Fraud systems became increasingly good at answering those questions with device signals, network tokens, biometrics, passkeys and transaction scoring.
AI agents break that clean model. A shopping agent can be genuine. The user can be genuine. The payment credential can be genuine. The merchant can be genuine. And the purchase can still be wrong because the agent exceeded the permission it was given. A user may have said “book a refundable hotel under $250 a night near the conference,” while the agent buys a non-refundable $310 room because it interprets “near” as more important than the budget. Nothing was stolen. Yet the user did not authorize that exact transaction.
This article uses “permission fraud” as an editorial shorthand, not as a settled legal or card-network category. The more precise risk is authorization-scope failure: the gap between what a person delegated and what software ultimately executed. That gap can arise through malicious manipulation, compromised agents, expired mandates, weak controls, bugs, hallucinations, ambiguous instructions or merchants changing the final terms.
The issue is moving from theory into infrastructure. Visa, Mastercard, Google and Stripe are all building mechanisms that attach identity, user intent, spending constraints and audit evidence to agent-initiated payments. The common direction is revealing: the industry increasingly assumes that proving a payment credential is legitimate will not be enough. It will also need to prove that the transaction sat inside a specific mandate.
Figure 1. Agentic payments add delegation, scope and evidence layers on top of ordinary payment authentication.
Why This Risk Becomes Material as Agents Gain Autonomy
Consumers appear interested in AI assistance but much more cautious about fully autonomous spending. Mastercard’s 2026 Signals research says 85% of consumers are open to collaborating with an AI agent to find the best option and 74% are open to letting it complete specific commerce tasks at their request, but only about 10% are willing to let an agent complete a purchase autonomously. That gap is effectively a demand signal for permission controls.
The payments themselves are also starting to operate at machine scale. Visa and Artemis reported that the x402 machine-payment protocol had processed about 109.6 million adjusted transactions by April 21, 2026, while Stripe and Tempo’s newer Machine Payments Protocol had already processed roughly 115,000 transactions in its first weeks. Those are not directly comparable retail-card volumes, but they show why agent errors can behave differently from human errors: software can repeat the same mistake hundreds or thousands of times before anyone looks at a statement.
That creates a new operational asymmetry. A human might make one accidental purchase. An agent with standing authority can make the same policy mistake repeatedly, across merchants or subscriptions, at machine speed. Permission design therefore has to answer not only “what may the agent buy?” but also “how much can it lose before a circuit breaker stops it?”
Figure 2. Consumer interest falls sharply as AI moves from assistance to autonomous payment.
Five Ways a Legitimate Agent Can Create an Unauthorized Outcome
1. Scope creep: The user authorizes a narrow objective, but the agent optimizes for another variable and crosses a hard constraint. Example: “under $500” becomes $540 because the model treats a better flight time as worth the premium.
2. Expired authority: A mandate that was valid yesterday is reused after its time window expires, or a recurring task continues after the user has changed or revoked the instruction.
3. Merchant-side mutation: The user approves one cart, but price, shipping, quantity, subscription status or refundability changes before payment. Cryptographically binding the final checkout to the payment authorization is designed to stop this.
4. Agent compromise or prompt manipulation: The agent itself may be legitimate but is redirected by malicious content, an injected instruction, a compromised plug-in or another agent in the chain.
5. Ambiguous delegation: The user gives a broad instruction—“keep my groceries stocked” or “book the cheapest practical flight”—that requires judgment. The agent may technically comply while still producing a purchase the user reasonably says they never intended.
| The dangerous case is not always a fake agent. It is often a real agent with a real credential and an arguable—but contested—interpretation of the user’s authority. |
The Industry Is Building a “Mandate Layer” Above the Payment Rail
Google’s Agent Payments Protocol (AP2) makes mandates the core authorization object. An open mandate can let an agent act autonomously inside predefined constraints; a closed mandate binds authority to a particular checkout. The payment mandate is then tied cryptographically to the checkout, and signed receipts create an audit trail. AP2 explicitly describes those records as evidence that can be verified later in a dispute.
Visa Intelligent Commerce is pursuing a similar logic using agent-specific tokens, authenticated payment instructions and network-level controls. Visa says payment requests can be validated against the user’s original authenticated instruction and checked at authorization to confirm the intended merchant and correct amount. Commerce signals are then retained to help manage disputes.
Mastercard’s approach centers on Verifiable Intent and agentic tokens. Its 2026 trust framework describes permissions that can be restricted by agent, merchant, merchant category, amount, frequency, timeframe and use case, with a lifecycle that allows authority to be updated, withdrawn or expired.
Stripe’s Shared Payment Tokens likewise scope an agent’s payment credential to a specific seller, amount and time window. More revealingly, Stripe’s current agentic-commerce terms define the customer’s “Authority” to include spending limits, merchant restrictions and time-bound parameters—and assign responsibility to the agentic service provider in several cases where a transaction exceeds that authority or results from bugs, hallucinations or misinterpretation.
| Control | What it proves | Failure it is meant to stop |
| Agent identity | Which software agent is acting | Anonymous bot or impersonated agent |
| User authentication | The real user created/approved authority | Account takeover at delegation |
| Merchant/category limits | Where money may be spent | Agent buys from unapproved seller |
| Amount/frequency limits | How much and how often | Runaway spending or repeated micro-purchases |
| Expiry/revocation | Whether authority is still alive | Old mandate reused after user changes mind |
| Checkout binding | What exact goods/terms were approved | Price/cart changes after approval |
| Signed receipt/audit trail | What each party saw and executed | Evidence gap during chargeback |
Why Tiny Permission Failure Rates Can Become Expensive
Automation changes the cost curve. Suppose an agent ecosystem executes 100,000 payments a day. A 0.1% permission failure rate sounds excellent in a software dashboard, but it still creates 100 transactions a day that need refunding, investigating or defending. At 0.5%, that becomes 500. At 1%, 1,000.
This is an illustrative sensitivity analysis, not observed fraud data. Its purpose is to show why payment risk teams will care about extremely low error rates once agents operate continuously. A model that is “99.9% aligned” may still be unacceptable if each misalignment can move money.
Machine commerce can make the problem even more acute because individual transactions may be tiny but numerous. Visa’s research notes that many machine-native payments are fractions of a cent. Traditional chargeback infrastructure was designed around human-speed purchases, not a chain of thousands of automated economic actions that may need to be reconstructed after the fact.
Figure 3. Illustrative operational burden from small authorization-scope failure rates.
Chargebacks Get Harder When “Authorized” Has Two Meanings
A traditional card dispute often asks whether the cardholder authorized the use. Agentic commerce splits that question in two: Did the user authorize the agent? And did the agent authorize this specific transaction within the limits the user set? A transaction can pass the first test and fail the second.
That matters because existing consumer-law concepts were written around human delegates. Under U.S. Regulation Z commentary for credit cards, when a cardholder gives a card to another person and that person exceeds the authority granted, the use may still be treated as authorized until the card issuer has been told that the person is no longer authorized. Regulation E contains a similar concept for a person given an access device. Whether and how those doctrines map onto autonomous software agents, cryptographic mandates and platform terms is not fully settled. The legal definition of authority will therefore matter as much as the fraud model.
This is why the new agentic standards are obsessed with evidence. AP2’s dispute process verifies checkout mandates, payment mandates and receipts. Mastercard says Verifiable Intent records the cardholder’s authorization, specific instructions and the agent–merchant interaction. Visa’s commerce signals are intended to preserve the original instruction alongside the resulting purchase. Those records could become the agentic equivalent of a signed receipt plus 3-D Secure plus order history—except much more granular.
For merchants, that evidence may be especially important because “friendly fraud” is already costly before AI enters the picture. Visa cites a Merchant Risk Council survey in which 62% of merchants reported an increase in friendly fraud. Agentic commerce adds a new version: the customer may genuinely recognize the agent but dispute the agent’s interpretation of the task.
Who May Bear the Loss? A Practical Scenario Matrix
| Scenario | Likely dispute question | Evidence that matters most | Where risk may concentrate |
| Stolen card / stolen funding credential | Was there any valid authority at all? | Issuer authentication, token, device/fraud signals | Traditional fraud allocation; issuer/merchant/network rules |
| Agent exceeds explicit $ limit | Did execution breach a hard mandate? | Signed spend cap, payment request, timestamp, receipt | Agent platform/control layer if limit should have blocked |
| Permission expired before purchase | Was authority still valid at execution? | Mandate expiry, revocation log, token lifecycle | Credential/agent platform or processor depending on enforcement failure |
| Merchant changes cart after approval | Did merchant execute different terms? | Merchant-signed checkout hash, final cart, payment mandate | Merchant/acquirer side if evidence proves mutation |
| User gave broad instruction and dislikes result | Was this outside authority or merely bad judgment? | Natural-language instruction, policy constraints, conversation log | Hardest case; may resemble authorized/friendly dispute |
| Agent compromised by prompt injection | Was the agent still acting for the user? | Agent identity, tool chain logs, mandate constraints, security telemetry | Agent/platform liability may become central |
Expired Permissions and Recurring Purchases Are the Real Stress Test
One-off purchases are relatively easy: bind a mandate to a cart, amount, merchant and expiry. Ongoing tasks are harder. “Keep this subscription active unless the price rises more than 10%” requires persistent authority, state tracking and exception logic. “Reorder coffee when I have less than a week left” mixes inventory judgment with money movement. The agent’s permission needs a lifecycle rather than a one-time yes/no flag.
Mastercard’s 2026 framework explicitly contemplates permissions that can be updated, withdrawn or expired. Google AP2 distinguishes open mandates—useful for autonomous action—from closed mandates tied to a specific transaction. Visa says user instructions can be changed and authorization requests checked against the original instruction.
The consumer-law angle is important too. For preauthorized electronic fund transfers from a bank account, Regulation E generally requires authorization that is written or similarly authenticated, and the consumer must receive a copy. Agentic systems will need to fit their standing mandates into the legal requirements of the underlying rail rather than assume that a chat instruction overrides them.
What a Retail-Safe Permission Model Should Look Like
• Hard caps, not prompt-only caps: Spending and frequency limits should be enforced outside the language model in deterministic payment logic.
• Merchant and category boundaries: “Buy groceries” should not create a general-purpose credential usable at unrelated merchants.
• Short expiry for high-autonomy tasks: A permission to buy today should not quietly become permission to buy next month.
• Step-up approval for exceptions: Price increases, non-refundable terms, recurring billing, substitutions and new merchants should trigger human confirmation.
• One-click pause and revoke: Users need to stop an agent’s authority immediately without waiting for the agent to cooperate.
• Transaction preview and post-purchase receipt: The consumer should see both the instruction they gave and the final item/merchant/amount that resulted.
• Portable dispute evidence: The signed mandate, checkout and receipt should be retrievable even if the agent platform later fails or the user changes providers.
• Separate fraud and quality disputes: A valid mandate does not prove the product was delivered, authentic, refundable or fit for purpose.
Who Has the Strongest Incentive to Solve Permission Fraud?
Payment networks want agentic transactions to inherit the trust of cards rather than create a parallel fraud problem. That explains why Visa and Mastercard are pushing agent identity, intent and network-level controls. Merchants want proof that a disputed transaction matched the user’s instruction. Issuers want better signals before approving the payment. Agent platforms want enough delegated freedom to make the experience useful without becoming the default loss bearer when the model makes a mistake.
Stripe’s contractual language shows how quickly those incentives can become financial. In its preview terms for agentic-commerce agent services, Stripe says the platform user is responsible, as between the parties, for certain unauthorized agentic transactions when the customer did not authorize the transaction, the transaction exceeded the user’s authority, or it was caused by bugs, hallucinations or misinterpretations. That is not a universal industry rule, but it is a concrete example of liability moving toward the layer that designed and operated the agent experience.
A new business category may therefore emerge around permission infrastructure itself: mandate wallets, policy engines, agent identity, transaction attestation, revocation services, dispute evidence and liability insurance. In human payments, identity verification and fraud scoring became major businesses. In agentic payments, proving delegated authority may become just as valuable.
The Real Shift: From “Who Paid?” to “What Was Permitted?”
AI does not eliminate traditional card fraud. Stolen credentials, account takeover, fake merchants and social engineering will remain. What changes is that a growing share of legitimate payment credentials may be controlled by software acting under delegated authority.
That creates a new failure mode in the middle ground between fraud and buyer’s remorse. The user really did authorize the agent, but not necessarily the final action. The agent really did have access to the payment method, but perhaps not for that merchant, amount, time or product. The merchant may have accepted a technically valid payment while still being unable to prove that the transaction matched the buyer’s mandate.
The payment systems that scale agentic commerce will therefore need something stronger than authentication. They need permission that is specific, bounded, revocable, machine-enforceable and provable after the fact. The winner may not be the network that lets an AI agent pay fastest. It may be the network that can answer, months later and under dispute, exactly what the human allowed the machine to do.
| Retail takeaway: before giving an AI agent spending authority, ask five questions—What can it buy? Where can it buy? How much can it spend? When does permission expire? And what evidence will exist if you later dispute the purchase? |
Methodology and Source Notes
This article distinguishes live products and legal rules from forward-looking product descriptions. Visa Intelligent Commerce and several agentic-payment services remain in deployment or preview in some markets. “Permission fraud” is used here as an analytical label for authorization-scope failures; it is not presented as an established statutory or card-network fraud category. The quantitative error-rate chart is an illustrative sensitivity analysis, not measured fraud incidence. U.S. consumer-law discussion is general research, not legal advice.
1. Mastercard Signals: Encoding Trust / agentic-commerce consumer research — https://www.mastercard.com/news/eemea/en/newsroom/press-releases/en/2026/august/building-trust-for-agentic-commerce-mastercard-signals-report-explores-the-path-forward/ (85% collaboration, 74% specific tasks, 10% full autonomy)
2. Mastercard: Verifiable Intent — https://www.mastercard.com/global/en/news-and-trends/stories/2026/verifiable-intent.html (intent, instructions and dispute audit trail)
3. Mastercard Agent Pay for Machines — https://www.mastercard.com/us/en/news-and-trends/press/2026/june/mastercard-launches-agent-pay-for-machines.html (permissioning, spending limits and machine payments)
4. Google AP2 specification — https://github.com/google-agentic-commerce/AP2/blob/main/docs/ap2/specification.md (checkout/payment mandates, receipts and dispute verification)
5. Google AP2 agent authorization model — https://github.com/google-agentic-commerce/AP2/blob/main/docs/ap2/agent_authorization.md (open/closed mandates and delegated authority)
6. Visa Intelligent Commerce developer overview — https://developer.visa.com/capabilities/visa-intelligent-commerce/overview (agent-specific tokens, payment instructions and dispute signals)
7. Visa Trusted Agent Protocol — https://developer.visa.com/use-cases/trusted-agent-protocol (agent identity and transaction-specific authorization)
8. Visa / Artemis: Agentic Payments from the Ground Up — https://www.visa.com/en-us/thought-leadership/innovation/agentic-payments-from-the-ground-up (x402 and MPP transaction data; dispute challenges)
9. Visa post-purchase / dispute solutions — https://www.visa.com/en-us/solutions/post-purchase-solutions/merchants (friendly-fraud context and dispute evidence)
10. Stripe Agentic Commerce Suite — https://stripe.com/blog/agentic-commerce-suite (Shared Payment Tokens and scoped credentials)
11. Stripe Services Agreement – Agentic Commerce Agent Terms — https://stripe.com/legal/ssa-services-terms (authority definition and liability for unauthorized agentic transactions)
12. CFPB Regulation E §1005.2 and commentary — https://www.consumerfinance.gov/rules-policy/regulations/1005/2020-07-21/2/ (definition of unauthorized EFT and delegated access)
13. CFPB Regulation E §1005.10 — https://www.consumerfinance.gov/rules-policy/regulations/1005/10/ (preauthorized EFT authorization)
14. CFPB Regulation Z commentary §1026.12 — https://www.consumerfinance.gov/rules-policy/regulations/1026/2024-01-01/interp-12/ (actual, implied and apparent authority for credit-card use)
15. CFPB: credit-card dispute process — https://www.consumerfinance.gov/ask-cfpb/how-do-i-dispute-a-charge-on-my-credit-card-bill-en-61/ (billing dispute timing and process)
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

