Fraud, chargebacks and liability in agentic checkout for fashion
Card networks and payment providers have launched tokens and verification methods for AI agents, but who pays when an agent gets it wrong is still unsettled. Here is where fashion retailers stand.

KEY TAKEAWAYS Summary by the editors
- Worldpay reports that no liability shift exists for agentic transactions: properly authenticated, tokenised payments follow existing rules, but disputes short of fraud are still being allocated.
- Visa Intelligent Commerce (April 2025) and Mastercard Agent Pay (April 2025) use tokens scoped to an agent, with consumer-set spending limits.
- Under the published OpenAI delegated payment specification, settlement, refunds, chargebacks and compliance remain with the merchant and its payment provider.
- Verification of a genuine agent can use signed HTTP requests: Visa's Trusted Agent Protocol, announced October 2025 with Cloudflare, and Cloudflare's Web Bot Auth both rely on this approach.
- No agent-specific chargeback rate had been published in the sources reviewed, so fashion retailers should measure their own and keep early volumes limited.
Who is liable when an AI agent makes a payment?
There is no settled answer for every case. Worldpay reports that no liability shift exists for agentic transactions. Where an agent authenticates properly and a token is issued correctly, liability generally follows existing rules for authenticated tokenised transactions: the issuer carries fraud risk and the cardholder keeps chargeback rights. For disputes short of fraud, such as an agent buying the wrong item, allocation among merchant, issuer, acquirer and platform is still being negotiated.
For a fashion retailer the ordinary fraud question and the new dispute question are separate. Stolen credentials are covered by familiar rules. The wrong size, the misread instruction and the claim that an agent exceeded its authority are the uncertain cases, and fashion's high return rates make them more likely to arise.
The practical effect is that retailers cannot assume the network rules will protect them in unusual cases. Contracts with payment providers, the evidence held per order and the clarity of the shopper's confirmation step become the working defences. Each should be reviewed with the payments partner before agent volumes grow.
What have the card networks and processors introduced?
A summary by Digital Applied dates Visa Intelligent Commerce to 30 April 2025, describing tokenised credentials scoped to a specific agent with consumer-set spending limits. Mastercard Agent Pay with agentic tokens followed on 29 April 2025, extending tokenisation so a verified agent can transact, with consumer spend caps, merchant restrictions and real-time revocation. Stripe's Shared Payment Tokens are merchant-specific, amount-limited and time-limited, with limits enforced at the API level.
| Mechanism | Announced | What it addresses |
|---|---|---|
| Visa Intelligent Commerce | 30 April 2025 | Authorisation: tokenised credentials with spending limits |
| Mastercard Agent Pay | 29 April 2025 | Authorisation: agentic tokens, caps and revocation |
| Visa Trusted Agent Protocol | 14 October 2025 | Identity: merchants verify an agent via signed requests |
| Stripe Shared Payment Token | Date not stated in sources reviewed | Scoped, time-limited tokens for merchants |
| Cloudflare Web Bot Auth | Published documentation | Identity: cryptographically signed bot requests |

What do the published protocol rules say about chargebacks?
The OpenAI delegated payment specification, as quoted by Digital Applied, states that OpenAI is not the merchant of record and that settlement, refunds, chargebacks and compliance remain with the merchant and its payment service provider. Stripe's description of the Agentic Commerce Protocol similarly keeps the business as merchant of record, deciding whether to accept or decline each transaction using payment and fraud signals.
The same report says that, at the time of writing, neither Visa nor Mastercard had published a binding chargeback rule for agent-initiated disputes, and that no agent-specific chargeback rate had been published. A widely quoted figure of 324 million chargebacks refers to a forecast of total network chargebacks by 2028 and not to agent-attributed disputes, so it should not be used as evidence of agent fraud.
What new fraud and dispute patterns should retailers expect?
- Friendly fraud with a new excuse. Worldpay notes that a false claim that an agent went rogue can work as friendly fraud.
- Weak evidence of authorisation. Without a signed mandate showing what the shopper allowed, agent versus shopper disagreements are hard to win and issuers tend to side with the cardholder.
- Misidentified bots. Fraud tools that cannot tell a verified shopping agent from a malicious script either block legitimate sales or let bad actors through.
- Authentication friction in Europe. Strong customer authentication under PSD2 can prevent an agentic transaction from completing.
Worldpay adds that disputes of the kind where the shopper says the item was not what they wanted can often be won by merchants, but contesting each one is costly.
Fashion adds its own patterns. Resale of high-demand items, sizing-related returns and wardrobing already create friction in conventional checkout, and an agent channel could be used to scale them if controls are weak. Velocity limits, order value caps and account history checks remain relevant, and they are easier to apply when the agent is verified and each order carries a clear record of who authorised it and what limits applied.
How can a retailer verify that an agent is genuine?
Verification depends on the channel. Worldpay explains that API-based protocols reveal the calling platform, while agents browsing a website rely on tools such as Cloudflare's web bot authentication. Cloudflare documents a method in which a bot signs HTTP requests with a private key and publishes the public key in a directory on its own domain; the site checks the signature and Cloudflare recommends short expiry values to limit replay. Visa's Trusted Agent Protocol, built with Cloudflare on HTTP message signatures, aims at the same question of whether an agent is who it claims to be.

What should a fashion retailer do about liability now?
- Start with channels that use a published protocol and tokenised payments, and avoid unverified browsing agents at checkout.
- Cap order value and range for agent orders in the pilot period.
- Keep evidence for each order: the product data supplied, the variant chosen, the terms shown and the shopper's confirmation.
- Ask your payment provider in writing how it treats agent-initiated disputes and authentication.
- Report agent-channel chargeback and return rates separately from the website's.
- Revisit the position as card networks publish rules, and as regulators such as the UK's competition authority issue guidance.
Governance deserves a place on the finance agenda. The head of payments or risk should own the agent channel's dispute policy, and legal should confirm how consumer-protection rules apply in each selling country. Because the rules are still forming, build a review date into the pilot, for example every quarter, at which the team compares actual dispute and return data with its assumptions and decides whether to widen, hold or stop.
Frequently asked questions
Who is liable for fraud in agentic checkout?
For properly authenticated tokenised payments, Worldpay reports liability generally follows existing rules: the issuer carries fraud risk and the cardholder keeps chargeback rights. Disputes short of fraud, such as the wrong item, have no settled allocation.
Do chargebacks go to the merchant or the AI platform?
The OpenAI delegated payment specification, as quoted by Digital Applied, says settlement, refunds, chargebacks and compliance remain with the merchant and its payment provider, and that OpenAI is not the merchant of record.
Have Visa and Mastercard published chargeback rules for AI agents?
Reports reviewed for this article say neither had published a binding chargeback rule for agent-initiated disputes. Both have launched tokenised agent payment frameworks with spending limits.
How can a retailer tell a legitimate shopping agent from a bot?
Signed-request methods such as Cloudflare's Web Bot Auth and Visa's Trusted Agent Protocol let merchants verify an agent cryptographically, which user agent strings and IP lists cannot do reliably.
One edition every weekday morning. Read in five minutes. Free for industry professionals.




