Liability in agentic commerce

Person pushing a shopping trolley beneath a blue sky.

An agent buys something on a customer’s behalf. The purchase was not what the customer wanted, or it was not that customer at all. Who takes the loss?

Here is a question nobody in agentic commerce has answered, and it is going to matter sooner than the specifications suggest.

Work it through with one example

A customer connects a shopping agent to their account. They give it a budget and a broad instruction. The agent finds a supplier, places an order, and the money moves.

Two weeks later the customer disputes it. Perhaps the agent misread the instruction. Perhaps somebody else had access to the customer’s session when the agent was authorised. Perhaps the agent was running somewhere it should not have been.

Now count the parties.

The merchant accepted an order that arrived with valid credentials. The processor authorised a payment that passed every check it runs. The agent platform issued a mandate that was correctly signed and correctly scoped. The customer says they did not ask for this.

Every party did what it was supposed to do. The loss still exists, and it sits with whoever the rules say it sits with.

What the protocols actually cover

Read the published specifications and a pattern is obvious.

Visa’s Trusted Agent Protocol, Mastercard’s Agent Pay and Google’s AP2 all address the same two things. Is this agent who it says it is, and does it hold a mandate that authorises this action.

Those are good questions and the work being done on them is serious. Agent identity had to be solved before anything else could happen, and it is being solved quickly.

But identity and authorisation are not the whole of a transaction decision. They tell you the credential is valid. They do not tell you the circumstances the credential was used in.

An agent holding a perfectly valid mandate, executing from an environment that has been tampered with, presents exactly the same credential as one running where it should be. The mandate checks out either way. Nothing in the protocol looks at the machine.

That is not a criticism of the specifications. They were written to solve identity and they solve it. It is an observation about what is left over.

The part that gets settled slowly

Liability does not get decided by a specification. It gets decided by scheme rules, by regulators, and eventually by cases.

We have watched this happen before. Card-not-present transactions arrived in the 1990s and the rules that govern who eats a fraudulent one did not arrive with them. They were written afterwards, over about a decade, largely in response to where the losses actually landed. The industry did not reason its way to chargeback rules in advance. It absorbed losses first and codified afterwards.

Agentic commerce is at the front of that same process. The instruments are shipping now. The rules that decide who carries an agent-initiated loss are years away.

That gap is not theoretical. It is a period, starting roughly now, in which somebody is carrying that risk without a rule that names them.

Who is carrying it

Whoever accepts the traffic.

If you run a merchant, a marketplace, a payments business or a platform that is starting to see agent-initiated activity, the answer today is that you are absorbing the ambiguity. Not because anyone decided you should, but because losses default to the party closest to the transaction until somebody writes down otherwise.

Which means the useful question for the next two years is not “what does the protocol say”. It is “what evidence do I have about this transaction if it goes wrong”.

What actually helps

Not certainty. Nobody can offer certainty here, and any vendor who says they can resolve agentic liability is selling something that does not exist.

What helps is evidence. If a transaction is disputed eighteen months from now, the party carrying the loss will need to show what it knew at the time. Not just that the credential was valid, but what the circumstances were. Where the request came from. Whether the environment resembled anything that account had used before. Whether the machine behind the agent looked like a machine or like something pretending to be one.

That evidence has to be captured at the moment of the action, because it does not exist afterwards. A log of valid mandates tells you very little in a dispute where everybody agrees the mandate was valid.

The honest limit

We cannot resolve liability. No signal layer can. Where the loss lands is a legal and commercial question and it will be settled by people with more authority than any vendor in this space.

What a signal layer can do is give the party carrying the loss something to reason with, and something to show. That is a smaller claim than the ones being made around agentic commerce at the moment, and it is one we can actually stand behind.