The main agentic commerce risks are fraud aimed at AI shopping agents, agents being tricked by hidden instructions on web pages, and consumer protection rules that were written for humans pressing “buy.” For shoppers, the practical exposure is a wrong or fraudulent purchase that is harder to dispute; for small merchants, it is chargebacks, bot traffic and compliance duties that stay with the seller even when a chatbot made the sale.

None of this means you should avoid AI shopping tools. It means knowing where the weak points are, and setting things up so a mistake stays small. This guide covers the fraud, security and compliance side for both buyers and small sellers.

Agentic commerce risks at a glance

Risk What happens Who carries it first What limits it
Fake storefronts An agent is lured to a scam shop with low prices and hands over payment details Shopper, then card issuer Card protections, agent-specific tokens, spending caps
Prompt injection Text hidden on a page or in an email steers the agent to do something you did not ask Shopper Narrow tasks, confirmation screens, signed limits
Malicious bots Fraudsters use automated “agents” to test stolen cards or buy stock Merchant Bot detection, agent verification by card networks
Disputed purchases A buyer says the agent got it wrong or was never authorized Merchant, as merchant of record Consent records, order confirmations, clear policies
Unclear legal rights “Authorized” and “unauthorized” do not map neatly onto an agent’s actions Shopper and merchant Card issuer policy today; regulators are reviewing the rules

Fraud: criminals follow the agents

Visa has been the most specific about the numbers. In a November 2025 threat briefing, it reported a more than 450% increase in dark web posts mentioning “AI Agent” over six months, and a 25% increase in malicious bot-initiated transactions over the same period, with a 40% increase in the US. The same briefing describes three patterns that matter to ordinary shoppers:

  • Counterfeit merchants. Fake shops with unusually low prices are built to fool agents that compare prices, then collect the payment details for later misuse.
  • Brand impersonation. Conversational bots pose as trusted brands and build trust over time to extract personal information.
  • Scam setups at scale. AI is used to spin up fake websites, fake company identities and falsified documents quickly.

On the merchant side, Akamai’s July 2026 report, Securing the Agentic Storefront, found that 47.9% of AI bot traffic on its network between July and December 2025 hit the commerce sector. It also describes shopping agents that mimic human behavior, which makes bad bots harder to separate from legitimate ones, and attackers hijacking genuine AI assistants.

The consumer-facing version of this is the fake agent itself: an app or website that claims to shop for you and is really a way to collect card details. Our guide to fake AI shopping agents covers the warning signs.

Security: the prompt injection problem

An AI agent reads web pages, product listings and sometimes your email. Anything it reads can contain instructions. Prompt injection is when an attacker plants those instructions so the agent follows them instead of you.

OpenAI is unusually direct about this. In a December 2025 post on its Atlas browser, it wrote that prompt injection, “much like scams and social engineering on the web, is unlikely to ever be fully ‘solved’,” and listed “sending money” among the actions an attacker might try to trigger. Its advice to users: stay logged out when a task does not need your accounts, give specific, narrow instructions, and check confirmation screens before approving.

Protocol designers assume the same thing. Google’s AP2 specification states that “preventing prompt injection attacks is infeasible” and instead relies on signed spending limits so that “worst-case financial impacts are strictly bounded” (AP2 security considerations). In other words, the industry’s plan is to limit the damage, not to promise it will never happen. For a walkthrough of how these attacks play out in a shopping session, see our guide to AI browser agents and prompt injection.

Agentic commerce payment security: what protects the card

The good news is that most serious agent-checkout systems are built so the agent never holds your raw card number.

  • Scoped tokens. Checkout.com explains that OpenAI’s Agentic Commerce Protocol uses “delegated tokenization” and Google’s UCP uses a Google Pay cryptogram. The agent gets a token with narrower permissions than your card, alongside the network tokens that already protect online payments.
  • Signed authorization. Under AP2, a closed payment mandate names the payee, amount and payment method, and payment credentials are released “only upon receipt and verification of a final Payment Mandate” (AP2 security considerations).
  • Network-level checks. Visa says it offers zero liability for unauthorized charges and blocks more than 500 fraudulent transactions a minute (Visa). The card networks’ own agent programs are covered in our guide to Visa Trusted Agent Protocol and Mastercard Agent Pay.

These protections work best when a purchase stays inside a known system: a mainstream assistant, a recognized checkout and a card with its own limits. They do little if you paste your card details into an unknown “agent” website.

Agentic commerce compliance: what the rules say for shoppers

In the US, your baseline protections come from the payment method, not from the AI tool.

  • Credit cards. Federal law limits your responsibility for unauthorized charges to $50, and you can dispute billing errors, including goods “not delivered as agreed,” by writing to the issuer within 60 days of the first bill that shows the error (FTC).
  • Debit cards and bank transfers. Your liability for unauthorized transfers is the lesser of $50 or the amount taken if you report within two business days, up to $500 if you report later but within 60 days, and potentially unlimited after that (CFPB).

The hard part is the word “unauthorized.” You did authorize the agent. A March 2026 analysis from the Center for Data Innovation asks what happens “if an AI agent violated the consumer’s instructions, such as by autonomously ordering the wrong item or quantity,” and argues the CFPB should clarify that “consumer-authorized agents do not waive all error resolution rights.” Until that is settled, a wrong purchase by an agent you set up may be treated as a merchant dispute rather than fraud, and credit cards give you the broader set of dispute rights.

Lawmakers are looking at the gap. A discussion draft of the federal AI AGENT Act, released by Senator Mark Warner on June 29, 2026, would give AI agents “non-waivable, fiduciary-style duties,” including following user instructions and keeping auditable records. It had not been formally introduced as of that analysis.

In the UK, the FCA said in March 2026 that it may need to change payment rules, including the explicit consent requirement in the Payment Services Regulations 2017, because they were written for human decisions. The FCA’s Mills Review of AI in retail financial services, published July 6, 2026, named “consumer trust, control, consent and liability when things go wrong” among the key challenges. Rules differ by country, so check with your card issuer, and for a large loss, a consumer adviser or lawyer.

When an agent buys the wrong thing, our step-by-step guide to an AI agent purchase gone wrong covers refunds, chargebacks and who usually pays.

Agentic commerce compliance for small merchants

If you sell through an AI checkout, you are still the seller. OpenAI’s production guide says the merchant taking payment is the merchant of record, customers see your name on their statement, and “the merchant bears full responsibility for managing refunds and chargebacks” (OpenAI). Checkout.com says the same across agent checkouts: the merchant “retains responsibility for fraud, chargebacks, and disputes” (Checkout.com).

That has four practical consequences:

  1. Disputes from confused buyers. Checkout.com names consumer confusion about what the agent did as the biggest dispute driver, and says “the more transparent the agent’s actions are to the consumer, the fewer disputes you’ll see.” Send a clear order confirmation after every agent purchase.
  2. Keep the consent trail. Checkout.com recommends storing the consent data and spending limits attached to each agent order, because that is your evidence if a chargeback arrives.
  3. Card data scope. OpenAI warns that integrating directly with delegated payment handling “likely increases PCI scope” and may require a compliance attestation. Ask your payment provider which integration keeps that burden with them before you build.
  4. Bots versus buyers. With so much AI traffic hitting stores, blocking all bots can also block real agent customers. Card network agent-verification programs and your processor’s bot tools are the safer route than blanket blocking.

If you have not set up agent payments yet, our guide to accepting AI agent payments without code covers the no-developer options.

What shoppers can do today

  • Give an agent a narrow task (“this product, this size, under $80”) rather than an open errand.
  • Use a credit card, or a virtual card with a low limit, for agent purchases. Our guide to spending limits for AI agents shows where to set them.
  • Read the confirmation screen before approving: merchant name, item, total and shipping.
  • Use only agents built into services you already trust, and never type card details into an unfamiliar “AI shopper.”
  • Check your statement after agent purchases and report anything wrong quickly, because the dispute time limits above are short.

Where it goes wrong

  • A “yes” is still a yes. If you approved a basket on a confirmation screen, a card network may treat the purchase as authorized even if the agent chose badly. Disputes then run through the merchant’s return policy or a billing error claim.
  • Standing permissions. Pre-approved, “buy when the price drops” instructions let an agent act while you are not watching. Keep those limits tight and review them.
  • Debit cards carry more risk. Money leaves your account at once, and the protections depend on how fast you report.
  • Small shops absorb the chargeback. A merchant with thin margins pays the fee and loses the goods when a dispute goes against it, even when the agent, not the customer, caused the confusion.
  • The rules are moving. Protocols, card network programs and regulations are all changing in 2026, so what applies today may change within months.

How we checked this

We read primary sources: Visa’s agentic commerce threat briefing, Akamai’s 2026 commerce report, OpenAI’s merchant documentation and security post, the AP2 specification, FTC and CFPB consumer guidance, and published analyses of US and UK regulation. Facts checked on September 25, 2026.

Go deeper