If an AI agent purchase goes wrong, who pays usually depends less on the AI and more on how you paid. On a credit or debit card, the usual US protections under the Truth in Lending Act and the Electronic Fund Transfer Act, plus card-network chargeback rules, still apply. On stablecoins, there is generally no chargeback. The hard part is proving what you actually asked the agent to buy, and the refund and liability rules for that part are still being worked out.

This is not legal advice. It is a general explainer of an area where the rules are still changing. If a disputed purchase involves real money, talk to your card issuer, a consumer-protection body (in the US, the CFPB or your state attorney general; in the EU, your national consumer authority or a European Consumer Centre), or a lawyer who handles consumer finance.

How we checked this

We read the platforms’ own pages on who handles orders and refunds: OpenAI’s page on Instant Checkout and the Agentic Commerce Protocol, Stripe’s ACP documentation, Google’s help pages for purchases in AI Mode and agentic checkout with Google Pay, and Amazon’s “Buy for Me” announcement. For the card networks we used Visa’s Trusted Agent Protocol release and Intelligent Commerce page and Mastercard’s Agent Pay release; for consumer rights, the CFPB pages on disputing a credit card charge and unauthorized debit and bank transactions, the FTC’s guide to disputing credit card charges and the EU’s Your Europe page on payments. Legal and industry context comes from Bloomberg Law, Backbase, Payments Dive and Oliver Wyman’s September 2026 merchant survey write-up. Facts checked on September 24, 2026.

The four ways an agent purchase goes wrong

It helps to separate the problems, because each one leads somewhere different.

What happened Example Who you’d likely deal with first Main question
Wrong item You asked for a navy T-shirt; a red one arrives Merchant (returns) Can you show what you asked for?
Wrong amount or quantity The agent ordered three instead of one, or a pricier version Merchant, then card issuer Did you confirm that total?
Purchase you never allowed The agent bought something with no request from you, or someone else used your agent Card issuer / bank Was it “authorized” at all?
Merchant fraud or non-delivery Nothing arrives, or the seller vanishes Card issuer (chargeback) Same as any online purchase

The navy-versus-red example is not ours. It comes from Serge Elkiner, general manager of Paze at Early Warning Services, who told Payments Dive that a shopper in that spot might call the bank, which “doesn’t have a record of that specific consumer ordering the shirt because the agent made the purchase,” and then the shop, which “doesn’t have a record of it either.” That is the core gap in one sentence: the bank and the merchant saw a valid payment, and only you (and maybe the agent platform) know what you really asked for.

The first and fourth rows are the most familiar. A wrong item is a returns question, and non-delivery or merchant fraud is a normal online-shopping dispute that happens to have an agent in the middle. The middle rows are where agents make things murky.

Is an agent purchase “authorized”?

This is the question everything else hangs on. Card and bank protections treat an unauthorized transaction (someone used your card without permission) very differently from an authorized one that turned out badly (you paid, but the product was wrong).

When you set up an agent, link a card and let it check out, you have arguably authorized it to spend. Backbase, which builds banking software, frames agent liability around exactly this point: what was authorized, by which actor, and under what limit. The practical worry is that once a customer has given an agent general authority, a later bad purchase may not look unauthorized to a bank, which leaves less room for the stronger fraud-style protections. Bloomberg Law’s reporting quotes industry and legal voices calling authorization “another thorny question” and notes that regulators and courts will likely have to decide how old standards apply to AI shopping.

In practice, how you set up the agent matters:

  • Agents that ask you to confirm each order. OpenAI says that with Instant Checkout, users “confirm their order, shipping, and payment details” before the purchase goes through (OpenAI). If you tapped confirm on a screen that showed the item and total, you’ll have a hard time calling that purchase unauthorized. Your stronger argument is usually “not as described” or “wrong item shipped,” which is a merchant dispute.
  • Agents with standing permission to buy on their own. The authorization question gets harder here. You gave permission in general, but not for this specific purchase. Whether that counts as authorized under your card’s rules is exactly what the industry is still arguing about.

Visa and Mastercard both run agent programs meant to make that question easier to answer later. Visa’s Trusted Agent Protocol, announced in October 2025, lets agents pass “agent-specific cryptographic signatures” to merchants, carrying signals about agent intent, consumer recognition and payment information, so a merchant can tell a legitimate shopping agent from a malicious bot (Visa). Visa’s broader Intelligent Commerce program describes “spending limits, approval workflows, authentication requirements and trusted identity signals” (Visa). Mastercard’s Agent Pay, announced in April 2025, requires agents to be “registered and verified,” uses Agentic Tokens built on its existing card tokenization, says consumers “will have complete control over what the agent is allowed to purchase,” and promises “a process to help clarify agentic transactions that may be unfamiliar or unrecognized” (Mastercard).

What these programs add is evidence: which agent acted, for whom, and under what limits. That could help in a dispute, but the dispute rights themselves still come from your card agreement and the law. Our sibling guide on Visa Trusted Agent and Mastercard Agent Pay covers what changes for cardholders.

What the platform terms say about agent errors

OpenAI (Instant Checkout in ChatGPT). OpenAI is clear about its role: “Orders, payments, and fulfillment are handled by the merchant using their existing systems. ChatGPT simply acts as the user’s AI agent.” When you place an order, ChatGPT sends the details to the merchant, and “the merchant accepts or declines the order, processes the payment via their existing provider, and handles fulfillment and customer support exactly as they do today” (OpenAI). In plain terms, the merchant, not OpenAI, is who you ask for a return or refund.

The protocol behind this, the Agentic Commerce Protocol, includes “orders and webhooks” that track “order confirmation, shipping, delivery, and refunds,” and a “delegate authentication” piece that uses OAuth 2.0 so agents can “act on a buyer’s behalf with a business” (Stripe). So the plumbing to carry refund status back to the agent exists. That does not mean every merchant uses it, or that ChatGPT gives you a dispute button.

Google (AI Mode and agentic checkout with Google Pay). Google’s help page for buying in AI Mode says “your purchase is made directly with the merchant,” paid “with Google Pay using your payment and shipping info in Google Wallet,” and that “the merchant handles your payment, shipping, returns, and customer support.” Order confirmation emails come from the merchant, and for problems Google points you to the merchant’s customer support page. The feature is limited to signed-in users aged 18 and over in the US, in English, with eligible merchants (Google Search Help).

Google’s separate agentic checkout feature can buy a tracked product for you later. It “is designed to buy the product if the final price is the same as, or lower than the total price you confirmed,” and for cancellations, returns, delays or delivery issues Google says to “contact the merchant where you purchased the goods.” That page lists availability in the US and Australia, in English, for select merchants that accept Google Pay (Google Pay Help). A price-capped, buy-later setup is a clear case of standing permission, so screenshot the item and the price you confirmed.

Amazon (“Buy for Me”). Amazon’s announcement says the agent buys from the brand’s own website by “securely providing the customer’s encrypted name, address, and payment details,” after you confirm the delivery address, taxes, shipping fees and payment method. After that, “delivery, returns and exchanges, and customer service are managed by the brand store,” and you contact the brand with order questions. At launch in April 2025 it was live for “a subset of U.S. customers” in the Amazon Shopping app (Amazon). Our guide to Amazon “Buy for Me” walks through how the feature works and how to cancel.

The pattern is the same across all three platforms: the AI company places the order, and the merchant owns payment processing, returns and support. For how Google’s checkout protocol compares with OpenAI’s, see ACP vs UCP.

One general point from Backbase applies across platforms: many third-party agent tools “aren’t built for dispute resolution and may limit a customer’s ability to seek redress directly from the tool provider, leaving the bank as the practical point of accountability” (Backbase). Read the platform’s terms for a limitation-of-liability clause before you give an agent a card.

Who to complain to first

A sensible order, based on how these flows are built:

  1. The merchant. In ChatGPT, Google AI Mode and Amazon “Buy for Me,” the merchant handles support and returns (OpenAI, Google, Amazon). For a wrong item or wrong quantity, a normal return or cancellation request is usually fastest. Look for the merchant’s order confirmation email; that is your order number.
  2. The agent platform. Tell the platform what happened, especially if the agent misread your request. Even if the platform won’t refund you, its records of your conversation and the confirmed cart can support a dispute. Export or screenshot them now.
  3. Your card issuer or bank. If the merchant refuses, doesn’t respond, never delivers, or you believe the purchase was never authorized, file a dispute with your issuer. Bloomberg Law reports that chargeback and return standards set by banks and card networks still apply when an agent uses your card. Card disputes have time limits. For a credit card billing error, the CFPB says to call the issuer and also send a written notice within 60 days after the charge appeared on your statement (CFPB). For unauthorized debit or bank transfers, report within 60 days of the statement, and sooner is better (details below). Don’t let a slow merchant use up that window.
  4. A regulator or consumer body. If the issuer and merchant both refuse, US consumers can escalate to the CFPB (for the bank or card side) or report the merchant to the FTC. In the EU, your national consumer authority, or the European Consumer Centres network for a cross-border purchase, is the usual next step. The Your Europe payments page explains EU payment rights.

If you suspect someone else got into your account or agent, treat it as account compromise first. Our guide Your money was stolen: what to do in the first hour covers that.

Do chargeback rights apply? On stablecoin rails?

Credit cards. Bloomberg Law reports that if the agent is connected to your credit card, Truth in Lending Act protections and network chargeback rules still apply (Bloomberg Law). This is generally the strongest position for a buyer. The basics, from the US regulators:

  • Billing errors. Send a written dispute to the issuer’s billing-inquiry address within 60 days after the first bill with the error was sent. The issuer must acknowledge it within 30 days and resolve it within 90 days. While it investigates, you can withhold payment on the disputed amount but must pay the rest (FTC). If the issuer decides you’re right, it must remove the charge; if not, it must explain why in writing (CFPB).
  • Unauthorized charges. Federal law “limits your responsibility for unauthorized charges to $50” (FTC). Whether an agent purchase counts as unauthorized is the open question above.
  • Wrong or poor-quality goods. You can also dispute the quality of something you bought, but the FTC lists conditions, including that you bought it in your home state or within 100 miles of your billing address, and that “you must have tried to resolve the dispute with the seller first” (FTC). For an agent that ordered the wrong item, contacting the merchant first is part of the process, not just good manners. How the distance rule applies to an online order is a question for your issuer.

Debit cards. According to Eric Goldberg, a fintech and consumer finance partner at Davis Wright Tremaine quoted by Bloomberg Law, debit cards provide “somewhat less protection.” The Electronic Fund Transfer Act (implemented by Regulation E), which Bloomberg Law lists alongside the Truth in Lending Act as still applying to agent purchases, is the main US law for debit transfers. For unauthorized transactions, the CFPB explains that your liability depends on speed: report within two business days of learning of it and you owe at most $50; after that, up to $500 if you report within 60 days of the statement; after 60 days, you could be liable for the full amount if timely notice would have stopped the losses. The bank generally has 10 business days to investigate (20 for accounts open less than 30 days), usually must give provisional credit if it needs longer, and has up to 45 days to finish, or 90 days for debit card point-of-sale purchases, foreign transactions and new accounts (CFPB). These are rules for unauthorized transfers. A debit purchase you confirmed that then went wrong is mostly between you, the merchant and your bank’s own dispute policy.

EU payments. Backbase notes that Reg E in the US and PSD2 in the EU “already require an audit trail for disputes,” and that requirement “doesn’t disappear just because an agent, rather than a person, triggered it” (Backbase). On the consumer side, the EU’s Your Europe portal says that for fraudulent payments “you can only be asked to pay a maximum of €50,” and nothing at all if you were unaware of the loss, theft or misappropriation. For direct debits, you have the right to a refund within 8 weeks (Your Europe). Those rules cover fraud and direct debits. They don’t settle the case of an agent that bought the wrong thing with your consent, which in practice goes back to the merchant and your card provider’s dispute process.

Stablecoins. This is the big gap. Goldberg told Bloomberg Law that stablecoins, “often seen as a natural match for AI shopping chatbots,” “don’t allow for refunds or chargebacks” (Bloomberg Law). A stablecoin transfer to a merchant settles like cash. Getting money back depends on the merchant agreeing to send it back. If you let an agent pay in USDC, for example through the x402 pattern we explain in x402 in plain language, assume there is no bank to appeal to.

Goldberg’s own summary is worth quoting: “I don’t know that consumers are going to want agents to go out buying stuff if they have limited protections.”

Why proving intent is the hard part

The merchant side is worried about this too. In Oliver Wyman’s 2026 survey of merchant payment teams, “intent verification” ranked among the top concerns about agentic commerce, alongside rules and pricing. Merchants want to know the buyer really meant to buy. Buyers want to prove they didn’t mean to buy this.

JPMorgan Chase’s global head of merchant services, Mike Lozanoff, put the buyer’s fear plainly: “Could the agent hallucinate and buy something we didn’t tell it to buy?” If that happens, “the rules here are not fully formed yet” (Payments Dive).

Backbase’s recommendation to banks is to keep a record of “what was authorized, by what actor, and under what limit, the moment it happens” (Backbase). Visa’s agent signatures and Mastercard’s registered agents point the same way (Visa, Mastercard). Until banks and platforms keep that record reliably and share it with you, you are the one who has to keep it.

What to save before letting an agent buy

Think of this as your own intent log. None of it is complicated:

  • Your original request, word for word. Screenshot or export the chat where you told the agent what to buy, including size, color, quantity and budget.
  • The confirmation screen. If the agent shows a cart or order summary before paying, screenshot it with the total visible. For a buy-later setup like Google’s agentic checkout, capture the price cap you confirmed.
  • Any standing instructions. If you gave the agent rules (“never spend more than $50,” “only from these stores”), save where you set them and what they said.
  • The merchant’s confirmation email. It shows the actual seller, which may not be the brand you expected.
  • The card statement line. Note the merchant name and date as they appear on your statement, so you can match it quickly if you dispute.
  • Delivery evidence. Photos of what arrived, next to the request.

Two setup choices reduce the damage before anything goes wrong: pay with a credit card rather than debit or stablecoins where you can, and set spending caps. Our guide to spending limits for AI agents shows how to set them in ChatGPT, Gemini and at the card level.

What to watch out for

  • “Authorized” can work against you. Giving an agent broad permission to buy may make it harder to call a bad purchase unauthorized, a question Bloomberg Law calls “thorny.” Narrow permissions and per-order confirmation keep your options open.
  • The platform may not be the seller. OpenAI, Google and Amazon all describe the merchant as handling support and returns (OpenAI, Google, Amazon). Complaining only to the AI company may go nowhere.
  • Stablecoin payments are final. No chargeback, no issuer to appeal to (Bloomberg Law).
  • Dispute deadlines keep running. In the US, the credit card billing-error window is 60 days (FTC), and debit liability for unauthorized transfers grows the longer you wait (CFPB). A slow back-and-forth with a merchant can use up that window.
  • Debit cards are the weaker choice. A late report on an unauthorized debit transfer can cost you up to $500 or more, compared with the $50 cap on unauthorized credit card charges (CFPB, FTC).
  • The rules are moving. Industry and regulators are still working out who is responsible when an agent gets it wrong (Payments Dive).

Go deeper