When AI agents buy, who is liable for mistakes?
Shopify reported AI-driven traffic and orders tripled year over year in Q2 2026. Payments firms are seeking rules on liability for purchases made by AI agents.
On Shopify’s Q2 2026 earnings call, president Harley Finkelstein confirmed that AI-driven traffic and orders to merchants tripled year over year and that new buyer orders from AI channels arrive at nearly twice the rate of other channels. The scale of those transactions has prompted questions across the payments industry about liability when AI agents make purchases for consumers.
Retailers and infrastructure providers are enabling agentic commerce. Albertsons has made a shopping feature available through ChatGPT for Safeway customers, and several companies are developing wallets and identity systems so AI agents can complete transactions without a human clicking a purchase button.
Card networks and technology providers have concentrated first on authenticating agents and preventing impersonation. Authentication proves an agent had valid credentials but does not establish whether a consumer intended a specific purchase. One common example: a household permits an assistant to manage routine grocery orders; the agent reorders laundry detergent based on past patterns, the merchant fulfills the order, and credentials check out. The household had already bought detergent elsewhere that week, producing an unwanted outcome despite a valid transaction. “Authorization is not the same as intent.”
Evidence needed to resolve such disputes can sit outside the merchant’s systems. Merchants typically keep transaction histories, delivery confirmations and communication logs. Permissions, decision rules, and recommendation histories may exist on the agent platform, the wallet provider, or in a consumer’s settings. Reconstructing who set what permissions and whether settings changed before a purchase can require access to logs merchants do not control.
That evidence gap can leave merchants at a disadvantage in chargebacks and consumer complaints. A merchant can show an order was placed, authenticated and delivered but may not be able to show the instructions the consumer gave the agent beforehand. Without that context, transactions that appear legitimate can be difficult to defend.
Industry participants are advocating for risk-based controls instead of forcing consumers to reconfirm every AI-initiated purchase. Low-value routine items would face minimal friction while larger purchases, such as a high-value electronics order or an expensive flight, would trigger stronger verification. Machine learning and analytics are proposed to identify unusual agent-initiated patterns and surface relevant records more quickly to reduce dispute resolution costs.
Regulatory proposals are starting to address agent accountability. Delaware has proposed an Artificial Intelligence Company structure that would require entities run by autonomous agents to log agent activity and disclose autonomous status to counterparties. Those requirements would create traceability and record-keeping that could support dispute processes.
For merchants and payments providers, linking a transaction to the permissions granted to an agent and any subsequent dispute is a repeated priority. The engineering work that enables agents to make payments is proceeding now; industry participants are focused on defining evidence standards, data access protocols and dispute rules to record and explain agent-driven transactions when they are contested.








