Build1 publisher3 min readPublished
Agentic checkout liability is already decided, and the deciding factor is which card you attached
Regulation E asks whether a transfer was authorized. That question has no clean answer when software presses the button, and the consumer is the one who finds out.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Browsers and chat apps now hand AI agents a user's payment details and allow the agent to check out on the user's behalf.
- The analysis arguing that agentic purchase protection depends almost entirely on which card is attached, and recommending attaching the credit card, was published on dev.to under the headline 'Your AI Agent Bought the Wrong Thing. Who Pays?'
- In the US, debit cards and bank-account transfers fall under Regulation E, which implements the Electronic Fund Transfer Act.
- Regulation E turns on whether a transfer was authorized or unauthorized; an unauthorized electronic fund transfer is one initiated by a person other than the consumer without actual authority to initiate it, which in practice turns on demonstrable consent.
- Legal analyses through 2026 repeatedly describe the agent-purchase question under Regulation E as unresolved, because the rule never contemplated a consumer delegating open-ended purchasing authority to software.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
Browsers and chat apps will now hand an AI agent your payment credentials and let it complete a checkout [1]. The rule that governs what happens when it buys the wrong thing was written on the assumption that a human pressed the button, which means the funding instrument you attach is the real control, not any forthcoming AI regulation. That is the argument in a dev.to analysis of agentic payment liability [2], and the mechanics hold up.
In the US, debit cards and bank-account transfers sit under Regulation E, which implements the Electronic Fund Transfer Act [3]. Regulation E turns on a single binary: authorized or unauthorized. An unauthorized electronic fund transfer is one initiated by a person other than the consumer without actual authority to initiate it, which in practice comes down to demonstrable consent [4]. Now put an agent through that. You consented to the shopping. You did not consent to the specific pair of shoes at the specific price. Legal analyses through 2026 keep returning the same word, unresolved, because Regulation E never contemplated a consumer delegating open-ended purchasing authority to software [5].
Ambiguity in a consumer protection rule is not neutral. It resolves in whichever direction the bank argues, over months, at the consumer's expense [8]. The Consumer Bankers Association asked regulators in January 2026 to work the question through with the industry, including dispute resolution and liability where agent-driven transactions cause financial harm [6]. As of August 2026 no rule had arrived [7], roughly seven months later [3].
Credit cards run on a different statute, and the difference is structural rather than cosmetic. Under the Truth in Lending Act and Regulation Z, card use is authorized when the initiator had actual, implied or apparent authority [9] - a wider net, which makes it harder to call an agent's overreach fraud. The part that matters is the second one: TILA gives a dispute right for goods or services not accepted or not delivered as agreed, which does not require calling anything fraud [10]. Wrong item, duplicate order, nothing delivered - all of those land inside that provision. On a credit card, you have a path to your money that skips the authorization argument entirely. On a debit card, the authorization argument is the whole case [11].
Follow the money one step further and the loss usually stops at the merchant, not the bank and not the network [12]. Visa's VAMP and Mastercard's ECM chargeback monitoring programs do not distinguish by how a transaction was initiated; a ratio is a ratio [13]. Merchants are accordingly being told to capture evidence trails now: which agent acted, under what instruction, with what spending limit, and what confirmation the consumer saw [14]. The prediction in the source is that merchants who cannot defend these transactions will refuse them or bolt on confirmation steps that defeat the point of the agent [15].
The EU AI Act does not cover the gap yet. Autonomous financial decision-making can fall into the high-risk tier with human-oversight, transparency and documentation duties [16], but the Digital Omnibus, in force since 27 July 2026, pushed the Annex III standalone high-risk obligations from 2 August 2026 to 2 December 2027 [17], a 16-month slip [1], and high-risk AI embedded in regulated products to 2 August 2028 [18], 24 months [2]. Article 50 transparency kept its August 2026 date, but it obliges disclosure, not a refund [19].
Watch the checkout, not the rulemaking. Every extra confirmation screen an agent hits is a merchant pricing in unresolved liability.