Sign up
Subscribe
Home / news / Agentic AI Checkout Is Forcing New Fraud and Liability Rules in US and Canada
news

Agentic AI Checkout Is Forcing New Fraud and Liability Rules in US and Canada

Agentic AI Checkout Is Forcing New Fraud and Liability Rules in US and Canada

Trade groups and card networks are already writing the playbook for AI tools that can shop on a consumer’s behalf. For PSPs, acquirers, and merchant gateways, the real issue is not whether agentic checkout exists, but how to tell a legitimate agent from fraud, and who eats the loss when the agent gets it wrong.

  1. On July 22, 2026, the Financial Data and Technology Association (FDATA) released a white paper on agentic fintech and write access, covering the US and Canada. The paper says policymakers can extend existing rules to AI tools that move from read-only data access to customer-authorized instructions and payments, without building an entirely new regulatory regime from scratch.
  2. FDATA’s model has three stages: Read, Instruct, and Transact. It maps those stages to existing rules on data protection, liability, and alignment of interests, and calls for standing authorizations for scoped agent-initiated transactions plus clearer liability rules for write-access activity.
  3. That liability point is the bit merchants and payment providers will have to operationalize. If an AI agent is allowed to initiate payments, the question is no longer just whether the transaction is authorized in the abstract, but how authorization is scoped, how it is verified, and who is responsible when the agent acts outside the intended parameters.
  4. Visa has already moved ahead with Trusted Agent Protocol (TAP), developed with Cloudflare. TAP uses signed request headers so merchants can cryptographically distinguish a legitimate shopping agent from a bot before checkout starts, and verify the agent against a Visa-operated directory instead of treating every non-human visitor as suspicious.
  5. Visa built TAP after seeing a surge in AI-driven traffic to US retail sites, and it has launched with processors including Adyen, Stripe, Checkout.com, Fiserv, and Worldpay. That matters because once the major processors are in the room, the acquiring side stops being a theory exercise and becomes an implementation problem.

The core operational problem is that KYC, as it exists today, assumes a human shopper. Agentic checkout creates a buyer with no face, no traditional browser fingerprint, and no stable behavioral pattern for legacy fraud models to anchor to. Rapid sequential orders and cross-category purchases can look like compromised-account behavior under old rules, even when they are simply how an agent shops.

Chargebacks make the liability question harder. If an agent overspends, misreads a return policy, or buys the wrong item, the industry does not yet have a clean answer for how existing dispute frameworks such as Regulation E should allocate responsibility when the “buyer” is software acting under consumer authority.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!