“My agent did it” — and why your chargeback evidence is now worthless.
When an AI agent makes a purchase and the cardholder disputes it, the evidence merchants rely on to win — IP address, device fingerprint, navigation path — was generated by the agent, not a human. It proves nothing. Liability for agentic commerce is an unresolved storm, and right now the merchant eats it.
The accountability void
Agentic commerce breaks the dispute model. When a charge is contested, three parties point at each other — the user who deployed the agent, the company that built it, the platform where it bought — and consumer-protection rules push the cost onto the merchant or issuer by default. Visa, the IMF, and major law firms all name the same first risk: authorization — "did the human actually approve this?"
The deeper problem is evidentiary. The classic chargeback rebuttal — here's the customer's IP, device fingerprint, and click path — is meaningless when an agent generated all of it. An authorized agent and a hijacked one produce identical traffic. There is nothing in the transaction that ties it to a human's intent.
Why detection can't fix this
You cannot fingerprint your way to "the human meant it." Risk scoring, device intelligence, and bot detection were built to tell humans from bots — but in agentic commerce the agent is supposed to be there. The question isn't "is this a bot?" It's "did a real human authorize this bot to do this?" — and no signal in the stream answers it.
The missing artifact: a delegation receipt
Give the dispute an answer that holds. The human signs a scoped, revocable delegation — this agent may spend up to this amount, with these merchants, until this date — with a passkey and liveness. The agent signs each purchase under that delegation. The chain verifies offline to the originating human's ceremony. That receipt is the representment evidence: proof that a specific human authorized this scope, this amount, this merchant — not a probabilistic score, a cryptographic fact a card network or court can check without trusting anyone.
It draws the liability line cleanly. Inside the signed scope, the human authorized it — not a chargeback. Outside it, the agent acted without authority — and the receipt proves the merchant required authorization and the agent failed to present it.
Honest limits
This needs the agent ecosystem to carry and present the receipt, and the standards around it (AP2, Web Bot Auth) are still settling — which is exactly why the time to define the evidence format is now. It resolves authorization disputes; it doesn't adjudicate "the agent bought the wrong color," which is a returns and merchant-policy question, not fraud.
Frequently asked questions
Who's liable today when an AI agent buys something the user disputes? Unresolved — and that ambiguity defaults the cost onto merchants and issuers. A signed delegation receipt replaces the ambiguity with a verifiable record of what the human actually authorized.
How is this different from a device fingerprint or risk score? Those describe the traffic, which the agent generated. A delegation receipt records the human's authorization itself, signed on their device — it survives as evidence; a fingerprint doesn't.
Does this work with AP2 and card-network agent programs? Yes — it's designed to compose with them. AP2 carries payment intent; the delegation receipt adds the verifiable human authorization behind it, in their formats.
In agentic commerce the agent leaves fingerprints everywhere and proof of nothing. The receipt is the one thing that says a human meant it.