Visa made cardholders responsible for their agents. Now prove the cardholder agreed.
Liability moved to the consumer. The evidence did not follow. When a consumer disputes an agent purchase they say they never authorised, neither the merchant nor the issuer holds any artefact showing what the consumer actually instructed.
Visa made cardholders responsible for their agents. How do you prove they agreed?
Today you cannot. An April 2026 rule change made the cardholder formally responsible for purchases made by their AI agent, as if they had transacted themselves. The dispute infrastructure for agent transactions remains undefined, so the evidence that a cardholder agreed does not exist on either side.
- Visa's April 2026 rule change made the cardholder formally responsible for an AI agent's purchases as if they had transacted themselves. Mastercard shipped agentic commerce credential rules in the same period.
- Industry commentary through 2026 observed that liability rules arrived while dispute rules did not, leaving merchants absorbing outcomes by default.
- A consumer-signed mandate carrying merchant category, ceiling and expiry supplies the representment evidence that currently does not exist.
Part of Gaming and consumer marketplace identity
What changed, and what did not
In April 2026 Visa's rule change made the cardholder formally responsible for purchases their AI agent makes, treating them as though the cardholder had transacted themselves. Mastercard published agentic commerce credential rules over the same period, including provisions that agents may not use consumers' existing cards on file with merchants.
Payment industry analysis through 2026 made the same observation repeatedly: the networks activated agent payments and the dispute infrastructure needed to support them does not exist. Liability was allocated; the evidence framework was not built.
The dispute, as it will actually arrive
A consumer instructs an agent to book travel under $400. The agent books a $380 flight on a carrier the consumer dislikes, on dates adjacent to what they wanted, non-refundable.
The consumer disputes. Their position is that they did not authorise this purchase. The merchant's position is that the transaction was properly authenticated. Both are describing the same event accurately.
| Party | What they hold | What they cannot show |
|---|---|---|
| Consumer | A conversation in an agent vendor's app | That the instruction did or did not cover this purchase |
| Agent vendor | Conversation logs, possibly | No obligation to produce them; not a party to the dispute |
| Merchant | An authorised transaction | Any evidence about consumer intent |
| Issuer | The transaction record | The same |
The dispute resolves on the basis of network rules that were written for a human buyer, and in practice that means the merchant absorbs it.
Why conversation logs are not the answer
The instinctive fix is to have the agent vendor produce the conversation. Three problems.
- The vendor is not a party to the card dispute and has no obligation to produce anything on a representment timeline.
- A conversation is not a mandate. Book me a flight under $400 is genuinely ambiguous about carrier, timing and refundability, and reasonable people read it differently.
- The log is held by a party with a commercial interest in the outcome, which is the weakest evidentiary position available.
The Consumer Mandate Receipt
The consumer signs a bounded mandate before the agent transacts. Not a conversation — a scoped delegation.
{
"type": "manav-stmt/1",
"action": "agent_purchase_mandate",
"render": [
"Agent: [name, vendor]",
"Purpose: [travel booking]",
"Merchant categories: [permitted MCCs]",
"Maximum per transaction: [amount]",
"Maximum total: [amount]",
"Valid: [start]–[end]",
"Refundability required: [yes | no]"
],
"cardholder": "[credential assertion]"
}
The mandate is held by the consumer, presented with the transaction, and verifiable by the merchant and the issuer without either trusting the agent vendor.
Mapping to the dispute flow
| Dispute stage | Question | What the mandate supplies |
|---|---|---|
| Cardholder claim | Did the cardholder authorise this? | A signed mandate, or its absence |
| Merchant representment | Evidence of authorisation | The mandate, verified, covering this transaction |
| Pre-arbitration | Was the transaction within scope? | Category, amount and date comparison against the mandate |
| Arbitration | Network rules applied to evidence | A factual record rather than competing assertions |
The second row is the operative one. A merchant representing a transaction today has an authorisation record and nothing about intent. With a mandate, they have a consumer-signed document showing the transaction fell within what the consumer authorised.
What this does for the consumer
It cuts both ways, and that is the point. A consumer who signed a mandate permitting $400 purchases in travel categories for a week has a weaker dispute if the agent bought a $380 flight. A consumer who signed a mandate for $100 in grocery categories has a much stronger one if the agent bought a flight.
Under the new liability allocation, consumers bear the risk of their agents. A mandate is the only mechanism that lets them bound that risk in advance rather than argue about it afterwards.
The adoption question
Networks will eventually define agent dispute rules, and when they do this design may be superseded or absorbed. Nothing here predicts the outcome.
What is true now is that merchants are absorbing disputes with no representment evidence available, and the volume is growing. A merchant or issuer piloting mandate-backed agent transactions is building the evidence the rules will eventually require, and is doing so during the period when the absence costs them money.
Three positions, none of them satisfying
| Position | Consequence |
|---|---|
| The cardholder authorised it, by deploying the agent | Every agent transaction becomes final; consumer confidence collapses |
| The cardholder did not authorise it | Every agent transaction is disputable; merchants decline them |
| It depends on the scope they granted | Correct, and requires a record nobody keeps |
Objections and honest limits
“Strong customer authentication covers it.” The cardholder did authenticate — when they set the agent up, weeks earlier. The mechanism passes and carries no assurance about this purchase.
“The agent provider will hold the record.” Then the evidence is held by one party to the dispute. A scope grant is worth most when the party relying on it did not issue it.
What a cardholder scope record must contain
- The cardholder, authenticated with user verification. A person, not an account.
- The agent, identified. So the grant is not transferable.
- Per-transaction and aggregate ceilings. Both, because one alone is defeated by splitting.
- Merchant or category scope, and an expiry. So the grant does not outlive the intent.
- Immediate revocability. Enforced at the point of effect, not at a gateway.
Terms used here
- Agentic transaction
- A card transaction initiated by software acting for a cardholder, rather than by the cardholder at a device.
- Scope grant
- A signed delegation stating what an agent may do on someone's behalf, with limits and an expiry.
- Chargeback
- The dispute mechanism, which classifies transactions by how they were initiated — a classification agent transactions do not fit.
Frequently asked questions
Do the networks require this? No. The rules allocate liability and the dispute infrastructure for agent transactions was still undefined through 2026. This is a proposal for evidence the rules do not yet specify.
Does a mandate weaken consumer protection? It bounds it in advance rather than leaving it to argument. A consumer with a narrow mandate is better protected against an out-of-scope purchase than one with no mandate at all.
Who holds the mandate? The consumer, presented with the transaction. Holding it at the agent vendor would recreate the problem of evidence held by an interested party.
What if the agent vendor will not support it? Then transactions from that agent carry no mandate, and merchants can price that difference. That is a market signal rather than a technical blocker.
What changed in April 2026? Rule changes made cardholders formally responsible for purchases made by their AI agents, as if they had transacted themselves.
Does strong customer authentication help? It confirms the cardholder authenticated at setup, weeks before the purchase. The mechanism passes and says nothing about the transaction.
Who should hold the scope record? Nobody exclusively. It should be verifiable by the issuer, the merchant and the cardholder without calling the agent provider.
Where this fits in Manav
Manav proves a specific person authorised a specific action, without a vault, a token or surveillance. The biometric never leaves the device and the platform receives a signature rather than a profile.
Sources and further reading
- Reported Visa rule change, April 2026, on cardholder responsibility for AI agent purchases.
- Visa — security and trust perspectives on agentic commerce
- Payment industry analyses of undefined agent dispute infrastructure, 2026.