In 2026, a Spanish banking group and Mastercard reported completing what they describe as Europe’s first live end-to-end payment executed by an artificial intelligence agent. Not a demonstration. A real transaction, initiated and completed by software acting on someone’s behalf.

The industry term for this is agentic commerce, and the infrastructure is being built quickly. Visa has an initiative for it. Mastercard launched a product suite for it in the second quarter of 2026. There are currently four competing protocols for how it should work.

There is one question that almost none of the coverage addresses, because almost all of it is written for banks and merchants rather than for the person whose card is involved.

If the agent buys the wrong thing, who pays?

Table of contents


What agentic commerce actually means

Agentic commerce describes transactions initiated or completed by an AI agent acting on behalf of a person.

The distinction that matters is between recommending and doing. An AI that suggests three flights and leaves you to book one is a shopping assistant, and those have existed for years. An AI that compares the three flights, selects one against criteria you gave it, and completes the payment is doing agentic commerce. The difference is whether money moves without a human pressing the final button.

Everything difficult about this topic follows from that one distinction. Recommendation carries no financial consequence when it is wrong. Execution does.

How an AI agent is supposed to pay for something

The obvious approach — give the agent your card number — is exactly what the payment industry is trying to avoid, and understanding why explains the architecture being built.

The mechanism is tokenisation. Rather than handing over your actual card details, the system issues a token: a stand-in credential that represents your card for a specific, constrained purpose. Visa’s Intelligent Commerce initiative provides APIs and SDKs covering tokenisation, authentication and transaction controls designed specifically for AI agents, with partners including Anthropic, IBM, Microsoft, Mistral AI, OpenAI, Perplexity, Samsung and Stripe.

Three things the industry is trying to establish alongside it:

Authentication — proving the agent is acting for you, and that you authorised this category of action.

Transaction controls — limits on amount, merchant, frequency or category, so delegated authority is bounded rather than open-ended.

An audit trail — a record of what the agent did and on what basis, which matters enormously for the dispute question later.

That is a sensible design. The gap between a sensible design and a settled consumer protection framework is where this article lives.

Four protocols, no standard

Here is a detail that reads as technical trivia and is actually the most important thing for a consumer to understand.

There are currently at least four competing foundational protocols in this space: Anthropic’s Model Context Protocol (MCP), OpenAI and Stripe’s Agentic Commerce Protocol (ACP), and Google’s Agent Payments Protocol (AP2) and Universal Commerce Protocol (UCP).

Four protocols means the plumbing is not settled. In payments, unsettled plumbing has a specific consequence: the rules that govern what happens when something goes wrong are not settled either.

Compare this to the card system you use today. When a card payment fails or a merchant does not deliver, an enormous, boring, decades-old apparatus of scheme rules, chargeback rights and regulatory obligations determines what happens next. You mostly never see it, which is the point. That apparatus was not built in a year, and it does not yet exist in mature form for agent-initiated transactions.

This is not an argument that agentic commerce is unsafe. It is an argument for reading the terms of any specific implementation rather than assuming familiar protections carry over unchanged.

The liability question

This is the section written for you rather than for a bank, and the honest answer has to start with an admission: it depends on the implementation, and it is not fully settled.

What can be said clearly is the shape of the question. Three scenarios, with genuinely different characters.

The agent did what you asked, and you did not want the result. You told it to book the cheapest flight; it booked one with a nine-hour layover. The agent performed correctly against poorly specified instructions. This is closest to an ordinary consumer regret, and existing merchant terms — refund policies, cancellation windows — are likely to be where you end up.

The agent did something you did not authorise. It exceeded a limit, bought from a merchant you excluded, or misread its instructions. This is the genuinely unresolved case. Whether it is treated as an unauthorised transaction — with the strong protections that usually attach — or as an authorised transaction the agent got wrong is precisely the question the frameworks are still working out.

The agent was manipulated. Content the agent read contained instructions that changed its behaviour. This is prompt injection applied to a system holding payment credentials, and it is the scenario the industry is least prepared to adjudicate. Whose failure is it — yours, the agent vendor’s, the merchant hosting the manipulated content, or the payment network’s?

TechyKnow’s position: the third scenario is the one to watch, and it is the reason the transaction controls matter more than the convenience. A spending limit is not a nice-to-have feature. It is the mechanism that bounds your exposure in the case where nobody yet knows who is responsible.

We are not offering a legal view, and neither should anyone else writing about this. What we can say is that anyone telling you liability is clearly resolved is describing one company’s terms and conditions, not a settled framework.

Diagram comparing an AI shopping assistant that recommends with an AI agent that completes the purchase

What could go wrong, specifically

Not to alarm — to make the risk concrete enough to plan around.

Specification failure. You asked for something ambiguous and got a technically compliant answer you did not want. The most common and least serious failure.

Scope creep. The agent takes an action reasonable in isolation but outside what you intended — booking a hotel because the flight arrived late, when you only asked about flights.

Merchant confusion. Repeated or duplicated orders when an agent retries a step it thinks failed. The industry-standard term is idempotency, and it is a well-understood engineering problem that is nonetheless a common early failure mode.

Manipulation. As above. An agent that reads product pages, reviews or emails is reading content someone else wrote.

Subscription drift. An agent authorised for recurring purchases continuing past the point you would have stopped, because nothing prompted you to reconsider.

Notice that only one of these involves anything resembling fraud. Most agentic commerce failures will be mundane, and mundane failures at scale are exactly what dispute systems exist to handle.

Where this is actually up to

It is worth calibrating expectations, because the coverage runs hot.

The infrastructure is real and being built by serious parties. Visa and Mastercard both have live initiatives. Real transactions have been completed. Major AI vendors are partnered in.

The scale is early. Industry projections describe agentic commerce reaching a small single-digit percentage of digital transactions by the end of the decade, with much larger numbers cited for the 2030s. Those are forecasts from interested parties, and they should be read as directional rather than as data — but even the optimistic versions describe something that is small now and grows over years.

The consumer-facing reality in most markets today is that this is arriving as an opt-in feature inside specific products rather than as a general capability. You are unlikely to encounter it by accident. You are increasingly likely to be offered it.

What to check before you enable it

Five questions, answerable from any implementation’s settings and terms.

  1. What is the spending limit, and can I set it lower? If there is no limit, that is the finding.
  2. Which merchants or categories can it transact with? Bounded is better than open.
  3. Does anything require my approval, and what? A confirmation step before purchase removes most of the risk while keeping most of the convenience.
  4. How do I see what it did? If you cannot review a transaction log, you cannot dispute what you cannot reconstruct.
  5. What do the terms say about disputes? Specifically: is an agent-initiated transaction treated as authorised by you? That single answer tells you more about your exposure than anything else on the page.

If the answers are unsatisfying, the reasonable position is to wait. The convenience gain from letting an agent complete a purchase rather than presenting you with one is genuinely modest, and it will still be available when the frameworks mature.

The broader pattern is one TechyKnow has traced across stablecoin adoption and infrastructure and decentralised applications and Web3: payment technology consistently arrives before the rules that govern it, and the people who adopt earliest carry risks that later adopters never see, because the rules get written in response to what went wrong.

The practical next step: if any service offers you agent-initiated purchasing, find the spending limit setting before you find the convenience. If there is not one, that is your answer for now.


FAQs

What is agentic commerce?

Agentic commerce describes transactions initiated or completed by an AI agent acting on a person’s behalf. The distinction from a shopping assistant is execution — an assistant recommends and you buy, while an agent completes the purchase itself.

Can an AI agent really make a purchase for me?

Yes. Mastercard launched its Agent Suite in Q2 2026, Visa runs an Intelligent Commerce initiative, and a Spanish banking group and Mastercard reported completing what they describe as Europe’s first live end-to-end payment executed by an AI agent. In most markets it currently arrives as an opt-in feature inside specific products.

Who is liable if an AI agent buys the wrong thing?

It depends on the implementation and is not fully settled. If the agent followed your instructions and you disliked the result, ordinary merchant refund terms apply. If it exceeded its authority or was manipulated, whether that counts as an unauthorised transaction is exactly what the frameworks are still working out. Check the specific terms rather than assuming card protections carry over.

How do AI agents pay without having my card details?

Through tokenisation. Rather than holding your actual card number, the agent uses a token that stands in for your card for a constrained purpose, alongside authentication proving it acts for you and transaction controls limiting amount, merchant or category.

What is the Agentic Commerce Protocol?

ACP is a protocol from OpenAI and Stripe for agent-initiated transactions. It is one of at least four in play, alongside Anthropic’s Model Context Protocol and Google’s Agent Payments Protocol and Universal Commerce Protocol. The existence of four competing standards is a sign the infrastructure is not yet settled.

Is agentic commerce safe?

The technical design — tokenisation, authentication, transaction controls — is sensible. The unresolved part is the dispute and liability framework, which in conventional card payments took decades to mature. Setting a spending limit and requiring approval for purchases addresses most practical risk.

Can an AI agent be tricked into buying something?

This is a recognised concern. Agents that read external content such as product pages, reviews or emails are reading material written by others, which can contain instructions that alter behaviour — the same prompt-injection problem affecting AI agents generally. It is the scenario the liability frameworks are least prepared for.

Should I let an AI agent use my card?

That is a personal judgement, and a reasonable one either way. Before enabling it, check the spending limit, merchant restrictions, approval requirements, transaction log and dispute terms. If the terms do not state clearly how disputes are handled, waiting costs you very little.