An AI agent orders you the wrong size, the wrong color, or a hundred mugs instead of one. The charge is already on your card. So who’s on the hook — you, the retailer, or the company that built the agent?
Right now, the honest answer is: mostly you. Retailers and AI companies are actively writing the rules of agentic shopping in real time, and so far, most of those rules point the liability back at the person who granted the AI permission to buy things in the first place.
What Is an AI Shopping Agent, and How Common Are These Mistakes?
An AI shopping agent is software that can search for products, compare prices, add items to a cart, and in some cases complete checkout — all with limited or no step-by-step confirmation from a human. ChatGPT’s Instant Checkout, Perplexity’s Comet browser, Amazon’s “Buy for Me,” and Google’s Gemini shopping integrations are all live examples of this category, sometimes described in legal writing as “transactional agents” — systems that don’t just answer questions but actually move money.
Adoption is already well ahead of the legal groundwork. A global survey by fraud-prevention firm Riskified found that nearly three in four shoppers are already using AI somewhere in their shopping journey, and 70 percent said they’re at least somewhat comfortable letting an agent complete a purchase on their behalf, based on results reported by Barchart. A separate Ipsos poll found more than half of US adults would let an AI agent buy something without asking for final approval first, according to eMarketer’s reporting on Target’s policy changes.
Mistakes are already showing up alongside that adoption. Reporting on Amazon’s “Buy for Me” feature described cases where the tool pulled in products from sellers who hadn’t actually opted into the program, producing orders that were inaccurate or simply impossible to fill — a mess detailed in a critical breakdown of early agentic commerce rollouts. The same piece noted Google faced criticism for how aggressively its shopping agent pushed upsells during checkout.
What Do Retailers Say About Who’s Responsible?
Retailers have started answering the liability question directly in their terms of service, and the answer isn’t in the shopper’s favor.
Target updated its terms as it prepared to roll out a Google Gemini shopping integration, and the update is explicit: once a customer authorizes a third-party AI agent to access their account, any resulting purchase counts as a transaction the customer authorized — mistakes included. According to eMarketer’s coverage of the change, Target’s terms state plainly that it can’t guarantee an agent “will act exactly as you intend in all circumstances,” and that the customer still has to pay even if the agent buys the wrong item or acts on an incorrect price. The retailer isn’t hiding the tradeoff either — the same reporting notes that Target’s own disclaimers acknowledge the risk this creates for customer trust, even while shifting the legal exposure away from the company.
That’s the pattern to expect from most retailers for now: they’ll let you connect an AI agent to your account, but the fine print treats the agent’s actions as your actions, full stop.

What About the Company That Built the Agent?
This is where things get murkier, and where a lot of the unresolved legal debate is happening.
Legal analysts at Stanford Law’s Codex program have argued that AI companies offering shopping agents — what they call “Transactional Agent Providers” — can’t simply wave away responsibility by treating the agent as an independent actor. Their analysis walks through a blunt point: liability doesn’t disappear just because software, rather than a person, made the mistake, and companies offering these tools should expect to be the ones holding the risk when something goes wrong, as laid out in Stanford’s two-part breakdown of transactional agent law. The follow-up piece walks through concrete failure scenarios — an agent that orders 100 units instead of one, or maxes out someone’s card on duplicate purchases — and frames these as the kind of “mistakes at AI scale” that current law was never built to handle cleanly, detailed in part two of the series.
There’s already a real legal precedent that AI companies can’t fully hide behind a “the bot said it, not us” defense. In a widely cited case, a Canadian tribunal held Air Canada responsible after its website chatbot gave a customer inaccurate information about a bereavement discount. The airline argued it couldn’t be held liable for its own chatbot’s statements — a defense the tribunal rejected outright, a case discussed in a legal analysis of AI agent responsibility published on arXiv. It wasn’t a shopping-agent case specifically, but it’s the closest thing the industry has to a real ruling on whether “the AI did it” is a valid legal shield — and so far, courts don’t seem inclined to accept that argument.
Are There New Laws Being Written For This?
Yes, though most of them aren’t finished yet.
The European Union has overhauled its product liability rules with a new directive — Regulation (EU) 2024/2853 — that updates the decades-old framework for defective products to account for software and AI systems more directly. EU member states have until December 9, 2026 to bring their national laws in line with it, based on legal analysis tracked by JD Supra’s coverage of the directive. Separately, the EU AI Act — the first AI-specific legal framework in the bloc — adds another layer of compliance obligations, though legal experts note it wasn’t designed to cleanly mesh with existing privacy and liability law, creating gaps that transactional agent providers will have to navigate as more of these tools launch.
In the US, there’s no single federal law addressing AI shopping agent liability yet. Instead, the rules are being written contract by contract, through retailer terms of service, and increasingly through the payment networks themselves.
How Are Visa, Mastercard, and Other Payment Networks Handling This?
This is arguably where the most concrete progress is happening, because card networks have a direct financial stake in knowing who pays when an agentic purchase goes wrong.
Mastercard’s Agent Pay framework, launched in partnership with Microsoft, IBM, and Braintree, issues a tokenized credential — called an Agentic Token — that’s scoped to a specific AI agent, a specific merchant, and a specific spending policy, rather than handing the agent a raw card number. According to a breakdown of the program, liability for these transactions follows Mastercard’s existing tokenized-transaction rules: the card issuer carries fraud liability when the token was properly issued and the agreed policy was followed at checkout, and the consumer keeps normal chargeback rights, as explained by a support resource covering Agent Pay.
Visa has taken a similar approach with its Trusted Agent Protocol and broader Intelligent Commerce initiative, designed to help merchants tell the difference between a legitimate AI agent and a bot impersonating one, and to give every agent-driven purchase a verifiable trail back to the person who authorized it, according to Visa’s own announcement of the protocol. American Express has followed with its own agent purchase protection commitment for cardholders.
But even the payment industry admits the bigger disputes remain unsettled. Worldpay’s agentic commerce lead put it plainly: liability allocation between the merchant, the card issuer, and the AI agent’s platform “remains largely unresolved once a dispute moves past straightforward fraud,” according to Worldpay’s own analysis of the current landscape. In other words, the networks have built the plumbing to track who authorized what — but deciding who actually eats the cost when an agent simply makes a bad call, rather than gets hacked or spoofed, is still being negotiated case by case.
Mastercard and Visa have also begun working with Ant International on a shared “know-your-agent” framework, aimed at letting different networks and wallets verify an agent’s identity consistently — a step industry executives frame as foundational to building trust in the system at all, as reported by American Banker.
So Who Actually Pays When the Agent Gets It Wrong?
Based on where things stand today, the practical answer breaks down into three layers:
If you gave the agent permission to buy things, you’re probably paying. Most retailer terms of service, following Target’s lead, treat an authorized agent’s purchases as your own actions — including its mistakes. This is the default right now, and it’s unlikely to change quickly, since it’s the position that costs retailers the least.
If the agent was hijacked, spoofed, or acted outside its authorized limits, the card network’s fraud protections likely apply. This is where tokenized agent credentials from Mastercard and Visa matter — if a fraudster impersonated an agent or exceeded the spending mandate a token was scoped to, that starts to look like standard unauthorized-transaction fraud, which issuers are already equipped to handle.
If the AI company itself gave objectively false information that led to the mistake — quoting a wrong price, misdescribing a product, confirming an order it shouldn’t have — the Air Canada precedent suggests courts may not let AI companies simply disclaim responsibility for what their own software said, even if that hasn’t been tested yet in a shopping-specific case.
The honest summary is that the industry is building fraud-detection infrastructure faster than it’s answering the harder legal question of who’s at fault when nothing was hacked and nothing was fraudulent — the agent just made a bad decision that a careful human wouldn’t have made.
What Should Shoppers Actually Do Right Now?
Until the legal and contractual dust settles, a few practical habits matter more than they might seem to:
- Read what permissions you’re actually granting before connecting an AI agent to a retail account — most terms of service now spell out, in plain language, that you’re accepting responsibility for the agent’s mistakes.
- Set spending limits and category restrictions where the platform allows it, since tokenized agent frameworks are built around exactly these kinds of bounded mandates.
- Keep a human-confirmation step for anything expensive or irreversible. Every framework built so far — Visa’s, Mastercard’s, and the independent Agentic Commerce Protocol from Stripe and OpenAI — is designed around the idea that low-value, repeat purchases can run autonomously, while larger purchases should still get a final human check.
- Treat “the AI bought the wrong thing” the same way you’d treat any other unauthorized-charge dispute: document what happened, and raise it with your card issuer if fraud or a platform error, rather than simple bad judgment, seems to be the cause.
Also Read: 10 Jobs Humanoid Robots Could Replace in the Future
Frequently Asked Questions
Who is responsible when an AI shopping agent buys the wrong product?
Under most current retailer terms of service, the person who authorized the AI agent to access their account is responsible for the purchases it makes, including mistakes. Card issuers may step in if the transaction involved fraud or exceeded the agent’s authorized limits.
Can I get a refund if an AI agent buys the wrong item?
It depends on the retailer’s standard return policy, not on the fact that an AI made the purchase. Most retailers, including Target, treat agent-driven purchases as ordinary transactions once they’re authorized — so normal return and refund rules apply, but there’s no special AI-mistake protection built in yet.
Has any court ruled on AI agent liability for purchases?
Not specifically for shopping agents yet, but a Canadian tribunal held Air Canada responsible after its chatbot gave a customer false information, rejecting the airline’s argument that it wasn’t liable for its own AI’s statements. That case is widely cited as a signal of how courts may treat AI-driven mistakes more broadly.
Are Visa and Mastercard building rules for this?
Yes. Both have launched agentic commerce frameworks — Mastercard’s Agent Pay and Visa’s Trusted Agent Protocol — that issue verified, scoped credentials to AI agents and apply existing fraud-liability rules when a token is properly issued and used within its agreed limits.
Is there a law specifically about AI shopping agent mistakes?
Not yet in the US. The EU has updated its product liability directive and AI Act, with member states required to comply by December 2026, but neither law was written specifically around shopping agents, and US regulation currently relies on a patchwork of company terms of service rather than dedicated legislation.
Should I let an AI agent make purchases without confirming each one?
Most current frameworks are designed around limiting fully autonomous purchases to low-value, repeat orders, while recommending a human confirmation step for anything expensive or hard to reverse. That’s a reasonable line to draw for your own shopping until liability rules are clearer.


