DEV Community

The Agent Loop
The Agent Loop

Posted on

Who eats the loss when your AI agent spends your money?

Drafted with AI help, human-reviewed by The Agent Loop.

How the rails read as of October 2026. Not legal advice; your issuer agreement and your jurisdiction beat anything here.

When your AI agent buys something with your card details, the loss lands on you. Every liability rule on these rails turns on a single question: was the transaction unauthorized? Hand an agent your credentials and, by the text of those rules, the transaction was authorized. That is the whole trick.

The five-line version:

  • US Regulation E excludes transfers by anyone you "furnished the access device", and the official commentary says you are fully liable even when they exceed the authority you gave.
  • Visa's zero-liability policy "solely covers unauthorized payments". A purchase your agent made with your blessing isn't one.
  • We could find no rule, issuer policy, or court decision that treats "an AI did it" as a defense (checked October 2026). The industry calls it an open question.
  • The one bound that works today is set before the damage: hard limits on a pre-funded card.
  • The lever during the damage: tell the bank that person's transfers are no longer authorized, and the protections re-engage.

The three ceilings

Two readers of our bank-accounts post drew the frame I wish I had used. Ownership is one ceiling (can an agent hold the account). Authentication is a lower one (did this transaction get strong customer authentication). The third ceiling is the one this post is about: liability, who eats the loss when it goes wrong (mickyarun's comment). Ownership debates take years. A disputed charge lands this month.

What the rules actually say

Regulation E defines an "unauthorized electronic fund transfer" as one initiated by a person other than you "without actual authority to initiate the transfer" (12 CFR 1005.2(m)). The same paragraph excludes transfers initiated "by a person who was furnished the access device to the consumer's account by the consumer". You gave your agent the card. It is that person.

The official staff commentary closes the escape hatch: if you grant authority to a person, "such as a family member or co-worker", and they exceed the authority given, "the consumer is fully liable for the transfers" until you tell the bank otherwise (Official Staff Commentary 2(m)-2, via CFPB's EFT FAQs). Banking-industry commentary puts it as a sandwich-versus-Tesla story: tell someone to buy a sandwich, they buy a Tesla, that's not a bank problem (Backbase, 2026).

The caps in 1005.6 ($50 in two days, $500 within sixty, unlimited after) only attach to unauthorized transfers. Your agent's purchase never enters that machinery.

Visa's side matches: the fraud-risk FAQ says zero-liability "solely covers unauthorized payments", excludes transactions "initiated by the consumer", and doesn't apply to certain commercial cards (Visa Direct Fraud Risk FAQ). Issuer cardholder agreements go further and may exclude any transaction made "by a person authorized to transact business on the account" or one that "exceeds the authority given by the account owner" (example issuer terms).

The EU has the same shape from a different direction. PSD2 Article 74 puts unauthorised-transaction losses on the payer up to €50, and removes even that when strong customer authentication was not used (EBA, Article 74). But the shield is built for stolen instruments, not delegated ones. Whether an AI agent you authorized counts as an authorized delegate remains an open question.

Who eats it: four setups

Setup Who eats the bad purchase The bound
Personal card, agent has your credentials You, fully Whatever the agent can reach
Same, after you revoke with the bank Back into the normal dispute process Regulation E caps re-attach
Pre-funded card, hard daily limit You, up to the limit The limit, per day
Registered agent on Amex's network Amex, per its published commitment Their terms

Rows three and four are the whole policy debate compressed. hannune, the second commenter, wrote what I now consider the design rule: a pre-funded card with a hard daily limit "makes the card the unit of audit instead of the agent" (thread). Open-ended liability plus an autonomous spender is the default row, and the one nobody should be in.

What is actually moving in 2026

Honesty requires the parts that cut against us:

  • Merchants got a new weapon first. Visa's compelling-evidence 3.0 rule (April 2023) invalidates a fraud dispute when evidence shows the cardholder or an authorized person participated in the transaction. "My agent did it" can therefore lose at the merchant fight-back stage too, on the device, IP, and login history the agent itself generated (Visa merchant FAQ).
  • The networks shipped the front end before the back end. Visa expanded its Agentic Ready program globally in late April 2026; Mastercard and Santander ran Europe's first live regulated agent payment in March 2026; Amex published an agentic commerce kit and a commitment to cover erroneous purchases by registered agents (Chargebacks911 via Finopotamus, May 2026). The same piece warns the dispute infrastructure behind those launches "remains almost entirely unaddressed", against a Mastercard forecast: chargebacks growing 24% to 324 million a year by 2028, before agent impact.
  • The protocol layer is where the fix lives. Visa's Trusted Agent Protocol, Mastercard Agent Pay, and Google's AP2 all aim at the real problem: cryptographically proving what the consumer authorized the agent to do at the moment of delegation, not reconstructed after a dispute (Chargeflow, July 2026).
  • Regulators stepped aside on purpose. The Fed, OCC, and FDIC's SR 26-2 (April 2026) explicitly placed generative and agentic AI outside its updated model-risk guidance as "novel and rapidly evolving". No country has agentic-commerce liability law; PSD3 is still being negotiated (Chargeflow, CentsChat).

My own limit, checked twice while writing: I looked for one published rule, decision, or issuer policy that treats an agent as a special case, and found none. If you know one, the comments are for exactly that.

Three questions before you hand over a card

From mickyarun's test, made operational:

  1. Who is the accountable party on this rail, and does zero-liability even apply to this card type (commercial cards are the known carve-out)?
  2. What reverses this transaction, on what clock, and whose logs count as evidence, mine or only the bank's?
  3. What is the worst day? If the answer is open-ended, the daily limit comes before the agent, not after.

Bottom line: liability is the ceiling that falls first. Until a rule says otherwise, on the payment rails your agent is you: it spends under your authority, it loses under your name. Keep the bound small, know your revocation line, and ask the three questions first.

FAQ

Is my AI agent's purchase "unauthorized" under Regulation E?
Almost certainly not, if you gave the agent your credentials. The definition excludes transfers by a person you furnished with the access device; the staff commentary holds you fully liable even when they exceed the authority you granted.

Does Visa zero-liability save me from my agent's mistake?
No. The policy covers unauthorized payments only. Purchases you initiated or delegated don't qualify, and issuer terms may add explicit carve-outs for authorized persons and commercial cards.

Is the AI company liable instead?
Not under anything we could source as of October 2026. Industry reviews call the question open, and Amex's registered-agent commitment is the one published exception that shifts loss from you to a network.

What should I do before giving an agent spending access?
Run the three questions above, put the agent on a pre-funded card with a hard daily limit, and write down the revocation path (who to call to make their transfers unauthorized again) before the first transaction.

Related on The Agent Loop

Sources

  1. 12 CFR 1005.2: Definitions, including "unauthorized electronic fund transfer" (CFPB)
  2. CFPB Electronic Fund Transfers FAQs, incl. Staff Commentary 2(m)-2
  3. 12 CFR 1005.6: Liability of consumer for unauthorized transfers
  4. Visa Direct Risk and Compliance FAQ
  5. Visa Evolution of Compelling Evidence, Merchant FAQs (March 2023)
  6. PSD2 Article 74, EBA Single Rulebook
  7. Issuer zero-liability exclusion example, Credit Union of Colorado
  8. Who's liable when a customer's AI agent authorizes the wrong payment (Backbase)
  9. AI Agent Chargeback Liability (Chargeflow, July 2026)
  10. Chargebacks911 warns AI agents are creating a new era of dispute risk (Finopotamus, May 2026)
  11. Agentic payments are coming. Accountability is not optional. (CentsChat, June 2026)
  12. mickyarun, comment on Can an AI agent have a bank account in 2026?
  13. hannune, same thread

If this post changed how you read your own exposure, tap the unicorn below; one click, and it is the only metric Dev.to shows me. Follow The Agent Loop for the rest of this series on where agent money actually goes.

Every post also lands in an inbox: subscribe by email, one email per post and nothing else.


Has your agent ever spent money you didn't expect? What did the bank or card issuer say the moment you told them an agent did it? Reply below.

Top comments (0)