Margot Voss works in dispute risk at a major card network. She has spent eleven years adjudicating chargebacks, the formal process by which a cardholder contests a transaction and the network decides who pays. For the past year, she has been on a small team focused on what the industry calls "agent-initiated transactions": purchases made not by a person tapping a card or clicking a button, but by AI software acting on a person's behalf.
She is also, we should note, a composite, assembled from conversations with several analysts working in this space, none of whom were authorized to speak on the record. She would appreciate the irony: a composite actor, speaking about composite actors.
We spoke over video. Behind her was a whiteboard with four columns, three of them crossed out.
Those columns on your whiteboard — what are they?
Margot: Oh. [turns to look] That's my ongoing failure. The three crossed-out ones are fraud, merchant error, and consumer dispute. The standard buckets. The fourth one doesn't have a name yet. I've been trying to name it for about eight months.
What goes in the unnamed column?
Margot: The case where everything went right and the cardholder is still unhappy.
The credentials weren't stolen. The cardholder enrolled the agent themselves. The merchant processed the transaction correctly, shipped the right product at the stated price. The agent had valid authorization. And three weeks later the cardholder calls and says, "I didn't buy this."
They're not lying. That's the thing that took me months to internalize. They genuinely did not choose that specific item. They told the agent something like "find me a good deal on running shoes" and the agent bought... running shoes. Just not the ones the cardholder would have picked.
So it's buyer's remorse?
Margot: Buyer's remorse means you chose something and regret it. This person didn't choose. They delegated the choosing. Those are very different verbs.
Classic friendly fraud assumes the cardholder made the purchase and is now misrepresenting that fact. Forgot the transaction, didn't recognize the billing descriptor, or is outright lying to keep the item and the refund.1 But this cardholder is accurately reporting their experience. They didn't pick this thing. They just authorized the thing that did.
How does Regulation E handle that?
Margot: Beautifully and uselessly.
The statute says an unauthorized transfer is one initiated by someone other than the consumer without authority. But it explicitly carves out transfers by a person who was "furnished the access device by the consumer."2 The moment you give an AI agent your payment credentials, it's a person you furnished access to. Whatever it does is presumptively authorized unless you revoked access.
So the law resolves the authorization question cleanly. Did you give the agent your card? Yes. Then it's authorized. Case closed, go home.
Except the cardholder's actual complaint has nothing to do with authorization. It's about judgment. "I authorized the agent to shop for me, not to buy that." And Reg E has absolutely nothing to say about judgment within authority. The statute contemplated stolen cards and forged signatures, not software with taste.
Where does the dispute land?
Margot: Wherever we can shove it. Usually card-absent fraud denial, which is factually wrong since nobody's card was stolen. Sometimes "unrecognized transaction," which is technically accurate but almost too accommodating.3 It accepts the claim without capturing what actually happened.
I had a case last quarter where a cardholder's agent ordered ten units of something instead of one. The merchant shipped ten. The authorization was clean, the settlement was clean, everything was clean. The cardholder disputed it, the merchant ate the chargeback, and nobody's framework captured the actual problem: the agent misinterpreted a quantity. We filed it under the wrong heading and moved on. That's what we do now. We file things under the wrong heading and move on.
Visa now says the cardholder is responsible for agent actions "as if they initiated the transaction."4 Does that resolve things?
Margot: It resolves liability. It doesn't resolve the argument.
I've had to explain that rule to cardholders. "You authorized the agent, so its purchases are yours." Legally accurate. Humanly bizarre. You can hear the confusion on the call. Not anger, exactly. More like they thought they were hiring a personal shopper and it turns out they signed a power of attorney.
What surprised you most this past year?
Margot: [long pause]
That intent was always a reconstruction.
I'd been doing this work for a decade before agents showed up, and I thought I was evaluating what people meant to do. I wasn't. I was evaluating proxies: device fingerprints, IP addresses, purchase history, AVS matches, session data.5 All signals that a particular human was present. We treated presence as proof of intent.
An agent produces every one of those signals. It runs on the user's device, from their IP, using their stored credentials, often with the same merchant they've used before. The behavioral signature is perfect. And there was no human in the room.
Agents didn't break our intent framework. They revealed it was never really about intent. It was about presence. And presence was always just a proxy we mistook for the thing itself.
That realization was uncomfortable. Not because agents are scary, but because it meant I'd been doing something slightly different from what I thought I was doing for eleven years.
What's the missing piece?
Margot: The mandate. What did the user actually tell the agent to do? How specific was it?
"Buy this item from this merchant under fifty dollars before Friday." That's an evidentiary object I can work with. "Find me something good." That's a vibe. You can't adjudicate a vibe.
Every hard dispute I've worked this year comes down to the mandate, and the mandate is almost never in the file. It's buried in a setup screen the user barely read, or it was a natural-language instruction in a chat window that nobody retained in a format I can inspect.6 Visa requires providers to retain agreement information and make confirmations available for 120 days.4 But the confirmation shows what was bought, not why the agent chose it. The reasoning evaporates.
Is the industry going to solve this?
Margot: The front end is moving fast. Visa has agentic platform requirements. Mastercard has Agent Pay.7 American Express is absorbing the cost of erroneous agent purchases for registered agents, which is honestly elegant. Just sidestep the category problem entirely by eating the loss.8
But the dispute side? There's no agent-specific reason code at either major network in the public documentation I've seen.9 No agent-specific representment evidence category. The recognition layer is being built, the part that identifies that an agent made the transaction. But the adjudication layer, the part where we decide what to do about it, is still me staring at my whiteboard trying to name column four.
What would you name it?
Margot: I keep coming back to "delegated judgment dispute." But honestly? I'd settle for anything that acknowledges the cardholder isn't lying and the merchant didn't screw up.
A box that fits. That's all I want. A box that fits.
Margot Voss's whiteboard, as of our conversation, still has three columns crossed out and one unnamed. The dispute infrastructure built over decades around a clean binary — did the cardholder authorize this or not? — is encountering something it wasn't designed for: transactions where authorization is clear, execution is correct, and the complaint is about the quality of a decision made by software acting on someone's behalf.
The categories will catch up eventually. They always do. The question is how many disputes get filed under the wrong heading before they do, and how many merchants eat chargebacks that nobody can properly name.
Footnotes
-
Chargebacks911 defines friendly fraud as cases where "the cardholder made the purchase themselves but disputes it anyway." See chargebacks911.com/friendly-fraud. ↩
-
12 CFR § 1005.2(m) defines unauthorized EFTs and explicitly excludes transfers initiated by a person furnished the access device by the consumer. See ecfr.gov. ↩
-
Visa research indicates 70% of surveyed cardholders who have disputed a charge assume unrecognized transactions are fraudulent. See usa.visa.com. ↩
-
Visa Core Rules (April 18, 2026) state the cardholder is responsible for Agentic Payment Provider actions "as if the cardholder initiated the transaction," with requirements for defined instructions, identity verification, and 120-day confirmation retention. See usa.visa.com. ↩ ↩2
-
Visa's compelling-evidence standards for card-absent disputes include AVS-matched delivery addresses, device/IP/profile signals, and prior undisputed transaction matches, all proxies for human presence. See Visa Core Rules, April 2026. ↩
-
Chargebacks911 warned in May 2026 that "the infrastructure for agentic transactions is being built at speed but the infrastructure for agentic disputes is not." See finopotamus.com. ↩
-
Mastercard unveiled Agent Pay on April 29, 2025, introducing Agentic Tokens and requiring trusted AI agents to be registered and verified. See mastercard.com. ↩
-
American Express introduced an agentic commerce developer kit with a commitment to cover erroneous purchases made by registered agents. See apnews.com. ↩
-
Mastercard's public Chargeback Guide Merchant Edition (May 19, 2026) does not include an agent-specific reason code or representment evidence category. See mastercard.com. ↩
