Choose your region/language

Select your desired region and language below.

Choose your language

The site for the European Union is available in six languages.

Choose your language

The global site is available in five languages.

The Customer Is an AI Agent. And Who Is Liable?

The major card networks wired the banks of continental Europe for payments by AI agents in less than a year. What happens when the agent buys the wrong thing on the basis of a perfectly correct instruction is something nobody has decided yet.

On March 2 of this year, in Madrid, a piece of pure software bought something for the first time inside a regulated European banking framework.

Image Credits: Forbes España

Banco Santander and Mastercard announced that an AI agent had completed a payment from start to finish – over the bank’s live payment infrastructure. The transaction was small and controlled. The press release was carefully worded. It was not about the purchase. It was about the fact that the rail had worked under real conditions.

After that, things moved quickly. In June, Mastercard let the market know that all of its card-issuing banks in Europe had been enabled for Agent Pay at the network level and that banks across the continent had carried out controlled but real agentic transactions using passkey authentication. The published list ranged from Santander and UniCredit to Deutsche Bank, DZ Bank and N26. In July, at its payments forum in Paris, Visa announced that AI agents were now shopping at independent merchants – lastminute.com, Frasers, Cleverbridge, BrickDepot – on behalf of cardholders at more than 30 European issuers, among them Commerzbank, comdirect, Deutsche Kreditbank and S-Payment, the payments company of the Sparkassen-Finanzgruppe, the group of Germany’s savings banks.

Read the two lists together and something becomes visible that the individual announcements tend to hide. Germany’s private banks, its cooperative sector and its savings banks – the three pillars of the German banking system – have all let an agent pay within just a few months. The pipes have been laid.

What is not finished is everything else. There is no settled answer to the question of who bears the loss when an agent, acting on a valid instruction and authenticated by its user, books the wrong flight. There is no supervisory position on whether a single passkey confirmation can cover a purchase whose amount and merchant the agent will only determine later. Europe’s new rulebook for payments, agreed after years of negotiation, was finalized before even a single agent had paid on a live European rail. And the continent’s own sovereign payment system, built to reduce its dependence on the American card networks, has so far had almost nothing to say about agents.

This gap between the rail and the rules is the real story of agentic payments – as the industry calls payments that are made by agents – in Europe. It will decide more about the next decade of commerce than any single protocol.

Built on the old rails, on purpose

It is worth understanding what the networks actually shipped, because the design decision explains the consequences.

Neither Visa nor Mastercard built a new payment system for agents. They extended the card model. In Visa’s version, the consumer authenticates once with a Visa Payment Passkey that is bound to a specific instruction; the agent then acts within the parameters the consumer has set and pays with a tokenized card. On the merchant side, a Trusted Agent Protocol and an Agent Directory, implemented through infrastructure providers such as Cloudflare and Akamai, make sure that a website can recognize a verified agent and tell it apart from unverified bot traffic – without having to rebuild its checkout. Mastercard’s Agent Pay rests on the same principle: the consumer authorizes an agent with credentials they already trust, and the network carries the transaction.

Mathieu Altwegg, Visa’s head of products for Europe, has been open about the logic behind it: it is the same approach the company used to scale contactless payments. That is the decisive clue. Contactless did not invent a new liability regime. It inherited the card regime and adjusted a few of its parameters – amount limits, cumulative limits, the question of when a PIN is required. Agentic commerce is being built the same way: reuse the tokens, reuse the authentication, reuse the network’s dispute rules – and change the parameters.

 

There is real wisdom in this. The card model brings chargebacks, fraud liability rules and four decades of dispute resolution practice along with it. A consumer whose agent is cheated by a fake merchant is about as well protected as a consumer is today. The law firm Osborne Clarke describes agentic payments not as a regulatory regime of their own but as a new operating model – one that will test in practice whether the existing mechanisms of consent, strong authentication, fraud control and liability actually hold up. That is exactly right, and that is exactly the problem. These mechanisms were designed around a person who chooses, a person who initiates and a person who confirms. Agents break this chain right in the middle.

Authorized, but wrong

European payments law divides the world into two categories. A transaction is either authorized – the payer consented – or it is not. If it is not authorized, the bank refunds it, with narrow exceptions. If it is authorized, it belongs to the consumer, and any claim is directed against the merchant.

An agentic transaction is authorized by design. The user gave an instruction. The passkey confirmed the user’s identity and linked it to that instruction. The entire architecture of the network exists to make the authorization unambiguous. So when the agent books the 6:40 a.m. flight instead of the 6:40 p.m. one, orders the wrong size or orders the same item twice because a page was reloaded, the transaction is not unauthorized. It is authorized – and it is wrong.

Today’s framework has nothing at all for this category. Chargeback rules address the merchant’s failure: goods not delivered, goods not as described, a purchase billed twice by the seller. They do not address the agent’s failure, where the merchant did everything right and the software on the buyer’s side did not. The loss has to land somewhere, and there are only three candidates: the user, the agent’s provider or the card-issuing bank.

German civil law does not make any of this easier. The German Civil Code knows representation by a person; it does not know a software agent as a representative. The courts have long treated declarations that a computer system generates automatically as declarations of whoever uses the system. By that logic, the agent’s purchase is simply the user’s own declaration of intent – a mistaken one, perhaps, but theirs. The ways to rescind a mistaken declaration are narrow, and they were written for typos and garbled transmissions, not for a model that has misunderstood a preference.

The European Union had the chance to regulate exactly this class of problems and let it pass: in 2025, the Commission withdrew its proposal for an AI Liability Directive. The revised Product Liability Directive, which now treats software as a product, will cover defective agents in some cases. But a purchase that a properly working agent executed badly is not readily a product defect.

What Europe did finish is its payments package. On November 27, 2025, the European Parliament and the Council reached a provisional political agreement on the third Payment Services Directive (PSD3) and the Payment Services Regulation (PSR) – four months before the Santander transaction. The final compromise texts were published on April 23, 2026. They tighten fraud liability: a payment service provider that fails to implement adequate fraud prevention mechanisms is liable for its customers’ losses, and there is a new right to a refund in cases of impersonation fraud. They also impose real governance duties on issuers that outsource strong customer authentication to a technical service provider – due diligence in advance, written agreements on the scope and the responsibilities, unrestricted rights of access and audit. Publication in the Official Journal was expected in the summer; law firms warned that it could slip into September. The regulation then applies 21 months after it enters into force.

Do the math. The first rulebook of the agent era takes effect in 2028, and it was written for a world in which a person confirms every single payment. Judging by this one, the next revision is a decade away. In other words, the operating rules for agentic payments in Europe will be written first in private law – in the rulebooks of the card schemes, in the banks’ terms and conditions, in the contracts of the agent platforms – and only later, if ever, in public law. Anyone who wants to know how liability will actually work in 2027 should read the scheme rules of Mastercard and Visa and the special conditions of their bank, not the Official Journal.

The mandate problem

Beneath the liability question lies a more technical one, and it is the one supervisors have to answer first.

Strong customer authentication under European law requires that the authentication be dynamically linked to a specific amount and a specific payee. That is what makes a passkey confirmation meaningful in the first place: you approve this payment, to this merchant, for this sum. But the whole point of an agent is to decide some of these things after you have stopped watching. If the agent is told to find the cheapest nonstop flight for less than €300, the payee is unknown at the moment of authentication, and the amount is a ceiling, not a number.

There are only two ways out. One is to authenticate again at the moment of purchase – which amounts to a checkout with extra steps and defeats the purpose. The other is to accept that an agent operates under a mandate with limits, which has never been the model of a one-off card purchase. Europe does have mandate-shaped instruments – merchant-initiated transactions, direct debit mandates, standing orders – and the industry’s early answer is to borrow their logic. In a proof of concept that Nuvei, Visa, Arvato Systems and the fashion brand Kings and Priests completed in July, a merchant’s agent bought and paid inside the agent itself, with no handoff to a separate checkout, governed by guardrails that the buyer had set: spending limits and approved categories. Visa’s own description of its program says that every transaction is linked to a verified user and to that user’s explicit instruction.

Whether an instruction with a ceiling satisfies the requirement of dynamic linking is a question that no European supervisor has yet answered publicly. Until one does, every agent payment in Europe rests on an interpretation. And the new package’s outsourcing rules mean that an agent platform that takes over part of the authentication becomes, in supervisory terms, the bank’s technical service provider – a party the issuer must be able to vet, bind by contract, audit and get rid of again. That is not an app store relationship. It is the relationship a bank has with the vendor of its core banking system, and it will determine which agent companies banks are willing to work with at all.

Trust follows liability

Meanwhile, the consumer is waiting for none of this. A survey by Product.ai in April found that only 14 percent of consumers trust an AI agent to make purchases on their behalf; 86 percent check its recommendations before they buy anything. An analysis published ahead of this month’s Agentic Commerce & Payments Summit in Stockholm – the first conference devoted entirely to this intersection, and one whose coverage describes it as the moment the conversation shifted from feasibility to control and liability – set the forecast by Juniper Research, according to which agentic commerce will reach a volume of $1.5 trillion by 2030, against the volume that is actually flowing today: around $28,000 a day. Even the much-cited transaction numbers of the crypto-adjacent x402 protocol turn out on closer inspection to be mostly protocol signals, not purchases.

On the merchant side, things look quite different. A survey of merchants in Germany, Austria and Switzerland by msg for banking, whose full report is due to appear at the end of September, found more than 80 percent of respondents already working on agentic payments. This divergence – merchants pushing ahead, consumers holding back – is familiar from every payment innovation of the past thirty years, and it resolves itself the same way every time. Consumers did not learn to trust online shopping because the technology got better. They learned it because the card networks put a chargeback behind every single purchase and the loss was no longer theirs to carry. Contactless payments took off when the liability shift and the amount limit made a lost card somebody else’s problem.

The lesson can be generalized: trust follows liability, not the other way around. The 14 percent will become 60 percent on the day a bank tells its customers in writing what happens when the agent gets it wrong – and the answer is: “Not your problem.” The first issuer in Germany to offer such an agent guarantee will not be doing charity. It will be winning primary banking relationships.

The identity layer is only half built

Visa’s Agent Directory solves an important problem: it tells a merchant which agent is knocking at the door. But that is identity for the benefit of the seller. The buyer’s side of the relationship – which agent is acting, under whose mandate, with what authority and within what limits – has no comparable infrastructure, and it is the harder half.

Banks already know this problem under a different name. Know your customer is a set of questions: who are you, on whose behalf are you acting, and what are you authorized to do? Corporate banking has answered these questions for centuries with powers of attorney, signing authorities and spending limits, and every commercial banker in Germany maintains these records for the companies they look after. Visa has said that its agent model will be extended to corporate and B2B payments. When that happens, the agent will not arrive at the retail counter. It will arrive at the corporate banking desk, where a mandate is already a document with a signature – and where the bank’s oldest product, the authority to act on behalf of someone else, becomes what the agent needs before it may move a single euro.

That is the piece nobody has shipped yet. Checking whether an agent is a real, registered agent is a nearly solved problem. Checking whether this agent acts for this company under this mandate, and whether the mandate actually covers this action, is where the next generation of infrastructure – and the next generation of disputes – is going to live.

The sovereignty question

All of this is happening on American rails, and Europe has noticed.

Wero, the wallet of the European Payments Initiative – a consortium of 16 banks and payment service providers backed by the Eurosystem – exists precisely to reduce the continent’s dependence on Visa, Mastercard and the wallets of the big tech companies. Its path in 2026 has been one of reach: acceptance in e-commerce, a hub agreement with the national systems of the European Payments Alliance to connect well over a hundred million users, Raiffeisen Bank International joining, and the commitment by N26 to offer Wero in Germany, France and the Netherlands in the second half of the year. Political pressure to reduce the dependence on the US networks intensified in early 2026, and the European Central Bank has held out the prospect of a digital euro by 2029.

Agents barely feature in any of this. The card networks, by contrast, have named their programs, listed their banks and shipped their protocols. There is a certain irony in the fact that DZ Bank and S-Payment – the central institutions of the cooperative sector and of the Sparkassen-Finanzgruppe, the two groups most closely identified with a European payment alternative – carried out their very first agent transactions on Mastercard and Visa.

The stakes of the sovereignty question are higher this time than they were with the card, and for a concrete reason. A card rail moves money. An agent rail moves money and defines identity: which agents are trustworthy, under which mandate, verified by whom. If Europe imports the agent standard the way it imported the card standard, it is not merely renting the pipe. It is renting the directory – the register of who may act on behalf of whom – and that is a far more strategic dependence than interchange fees.

What comes next

Three predictions, phrased so that they can turn out to be wrong.

First: the defining dispute of agentic commerce in Europe will not be a fraud case. It will be a case of “authorized, but wrong”: a consumer, a bank and an agent provider arguing over a purchase that every single system authenticated correctly. The court will reach for the mandate – and will find that nobody ever wrote one down.

Second: the banks’ terms and conditions will define agent liability years before the legislator does. The PSR will apply in 2028 without an answer; the scheme rules and the special conditions will have one by 2027. That makes the wording of these documents over the coming twelve months one of the more consequential matters in European finance – and outside the payments departments, almost nobody ever reads them.

Third: the mandate becomes the product. Someone has to issue the instrument that says this agent may act for this person or this company within these limits, and has to vouch for it. Banks have issued this instrument – on paper – for as long as there have been banks. Whether they issue the digital version or leave it to the networks and the platforms is the real decision the industry faces. Germany’s three banking pillars, which have already let the agent pay, now have to make that decision deliberately.


Sources and further reading

Nuicorn