They compress the buying journey and can obscure where intent changed, where an action was authorised and who should be accountable. That makes chargebacks, impersonation and mistaken purchases more likely because the shopper may not recognise the payment context or may not fully understand what the agent approved.
Why agent-driven purchases shift fraud from checkout to authorization
Agent-driven purchases compress the decision and payment steps into fewer visible moments, so the fraud question moves from “did the shopper type the card details?” to “was this action really intended, understood and approved?” That matters because the payment may be valid on paper while the underlying consent, scope or context is disputed after the fact.
When an agent can search, compare and buy in one flow, small changes in intent become harder to spot. A shopper may approve a recommendation, but not realise the agent has crossed into a binding purchase, a higher quantity, a renewal or a different seller. The risk is not just theft, it is ambiguity.
That ambiguity is what makes disputes more likely. If the person whose account or payment method was used later says “I did not mean to authorise that,” the merchant, issuer and platform all have less evidence to separate genuine preference from mistaken approval. Agentic commerce therefore creates a wider gap between technical execution and human understanding.
Why disputes become harder to resolve after the purchase
Chargebacks and payment disputes usually rely on the parties being able to reconstruct intent, consent and transaction context. Agent-driven purchases weaken that reconstruction because the buyer may not remember the intermediate prompts, the merchant may only see a legitimate payment request, and the platform may not retain enough evidence about what the agent showed the user before submitting the order.
That problem is amplified when the agent uses stored payment credentials, delegated access or a shared household account. In those cases, it can be unclear whether the transaction belongs to the account owner, another authorised user, or an attacker who gained partial access and used the agent to make the purchase look routine.
Fraud teams should treat this as an attribution problem as much as a payment problem. If the system cannot prove which principal saw the offer, which principal approved it and what the agent was allowed to do, then dispute handling will lean toward manual review, longer resolution times and more conservative fraud decisions.
What makes agentic buying especially attractive to attackers
Fraudsters like flows that reduce friction, hide decision points and blur accountability. An agent-driven purchase can do all three. It may reuse authenticated sessions, cached preferences or trusted device context, which gives an attacker a chance to ride along with legitimate behaviour rather than force an obvious account takeover.
That is why agentic commerce identity has to be treated as a first-class control problem, not a UX feature. The same is true for AI agent authorisation, because the buyer’s risk depends on whether the agent is allowed to act per purchase, per merchant or per threshold, rather than with open-ended authority.
Where a purchase is made through a browser or device agent, browser and computer-use agent security becomes directly relevant, because session reuse, site scope and confirmation handling can turn a convenience feature into a fraud path. The strongest attacks do not look exotic, they look like normal shopping with the wrong actor in control.
Risk and Threat Considerations
Agent-driven purchasing increases exposure to mistaken-purchase disputes, impersonation, and refund abuse because the same workflow can hide both weak consent and malicious action. The more the agent is trusted to act without a fresh human checkpoint, the easier it is for an attacker or confused user to create a transaction that appears authorised but is later contested.
Failure mechanism: The agent can execute a purchase using valid credentials or a valid session while the user never sees, fully understands, or remembers the final transaction details, which breaks the evidentiary chain for intent and approval.
Impact: Merchants and payment providers face more chargebacks, more manual investigation, higher false-positive fraud flags, and more cases where the dispute cannot be resolved cleanly because the approval context is missing or ambiguous.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agent purchases depend on delegated authority and approval scope. |
| ASI09 — Human-Agent Trust Exploitation | Disputes often arise when users overtrust the agent's shopping decisions. | |
| Recommendation — Enforce per-action approval boundaries before an agent can submit binding orders. Add a final human confirmation gate for any order that changes price, quantity or seller. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Purchases hinge on whether the acting session or credential truly represents the buyer. |
| NHI-10 — Human Use of NHI | Agent purchases can blur who actually approved the transaction. | |
| Recommendation — Require stronger step-up verification before high-value or unusual purchases. Preserve explicit user approval records for any purchase the agent executes. | ||
| NIST SP 800-53 Rev 5 | AU-2 — Audit Events | Disputes need evidence of the approval and transaction path. |
| IA-2 — Identification and Authentication (Organizational Users) | Purchase authority must be tied to a verified principal before execution. | |
| Recommendation — Log the approval prompt, selected item set and final submitted order. Require reauthentication before orders that move beyond browsing or comparison. | ||
Practitioner Guidance
What to verify: For any agent that can complete a purchase, verify that the system records the user-visible offer, the final order summary, the approval event and the exact scope of authority used. If you cannot reconstruct those four points, you should expect dispute friction even when the payment itself is technically valid.
Decision rule: If the agent can change quantity, seller, subscription terms, shipping destination or payment instrument, require an explicit confirmation step immediately before submission. If it only suggests items and never binds the user, the fraud profile is materially lower.
What good looks like: The user can tell, after the fact, exactly what was approved and why; the merchant can show that same context; and the agent’s action history matches the approved scope without relying on guesswork.
Practitioner takeaway: The control objective is not to stop automation, it is to make every transaction that can create financial loss both narrowly authorised and easy to attribute when challenged.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org