Aaron Cheiffetz is an analyst and executive strategist in the financial services industry, working with banking leaders on artificial intelligence governance, enterprise architecture, regulatory compliance and operational resiliency. He is based in Charlotte, North Carolina.
In the debit-card context, Regulation E generally limits a consumer's liability for unauthorized transfers involving a lost or stolen debit card to $50 if the loss is reported within two business days. But Regulation E excludes from its definition of an “unauthorized electronic fund transfer” a transfer initiated by a person to whom the consumer furnished the access device, unless the consumer has notified the financial institution that transfers by that person are no longer authorized.
The official commentary goes further: if a consumer furnishes an access device and grants another person authority to make transfers, the consumer can remain liable even when that person exceeds the authority given. Regulation E defines "person" to include both natural persons and organizations, including corporations.

What it doesn't say is how that rule applies when credentials are furnished to software operated by a company. A January research report by the Consumer Bankers Association asks whether sharing credentials with an AI tool could trigger this exclusion and leave the consumer responsible for the agent's mistakes.
In the credit-card context, the Truth in Lending Act, implemented by Regulation Z, provides a similar unauthorized-use framework that turns on whether another person had actual, implied, or apparent authority to use the account. Here too, it's unclear how that rule applies when an AI tool acts on a cardholder's behalf.
Visa and Mastercard have zero-liability policies for unauthorized transactions that go beyond federal law. But those policies still depend on a transaction being classified as unauthorized. They don't clearly resolve what happens when a consumer authorized an agent to transact but disputes whether a particular purchase fell within the scope of that authority.
These are the kinds of issues that should be addressed in agentic payment frameworks, which Mastercard and Visa are developing. Such frameworks envision the payment system recording or validating instructions given by users to agents and taking steps to make sure agents and merchants are who they purport to be and that transactions remain consistent with the consumer's mandate.
But a host of questions remain. There's no clear legal rule for who bears the loss when an AI tool exceeds its mandate. That's a problem for issuers as they contemplate making credentials available to AI tools.
Where risks aren't adequately addressed and priced, issuers may be tempted to act defensively by agreeing to credential-sharing only with sophisticated AI-tool providers under negotiated contracts, adopting onerous identity-confirmation processes, or refusing transactions in some circumstances. All of this would tilt the playing field in favor of incumbent platforms.
Some clarity about liability for unauthorized transactions will be important before agentic payments are rolled out more broadly. Voluntary efforts by banks and payment networks won't go far enough to assuage concerns. More fundamental issues of consumer liability need to be addressed.
At minimum, three things need to happen.
First, laws should distinguish between a consumer’s own acts and the acts of others, including AI tools acting on a consumer's behalf. Second, when consumers give others authority to initiate financial transactions, the parameters of that authority, such as amounts, merchants, timing, and other limits, should be documented in a form the payment system can use. Third, the allocation of losses among issuers, payment networks, merchants, and AI-tool providers should not be an issue for consumers.