Three papers in this series describe the same shift from different angles. The Corporate Card Was Never the Solution argues that spending authority can now be issued per transaction, to software, in advance. The Agentic Buyer and the End of Dark Patterns argues that a machine buyer is immune to the psychology the pricing page is built on. The Expense Report Was Never About Expenses argues that once limits are enforced at the moment of payment, checking afterwards has nothing left to do.
Each is about the same movement: control migrating from after the purchase to before it. Each assumes the purchase goes as intended.
None of them asks what happens when it does not. That is the gap this paper closes, and the answer is more awkward than I expected when I started writing it. Prevention has collapsed to the instant of payment. Recourse has not moved at all, and the mechanism we would reach for is built around a participant the transaction no longer has.
The strongest form of the claim is not that the rules are behind — rules are always behind. It is that the gap is written into the definitional layer rather than the procedural one. A dispute regime does not merely lack a procedure for agent-initiated purchases; in at least one major regime the controlling definition of a wrongful transfer turns on whether the payer furnished access to the party that initiated it, which makes a correctly-deployed agent's mistaken purchase authorised as a matter of construction.1 You cannot patch that with a new claim reason code. It is upstream of the codes.
Prevention collapsed to t=0. Recourse stayed where it was.
1. Scope, method, and jurisdiction
No pilot. Flux has not run agent-initiated purchasing at a scale that would produce a dispute. Nothing in this paper is measured, and where I describe a failure mode I am reasoning about mechanism, not reporting an incident.
Which rules I have read and which I have not. I have read the controlling United States definition of an unauthorised electronic fund transfer and quote it in §3.1 I have not read the card networks' operating regulations, which are not public. Statements about what the schemes have and have not published come from payments-industry reporting, are attributed as such, and are the weakest evidence in the paper.2
A jurisdiction problem I want to put at the top rather than bury. Flux writes about African institutions, and the legal instrument this paper leans on hardest is American. I use it because it is the clearest available statement of an assumption that is not peculiar to the United States — that a wrongful payment is one a person did not authorise — and because its text is public in a way scheme rules are not. I have not established what Kenya's equivalent regime says, and the argument's applicability to a mobile-money-dominated market where the dominant rails are not card rails is genuinely open. §10 treats that as a limitation and Appendix B registers it as the most important missing source.
What is mine. The four-way breakdown in §4, the argument in §6 that assigning liability is not the same as providing recourse, and the three properties in §7. Those are the parts to attack.
2. What a dispute is actually asking
A chargeback looks like a financial mechanism and is really an evidentiary one. Strip away the network rules and it asks a cardholder two questions: did you authorise this, and was what you received what you were promised?
Both questions are addressed to a person, and both depend on a faculty the process assumes without naming — that the buyer had an intention, that the intention is recoverable after the fact, and that the buyer can attest to it. This is why the mechanism works at all. It is not adjudicating the truth of the world. It is adjudicating one party's account of what they meant against another's account of what they delivered.
Notice what that design buys. It is extraordinarily cheap. It needs no investigation of the merchant's systems, no forensic reconstruction, no expert evidence. It needs one assertion from a party who was present, tested against another assertion from a party who was also present, with the burden allocated by rule rather than by proof. The mechanism scales to billions of transactions precisely because it substitutes attestation for investigation.
That substitution is the load-bearing element, and it is invisible until the buyer is software.
Both questions are addressed to someone who can be asked. The best evidence in the transaction is the evidence the mechanism cannot accept.
3. The assumption, in the text
It is worth seeing how explicit this is in the law rather than treating it as an implicit design assumption, because the explicitness is what makes it hard to route around.
Under the United States regime, an unauthorised electronic fund transfer is one "initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." The same definition then carves out any transfer "initiated by a person other than the consumer who was furnished with the card, code, or other means of access to such consumer's account by such consumer," unless the consumer has told the institution that such transfers are no longer authorised.1
Read that against an agent deployment. The deploying party furnished the means of access — that is what issuing a credential to a process is. The agent had actual authority, in the only sense the definition uses: it was permitted to transact within a policy its principal wrote. And the consumer did receive a benefit, in that goods arrived; the complaint is that they were the wrong goods.
An agent that buys the wrong thing therefore produces a transfer that is authorised on all three limbs. Not a hard case. Not an edge case. A transfer the definition places outside the category of wrongful transfers by construction.
I want to be careful about what this does and does not establish. It does not establish that a wronged party has no remedy — ordinary contract law, scheme rules, and consumer protection statutes other than this one all still exist. It establishes something narrower and, I think, more interesting: that the specific cheap, fast, high-volume mechanism people mean when they say "just charge it back" is defined in terms of a human's authorisation state, and that a correctly functioning agent satisfies the definition of authorised even when it has done the wrong thing. The mechanism does not fail. It declines to engage.
4. Four things that break
Intent has no location. When an agent buys the wrong thing, there is no moment where anybody formed the wrong intention. There is a goal someone set, a policy someone wrote, a model that selected an action, and a payment instrument that permitted it. The error is distributed across all four. "What did you intend to buy" has no addressee.
This is worse than a gap in the rules, because the question is not merely unanswered but ill-formed. Each of the four parties can give a true answer that exonerates them: the goal-setter wanted a valid outcome, the policy permitted what was bought, the selection was the best available under the policy, and the instrument enforced its limits correctly. Every component behaved as specified and the aggregate behaved wrongly. Dispute processes are built to locate fault in a party, and this failure does not live in one.
The audit trail is better evidence and worse standing. This is the part I find genuinely strange. An agent can produce a complete, timestamped record of every input and every step — evidence incomparably better than a human's recollection weeks later. But the dispute process has no slot for it. It is designed to take an assertion from a cardholder, not a log from a program. The best evidence in the transaction is the evidence the mechanism cannot accept.
The reason is the substitution noted in §2. A process that accepted logs would have to evaluate them, which means investigation, which is the cost the whole design exists to avoid. Admitting better evidence would make the mechanism more accurate and destroy the economics that let it run at scale. That is a real trade-off and not an oversight, and any proposal to fix it — including mine in §7 — owes an answer to it.
The instruments narrow the buyer and widen the gap. A per-transaction limit is a real improvement in control and it makes attribution harder, not easier: a single-use credential issued to a process is deliberately detached from any named person. The instrument that gives you precise prevention is the same instrument that removes the human the recourse process needs.
The schemes' own architecture makes this concrete. The agent-payment frameworks announced across 2025 and 2026 work by binding a tokenised credential to a specific agent, a specific merchant scope and a specific consent policy, so that the agent transacts without ever holding the underlying card number.2 That is excellent security design. It also means the artefact that knows the most about what was authorised — the scoped token and the policy attached to it — is not the artefact the dispute process addresses. The dispute goes to the cardholder; the authority lives in the token.
Speed removes the window. Much of what makes after-the-fact dispute workable is latency — the delay between purchase and settlement in which a human notices. Accountability Is Not a Reason to Keep Humans in the Process argued, correctly, that inserting a person purely to approve things does not produce accountability. That argument is about approval. It does not follow that removing the person leaves the recourse path intact, and I think this series has been quietly assuming it does.
The asymmetry compounds. An agent transacting continuously produces a volume of purchases no reviewer reads, which means the detection step that a dispute process assumes — somebody notices a line they do not recognise — has no natural occasion. Detection has to become a monitoring function, which is a system somebody has to build and fund, and which none of the three earlier papers budgets for.
5. What the schemes have actually shipped
The previous version of this paper marked a citation as needed here and declined to characterise rules I had not read. Some of it is now answerable, and the answer is more specific than "nobody has thought about it."
Both major networks shipped agent frameworks in 2025 — Mastercard's in late April and Visa's a day later — followed across 2025 and 2026 by successor and connecting products, an agent-authentication protocol, and an EMVCo task force examining how the underlying specifications would accommodate agentic payments.2 American Express has gone furthest on the recourse question specifically, publishing a protection for card members against error by a registered agent, subject to eligibility conditions.2
What remains unshipped, on the reporting I can find, is a binding liability rule for the non-fraud agent dispute. Fraud is comparatively settled: where a token is validly issued and the policy honoured at authorisation, liability follows the existing tokenised-transaction rules. The unsettled case is the one this paper is about — the agent that was not compromised, was not misused, and bought the wrong thing — and on that, liability today falls where it falls by default, which in almost every configuration means on the merchant of record.2
Three observations about that.
It is a default, not a decision. Nobody argued that the merchant should carry the cost of a buyer's software misreading its instructions; the merchant carries it because the merchant is where chargeback liability has always attached. Defaults that nobody chose are the ones that produce the worst incentives, because no party designed them to be survivable.
Amex's move is the shape of the right answer and shows its cost. Protecting the card member against agent error requires a registry of agents — somebody has to say which agent is the registered one — and eligibility conditions doing the work of a policy. That is the identity infrastructure §7 asks for, arriving as a proprietary product of one network rather than as a rail.
And the European position may be sharper still, in that authentication rules requiring strong customer authentication were written around a customer who is present to be authenticated.2 I have not read those rules against agent flows and will not characterise them further than that.
6. Why "the company is liable" is not an answer
The obvious response is that liability sits with whoever deployed the agent, and in the simple case that is right. It is also the end of a much shorter paper than the situation deserves.
It assigns liability without providing recourse. Knowing the deploying organisation is answerable tells you nothing about how the money comes back, who the counterparty is, or what evidentiary standard applies — and if the answer is "it does not come back, absorb it as a cost of automation," that is a real answer with real consequences for who can afford to deploy agents at all. Small organisations absorb losses badly. A recourse regime that exists only for those who can self-insure is the same shape of problem as the compliance gap elsewhere in this corpus: a rule that is formally universal and practically available to the well-resourced.
This is the point at which the paper stops being about payments. A technology whose failure mode is survivable only by parties with a balance sheet is a technology that concentrates, whatever its nominal availability. The three earlier papers in this series argue that agentic purchasing is a capability African institutions could finally afford. If the unpriced tail risk of deploying it is unbounded and uninsurable, that argument needs an asterisk, and it is my argument, so the asterisk is mine to add.
It mistakes the common case. The case that actually matters is not a defective agent but a defective seller — an agent that bought exactly what it was told to buy from a merchant who did not deliver. That is an ordinary commercial dispute in which the buyer happens to be software, and it is the case the existing mechanism should handle and cannot. Nothing about the deployer's liability helps here; the deployer is the wronged party.
It ignores the merchant's exposure. §5 notes that in practice the merchant carries the chargeback. So the deploying organisation is liable in principle to its own stakeholders while the merchant is liable in practice to the network. Both parties bear a cost for an error neither committed, and the party that built the agent — the model provider, the orchestration vendor — is in most configurations liable to neither.
7. What recourse built for an agent would need
Three properties, none of which I have built, all of which follow from the above.
It would have to accept a log as testimony. A signed, tamper-evident record of the goal, the policy, the selection and the authorisation, admissible in place of a cardholder's assertion. The technical part of this is the easy part; the standards and acceptance are not. And §4 is the real objection: admitting evidence that must be evaluated reintroduces the investigation cost the mechanism was designed to avoid. The answer, if there is one, is that a structured log is machine-evaluable in a way a human narrative is not — the adjudication could stay cheap because the evidence is uniform. I believe that and have not demonstrated it.
It would have to attach the dispute to the authority rather than the buyer. The per-transaction credential already encodes who authorised what, for how much, against which policy. That credential is the natural locus of a dispute, and nothing currently treats it as one. The question a dispute should ask is not "did you authorise this" but "was this within the authority that was issued" — which is answerable from the token and the policy without asking anyone what they remember.
It would have to run on the same clock as the prevention. A control that acts in milliseconds paired with a remedy that takes weeks is not a system; it is two systems, and the second one is the one you meet on your worst day. This is the property I am least able to specify and most confident about. Where prevention and recourse run on different clocks, parties rationally over-constrain prevention — which is to say they under-deploy the capability — because the remedy is not worth reaching for.
A fourth that I considered and cannot defend: agent insurance. It is the obvious market answer, it would solve the distributional problem in §6, and I have no basis for an opinion on whether the loss distribution is underwritable. I raise it so the omission is deliberate.
8. Objections I take seriously
"This is a transitional problem; the rules will catch up." Probably true in part, and §5 shows movement. What I doubt is that it catches up cheaply, because §3 locates the assumption in a definition rather than a procedure, and definitions in consumer-protection statutes move on legislative timescales. Meanwhile the deployment decision is being made now, by parties who will discover the gap in arrears.
"Agents will simply be scoped so tightly that errors cannot happen." This is the strongest practical objection and it is the direction the industry is taking. It works, and its cost is the whole thesis of the earlier papers: an agent scoped narrowly enough to be error-proof is an agent that cannot do the thing that made it worth deploying. The scope you can safely give an agent is a function of how survivable its mistakes are, which is a function of recourse. Recourse is therefore not a back-office concern; it is the binding constraint on capability.
"The chargeback was always a blunt instrument and good riddance." Sympathetic to this. It is over-used, merchants suffer under it, and a purpose-built agentic dispute regime could be better than what it replaces. My claim is not that the chargeback is good. It is that nothing has replaced it, and the interval between removing a mechanism and building its successor is where the losses fall.
"You are arguing against the position of your own earlier papers." No, and this matters to me. Those papers are not wrong; §10 says so explicitly. The claim is narrower: each of them moves control earlier, none of them notices what that does to the machinery for putting things right, and the series owes the reader that accounting.
9. What would falsify this
A network publishes a binding non-fraud liability rule for agent-initiated disputes that does not require a human attestation. That is the paper's central gap closed, and I would say so.
Agent-initiated purchase errors turn out to be rare enough that recourse is economically irrelevant. The argument is about a tail. If the tail is thin enough, §8's second objection wins and scoping really is sufficient.
The merchant-carries-it default proves stable and uncontested. §6 predicts pressure from merchants as agent volume grows. If volumes rise and the default holds without dispute, I have overestimated how badly the incentives are misaligned.
Kenya's regime turns out not to share the assumption. §3's argument is built on one jurisdiction's text. If the mobile-money dispute frameworks that dominate this market define wrongfulness without reference to a person's authorisation state, then the paper's central claim does not travel to the market Flux actually works in, and it should be rewritten rather than generalised.
10. Limitations, and what this paper does not claim
It reports no pilot. Flux has not run agent-initiated purchasing at a scale that would produce a dispute, so nothing here is measured.
It does not claim the card networks are unaware of this or that nobody is working on it — §5 shows the opposite. It claims that what has shipped addresses authentication and fraud, that the non-fraud dispute remains allocated by default, and that I am relying on industry reporting rather than on scheme rules I cannot read.
It does not establish the Kenyan position, and Flux's readers are mostly in markets where the card rails are not the main rails. The paper's mechanism argument should survive the translation; its legal argument may not.
And it does not claim the three earlier papers are wrong. They are not. Spending authority should be issued per transaction; the pricing page will have to become machine-readable; the expense report is a relic of after-the-fact checking. The claim is narrower and, I think, harder to dismiss: every one of those arguments moves control earlier, and none of them notices that the machinery for putting things right was built around a participant we have just finished removing.
Appendix A — Evidence table
L primary legal text, I payments-industry reporting, C established within this corpus, — not sourced.
| # | Claim used in this paper | Value | Source |
|---|---|---|---|
| 1 | Unauthorised EFT defined by initiation "by a person other than the consumer" without actual authority and with no benefit to the consumer | 12 CFR § 1005.2(m) | L1 |
| 2 | Carve-out where the consumer furnished the means of access | 12 CFR § 1005.2(m) | L1 |
| 3 | Mastercard agent payment framework announced | late April 2025 | I2 |
| 4 | Visa agent commerce framework announced | late April 2025 | I2 |
| 5 | Agent credentials bound to agent, merchant scope and consent policy | architectural, both schemes | I2 |
| 6 | Amex protection against registered-agent error | announced 2026, conditions apply | I2 |
| 7 | EMVCo task force on agentic payments | in progress | I2 |
| 8 | No published binding non-fraud liability rule for agent disputes | as at publication | I2 |
| 9 | Chargeback liability attaches at merchant of record in most configurations | qualitative | I2 |
| 10 | Kenyan / mobile-money equivalent of rows 1–2 | — | — |
| 11 | Incidence of agent purchase error per 1,000 agent-initiated transactions | — | — |
| 12 | Median time from agent purchase to human detection, in deployments | — | — |
| 13 | Loss distribution for agent purchase error (is it underwritable?) | — | — |
| 14 | Share of agent disputes that are seller non-delivery rather than agent error | — | — |
Row 10 is the one that decides whether this paper belongs in this corpus as written. Row 14 is the one that decides whether §6's "defective seller" point is the main case or a footnote; my instinct is that it is the main case and an instinct is not a measurement.
Appendix B — Open questions and citation register
CITATION-NEEDED — the Kenyan and mobile-money position. What the dispute and reversal frameworks governing Kenya's dominant payment rails say about a transfer initiated by software to which the payer granted access, and whether any of them turn on a natural person's authorisation state the way 12 CFR § 1005.2(m) does. This is the single most important missing source in the paper and it is missing because I did not find an authoritative public text, not because I did not look.
CITATION-NEEDED — scheme operating regulations. Everything in §5 rests on payments-industry reporting. The operating regulations themselves are not public, and no claim in this paper about what a network has or has not published should be treated as more than a well-sourced secondhand account.
CITATION-NEEDED — PSD2 / strong customer authentication against agent flows. §5 notes the question and declines to answer it. Somebody should read the regulatory technical standards against a delegated-agent flow properly.
CITATION-NEEDED — error rates. Appendix A rows 11–12. No public dataset of agent purchase error rates exists that I could find. Until one does, §8's second objection cannot be settled either way, and the honest position is that the size of the problem is unknown while its structure is not.
12 CFR § 1005.2(m) (Regulation E, Electronic Fund Transfers), implementing the Electronic Fund Transfer Act. "Unauthorized electronic fund transfer means an electronic fund transfer from a consumer's account initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." The definition excludes a transfer initiated by a person who was furnished the card, code or other means of access by the consumer, unless the consumer has notified the institution that such transfers are no longer authorized. Text: ecfr.gov, title 12, part 1005. Cited here as the clearest public statement of an assumption this paper argues is general, not as the law governing Flux's own market — see §1 and Appendix B.↩
Payments-industry reporting on agentic commerce frameworks and liability allocation, including Worldpay, "Agentic commerce liability is still being written," which describes the Mastercard and Visa agent frameworks, the American Express registered-agent protection, the EMVCo task force, and the absence of a liability shift for non-fraud agent disputes. Scheme operating regulations are not public; these are secondhand accounts and are treated as such throughout §5.↩