← Writing · Open Finance & Inclusion
Flux Working Paper No. 38

The Chargeback Assumes a Human

Ken Ruto · Flux (FluxImpact) · September 2026 · 22 min · Updated Sep 2026
Revision history
2026-09-18 — full white-paper revision: scope/jurisdiction section, the Regulation E definition read against agent deployments, what the card schemes have shipped, objections, falsification conditions, evidence table and citation register.
↩ Read as essay
BibTeX · RIS
Abstract

The Flux procurement trust series argues across three papers that spending control is migrating from after a purchase to before it. Each assumes the purchase succeeds. This paper examines the failure case and argues that prevention has collapsed to the instant of payment while recourse has not moved, because the dispute mechanism is evidentiary rather than financial and is built around a participant the transaction no longer contains. The gap sits in the definitional layer, not the procedural one: the controlling United States definition of an unauthorised electronic fund transfer turns on initiation by a person other than the consumer, without actual authority, yielding the consumer no benefit — and expressly excludes transfers initiated by anyone the consumer furnished with means of access. A correctly deployed agent that buys the wrong thing satisfies every limb, so the mechanism does not fail but declines to engage. Four consequences follow: intent is distributed across a goal, a policy, a model selection and an instrument, with no addressee; the agent's timestamped log is superior evidence the process has no slot for, because admitting it would reintroduce the investigation cost the design exists to avoid; scoped credentials improve prevention precisely by detaching the transaction from a named person; and continuous transacting removes the occasion for human detection. The paper surveys what the card schemes have actually shipped, argues that assigning liability to the deployer provides no remedy and mistakes the common case of a non-delivering seller, and sketches three properties agent-appropriate recourse would require. No pilot is reported.

Keywords: agentic commerce, payments, chargebacks, dispute resolution, procurement, AI agents, liability, audit trails

Three papers in this series describe the same shift from different angles. The Corporate Card Was Never the Solution argues that spending authority can now be issued per transaction, to software, in advance. The Agentic Buyer and the End of Dark Patterns argues that a machine buyer is immune to the psychology the pricing page is built on. The Expense Report Was Never About Expenses argues that once limits are enforced at the moment of payment, checking afterwards has nothing left to do.

Each is about the same movement: control migrating from after the purchase to before it. Each assumes the purchase goes as intended.

None of them asks what happens when it does not. That is the gap this paper closes, and the answer is more awkward than I expected when I started writing it. Prevention has collapsed to the instant of payment. Recourse has not moved at all, and the mechanism we would reach for is built around a participant the transaction no longer has.

The strongest form of the claim is not that the rules are behind — rules are always behind. It is that the gap is written into the definitional layer rather than the procedural one. A dispute regime does not merely lack a procedure for agent-initiated purchases; in at least one major regime the controlling definition of a wrongful transfer turns on whether the payer furnished access to the party that initiated it, which makes a correctly-deployed agent's mistaken purchase authorised as a matter of construction.1 You cannot patch that with a new claim reason code. It is upstream of the codes.

KANAIRO://WP38 — ONE HALF MOVED, THE OTHER DID NOT PREVENTION COLLAPSED TO t=0. RECOURSE STAYED WHERE IT WAS. AUTHORITY WP11 · WP18 PER-TRANSACTION LIMITENFORCED BEFORE THE BUY SETTLED IN MILLISECONDS. RECOURSE BUILT FOR CARDHOLDERS NOTICED FILED RESOLVED SCHEMATIC — THE SHAPE IS THE CLAIM, NOT THE INTERVALS CHARGEBACKREQUIRES A HUMAN THE AGENT CANNOT ATTEST TO WHAT IT MEANT TO BUY. NOTHING IN THE LANE BELOW KNOWS THAT YET. THREE PAPERS ASKED WHAT CHANGES WHEN AGENTS BUY. THIS ONE ASKS WHAT HAPPENS WHEN THEY BUY WRONGLY. Prevention collapsed to t=0. Recourse stayed where it was.

1. Scope, method, and jurisdiction

No pilot. Flux has not run agent-initiated purchasing at a scale that would produce a dispute. Nothing in this paper is measured, and where I describe a failure mode I am reasoning about mechanism, not reporting an incident.

Which rules I have read and which I have not. I have read the controlling United States definition of an unauthorised electronic fund transfer and quote it in §3.1 I have not read the card networks' operating regulations, which are not public. Statements about what the schemes have and have not published come from payments-industry reporting, are attributed as such, and are the weakest evidence in the paper.2

A jurisdiction problem I want to put at the top rather than bury. Flux writes about African institutions, and the legal instrument this paper leans on hardest is American. I use it because it is the clearest available statement of an assumption that is not peculiar to the United States — that a wrongful payment is one a person did not authorise — and because its text is public in a way scheme rules are not. I have not established what Kenya's equivalent regime says, and the argument's applicability to a mobile-money-dominated market where the dominant rails are not card rails is genuinely open. §10 treats that as a limitation and Appendix B registers it as the most important missing source.

What is mine. The four-way breakdown in §4, the argument in §6 that assigning liability is not the same as providing recourse, and the three properties in §7. Those are the parts to attack.

2. What a dispute is actually asking

A chargeback looks like a financial mechanism and is really an evidentiary one. Strip away the network rules and it asks a cardholder two questions: did you authorise this, and was what you received what you were promised?

Both questions are addressed to a person, and both depend on a faculty the process assumes without naming — that the buyer had an intention, that the intention is recoverable after the fact, and that the buyer can attest to it. This is why the mechanism works at all. It is not adjudicating the truth of the world. It is adjudicating one party's account of what they meant against another's account of what they delivered.

Notice what that design buys. It is extraordinarily cheap. It needs no investigation of the merchant's systems, no forensic reconstruction, no expert evidence. It needs one assertion from a party who was present, tested against another assertion from a party who was also present, with the burden allocated by rule rather than by proof. The mechanism scales to billions of transactions precisely because it substitutes attestation for investigation.

That substitution is the load-bearing element, and it is invisible until the buyer is software.

KANAIRO://WP38 — THE QUESTION WITH NO ADDRESSEE A DISPUTE IS AN EVIDENTIARY MECHANISM, NOT A FINANCIAL ONE CARDHOLDER AGENT "DID YOU AUTHORISE THIS?" ASSUMES A PARTY THAT CAN BE ASKED "WAS IT WHAT YOU WERE PROMISED?" ASSUMES A RECOVERABLE INTENTION ? ? NO ADDRESSEE NO INTENTION THE AGENT'S SIGNED LOG GOAL · POLICY · SELECTION · AUTHORISATION COMPLETE, TIMESTAMPED, TAMPER-EVIDENT NO SLOT TO RECEIVE IT BETTER EVIDENCE · NO STANDING THE BEST EVIDENCE IN THE TRANSACTION IS THE EVIDENCE THE MECHANISM CANNOT ACCEPT. Both questions are addressed to someone who can be asked. The best evidence in the transaction is the evidence the mechanism cannot accept.

3. The assumption, in the text

It is worth seeing how explicit this is in the law rather than treating it as an implicit design assumption, because the explicitness is what makes it hard to route around.

Under the United States regime, an unauthorised electronic fund transfer is one "initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." The same definition then carves out any transfer "initiated by a person other than the consumer who was furnished with the card, code, or other means of access to such consumer's account by such consumer," unless the consumer has told the institution that such transfers are no longer authorised.1

Read that against an agent deployment. The deploying party furnished the means of access — that is what issuing a credential to a process is. The agent had actual authority, in the only sense the definition uses: it was permitted to transact within a policy its principal wrote. And the consumer did receive a benefit, in that goods arrived; the complaint is that they were the wrong goods.

An agent that buys the wrong thing therefore produces a transfer that is authorised on all three limbs. Not a hard case. Not an edge case. A transfer the definition places outside the category of wrongful transfers by construction.

I want to be careful about what this does and does not establish. It does not establish that a wronged party has no remedy — ordinary contract law, scheme rules, and consumer protection statutes other than this one all still exist. It establishes something narrower and, I think, more interesting: that the specific cheap, fast, high-volume mechanism people mean when they say "just charge it back" is defined in terms of a human's authorisation state, and that a correctly functioning agent satisfies the definition of authorised even when it has done the wrong thing. The mechanism does not fail. It declines to engage.

4. Four things that break

Intent has no location. When an agent buys the wrong thing, there is no moment where anybody formed the wrong intention. There is a goal someone set, a policy someone wrote, a model that selected an action, and a payment instrument that permitted it. The error is distributed across all four. "What did you intend to buy" has no addressee.

This is worse than a gap in the rules, because the question is not merely unanswered but ill-formed. Each of the four parties can give a true answer that exonerates them: the goal-setter wanted a valid outcome, the policy permitted what was bought, the selection was the best available under the policy, and the instrument enforced its limits correctly. Every component behaved as specified and the aggregate behaved wrongly. Dispute processes are built to locate fault in a party, and this failure does not live in one.

The audit trail is better evidence and worse standing. This is the part I find genuinely strange. An agent can produce a complete, timestamped record of every input and every step — evidence incomparably better than a human's recollection weeks later. But the dispute process has no slot for it. It is designed to take an assertion from a cardholder, not a log from a program. The best evidence in the transaction is the evidence the mechanism cannot accept.

The reason is the substitution noted in §2. A process that accepted logs would have to evaluate them, which means investigation, which is the cost the whole design exists to avoid. Admitting better evidence would make the mechanism more accurate and destroy the economics that let it run at scale. That is a real trade-off and not an oversight, and any proposal to fix it — including mine in §7 — owes an answer to it.

The instruments narrow the buyer and widen the gap. A per-transaction limit is a real improvement in control and it makes attribution harder, not easier: a single-use credential issued to a process is deliberately detached from any named person. The instrument that gives you precise prevention is the same instrument that removes the human the recourse process needs.

The schemes' own architecture makes this concrete. The agent-payment frameworks announced across 2025 and 2026 work by binding a tokenised credential to a specific agent, a specific merchant scope and a specific consent policy, so that the agent transacts without ever holding the underlying card number.2 That is excellent security design. It also means the artefact that knows the most about what was authorised — the scoped token and the policy attached to it — is not the artefact the dispute process addresses. The dispute goes to the cardholder; the authority lives in the token.

Speed removes the window. Much of what makes after-the-fact dispute workable is latency — the delay between purchase and settlement in which a human notices. Accountability Is Not a Reason to Keep Humans in the Process argued, correctly, that inserting a person purely to approve things does not produce accountability. That argument is about approval. It does not follow that removing the person leaves the recourse path intact, and I think this series has been quietly assuming it does.

The asymmetry compounds. An agent transacting continuously produces a volume of purchases no reviewer reads, which means the detection step that a dispute process assumes — somebody notices a line they do not recognise — has no natural occasion. Detection has to become a monitoring function, which is a system somebody has to build and fund, and which none of the three earlier papers budgets for.

5. What the schemes have actually shipped

The previous version of this paper marked a citation as needed here and declined to characterise rules I had not read. Some of it is now answerable, and the answer is more specific than "nobody has thought about it."

Both major networks shipped agent frameworks in 2025 — Mastercard's in late April and Visa's a day later — followed across 2025 and 2026 by successor and connecting products, an agent-authentication protocol, and an EMVCo task force examining how the underlying specifications would accommodate agentic payments.2 American Express has gone furthest on the recourse question specifically, publishing a protection for card members against error by a registered agent, subject to eligibility conditions.2

What remains unshipped, on the reporting I can find, is a binding liability rule for the non-fraud agent dispute. Fraud is comparatively settled: where a token is validly issued and the policy honoured at authorisation, liability follows the existing tokenised-transaction rules. The unsettled case is the one this paper is about — the agent that was not compromised, was not misused, and bought the wrong thing — and on that, liability today falls where it falls by default, which in almost every configuration means on the merchant of record.2

Three observations about that.

It is a default, not a decision. Nobody argued that the merchant should carry the cost of a buyer's software misreading its instructions; the merchant carries it because the merchant is where chargeback liability has always attached. Defaults that nobody chose are the ones that produce the worst incentives, because no party designed them to be survivable.

Amex's move is the shape of the right answer and shows its cost. Protecting the card member against agent error requires a registry of agents — somebody has to say which agent is the registered one — and eligibility conditions doing the work of a policy. That is the identity infrastructure §7 asks for, arriving as a proprietary product of one network rather than as a rail.

And the European position may be sharper still, in that authentication rules requiring strong customer authentication were written around a customer who is present to be authenticated.2 I have not read those rules against agent flows and will not characterise them further than that.

6. Why "the company is liable" is not an answer

The obvious response is that liability sits with whoever deployed the agent, and in the simple case that is right. It is also the end of a much shorter paper than the situation deserves.

It assigns liability without providing recourse. Knowing the deploying organisation is answerable tells you nothing about how the money comes back, who the counterparty is, or what evidentiary standard applies — and if the answer is "it does not come back, absorb it as a cost of automation," that is a real answer with real consequences for who can afford to deploy agents at all. Small organisations absorb losses badly. A recourse regime that exists only for those who can self-insure is the same shape of problem as the compliance gap elsewhere in this corpus: a rule that is formally universal and practically available to the well-resourced.

This is the point at which the paper stops being about payments. A technology whose failure mode is survivable only by parties with a balance sheet is a technology that concentrates, whatever its nominal availability. The three earlier papers in this series argue that agentic purchasing is a capability African institutions could finally afford. If the unpriced tail risk of deploying it is unbounded and uninsurable, that argument needs an asterisk, and it is my argument, so the asterisk is mine to add.

It mistakes the common case. The case that actually matters is not a defective agent but a defective seller — an agent that bought exactly what it was told to buy from a merchant who did not deliver. That is an ordinary commercial dispute in which the buyer happens to be software, and it is the case the existing mechanism should handle and cannot. Nothing about the deployer's liability helps here; the deployer is the wronged party.

It ignores the merchant's exposure. §5 notes that in practice the merchant carries the chargeback. So the deploying organisation is liable in principle to its own stakeholders while the merchant is liable in practice to the network. Both parties bear a cost for an error neither committed, and the party that built the agent — the model provider, the orchestration vendor — is in most configurations liable to neither.

7. What recourse built for an agent would need

Three properties, none of which I have built, all of which follow from the above.

It would have to accept a log as testimony. A signed, tamper-evident record of the goal, the policy, the selection and the authorisation, admissible in place of a cardholder's assertion. The technical part of this is the easy part; the standards and acceptance are not. And §4 is the real objection: admitting evidence that must be evaluated reintroduces the investigation cost the mechanism was designed to avoid. The answer, if there is one, is that a structured log is machine-evaluable in a way a human narrative is not — the adjudication could stay cheap because the evidence is uniform. I believe that and have not demonstrated it.

It would have to attach the dispute to the authority rather than the buyer. The per-transaction credential already encodes who authorised what, for how much, against which policy. That credential is the natural locus of a dispute, and nothing currently treats it as one. The question a dispute should ask is not "did you authorise this" but "was this within the authority that was issued" — which is answerable from the token and the policy without asking anyone what they remember.

It would have to run on the same clock as the prevention. A control that acts in milliseconds paired with a remedy that takes weeks is not a system; it is two systems, and the second one is the one you meet on your worst day. This is the property I am least able to specify and most confident about. Where prevention and recourse run on different clocks, parties rationally over-constrain prevention — which is to say they under-deploy the capability — because the remedy is not worth reaching for.

A fourth that I considered and cannot defend: agent insurance. It is the obvious market answer, it would solve the distributional problem in §6, and I have no basis for an opinion on whether the loss distribution is underwritable. I raise it so the omission is deliberate.

8. Objections I take seriously

"This is a transitional problem; the rules will catch up." Probably true in part, and §5 shows movement. What I doubt is that it catches up cheaply, because §3 locates the assumption in a definition rather than a procedure, and definitions in consumer-protection statutes move on legislative timescales. Meanwhile the deployment decision is being made now, by parties who will discover the gap in arrears.

"Agents will simply be scoped so tightly that errors cannot happen." This is the strongest practical objection and it is the direction the industry is taking. It works, and its cost is the whole thesis of the earlier papers: an agent scoped narrowly enough to be error-proof is an agent that cannot do the thing that made it worth deploying. The scope you can safely give an agent is a function of how survivable its mistakes are, which is a function of recourse. Recourse is therefore not a back-office concern; it is the binding constraint on capability.

"The chargeback was always a blunt instrument and good riddance." Sympathetic to this. It is over-used, merchants suffer under it, and a purpose-built agentic dispute regime could be better than what it replaces. My claim is not that the chargeback is good. It is that nothing has replaced it, and the interval between removing a mechanism and building its successor is where the losses fall.

"You are arguing against the position of your own earlier papers." No, and this matters to me. Those papers are not wrong; §10 says so explicitly. The claim is narrower: each of them moves control earlier, none of them notices what that does to the machinery for putting things right, and the series owes the reader that accounting.

9. What would falsify this

A network publishes a binding non-fraud liability rule for agent-initiated disputes that does not require a human attestation. That is the paper's central gap closed, and I would say so.

Agent-initiated purchase errors turn out to be rare enough that recourse is economically irrelevant. The argument is about a tail. If the tail is thin enough, §8's second objection wins and scoping really is sufficient.

The merchant-carries-it default proves stable and uncontested. §6 predicts pressure from merchants as agent volume grows. If volumes rise and the default holds without dispute, I have overestimated how badly the incentives are misaligned.

Kenya's regime turns out not to share the assumption. §3's argument is built on one jurisdiction's text. If the mobile-money dispute frameworks that dominate this market define wrongfulness without reference to a person's authorisation state, then the paper's central claim does not travel to the market Flux actually works in, and it should be rewritten rather than generalised.

10. Limitations, and what this paper does not claim

It reports no pilot. Flux has not run agent-initiated purchasing at a scale that would produce a dispute, so nothing here is measured.

It does not claim the card networks are unaware of this or that nobody is working on it — §5 shows the opposite. It claims that what has shipped addresses authentication and fraud, that the non-fraud dispute remains allocated by default, and that I am relying on industry reporting rather than on scheme rules I cannot read.

It does not establish the Kenyan position, and Flux's readers are mostly in markets where the card rails are not the main rails. The paper's mechanism argument should survive the translation; its legal argument may not.

And it does not claim the three earlier papers are wrong. They are not. Spending authority should be issued per transaction; the pricing page will have to become machine-readable; the expense report is a relic of after-the-fact checking. The claim is narrower and, I think, harder to dismiss: every one of those arguments moves control earlier, and none of them notices that the machinery for putting things right was built around a participant we have just finished removing.


Appendix A — Evidence table

L primary legal text, I payments-industry reporting, C established within this corpus, not sourced.

# Claim used in this paper Value Source
1 Unauthorised EFT defined by initiation "by a person other than the consumer" without actual authority and with no benefit to the consumer 12 CFR § 1005.2(m) L1
2 Carve-out where the consumer furnished the means of access 12 CFR § 1005.2(m) L1
3 Mastercard agent payment framework announced late April 2025 I2
4 Visa agent commerce framework announced late April 2025 I2
5 Agent credentials bound to agent, merchant scope and consent policy architectural, both schemes I2
6 Amex protection against registered-agent error announced 2026, conditions apply I2
7 EMVCo task force on agentic payments in progress I2
8 No published binding non-fraud liability rule for agent disputes as at publication I2
9 Chargeback liability attaches at merchant of record in most configurations qualitative I2
10 Kenyan / mobile-money equivalent of rows 1–2
11 Incidence of agent purchase error per 1,000 agent-initiated transactions
12 Median time from agent purchase to human detection, in deployments
13 Loss distribution for agent purchase error (is it underwritable?)
14 Share of agent disputes that are seller non-delivery rather than agent error

Row 10 is the one that decides whether this paper belongs in this corpus as written. Row 14 is the one that decides whether §6's "defective seller" point is the main case or a footnote; my instinct is that it is the main case and an instinct is not a measurement.

Appendix B — Open questions and citation register

CITATION-NEEDED — the Kenyan and mobile-money position. What the dispute and reversal frameworks governing Kenya's dominant payment rails say about a transfer initiated by software to which the payer granted access, and whether any of them turn on a natural person's authorisation state the way 12 CFR § 1005.2(m) does. This is the single most important missing source in the paper and it is missing because I did not find an authoritative public text, not because I did not look.

CITATION-NEEDED — scheme operating regulations. Everything in §5 rests on payments-industry reporting. The operating regulations themselves are not public, and no claim in this paper about what a network has or has not published should be treated as more than a well-sourced secondhand account.

CITATION-NEEDED — PSD2 / strong customer authentication against agent flows. §5 notes the question and declines to answer it. Somebody should read the regulatory technical standards against a delegated-agent flow properly.

CITATION-NEEDED — error rates. Appendix A rows 11–12. No public dataset of agent purchase error rates exists that I could find. Until one does, §8's second objection cannot be settled either way, and the honest position is that the size of the problem is unknown while its structure is not.

  1. 12 CFR § 1005.2(m) (Regulation E, Electronic Fund Transfers), implementing the Electronic Fund Transfer Act. "Unauthorized electronic fund transfer means an electronic fund transfer from a consumer's account initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." The definition excludes a transfer initiated by a person who was furnished the card, code or other means of access by the consumer, unless the consumer has notified the institution that such transfers are no longer authorized. Text: ecfr.gov, title 12, part 1005. Cited here as the clearest public statement of an assumption this paper argues is general, not as the law governing Flux's own market — see §1 and Appendix B.

  2. Payments-industry reporting on agentic commerce frameworks and liability allocation, including Worldpay, "Agentic commerce liability is still being written," which describes the Mastercard and Visa agent frameworks, the American Express registered-agent protection, the EMVCo task force, and the absence of a liability shift for non-fraud agent disputes. Scheme operating regulations are not public; these are secondhand accounts and are treated as such throughout §5.

Provenance
Flux Working Paper No. 38 · Ken Ruto, Flux (FluxImpact)
Published 14 Sep 2026 · revised 18 Sep 2026
Content hash (SHA-256): 018ed7c80a299de6… · build ce0a586
DOI: pending deposit
Ken Ruto
About the author
Ken Ruto

Founder of Flux. Building vertical AI-powered SaaS for Africa's institutions — and writing the thesis behind every bet. kenruto.fluximpact.org →

Share X LinkedIn WhatsApp
Did this land?
Was it useful?

Comments

No comments yet — be the first.

Replying to · cancel
Get new essays

No spam — just the next piece when it's out.

Think I got something wrong? Highlight any sentence to push back on it — or It comes straight to me, never shown publicly.

Push back
The procurement trust series
11 min
The Corporate Card Was Never the Solution
Every procurement solution since 1950 — charge cards, corporate cards, P-cards, virtual cards — has been a partial answer to the same trust problem: how do you authorize a specific transaction without manually validating every purchase after the fact? Stripe's agent wallet, launched April 2026, is the first complete answer.
12 min
The Agentic Buyer and the End of Dark Patterns
The SaaS pricing page is not where a company tells you what its product costs. It is where a company attempts to alter your decision-making. An AI procurement agent has no psychological vulnerabilities. It cannot be anchored, socially pressured, or confused by artificial urgency. This is going to restructure B2B software pricing — structurally, not incrementally.
7 min
The Expense Report Was Never About Expenses
The expense report is one of the most universally resented administrative instruments in corporate life. Understanding why it exists — what it is actually for — is the prerequisite for understanding why agentic payment infrastructure makes it obsolete.