An agent buys the wrong flight. The cardholder delegated authority. The agent acted within scope. The result was a ticket to São Paulo on the wrong date. Under Visa's rules, which now define an Agentic Transaction and require 120-day retention of order confirmations, the cardholder is responsible for the agent's actions "as if the Cardholder initiated the Transaction." This is already live. Real agents completing real purchases in European commerce. Real disputes will follow.
The trouble is that the dispute machinery was built for a world it no longer describes. Existing reason codes sort failures into categories designed for human-initiated transactions: fraud, authorization failure, processing error, consumer dispute. "The agent translated my intent badly" fits none of them. Visa's own thought leadership acknowledges there is "no settled way" to unwind a wrong payment once agents transact at machine speed. The taxonomy assumes the buyer either was the cardholder or followed explicit instructions. It has no slot for an intermediary that interpreted what the cardholder probably meant and got the interpretation wrong.
Payments will solve this. The institutional infrastructure there is already dense enough to absorb a new failure category. The structural pattern that chargebacks encode, though, is worth understanding precisely, because almost nothing else in the agent ecosystem has developed anything like it.
A chargeback has specific institutional bones: a taxonomy that names the nature of the failure, a bounded window for contestation, a defined adjudication sequence, and clear cost allocation. Someone pays at every stage. A $15 to $20 fee attaches to the dispute itself. Merchants whose chargeback rates exceed network thresholds face monitoring programs, fee increases, eventual termination. The reason merchants invest in fraud prevention is that the cost structure makes neglect expensive. Remove cost allocation and you remove the feedback loop. The system stops self-correcting.
This cost-allocation structure is absent everywhere else agents act on delegated authority. A coding agent produces a pull request that passes automated checks but breaks the intent of the feature. A support agent closes a ticket in a way that satisfies the resolution metric but harms the customer. Code has diffs, tests, rollback. Payments have dispute codes and arbitration. These are disagreement infrastructures, and they matter. But disagreement infrastructure and cost-allocation infrastructure are different things entirely. GitHub's terms place responsibility on users for reviewing AI output. OpenAI's agreement caps liability at twelve months of fees. These are legal positions. They tell you who the contract says is liable. They do not give you a process for contesting an authorized-but-wrong action, categorizing what went wrong, or making neglect expensive enough to prevent.
Cost allocation changes behavior. An accountability structure creates incentives for the system to improve. A liability disclaimer assigns blame after the damage is done.
Every system of delegated authority eventually develops a mechanism for contesting authorized-but-wrong actions. The agent ecosystem will too. The question is whether that mechanism arrives through deliberate institutional design or through the slower, more expensive process of waiting for failures to accumulate until someone builds the machinery in response. We have collectively managed transitions like this before. We have also collectively managed to defer them until the cost of deferral exceeded the cost of design. Someone always pays. It is rarely the people who chose to wait.
- Task success ≠ safe execution: A Singapore/Korea AI Safety Institute evaluation found that agents completing tasks correctly still leaked data through unnecessary access or inappropriate disclosure, reinforcing that "authorized" and "acceptable" measure different things.
- Traces don't carry mandate: A June 2026 preprint on delegated-execution observability argues that identical audit logs can mean incompatible things depending on the delegation assignment, which is exactly the evidentiary gap a chargeback-like process would need to close.
- Mastercard's parallel architecture: Mastercard launched Agent Pay for Machines in June 2026 with credentialing, permissioning, and settlement for machine-speed transactions, and a partner quote explicitly names chargebacks and dispute resolution as design considerations.
- Web traffic gets purpose labels: Cloudflare's updated bot docs now classify AI traffic into Search, Agent, and Training categories with different default policies for each, showing that recognition-before-negotiation is becoming infrastructure beyond payments.

