The first hard question regulators are asking about agentic commerce isn't about AI safety in the abstract. It's about chargebacks.
When an AI agent buys something on a consumer's behalf — a flight, a restaurant reservation, a bulk order of industrial fasteners — and the merchant doesn't deliver, or the agent misunderstood the instructions, or the price that was authorized turned out to be different from the one that posted: who files the dispute? Under which account? And who has the legal obligation to make the consumer whole?
That question arrived formally in the US regulatory apparatus on June 27, 2026.
New York's Financial Regulator Puts Agentic Commerce on Notice
Speaking at the New York Federal Reserve's Innovation Conference, Kaitlin Asrow, Acting Superintendent of the New York Department of Financial Services, made the most explicit regulatory statement to date on autonomous agent transactions:
"The idea that a transaction can self-execute is a little jarring to a regulator."
Asrow's remarks weren't a condemnation of the technology. They were something more consequential: a signal that NYDFS — which regulates most major US financial institutions — is actively building a regulatory position on agentic commerce, and that the existing consumer protection framework may not be adequate for what the industry is already doing.
"How do I make sure that consumers are protected throughout?" she asked. "There's no one way in which AI is being applied, and there's no one way to do it right. But there's a lot of ways to do it wrong."
That last line is the one the industry should sit with. NYDFS has a track record of acting unilaterally when federal oversight lags. Its 2017 cybersecurity regulation became the de facto national standard well before federal equivalents existed. Its stablecoin framework — updated as recently as June 9, 2026 — set a template that other states and federal regulators have since adopted. If NYDFS issues agentic commerce guidance, it effectively becomes the US baseline.
What the Liability Gap Looks Like in Practice
To understand why Asrow's remarks matter, you need to understand how current chargeback and dispute mechanisms work — and why they were not built for autonomous agents.
Under Regulation E, consumers have strong protections when unauthorized transactions occur on their accounts: the burden is on the financial institution to demonstrate the transaction was authorized. The framework assumes a human being was the decision-maker. If that human disputes a charge, there's a well-established process: investigation, provisional credit, resolution.
Agentic transactions break this model in three ways.
First, authorization is ambiguous. A consumer might tell an agent "buy me a flight to Chicago next Tuesday under $400" — and the agent books a connecting flight for $389. The consumer didn't explicitly authorize that specific flight. Did they authorize it? Did the agent exceed its mandate? The answer isn't obvious, and the dispute resolution process wasn't designed to evaluate it.
Second, the liability chain is unclear. In a traditional transaction, the merchant, the card network, and the card-issuing bank all share defined responsibilities. Add an AI agent into the middle — running on infrastructure owned by a third-party AI provider, operating under delegation from the consumer — and every step in that chain becomes contested. Who is the "merchant of record" when the agent is doing the buying? If the agent was provided by the bank, does the bank's fiduciary duty extend to the agent's decisions?
Third, chargebacks could be weaponized. Asrow specifically flagged the chargeback vulnerability: unaddressed liability gaps could expose banks to mass consumer redress demands, as consumers use dispute mechanisms to reverse purchases they instructed agents to make, then later regretted. This isn't hypothetical — it's exactly the fraud pattern that emerged with early mobile payments.
Robinhood's Position: Users Bear the Risk
The clearest test case for how industry is currently resolving the liability question is Robinhood.
On May 27, 2026, Robinhood became the first major retail financial platform to offer consumers a dedicated agentic credit card — a virtual Robinhood Gold card that third-party AI agents can use autonomously to make purchases. Alongside it, Robinhood opened its trading platform to AI agents, allowing them to autonomously execute stock trades from a dedicated sandbox account separated from the user's main portfolio.
The product design is thoughtful from a risk-containment standpoint. Consumers set hard spending limits on the agent card. They can require manual approval on individual transactions. They can disconnect an agent instantly. The trading sandbox is isolated from the main portfolio. And agents earn 3% cash back — the same rate as human cardholders — suggesting Robinhood views agent-initiated purchases as economically equivalent to human-initiated ones.
But Robinhood's stated position on liability is stark: the customer bears ultimate responsibility for what their agent does.
That position may be legally defensible today, while the regulatory framework remains undefined. Existing laws like FINRA supervision rules, SEC best execution standards, and Regulation E were not designed with autonomous AI execution in mind. No definitive guidance has been issued by the SEC, CFTC, or federal banking regulators. Robinhood is operating in a gap.
What NYDFS is signaling is that the gap may not remain open much longer.
Why This Is Happening Now
The scale of agentic commerce is growing fast enough that regulators can no longer treat it as a pilot program to be observed.
Salesforce released the latest data point on June 24, 2026, when it announced the general availability of Agentforce Commerce — its Shopper Agent (B2C), Buyer Agent (B2B), and Merchant Agent are now in full production across a platform used by 78 of the top 2,000 North American online retailers, collectively responsible for more than $192 billion in web sales in 2025.
The underlying numbers explain why Salesforce accelerated the release: online traffic from AI assistants to retail sites grew 119% year-over-year in the first half of 2025. Retailers that deployed their own shopper agents achieved 59% faster sales growth than those that didn't. AI-referred traffic is converting at eight times the rate of social media referrals — a ratio that, if it holds, makes agentic traffic channels more valuable than anything social commerce produced in its entire first decade.
The B2B Buyer Agent is particularly revealing about where this is going. A business buyer can now text, in plain language: "Need 40 cases of the 16-oz fasteners, same as the March order" — and the agent confirms the SKU via image recognition, applies the buyer's contract pricing, and completes the order, all without the buyer logging into a portal. This summer, Salesforce will plug its product catalog directly into ChatGPT and Google Gemini, meaning AI shopping assistants will query live Salesforce merchant data without a human intermediary.
When transactions like these go wrong — wrong SKU, wrong quantity, wrong price tier applied — the dispute doesn't fit cleanly into any existing framework. The Salesforce architecture addresses part of this: Salesforce remains merchant of record in all AI-assisted transactions, and orders route through the existing platform alongside loyalty and marketing data. But that only handles one node in the chain. What about when the agent is running on OpenAI infrastructure, buying through a Salesforce merchant, using a Robinhood card?
The Three Questions Regulators Are Now Asking
Asrow's remarks outlined three specific concerns that will shape any regulatory framework NYDFS eventually issues:
1. Who is liable when an agent transacts? The current default — users bear liability — may not survive first contact with class-action litigation. If a bank provides the rails, issues the card, and profits from the transaction, courts may determine it shares responsibility for ensuring the agent acted within the consumer's actual intent.
2. How do long-standing consumer protections transfer to agent-to-agent transactions? The consumer protection framework was built assuming a human was the last decision-maker in every purchase. Agents destroy that assumption. If Agent A (running on behalf of a consumer) negotiates with Agent B (running on behalf of a merchant), and the consumer later disputes the outcome, Regulation E and Uniform Commercial Code frameworks give inconsistent answers about who prevails.
3. How do you govern something you can't audit in real time? Traditional financial supervision assumes regulators can examine the decision-making process — transaction logs, communications, authorization chains. AI agent decision-making is often opaque, fast, and distributed across multiple providers. NYDFS will likely require some form of audit trail requirement that captures agent decision points in human-readable form.
The State-Level Regulatory Race
NYDFS is not acting alone. Asrow specifically noted that New York is coordinating with Rhode Island, New Jersey, and California — the four states that have historically driven US financial regulatory innovation ahead of federal action.
California has already moved on AI transparency in advertising and data brokerage. Rhode Island has been active on algorithmic lending. New Jersey has engaged on AI in insurance pricing. If these four states converge on a shared agentic commerce framework — even informally — it creates the same market dynamic as California's emissions standards: companies comply with the most stringent version rather than building 50 different approaches.
That's actually how NYDFS would prefer to work. The department has consistently cited the risk of regulatory fragmentation: merchants and financial institutions can't build robust systems if they need to satisfy a patchwork of incompatible state rules. A coordinated approach would allow the industry to build to one standard.
What Comes Next
The practical industry question is: what should companies do now?
The liability ambiguity is not a reason to slow agentic commerce deployments — the competitive economics are too compelling. But it is a reason to build explicit liability frameworks into agent authorizations before regulators impose them.
Several patterns are already emerging from forward-thinking deployments:
- Explicit authorization scopes: Writing agent permissions in language that mirrors existing consumer protection frameworks ("authorized to purchase items under $X that match category Y from merchant list Z") creates a paper trail that supports dispute resolution.
- Human-readable transaction logs: Capturing agent decision chains in plain language at each step — not just a transaction record, but a reasoning record — positions companies for the audit requirements that are coming.
- Segregated agent accounts: Robinhood's model of dedicated agent cards and sandbox trading accounts, separate from primary accounts, limits the blast radius of disputes and creates a clear transaction perimeter for regulators.
- Liability chain documentation: Getting explicit written agreements among the AI provider, the payment rail, and the merchant about who bears responsibility in which failure modes — before the failure happens.
None of this is regulatory compliance yet. It's prudent engineering against the regulatory framework that is clearly on its way.
The Bigger Picture
The liability question sits at the center of a deeper tension in agentic commerce: the technology works best when agents act with genuine autonomy, but genuine autonomy makes existing legal frameworks uncomfortable.
Consumer trust in agents will ultimately depend on knowing that autonomous purchases are covered by the same protections as human purchases. If a consumer deploys an agent, and the agent overpays, or buys the wrong thing, or gets scammed by a fraudulent merchant — and the consumer's recourse is "you authorized the agent, so you're liable" — the consumer trust model collapses.
Agents don't get to be trusted proxies unless they carry consumer-grade protections with them. And consumer-grade protections require a regulatory framework that assigns responsibility clearly.
Kaitlin Asrow's remarks on June 27 are the first sign that the US regulatory apparatus has decided that framework is overdue. The industry now has a window — probably 12 to 18 months, based on how NYDFS has moved on analogous issues — to demonstrate that it can govern itself before the rules are written for it.
The chargeback question isn't a technical detail. It's the question that determines whether agentic commerce becomes a durable consumer product or a liability exposure waiting to unwind.
Sources
- New York financial regulator zeroing in on agentic commerce — American Banker, June 27, 2026
- Robinhood opens platform to AI agents for trading, credit card purchases — Reuters, May 27, 2026
- Your AI agent can now trade for you on Robinhood. And buy stuff with your credit card too — CNBC, May 27, 2026
- Robinhood Agentic Trading: AI Governance and Liability — FintechLaw.ai
- Salesforce releases AI agents among B2B ecommerce updates — Digital Commerce 360, June 24, 2026
- As AI Agents Transform Commerce, Salesforce Unleashes Its Biggest Agentforce Commerce Release Yet — Salesforce, June 2026
- Salesforce Launches Agentforce Commerce as AI Shopping Traffic Jumps 119% — Futurum Group
- Agentic commerce in 2026: Where we stand and what lies ahead — Fintech Futures