Présentation de notre nouvelle plateforme dédiée aux développeurs
Présentation de notre nouvelle plateforme dédiée aux développeurs
Présentation de notre nouvelle plateforme dédiée aux développeurs
Présentation de notre nouvelle plateforme dédiée aux développeurs
/
Prévention de la fraude
1er décembre 2025
Oct 7, 2026

Preventing Fraud and Chargebacks in Agentic Commerce

Logo circulaire blanc comportant, en son centre, des formes entrelacées, entouré de lignes elliptiques qui se chevauchent et ressemblent à des orbites, ainsi que de losanges bleus dispersés.

rétrofacturation?
Ce n'est plus votre problème.

Récupérez 4 fois plus d'rétrofacturation s et PRÉVENTION jusqu'à 90 % des messages entrants, grâce à l'IA et à un réseau mondial de 20 000 commerçants.

Plus de 600 avis
Aucune carte bancaire n'est nécessaire.

En bref :

  • Agentic commerce fraud is fraud, disputes and wrongful declines that occur when an AI agent, not the cardholder, completes checkout.
  • Device, behavior and velocity signals break on agent orders, so verify the agent itself with signed requests, tokenized credentials and a recorded mandate.
  • Score each order against its mandate and the customer’s history after checkout, and confirm with the customer before fulfillment when it deviates.
  • Most disputes on legitimate agent orders trace to forgotten approvals and delegated mistakes, so store the agent ID and consent record as evidence.
  • Chargeflow Prevent scans orders after checkout and before fulfillment, Alerts catch disputes before they become chargebacks, and Automation submits evidence for those that still go through.
Chargement du lecteur AudioNative de synthèse vocale d'Elevenlabs…

Un guide pratique rédigé par Ben, spécialiste des stratégies de lutte contre la fraude et les rétrofacturations chez « Chargeflow» et mentor au MRC

Le commerce agentique redéfinit les règles du jeu en matière de risques

Agentic commerce fraud is fraud, disputes and wrongful declines that occur when an AI agent, rather than the cardholder, completes the checkout. This guide is the operations playbook for legitimate agent orders: how to verify the agent, tokenize its credentials, score the order after checkout and be ready for the dispute. For attacks by malicious agents and spoofed bot traffic, read our guide to preventing AI agent fraud.

AI agents are not only affecting purchases, but they are also starting to make them. As these automated systems handle more of the buying process, new problems arise in how merchants detect fraud, understand customer intent, and avoid chargebacks. 

Je constate cette évolution au quotidien. Les données relatives aux contestations révèlent une tendance à la hausse : de plus en plus de clients contestent des prélèvements résultant de décisions automatisées qu’ils ne comprennent pas pleinement ou auxquelles ils ne s’attendaient pas. Grâce à mon travail de mentorat auprès des équipes chargées de la lutte contre la fraude, à ma participation au comité de lutte contre la fraude du MRC et à ma collaboration quotidienne avec les services opérationnels des commerçants, j’observe comment les clients comme les fraudeurs s’adaptent à cette nouvelle façon de faire ses achats. 

This guide focuses on issues already appearing in dispute queues, rather than predictions about the distant future. These cases show how quickly agent-driven purchasing is shaping post-purchase risk. Who ends up paying for those disputes is covered in our guide to AI agent chargeback liability.

Ce que le commerce agentique change en matière de fraude

Les outils traditionnels de lutte contre la fraude partent du principe qu'un être humain est à l'origine de chaque action. Cette hypothèse commence à s'effriter dès lors que l'acheteur est un agent autonome.

Visa’s own research on agentic commerce makes the same point: current payment infrastructure was designed around human interaction and will need to adapt (The Rise of Agentic Commerce). At Sibos on September 29, 2026, Federal Reserve Governor Christopher Waller described the authentication shift in his speech Payments in the Age of AI Agents: the question moves from proving that a buyer is an authorized payer to proving that an agent has the authority to pay on the buyer’s behalf. He added that fraud models and rules will need to be recalibrated for agent payment patterns.

À mesure que les agents acquièrent davantage de contrôle, bon nombre des indicateurs traditionnels perdent de leur fiabilité. Les empreintes numériques des appareils, les modèles de profil comportemental, les signaux de friction et les chemins de navigation reposent sur des comportements humains. Les agents agissent désormais de manière prévisible et « cohérente avec le fonctionnement des machines », ce que les systèmes existants ne sont pas en mesure de traiter.

Intent becomes much harder to verify. Sometimes the customer expected the agent to take action, but not in the specific manner in which it was taken. Sometimes the agent acted on learned logic that the customer had overlooked or forgotten. Fraudsters are leveraging that lack of clarity. Legitimate customers are, at the same time, disputing charges because of their own confusion versus deliberate misuse. Stopping that loss means building chargeback fraud prevention into the order flow, not only the dispute queue.

Le risque va bien au-delà de la fraude. On constate un décalage croissant entre les attentes des clients et les décisions prises par leur agent.

The figures below explain why fraud teams now treat agent orders as their own risk class instead of a variation of card-not-present fraud.

$42B
Projected global chargeback cost to merchants by 2028
1 in 10
Consumers projected to routinely use AI agents to shop and pay by 2030
25%
Rise in malicious bot-initiated transactions over the six months to November 2025

Sources: Mastercard, June 2025 (nearly half of the $42B is reported as fraudulent); Mastercard, September 2026; Visa, November 2025.

Real-World Scenarios Ben Is Already Seeing

Among merchants using agent-driven purchasing, several consistent patterns are emerging. They appear in dispute reports, customer support threads, and fraud reviews, reflecting how quickly agentic commerce is changing post-purchase risk. Frank Frantz’s Money20/20 insights on agentic commerce and its impact on fraud and chargebacks show the same shift: AI-driven purchasing is already altering fraud and customer intent.

Four patterns show up most often:

A. Achats effectués par l'IA dont le client ne se souvient pas

De nombreux commerçants sont déjà confrontés à des litiges concernant des commandes qui ont été techniquement autorisées, mais qui n'ont pas été demandées sciemment par le client. Un agent peut commander à nouveau des articles en se basant sur le comportement passé, la disponibilité ou l'analyse des préférences. Pourtant, il se peut que le client ne se souvienne pas avoir donné son accord ou qu'il ne remarque jamais le processus automatisé qui s'exécute en arrière-plan.

Lorsque le débit apparaît, le client a instinctivement tendance à nier toute implication. Même si la commande est légitime, le commerçant ne peut pas facilement prouver l'intention, car ce n'est pas l'homme qui a effectué la transaction. C'est l'Agent qui l'a fait. 

In most cases, confusion directly results in a chargeback. Because the cardholder genuinely does not recall the approval, it behaves like friendly fraud on a legitimate order.

B. Erreurs commises par des tiers

Les agents sont conçus pour optimiser, et non pour interpréter le contexte humain. Il peut leur arriver de choisir un produit légèrement différent de celui attendu, de sélectionner un commerçant auquel le client ne ferait pas appel en temps normal, ou d'acheter une quantité erronée, en fonction de la manière dont ils ont analysé la demande ou les données.

Instead of contacting support, many customers go directly to their issuer when the agent’s choice falls outside their expectations. The dispute becomes the customer’s way of correcting what they see as an error, even though the transaction was technically valid from the agent's perspective. These expectation gaps are also the main dispute driver for AI shopping assistants, covered in AI shopping chargebacks.

C. Utilisation abusive des API d'automatisation

Les fraudeurs ont désormais compris que le trafic automatisé s'intègre nettement mieux que le trafic humain ou manuel. En imitant les comportements des agents ou en exploitant les points d'accès à l'automatisation, ils peuvent générer des transactions qui semblent structurées, cohérentes et à faible risque aux yeux des systèmes de détection de fraude traditionnels.

Because these flows bypass many human indicators, to the merchant, the activity appears normal and in line with legitimate automation. Only after the dispute is filed does the pattern reveal itself as synthetic. This approach is gaining traction because it passes through the gaps created by agent-driven workflows. The attacker side of this problem, including spoofed agents and fake storefronts, is covered in the companion guide on malicious agents.

D. False Positives Creating Future Chargebacks

Certains commerçants sont confrontés à des litiges qui trouvent leur origine dans des frictions au sein même du système de lutte contre la fraude, plutôt que dans la fraude elle-même.

Les processus gérés par un agent déclenchent parfois des règles de détection de fraude, nécessitent une vérification supplémentaire ou sont refusés. Le client se retrouve alors perplexe et frustré par la procédure, surtout lorsque l'agent a géré le processus « à l'abri des regards ». Plus tard, lorsqu'un prélèvement légitime apparaît, le client le conteste simplement parce que sa confiance dans le processus a déjà été ébranlée.

Ces situations sont tout à fait évitables, mais elles montrent à quel point le comportement de l'agent et les attentes humaines peuvent facilement se décaler.

The table maps each pattern to how the dispute is usually framed and the first control that helps. Which reason code each scenario lands in, and what counts as an authorized agent purchase, is covered in who is liable when AI agents shop for your customers.

PatternHow the dispute is usually framedFirst control that helps
A. Purchase the customer cannot recallUnauthorized-transaction claim from a genuine customerCustomer confirmation before fulfillment, plus a stored mandate record
B. Delegated mistakeNot-as-expected claim, or a fraud claim to reverse the orderOrder summary sent at purchase, mandate limits on quantity and price, a simple cancellation window
C. Spoofed agent trafficTrue fraud using stolen credentials or accountsAgent verification by signature and post-checkout scoring
D. False-positive frictionFraud claim after a declined or challenged flowTune rules for verified agents and tell the customer when step-up happens

Why Legacy Fraud Tools and Playbooks Break Down

La plupart des systèmes et outils de lutte contre la fraude liée au prépaiement ont été développés à une époque où un intervenant humain participait à chaque étape du parcours client. Le commerce piloté par des agents bouleverse ce modèle, ce qui signifie que certains des outils les plus performants de la pile technologique d'un commerçant ne fonctionnent plus comme prévu.

Les modèles de risque basés sur les appareils perdent tout leur sens.

Les modèles traditionnels s'appuient largement sur les caractéristiques des appareils pour identifier les comportements suspects. Lorsque l'« acheteur » est un agent évoluant au sein de serveurs ou d'environnements cloud, les attributs de l'appareil ne correspondent plus à l'identité ou à l'intention d'un être humain. Cela supprime un point d'ancrage majeur de la logique actuelle de détection des fraudes.

Les règles de Velocity commencent à classer de manière erronée les flux automatisés.

Les agents travaillent souvent selon des horaires ou des boucles logiques qui se répètent à des intervalles prévisibles. Les règles de vélocité traditionnelles (par exemple, celles basées sur l'heure exacte de l'activité) sont conçues pour signaler les comportements humains répétitifs. Elles signalent à tort l'activité normale des agents, générant ainsi des faux positifs qui entraînent des frictions, des pertes de revenus et des litiges en aval.

L'analyse comportementale ne permet pas d'interpréter les schémas non humains.

Les modèles qui s'appuient sur les mouvements de la souris, le défilement, les temps de pause ou la vitesse entre les actions perdent de leur efficacité, car les agents ne respectent pas les normes d'interaction humaines. Ce qui peut paraître suspect dans un contexte humain peut s'avérer tout à fait légitime lorsqu'un agent exécute le processus.

La vérification manuelle devient ingérable.

Les transactions traitées par des agents augmentent le volume tout en réduisant la visibilité. Les dossiers qui nécessitaient auparavant quelques minutes d’analyse ne comportent désormais plus les indices humains sur lesquels s’appuient les examinateurs. L’examen manuel ne peut pas s’adapter au rythme de l’automatisation, et même lorsque les équipes tentent de le faire, les résultats sont incohérents car les indices sous-jacents sont incomplets. Il est payant de considérer la gestion des rétrofacturations comme un système à part entière, et non comme une simple gestion de crise.

C'est lors des litiges que le fossé se creuse le plus.

Même lorsqu'un commerçant sait qu'une transaction est légitime, il devient nettement plus difficile de prouver l'intention. Les émetteurs exigent des preuves démontrant un lien clair entre le client et l'achat. Dans le commerce par procuration, une partie de cette démarche est déléguée. Sans nouveaux types de données justificatives, les commerçants perdent des litiges simplement parce que les preuves ne permettent pas de trancher le différend.

Les systèmes hérités ne tombent pas en panne parce qu'ils sont défaillants. Ils tombent en panne parce qu'ils n'ont jamais été conçus pour des environnements où ce sont des agents, et non des humains, qui se chargent d'une grande partie du parcours d'achat.

How To Verify a Legitimate AI Agent at Checkout

Because device and behavior signals no longer identify the buyer, verification moves to the agent itself. Five signals exist today. None is universal yet, so log each one and feed it into scoring instead of treating any single signal as a gate.

SignalWhat it provesComment ça marcheStatus as of October 2026
Signed agent requestThe request comes from an agent registered with a card network program, not a spoofed botIn Visa’s Trusted Agent Protocol, agents sign requests with HTTP Message Signatures (RFC 9421). You verify the signature against the published public key, check the timestamp (the specification uses an 8-minute window) and reject replayed nonces.Published specification with reference implementations
Network-tokenized credentialThe payment credential was issued to a registered agent instead of being a raw card numberMastercard Agent Pay uses Mastercard network tokens and know-your-agent registration. Visa Intelligent Commerce adds spending limits and approval workflows to agent credentials.Visa describes its program as still in deployment; Mastercard has not published rollout dates on its Agent Pay page
Recorded mandateThe customer authorized this agent for this kind of purchase, within set limitsThe Agent Payments Protocol (AP2) defines checkout and payment mandates as verifiable credentials, in an open form (constraints) and a closed form (a specific authorized transaction). Mastercard’s framework similarly requires authenticated user intent and explicit consent.AP2 is at version 0.2 and supports card payments
Shared payment tokenCredentials reach you through the agent without exposing raw card data, and you stay merchant of recordThe Agentic Commerce Protocol passes a shared payment token, and Stripe’s Shared Payment Token is the first compatible payment method.Open standard; merchant discovery is still in development
Network agent probability scoreAn issuer-side likelihood that an AI agent initiated the transactionMastercard’s AI Transaction Probability Score helps issuers approve legitimate agent purchases and is paired with shared agentic trust and intelligence signals.Rolling out for testing in the US (Mastercard, September 2026)

When no signal is present, treat the order as an unverified agent order and log that no agent identity was presented. Do not decline it automatically, because that creates the false-positive disputes described in pattern D. Send it to the scoring step below instead. Authentication at mandate creation, such as a 3D Secure 2 challenge when the customer first authorizes the agent, also gives you an issuer-backed record of the customer’s participation. Network programs change quickly, so track them in agentic commerce regulation.

Scoring Signals That Still Work for Agent Orders

Once the agent is identified, score the order itself. These signals do not depend on a human device or mouse movement, so they stay usable on agent traffic. They sit on top of your baseline ecommerce fraud prevention controls such as AVS, 3D Secure and velocity limits.

SignalWhat to compareAction when it fails
Order versus mandateCart total, quantity, merchant category and delivery date against the limits the customer setHold the order and confirm with the customer
Order versus customer historyReorder cadence, typical basket, usual shipping address, account ageVerify before fulfillment when the order falls outside the pattern
Credential and account consistencyToken age, billing and shipping match, whether the login tied to the order is establishedTreat a new account, new token and high value together as high risk

Two more signals need data from outside your store: whether the same agent has produced clean, undisputed orders over time, and whether it or its credential has produced disputes at other merchants. Raise the review threshold for new or inconsistent agents and relax it for agents with a clean history. Replace velocity rules based on the hour of human activity with per-agent and per-credential velocity, so a scheduled reorder is not flagged as a burst.

The Move to Post-Purchase Intelligence (Ben’s POV)

À mesure que le commerce assisté par des agents prend de l'ampleur, les signaux les plus pertinents apparaissent souvent après la transaction, et non avant. Les contrôles préalables à l'achat ont été conçus pour tenir compte du comportement humain et des difficultés rencontrées lorsque l'intention est partagée entre un humain et un agent. Dans ce contexte, pour prévenir les pertes, il est nécessaire de disposer d'une meilleure visibilité sur des éléments qui ne se précisent qu'une fois la commande passée.

Les données post-achat comblent les lacunes laissées par les systèmes traditionnels. Elles permettent de répondre à des questions qui ne peuvent être résolues au moment du paiement, notamment :

  • Cette commande est-elle cohérente au regard du comportement passé du client, ou témoigne-t-elle d'une confusion ou d'une automatisation involontaire ?
  • Cet agent est-il reconnu par un réseau de commerçants plus large, ou s'agit-il d'un nouvel agent, non vérifié ou dont le comportement est irrégulier ?
  • Des transactions similaires effectuées auprès d'autres commerçants ont-elles donné lieu à des litiges laissant supposer une utilisation abusive ou de nouvelles techniques de fraude ?
  • Y a-t-il des incohérences dans les attributs d'identité ou d'appareil qui pourraient indiquer une manipulation derrière l'automatisation ?

These signals offer context that pre-purchase tools cannot. They help determine when an agent acted outside customer expectations, when automation is being abused, and when a familiar pattern is likely to convert into a dispute. The wider goal is to prevent eCommerce chargebacks across the store.

Until today, in many cases, the only reliable way to understand intent well enough to intervene before the issuer becomes involved has been post-purchase analysis. It gives merchants a chance to reach out, verify, correct mistakes, or cancel orders before they become chargebacks, and for physical goods, before the products are shipped.

L'intelligence post-achat est bien plus qu'une simple mise à niveau. Il s'agit d'un changement indispensable dans la manière dont les commerçants protègent leurs revenus, dans un contexte où ce sont les agents, et non plus les humains, qui initient une part croissante du processus d'achat.

A cancelled and refunded order never becomes a dispute, so it never counts toward your monitoring ratios: Visa’s VAMP flags merchants as Excessive at a 1.5% ratio from April 2026, and Mastercard’s ECM program starts at a 1.5% chargeback ratio with 100 or more chargebacks (see VAMP and ECM chargeback thresholds). Use a simple triage rule for every agent order:

ConditionActionQuand
Verified agent, order inside the mandate and the customer’s historyApprove and fulfillAutomatically
Verified agent, order outside the mandate or history (quantity, price, new category, new address)Message the customer to confirm and hold fulfillmentBefore shipment
Agent identity missing or signature fails, credential otherwise validScore on order and customer history, step up if risk is highBefore shipment
Agent identity fails and the order has other risk signals (new account, mismatched addresses, dispute history elsewhere)Cancel and refundBefore shipment
Digital or instant-delivery goodsDelay the download link or credit grant until the score returnsBefore delivery

Dispute Readiness for Agent Transactions

Some agent orders will still be disputed, so capture the record at the time of purchase: the agent identifier and its verification result, the mandate or consent record (scope, limits, timestamp), the order confirmation sent to the customer and any reply, delivery proof, and the account and delivery-address history. The full checklist and templates are in the agentic commerce chargebacks evidence playbook.

Visa’s Compelling Evidence 3.0 can move liability back to the issuer on Visa 10.4 fraud disputes when you show at least two prior undisputed transactions made 120 to 365 days earlier, with matching data points such as IP address, device ID, account login and delivery address. Agent traffic usually runs from provider infrastructure, so IP and device matches may point to the agent instead of the customer. Capture the account login and delivery address on every agent order so the match still holds. Details are in Visa Compelling Evidence 3.0 explained.

How Chargeflow Prevents and Supports Merchants in Agentic Commerce

Bien que ce guide ne soit pas axé sur les produits, il est important de reconnaître que les commerçants ont besoin d’outils qui tiennent compte des réalités des achats effectués par des agents. L'automatisation engendre des failles que les systèmes anti-fraude traditionnels n'ont jamais été conçus pour gérer, et de nombreux commerçants recherchent des moyens pratiques de combler ces failles sans ajouter de friction ni d'effort manuel. Comme le souligne Mysterium VPN, un VPN résidentiel peut également permettre un accès à distance plus sécurisé à la boutique en chiffrant l'ensemble du trafic des appareils sur un réseau Wi-Fi public ou partagé, aidant ainsi les équipes des commerçants à protéger les identifiants de connexion, les cookies et les sessions d'administration lorsqu'elles examinent des commandes ou des litiges en dehors du bureau.

Chargeflow Prevent scans each order after checkout and before fulfillment. It scores the order with post-purchase signals and intelligence from a network of 20,000+ merchants, then cancels, verifies or approves the order before anything ships, with a false-positive rate under 0.1%. Pricing is $0.40 per scanned transaction, and the first 1,000 scans are free. It does not replace the agent-verification signals above. It adds the order-level and network-level view they cannot provide.

Each stage of the order lifecycle needs its own control:

ScèneControlChargeflow product
At checkoutAgent verification, tokenized credentials, mandate captureYour payment stack and agent-protocol support
After checkout, before fulfillmentOrder scoring, customer confirmation, cancel or approvePRÉVENTION
After a dispute notice, before it becomes a chargebackRefund or resolve through card network alert programsAlerts, $29 per deflected chargeback (how chargeback alerts work)
After a chargeback is filedEvidence assembly and submissionAutomation, 25% of recovered chargebacks (chargeback recovery)

My goal is not to promote a specific solution, but to emphasize that merchants now need preventive layers that reflect how commerce is changing. Agent-driven transactions require a different type of visibility.

Foire aux questions

What is agentic commerce fraud?

Agentic commerce fraud is any fraud, dispute or wrongful decline that occurs when an AI agent, not the cardholder, completes the checkout. It covers malicious or spoofed agents, and also legitimate orders that the customer later disputes because they did not expect or remember what the agent bought.

Why is agentic commerce important for fraud prevention?

Fraud tools built on device, behavior and velocity signals assume a human buyer, and agent orders break those signals. Legitimate agent orders also produce disputes from forgotten approvals and delegated mistakes that legacy tools cannot tell apart from fraud. Federal Reserve Governor Christopher Waller said in September 2026 that fraud models and rules will need to be recalibrated for agent payment patterns.

How do you prevent fraud in agentic commerce?

Verify the agent through signed requests, network-tokenized credentials and a recorded mandate. Score each order against the mandate and the customer’s history after checkout, confirm with the customer before fulfillment when the order deviates, and keep the agent ID and consent record as dispute evidence.

How do agentic payment solutions prevent fraud?

Card networks issue tokenized credentials to registered agents, attach limits such as spending caps and approval workflows, and let agents sign requests so merchants can verify them. These measures confirm who the agent is and what it was authorized to do. They do not remove disputes from forgotten or mistaken purchases, which is why post-checkout screening and evidence capture still matter.

How is agentic commerce fraud detected?

Detection shifts from device and behavior signals to agent identity, mandate match and history. Compare each order with the mandate limits and the customer’s past orders, track whether an agent has produced clean orders on your store, and use network-level dispute history. Run velocity rules per agent and per credential instead of per hour of human activity.

What should you look for in an agentic commerce fraud prevention solution?

Look for support for agent identity signals from the card networks, scoring that does not rely on device or mouse behavior, a decision before fulfillment, a low false-positive rate, and a path to evidence submission for disputes that still occur. Chargeflow Prevent scans orders after checkout and before fulfillment with a false-positive rate under 0.1%.

Who pays when a legitimate agent purchase is disputed?

Under existing card-not-present rules the merchant generally carries the chargeback unless a liability shift applies, and network rules for agent-specific cases are still being defined. The split between merchant, agent platform, issuer and customer is covered in the AI agent chargeback liability guide.

PARTAGER CET ARTICLE
Logo circulaire blanc comportant, en son centre, des formes entrelacées, entouré de lignes elliptiques qui se chevauchent et ressemblent à des orbites, ainsi que de losanges bleus dispersés.

rétrofacturation?
Ce n'est plus votre problème.

Récupérez 4 fois plus d'rétrofacturation s et PRÉVENTION jusqu'à 90 % des messages entrants, grâce à l'IA et à un réseau mondial de 20 000 commerçants.

Plus de 600 avis
Aucune carte bancaire n'est nécessaire.
s'abonner

Les dernières actualités sur l'rétrofacturation, la fraude et le commerce électronique, directement dans votre boîte mail. Chaque semaine.

Inscrivez-vous dès maintenant pour ne rien manquer des dernières tendances !
En indiquant votre adresse e-mail, vous acceptez nos Conditions d'utilisation et notre Politique de confidentialité
Schéma composé de lignes pointillées et courbes formant des arcs segmentés, mis en évidence par trois repères en forme de losange bleu situés à gauche.Motif abstrait en forme de grille circulaire, avec des repères en forme de losanges bleus sur un fond moitié noir, moitié blanc.