When an AI agent makes the wrong payment, who carries the loss?

read time: 5 mins read time: 5 mins
07.09.26 07.09.26

Agentic payments turn a one-off instruction into an ongoing mandate. Before the technology scales, fintechs need a better answer to what counts as consent - and what happens when an authorised agent produces an unauthorised outcome.

Imagine asking an AI agent to pay every supplier invoice that matches an approved purchase order, move spare cash to the best available account, or book the cheapest journey that meets a set of preferences. The payment is no longer the result of a human clicking 'confirm' after reviewing a single transaction. It is the result of a system interpreting a standing set of objectives and acting within them.

This is no longer a distant policy question. The Government's July 2026 consultation on modernising payment services regulation asks specifically whether existing rules on authentication, consent and liability for unauthorised transactions need to change for agentic payments. Its Financial Services AI Adoption Plan also identifies uncertainty over liability, consent and fraud as a material barrier to adoption.

The opportunity is obvious: less friction, smarter cash management and payments tailored to an individual's or business's priorities. The difficulty is that our familiar language of 'authorised' and 'unauthorised' payments does not fully describe what can go wrong when software has discretion.

In this article, we cover the importance of giving the user control and having audit trails and contracts in place to manage wrong payments.

Consent is becoming a permissions architecture

In a conventional payment journey, consent is usually connected to an identifiable payment or a familiar recurring instruction. An AI agent may instead receive authority to make a category of future decisions. The user expresses an outcome - reduce costs, avoid late fees or keep a balance above a threshold - and the agent decides how to achieve it.

That means consent cannot live only in a clause stating that the user authorises the technology to act. It has to be translated into operational limits the system can apply: maximum amounts, approved payees or categories, frequency, duration, permitted data sources, geographical restrictions, circumstances requiring fresh confirmation and a reliable mechanism for pausing or revoking authority.

Those controls are not merely technical features. They are the practical meaning of the mandate. If they are vague, hidden or difficult to change, the service may have formal consent without giving the user meaningful control.

The hardest failures sit between right and wrong

Some failures are easy to classify. A criminal who compromises an account and sends money to themselves has not become legitimate simply because an AI tool was involved. The more difficult cases occur where the agent stays within a broad permission but produces an outcome the user did not reasonably expect.

An agent might select a fraudulent merchant because of manipulated online content, pay a genuine invoice twice after misreading an update, choose an unsuitable product because a data feed was stale, or continue acting after a model change alters how it interprets a user's instructions. A business agent might pay an invoice that technically matches a purchase order even though the underlying goods are disputed.

In each example, the payment may have passed the system's authentication controls. The real question is whether the agent acted within the substance of the authority it was given. Treating every technically permitted transaction as the user's risk would make agentic services difficult to trust. Treating every unexpected outcome as the provider's responsibility could make useful automation uneconomic. The answer will need to reflect the quality of the permissions, safeguards and conduct of each participant.

The audit trail becomes part of the product

Disputes will be almost impossible to resolve if the only available record is that a payment occurred. Providers will need to reconstruct the decision: the instruction the user gave, the permissions in force, the information the agent relied on, the steps it took, any warning signs it encountered and why an additional confirmation was or was not requested.

This does not mean exposing a model's entire internal workings. It means retaining intelligible evidence of the transaction journey. That evidence will be important for complaints, fraud investigations, regulatory scrutiny and contractual disputes between the organisations in the payment chain.

It also creates a data-governance challenge. Decision logs may contain detailed information about spending habits, commercial relationships or financial vulnerability. They must be sufficiently complete to establish accountability without becoming an uncontrolled store of sensitive data.

Contracts must match the actual journey

An agentic payment may involve an AI provider, the fintech operating the interface, a wallet or payment initiator, the user's bank, a merchant and external data providers. Each participant may seek to describe itself as a limited technical intermediary. Collectively, that can leave a gap where the user expects someone to take responsibility but every contract points elsewhere.

The commercial arrangements should therefore match the end-to-end service. They need to define who sets and verifies the mandate, which party monitors suspicious behaviour, how model or service changes are tested, when an agent must stop, how incidents are communicated, who preserves the decision record and how losses and recovery costs are allocated. Customer terms should explain the service in the same way the product actually operates, rather than treating the AI as an invisible sub-process.

The allocation will vary by use case. A low-value purchasing assistant and an autonomous treasury tool should not have identical controls. What matters is that the answer is designed deliberately rather than discovered after the first disputed payment.

Control is the foundation of convenience

Agentic payments are often presented as the next removal of friction from commerce. Some friction, however, is protective. Transaction limits, clear notifications, confirmation thresholds, an immediate stop function and accessible human support can make delegation safer without defeating the purpose of automation.

The winning services will make users feel that they remain in control even when they are no longer clicking every button. Before launching an agent that can spend money, a fintech should be able to answer a simple question in plain English: if the agent makes a payment the customer never expected, what happens next?

For any support or further information, please contact our commercial team.

Sign up for legal insights

We produce a range of insights and publications to help keep our clients up-to-date with legal and sector developments.  

Sign up