When AI Commerce Meets the Liability Layer


OZ Signals

14 July, 2026

When AI Commerce Meets the Liability Layer

Issue 16 examined the agentic distribution layer: the growing set of AI assistants, platforms, protocols, and commerce providers that can influence which products are discovered and where transactions begin. That layer explains how demand is moving away from merchant-controlled storefronts and into machine-controlled environments. But distribution is only the visible part of the shift. Once an AI system moves from recommending a product to acting on a customer’s behalf, commerce inherits a harder question: who is responsible for proving that the action was legitimate?

The current commerce system was designed around a human buyer who browses, consents, enters credentials, accepts terms, and can later challenge the transaction. Agentic commerce separates those actions. A person may define a goal, an agent may interpret it, another service may supply product information, a payment network may authenticate the transaction, and a merchant may fulfil an order without ever seeing the original instruction. Every participant can complete its own technical function while the transaction still fails as an accountable commercial event.

The developments that surfaced between 7 July and 13 July show that the next bottleneck is no longer whether AI agents can reach merchants or initiate payments. It is whether the resulting transaction can be defended when intent, identity, product selection, delivery, or authorization is disputed. The next competitive layer in AI commerce will therefore be built around transaction evidence: systems that can prove what the customer requested, what authority was delegated, what the agent decided, what the merchant received, and where responsibility changed hands.

Signal 1: The Agentic Commerce Stack Is Splitting Around Liability

Activant Capital published the second part of its agentic commerce research on 9 July, separating the enablement market into four distinct problems: access, identity, settlement, and liability. Access asks whether an agent can reach a merchant’s commerce system. Identity asks whether the agent can prove who it represents. Settlement asks whether value can move successfully. Liability asks who absorbs the loss when the agent makes a mistake, exceeds its authority, or completes a transaction the customer later rejects.

This separation matters because the industry has often treated agentic commerce readiness as a technical integration problem. Under that model, merchants become agent-ready by exposing product data, supporting a protocol, authenticating an agent, and accepting an approved payment credential. Activant’s framing exposes the missing commercial layer: a technically valid transaction is not necessarily a defensible transaction. Authentication can prove which agent acted, but it cannot by itself prove that the agent correctly interpreted the customer’s request or remained within the customer’s intended authority.

The leverage therefore shifts toward companies that can create evidence across the complete delegation chain. This may include records of the original instruction, spending limits, substitution rules, timing constraints, product-selection logic, authorization events, merchant disclosures, and fulfilment outcomes. Payment processors, identity providers, agent platforms, insurers, dispute-management firms, and commerce infrastructure providers may all compete to become the system that stores or verifies this evidence.

The second-order implication is that liability may become the market’s real adoption gate. Merchants can tolerate an imperfect agent channel while volumes are small. They will be less willing to accept autonomous transactions at scale if every agent error arrives as an ordinary chargeback and the merchant has no access to the instruction or decision trail required to contest it.

Break: Agent authentication stops being sufficient when no one can prove that the authenticated agent followed the customer’s actual instruction.

Source: Enablement Layer

Signal 2: Delegated Checkout Is Retreating Where Accountability Remains With the Merchant

On 9 July, delivery-management company nShift published its mid-year assessment of AI shopping and reported a meaningful divergence between AI-led discovery and delegated checkout. According to the company, product discovery through AI systems had advanced rapidly, but the part where an agent independently completes the purchase had not developed at the same speed. nShift specifically noted that ChatGPT had moved direct checkout back toward more conventional merchant journeys while other agentic commerce protocols continued to develop.

This is structurally important because it challenges the assumption that discovery, checkout, and fulfilment will move into AI interfaces as one continuous transition. Discovery can be separated from the merchant with limited operational risk. An AI system can compare products, explain differences, and send a customer toward a merchant. Checkout is different. The moment an agent commits the order, the system must resolve shipping choices, address accuracy, availability, delivery expectations, substitutions, cancellations, returns, and customer-service responsibility.

Merchants currently remain responsible for most of those outcomes even when another system influenced or initiated the purchase. That creates an asymmetric structure: the agent controls the decision, but the merchant carries the operational and financial consequences. Sending the customer back to the merchant’s checkout is therefore not simply a temporary interface compromise. It restores a point where the merchant can capture consent, present terms, verify information, set delivery expectations, and generate evidence that can later be used in a dispute.

The second-order implication is that the checkout page may survive longer than expected, but its function will change. It may stop being the primary place where customers decide what to buy and become the final legal and evidentiary checkpoint before a machine-influenced decision becomes a merchant obligation.

Break: Checkout does not disappear merely because agents can pay; it remains wherever responsibility still has to be assigned.

Source: Checkout Reversal

Signal 3: Existing Chargeback Systems Cannot Explain Delegated Intent

Chargeflow published an analysis on 9 July examining how current regulation and chargeback rules apply to agentic transactions. The central problem is that existing consumer-protection and card-dispute systems were designed around transactions initiated directly by people or through familiar recurring-payment arrangements. They do not yet provide a clear framework for situations where a customer authorized an agent generally, but disputes the specific product, seller, price, timing, or substitution the agent selected.

This creates several transaction states that existing dispute categories struggle to distinguish. A payment may be technically authorized because the agent used a valid credential, but commercially contested because the agent exceeded a spending limit. A customer may genuinely have requested a purchase but argue that the agent selected the wrong specification. A merchant may receive an authenticated payment without receiving the customer’s original instructions. Under current systems, many of these cases could still be presented as unauthorized transactions, merchandise disputes, service failures, or first-party misuse, even though the underlying issue was delegated interpretation.

The structural change is that dispute management must move from proving possession of credentials to proving the scope of authority. Merchants will require evidence that connects the customer, the agent, the instruction, the chosen item, the authorization, and the fulfilled outcome. A payment token can show that a credential was permitted for use. It cannot show why the agent selected one product instead of another or whether the customer had approved that decision rule.

The second-order implication is that chargeback infrastructure could become a standard-setting force in agentic commerce. Whichever evidence card networks, issuers, regulators, and dispute platforms begin accepting will influence how agent instructions are recorded, how merchants expose policies, and how AI platforms design customer authorization. Dispute rules may shape agentic commerce architecture as strongly as payment protocols do.

Break: A valid payment credential no longer proves a valid purchase when the dispute concerns what the machine was allowed to decide.

Source: Liability Rules

Signal 4: The Original Instruction Is Becoming a Security Asset

Proof’s July fraud analysis, published on 13 July, argued that AI agents are already acting on real payment rails while the identity and security layer beneath those actions remains incomplete. The company also highlighted a growing agentic security problem: prompt injection, where external content or malicious instructions alter an agent’s behaviour. Proof cited the 2026 OWASP agentic security work, which maps prompt injection across multiple major categories of agent risk.

This creates a different form of transaction fraud. Traditional fraud prevention asks whether the buyer, credential, device, or payment behaviour appears legitimate. An agentic transaction can pass all of those checks while still being compromised. A legitimate customer may use a legitimate agent with a legitimate payment credential, but the agent’s decision may have been manipulated by merchant content, a third-party page, an injected instruction, poisoned memory, or another connected tool.

The commerce implication is that agent security and transaction evidence cannot remain separate disciplines. A merchant needs to know not only which agent arrived, but what instruction the agent was executing and whether that instruction changed before payment. Agent providers may need to preserve signed records of original goals, tool calls, policy checks, model outputs, and authorization steps. Merchants may also need independent verification that the final purchase request is consistent with the customer’s approved constraints.

The second-order implication is that customer intent itself becomes a protected commercial asset. Today, payment credentials are tokenized because exposing them creates financial risk. In agentic commerce, the original instruction and delegation policy may require similar integrity controls because manipulating those inputs can produce an apparently authorized but fundamentally corrupted purchase.

Break: Identity stops proving legitimacy when a verified agent can be redirected after the customer has granted authority.

Source: Agent Fraud

Signal 5: Merchant Trust Is Moving From Reputation to Verifiable Claims

Planet published an agentic commerce analysis on 13 July arguing that retailers are treating AI shopping as an interface problem when the deeper issue is trust in the data used by machines. In an agent-led purchase, products are evaluated against structured criteria rather than through a conventional storefront journey. This makes claims about price, availability, delivery, compatibility, returns, sustainability, and product suitability part of the machine’s decision infrastructure.

Human shoppers can interpret ambiguity. They may understand that an estimated delivery date is conditional, that an image is illustrative, or that a promotional claim requires qualification. An agent is more likely to process the available fields as operational facts. When those fields determine selection and purchase, inaccurate data stops being a content-quality issue and becomes evidence in a commercial dispute. A merchant that states an item is compatible, available, returnable, or deliverable within a particular period may be making a machine-readable promise that influences an autonomous decision.

The structural shift is from merchant reputation to claim-level verifiability. Reviews, brand strength, and historical trust will remain important, but agents will increasingly require evidence attached to specific commercial claims. Merchants may need timestamps, inventory provenance, delivery-confidence scores, policy versions, certification records, and structured exceptions that can travel with the product information into an AI decision system.

The second-order implication is that catalog infrastructure and dispute infrastructure will begin to converge. The same product fields that help an agent choose an item may later be used to determine whether that choice was reasonable and whether the merchant fulfilled what its data promised. Product information will therefore serve two functions: demand generation before the transaction and evidentiary defence after it.

Break: Product data stops being descriptive when machines use it as proof that a transaction should occur.

Source: Trust Data

The System That Is Emerging

The week’s developments point to a transaction accountability layer forming underneath agentic commerce. Previous infrastructure has focused on making products discoverable, merchants accessible, agents identifiable, and payments executable. Those capabilities allow a machine to reach a transaction. They do not make the transaction defensible.

The emerging system must preserve context across parties that currently see only fragments of the purchase:

  • The customer knows the intended outcome but may not see every decision the agent makes.
  • The agent platform sees the instruction and reasoning but may not control merchant fulfilment.
  • The merchant receives the order but may not receive the original delegation terms.
  • The payment network verifies the credential but may not know whether the item matched the customer’s intent.
  • The delivery provider proves fulfilment but not whether the purchase should have occurred.
  • The issuer receives the dispute but may lack the complete chain of evidence.

The new layer will connect these fragments into a verifiable transaction record. It will need to establish who authorized the agent, what decisions were delegated, which restrictions applied, what information influenced the selection, which commercial claims were presented, how payment was approved, and whether the merchant delivered against the exact terms available when the agent acted.

This will move control toward providers that can create evidence accepted across multiple systems. Agent platforms will want to prove correct execution. Merchants will want to defend legitimate orders. Payment networks will want cleaner liability allocation. Issuers will want to distinguish fraud from agent error and customer regret. Regulators will want a traceable explanation of how autonomous commercial actions occurred.

The old model assumes that responsibility can be reconstructed from separate records held by the merchant, payment provider, and customer. That model becomes unreliable when the decisive commercial logic occurs inside an external AI system. The new model will require transaction evidence to be generated at the moment of delegation and preserved across every subsequent handoff.

Core Truth: Agentic commerce will not scale on the ability to execute transactions; it will scale on the ability to prove why each transaction was allowed to happen.

For operators, this changes the definition of readiness. Supporting an agent-facing catalog or payment protocol is no longer enough. Businesses must decide what evidence they need before accepting agent-originated orders, which claims in their product data can be treated as contractual inputs, how agent instructions will be verified, and who will carry the loss when the evidence chain is incomplete.

Tool of the Week Cloudflare Agent Readiness

Cloudflare’s Agent Readiness tool evaluates whether a website can support AI-agent interactions across discoverability, machine-readable content, bot access controls, authentication, and transactional capabilities. It examines standards including robots.txt, Markdown delivery, Web Bot Auth, API catalogs, OAuth discovery, MCP server cards, and agent skills. Cloudflare’s broader scan of major websites found that many emerging agent standards remain barely adopted, showing how early the machine-facing web infrastructure still is.

Its structural value is not the score alone. The tool gives merchants and infrastructure teams a practical view of which controls exist before an agent enters a commercial workflow. In the context of this issue, Web Bot Auth and authorization discovery are especially important because transaction accountability begins by distinguishing identifiable, permitted agents from unknown automation. The tool does not solve liability, but it reveals whether the basic access and identity evidence required for a defensible agent interaction is present.

Source: Readiness Audit

Trend to Watch Agentic Distribution Management

The next important development will not simply be another shopping agent or checkout integration. It will be the addition of standardized evidence fields to commerce protocols. Watch for systems that record delegation scope, maximum spend, approved sellers, substitution permissions, expiry periods, product constraints, policy versions, and machine-readable consent alongside payment authorization.

This development may begin quietly through card-network rules, fraud-provider requirements, identity credentials, merchant APIs, insurance conditions, or enterprise procurement controls. Once a major network or platform defines the minimum evidence required to defend an autonomous transaction, merchants and agent providers will have to redesign their systems around it. The companies that control those evidence formats will influence how responsibility is divided across the entire agentic commerce stack.

AI commerce is now reaching the point where technical capability and commercial legitimacy separate. An agent may be able to discover, select, and pay for a product while the surrounding institutions remain unable to determine whether the transaction reflected valid intent. That gap will limit transaction values, merchant participation, insurance coverage, regulatory acceptance, and customer trust more than model performance will.

The next phase of OZ Signals will continue tracking how the market closes this gap: which institutions define acceptable agent authority, which records become mandatory, how disputes are classified, and where liability ultimately settles. The decisive infrastructure will not be the system that makes autonomous buying possible first. It will be the system that allows merchants, customers, networks, and regulators to trust the result after something goes wrong.

Box Hill (Sydney), NSW 2765, Australia
Unsubscribe

OZ Signals

OZ Signals is a weekly intelligence briefing on how AI is restructuring commerce systems. Built for founders, operators, and decision-makers who want high-signal insights, not noise.

Read more from OZ Signals
Diagram showing an AI agent connected to merchant data, financial accounts, payment infrastructure and shared commerce rules through a central control layer.

OZ Signals 25 August, 2026 View in browser The Control Plane for Agentic Commerce An AI agent can be given permission to spend money. That no longer looks like the difficult part. The harder problem is what happens after permission is granted. Which merchant records can the agent see? Which account can it touch? Which payment route can it use? Who decides whether a transaction looks legitimate? What happens when an agent moves across systems owned by different companies? Several releases this...

A diagram showing an AI agent inside a controlled economic boundary, connected to budgets, payment credentials, enterprise rules and approved transactions.

OZ Signals 18 August, 2026 View in browser When AI Gets a Budget, Not Just Permission The most important question in agentic commerce is quietly changing. It used to be: Can the agent make the payment?Now it is becoming: How much economic freedom should the agent have before a human needs to return? That distinction matters because autonomous commerce does not scale if every action needs fresh approval. But removing approval entirely creates a different problem. A company may have hundreds of...

AI agents positioned between brands and consumers, illustrating the emerging advertising layer where machines influence product discovery and purchase decisions.

OZ Signals 11 August, 2026 View in browser The Next Ad Market May Not Be Built for Humans For most of the internet, advertising has had one basic job: get a person's attention. A banner had to be seen. A search ad had to be clicked. A sponsored product had to catch the shopper before a competitor did. That assumption is starting to fail. This week, several developments pointed toward something stranger. Amazon described ads that can live inside AI shopping conversations. Time is experimenting...