Authorized Delegation, Flawed Execution — Agentic Commerce (2 of 4)
The agent had permission and still got it wrong — a failure mode our rails have no category for.
Second in my four-post series from the agentic commerce research. This is the part I found most interesting.
Fraud has a familiar shape: someone makes a charge you never approved. Decades of card infrastructure — detection models, chargeback rights, liability rules — exist to catch and unwind exactly that.
Agentic commerce introduces a whole category that doesn't fit the shape. I've been calling it authorized delegation, flawed execution: the agent had permission, and still got the purchase wrong. It bought the wrong item. It paid a worse price than it should have. It ordered ten when you meant one. It renewed a subscription you'd have cancelled. Nothing was stolen. No credential was compromised. No spending limit was breached. The delegation was completely real — the execution just wasn't what the human actually intended.
That's the problem. It's not fraud, and it's not a clean merchant dispute either. Our existing categories assume one of two things: an unauthorized actor, or a legitimate transaction that went bad on the merchant's side. An authorized agent making an honest error against a genuine instruction is neither of those. The permission was valid. The outcome was wrong. And there's no established rail to resolve that gap — no clear code for "the agent did what I told it, badly."
It matters because it won't be rare. Agents operate at machine speed and machine scale, and a small error rate across millions of delegated purchases isn't a rounding error — it's a support queue, a wave of dispute volume, and, underneath both, a trust problem. If people can't rely on delegation, they won't delegate.
The first real sign the industry sees this coming is already visible: American Express has committed to Agent Purchase Protection, a forward commitment aimed squarely at this failure mode. The full terms are still to come, but the direction is the tell — the category is real enough that someone is already building protection around it, before the volume has even arrived.
The question I keep landing on is who owns the resolution. When an authorized agent executes badly, whose problem is it — the cardholder's, the issuer's, the network's, or the agent developer's? Today there's no settled answer. And in payments, the settled answer tends to belong to whoever builds it first: the evidence trail, the consent record, the remedy. Whoever defines how this gets resolved defines the standard everyone else ends up adopting.
The full taxonomy — the other error types, and how they map to existing rails — is in the research, on The Payments Corner.
Franco Di Pietro
The Payments Corner
30+ years across payments, fintech, banking, and financial infrastructure. Operator-level perspectives on the systems that move money.
Related Insights
Citi's card-linked offer acquisition bets on cost, not on proven category economics
Citi's acquisition of Kard Financial rests on operational and financial logic—lower rewards spend, faster platform build—but the card-linked offer category itself has never demonstrated standalone profitability. Cardlytics, the only pure-play, has burned $1.15bn cumulatively since its 2018 IPO and generated negative shareholder equity last year.
The PayPal Valuation Paradox
Stripe and Advent walked away, PayPal lost nearly 13% in a day, and the takeover premium disappeared. The failed deal exposed a more important question: how much value is the public market actually assigning to Venmo?
Kraken's card is a bet on controlling the funding decision, not the transaction
Kraken's debit card—with its 2% rewards across multiple asset balances—is not a payments product disguised as one. It is a wallet-stickiness play that inverts traditional card architecture: instead of a card accessing a single account, the platform now decides which of many balances funds each purchase, moving the locus of control from the network to the issuer's financial operating system.