AI in banking

Who's liable when a customer's AI agent authorizes the wrong payment?

11 August 2026
5
mins read

No one has a clean answer yet, and that gap sits with the bank, not the customer.

‍

Kelvin Chen has spent his career on the regulatory side of exactly this question. He created and led the Federal Reserve Board's Innovation Policy team, setting the Fed's first frameworks for AI use inside supervised institutions. He later ran regulatory affairs at Capital One and Barclays. Today he's Head of Policy at the Consumer Bankers Association, where he co-authored CBA's white paper on agentic AI payments with Davis Wright Tremaine. On a recent episode of Banking Reinvented, he laid out to me where that liability question breaks down, and why it's arriving faster than most banks have mapped it.

For how a bank proves internally that it authorized an agent's action, see how banks prove accountability for an AI agent's decision. This piece picks up where that one leaves off: what happens when the agent involved isn't the bank's own, and who the customer's loss falls on. For the wider framework this sits inside, see the complete guide to AI governance in banking.

Regulation E protects customers, until the delegate is an AI agent

The Electronic Fund Transfer Act, implemented through Regulation E, was written for a world where a human authorizes every transaction. It caps consumer liability at $50 if reported within two days, rising toward unlimited liability the longer a fraud goes unreported. Visa and Mastercard eventually stopped even advertising the $50 cap. Zero liability became the default expectation.

That protection has one hard exception: authorized transactions. If a customer hands their card to a person and that person misuses it, the bank isn't on the hook. Kelvin's example: "I give you my payment cards and I say, Tim, go buy me a sandwich and you buy a Tesla. I can't then go to the bank and say, bank, make me whole."

Now replace the person with a browser extension or a shopping agent. The same exception applies, except the buyer is software the bank didn't build and can't audit. Kelvin's read: those consumer AI tools "are not built for customer service or remediation in case things go wrong," and many likely carry arbitration clauses that block a customer from getting redress anywhere at all.

The bank ends up as the only party left standing when the customer comes looking for their money.

Your bank is liable for agents it never built

This is the part that catches most banks off guard: the exposure isn't limited to agents a bank deploys itself. OpenAI launched ChatGPT Finances in May 2026, connecting Pro subscribers' bank, brokerage, and credit accounts through Plaid across more than 12,000 institutions.

Kelvin's math on adoption risk: at the time CBA published its white paper, OpenAI reported roughly 600 million monthly active users; by the time of the recording, that number had grown toward a billion. Even if a small percentage of that base routes financial decisions through a third-party agent, that's a lot of consumers. The bank sitting underneath the transaction rail still gets the call when something goes wrong.

Kelvin's summary of the moment: "Whether you want to be involved in agentic commerce or not, banks will be pulled in because at the end of the day, for almost all of the payment stacks, there will be a bank at the bottom."

Stablecoin rails compound the exposure. Kelvin's concern is that they would be able to enable new kinds of agentic transactions, particularly micro transactions, but they don't offer chargeback rights the way card networks do. A consumer who falls into that gap has fewer paths to being made whole, not more, and the bank has fewer tools to make them whole even if it wants to.

SR 26-2 excludes agentic AI from model risk oversight on purpose

Banks might assume model risk management already resolves the ambiguity here. It doesn't, and that's on purpose.

The Fed, OCC, and FDIC jointly issued SR 26-2 in April 2026, the first overhaul of model risk guidance in fifteen years. Generative and agentic AI are explicitly placed outside its scope, because the agencies consider the technology "novel and rapidly evolving."

Kelvin points to two guardrails loosening at once. First, a rulemaking eliminated disparate-impact liability for lending in the US. That's the theory that let regulators act when an automated decision hurt a protected group, even without intent to discriminate. It's gone now. Then, about two weeks later, SR 26-2 carved generative and agentic AI out of model risk oversight entirely.

Those changes happened because it's still being decided what should replace the frameworks they just narrowed. "For the first time in my career, we have this weird space where there's nothing clearer that applies on the models," Kelvin commented.

That vacuum doesn't erase the liability question. It just means no one has told banks yet who answers it. This is the same dynamic covered from the governance and risk-exposure side: a bank that waits for regulators to draw the line ends up governing after the fact instead of by design.

What banks can control when they can't control the agent

A bank can control the one thing inside its own perimeter: whether every payment, dispute, and exception that touches its rails carries a record of what was authorized, by what actor, and under what limit, the moment it happens, before a customer or a regulator ever asks.

That's a narrower version of how banks prove accountability for an AI agent's decision, applied specifically to the moment a third-party agent (not a bank-built one) initiates the transaction. It's also why governance has to be architectural rather than a policy layered on top: a policy document can't intercept a payment in flight, but a system that checks authority before execution can.

Dispute handling needs the same rebuild. Reg E and PSD2 already require an audit trail for disputes. That requirement doesn't disappear just because an agent, rather than a person, triggered it. Banks that already run dispute resolution as a governed, end-to-end flow are ready for this. Banks still running disputes as a back-office queue disconnected from trust and compliance aren't.

The same logic covers fraud. Kelvin's sandwich-and-Tesla scenario is really a fraud case once it hits a queue, and proactive fraud resolution exists to catch and resolve exactly that. None of this works without a trustworthy record. That means running deterministic and agentic workflows side by side, not trusting probabilistic output alone for payment decisions, and it means knowing which agent acted under whose authority before any of it.

What banks should do now

Map liability before an incident forces the question. That means knowing, for every payment flow a customer could route through an outside agent, not just the ones the bank built, what evidence exists if the customer disputes the outcome, and where the bank's own authority checks kick in regardless of who initiated the request. Backbase's Banking OS is built on that premise: a model, whoever built it, can propose an action, but the platform still owns the record of what was authorized and within what limit before that action executes on the bank's rails.

Frequently Asked Questions

Who is liable when an AI agent makes an unauthorized or mistaken payment?

It's unresolved. Regulation E protects consumers on unauthorized transactions but historically exempts banks from liability on transactions a consumer themselves authorized, even if that authorization was given to a third party who misused it. Whether an AI agent acting on a consumer's behalf counts as an "authorized" delegate, the way a person would, is the open question industry and regulators are actively debating.

Does Regulation E cover AI agents?

Not explicitly. Regulation E and the Electronic Fund Transfer Act were written in 1978 for human-initiated transfers. Regulators haven't updated the rule to address agent-initiated payments, which is why groups like the Consumer Bankers Association are pushing for early dialogue rather than waiting for enforcement to define the boundary by accident.

What happens if a customer's AI agent, one the bank didn't build, authorizes a bad transaction?

The bank is often still exposed. Because most payment stacks route through a bank at some point, banks can face consumer redress demands even when a third-party tool, like a browser agent or a consumer AI assistant, initiated the transaction. Many of those tools aren't built for dispute resolution and may limit a customer's ability to seek redress directly from the tool provider, leaving the bank as the practical point of accountability.

Do chargeback rights apply to agentic payments on stablecoin rails?

Generally, no, not in the way they do on card networks. Stablecoin and other alternative payment rails typically lack the chargeback infrastructure built into card networks, which means a consumer harmed by an agent-initiated transaction on those rails may have fewer paths to recovering their money.

About the author
Tim Rutten
Chief Marketing Officer, Backbase
Table of contents
Vietnam's AI moment is here
From digital access to the AI "factory"
The missing nervous system: data that can keep up with AI
CLV as the north star metric
Augmented, not automated: keeping humans in the loop