Payments controls were built around a clean question: did the cardholder initiate this transaction? Agents break the question into four that current systems cannot distinguish. Was the transaction initiated by the consumer directly, by the consumer’s agent acting inside its mandate, by an attacker who compromised a legitimate agent, or by an attacker’s agent impersonating a legitimate one? Chargeback rules, fraud models, and liability frameworks all assume the first case and approximate the rest.

The gap is not an edge case; it is the default state of every agent-initiated payment today. Until authorization records can attribute a transaction to a specific agent under a specific mandate, the liability lands wherever the contracts happen to push it, which is usually on the party least able to prevent the failure. I use the Liability Gap as the test for whether an agentic payments announcement changes anything structural: if it does not move the answer to "who owns this loss," it is a feature, not infrastructure.

The reporting that applies it

All frameworks · Methodology