← Back to blog
NewsAbout 6 min read

Shopify Let AI Agents Press Buy. The Merchant Still Eats the Dispute.

Published Oct 5, 2026
Shopify Let AI Agents Press Buy. The Merchant Still Eats the Dispute.

On September 28, 2026, Shopify added checkout support to its WebMCP tools. Until then, browser-based agents could search a catalogue and manage a cart, which meant they could get a shopper all the way to the edge of a purchase and then had to stop. The new tools finish the job. An agent can read the active checkout, change shipping or pickup details, apply discount codes, and submit the order.

Shopify's own description of the work is refreshingly mundane. Agents operating inside the buyer's browser should use the structured tools on the storefront and checkout instead of navigating HTML built for humans. That is a real improvement. Screen scraping breaks whenever a retailer ships a design change, and structured tools do not. Gil Greenberg, a Shopify staff product manager working on agentic commerce, posted about the change on X, and TechCrunch covered the rollout.

The mechanical details are strict in ways that matter. Agents cannot change the items in an order or enter new card details. They can select a saved card through Shop Pay if the buyer has authorized it, and any other payment method stays the buyer's job on the page. A Web Bot Auth signature is expected on requests, and without it bot detection will deprioritize or block the call. The standard three-page checkout gets no tools at all unless the shopper is checking out through Shop Pay. B2B, embedded checkout, mobile checkout SDKs, cross-shop carts, draft orders, and payment collection flows are excluded. The rollout is currently limited to Chromium-based browsers.

A plain unbranded brown paper shopping bag standing on a dark wooden surface

Buyer consent is written into the spec rather than left to the agent's judgment. Before calling complete_checkout, the agent has to display the current order and total and get permission to place it. If the total changes during the session, that permission has to be renewed. A Shop Pay approval or a Web Bot Auth signature does not count as consent. When a payment challenge such as 3D Secure appears, or an additional review step blocks the flow, control returns to the person on the page, and the documentation tells agents not to try to route around the handoff using other page controls.

The one sentence that should get read twice

Shopify's framing is efficiency, and on the efficiency question the company is on solid ground. Structured APIs beat visual scraping. There is also a useful internal test worth knowing about, in which Shopify compared WebMCP against traditional browser automation using GPT-4o on ten checkout tasks across two test shops. The comparison exists because the company knew the obvious objection was coming.

The open question arrives after the order is placed. OpenAI's Delegated Payment Spec, part of the Agentic Commerce Protocol it co-developed with Stripe, states the position in its key points: OpenAI is not the merchant of record, and settlement, refunds, chargebacks, and compliance remain with the merchant and their payment service provider. The same spec warns that integrating directly involves handling cardholder data and may affect PCI scope.

That is the whole arrangement in two sentences. The agent platform brokers the intent. The merchant carries the risk.

Nothing about this is hidden. Shopify's documentation says plainly that the merchant remains the merchant of record, and shop owners will recognize that sentence as the default reality of running a store. What has changed is the volume and the character of the transactions that sentence now covers. An agent that shops on behalf of a customer can complete a purchase the customer never fully examined, and when that purchase becomes a dispute, the merchant still has to win it.

Why chargeback defense gets harder

Winning a dispute usually means telling a story. This IP address, this device fingerprint, this browsing path, this click, this confirmation page. Dispute automation vendors have started pointing out that most of that story does not exist in the same form when an agent made the purchase. The device fingerprint belongs to an agent runtime rather than a consumer device. The navigation path is three API calls instead of a browsing session. The customer may never have seen the product page.

Chargeflow made this argument, and it is worth treating as a vendor claim from a company with a commercial interest in dispute tooling. The underlying mechanism, though, is not controversial. Chargeback evidence has always leaned on signals that a machine-mediated purchase does not produce in the same way.

There is a second problem that regulation has not caught up with. A customer who told an agent to buy something inexpensive and received something expensive did authorize the agent. Whether they authorized that particular transaction is a different question, and US federal rules built around Regulation E assume a binary answer. There is no settled framework for the middle of that range.

The card networks are moving in their own lanes. Mastercard flags agent-initiated transactions at the network level and operates a policy-based consent model where the cardholder sets per-transaction caps, monthly caps, allowed merchant categories, and an expiry window, with out-of-policy attempts failing before they reach the merchant. Visa's Core Rules added express agentic transaction language in April 2026, requiring identity verification under its Intelligent Commerce specifications. EMVCo has a task force looking at how its global specifications should handle agentic payments.

None of that lowers a merchant's dispute ratio. Visa's VAMP thresholds and Mastercard's excessive chargeback programme do not grant an exemption because a robot clicked buy.

One issuer blinked

The bright spot, and it is a narrow one, is American Express. On April 14, 2026, Amex announced its Agentic Commerce Experiences developer kit alongside Amex Agent Purchase Protection, which it described as industry-first coverage shielding eligible card members from charges caused by AI agent error. The conditions are specific: the agent has to be registered, and it has to send Amex the customer's authenticated purchase intent. Launch partners included Adyen, Stripe, PayPal, and Fiserv on the payments side, with Delta, Expedia, and Hilton as merchants.

That is a genuine commitment to absorbing some agent-caused loss. It is also scoped to Amex card members, registered agents, authenticated intent, and eligible cases. Visa and Mastercard have published frameworks and flags, not loss absorption.

What a merchant should do this week

Two actions are worth taking now, before the first agent dispute lands.

Tag agent-initiated orders in your own order data. If your platform surfaces an agent flag, store it on the order. If it does not, infer it from the checkout path and log that inference. The value of this is entirely in having a baseline. Six months of tagged agent orders tells you whether your agent-mediated purchases behave differently from the rest, and that is the single most useful thing you can bring to a dispute conversation or a PSP negotiation.

Then read your payment provider's agentic commerce documentation and find the paragraph that names the merchant of record. If your provider has not published one, that silence is also an answer.

Agentic checkout is going to become normal, because the alternative is an agent that can shop but cannot buy, and nobody wants to build that. For all the consent prompts, buyer confirmations, and verification layers, the published specs put the risk on the merchant. Merchants can read the specs themselves and decide whether they like that arrangement, but they cannot read their way out of it.

Related articles