Business Growth

The Trust Problem in Agent Transactions: Liability, Verification, and Dispute Evidence

In 2024, a Canadian tribunal rejected Air Canada's argument that its chatbot was a separate legal entity responsible for its own statements, ordering the airline to honor a discount the bot had invented (BCCRT, 2024). That small-claims decision, $650.88 in damages, became the most-cited data point in agentic commerce, because it answered the question every operator now faces: when software speaks or transacts for a business, the business owns the consequences. As agents move from answering questions to spending money, three trust problems compound: who is liable when an agent errs, how counterparties verify an agent is legitimate, and what evidence survives a dispute. This analysis maps the 2026 state of each, and the records a service business should be keeping now.

Joshua Agonya Pi'Rwot

By Joshua Agonya Pi'Rwot

Founder, Business Growth Accelerator

Executive summary

When an agent buys, sells, or promises on your behalf, courts treat it as you. This analysis covers the Air Canada precedent, cryptographic agent verification, mandate evidence, and how to build a dispute-ready audit trail.

Section 1

The five challenges at a glance

Trust infrastructure is the unfinished half of agentic commerce. The transaction side is well funded: ACP, AP2, Visa Intelligent Commerce, and Mastercard Agent Pay all shipped in 2025, each with its own answer to authorization (Stripe, 2025; Google Cloud, 2025; Digital Commerce 360, 2025). The accountability side lags. Dispute-management specialists warn that AI-initiated purchases are creating a new category of chargeback risk for merchants and banks, because existing dispute codes assume a human clicked the buy button (Chargebacks911, 2026). Early answers are emerging, American Express paired its 2026 agentic developer kit with a commitment to cover erroneous purchases by registered agents in its controlled environment (The Financial Brand, 2026), but coverage like that is the exception. The default remains that the merchant of record absorbs the dispute, whoever's software erred. Meanwhile the legal baseline set in Moffatt v. Air Canada is principal liability: the business answers for its automated representatives (BCCRT, 2024). The five challenges below organize the exposure: liability allocation, agent identity, intent evidence, dispute infrastructure, and the expanded fraud surface. The consistent operator lesson is that trust, in 2026, is built from records, and the cheapest time to create a record is at the moment of the transaction.

Section 2

Challenge one: liability lands on the principal, the Air Canada baseline

Moffatt v. Air Canada, decided by the British Columbia Civil Resolution Tribunal in February 2024, remains the clearest judicial statement on automated-agent liability. Jake Moffatt, booking travel after his grandmother's death, asked Air Canada's website chatbot about bereavement fares; the bot told him he could apply for the discount retroactively, contradicting the policy page it linked to. Air Canada refused the refund, and before the tribunal made what the adjudicator called a remarkable argument: that the chatbot was a separate legal entity responsible for its own actions. Tribunal member Christopher Rivers rejected it, finding the airline liable for negligent misrepresentation and awarding $650.88, holding that a company is responsible for all information on its website, whether from a static page or a chatbot (BCCRT, 2024; American Bar Association, 2024). The dollar amount is trivial; the principle is not. Legal commentators across jurisdictions read the case the same way: businesses cannot outsource accountability to their software (McCarthy Tétrault, 2024). For a service business deploying client-facing agents, quoting prices, describing scope, promising timelines, every agent statement is effectively a statement by the firm. The operational consequences are concrete. Constrain agents to retrieval from approved sources rather than open-ended generation on pricing and policy questions. Keep the authoritative policy text in one place the agent cannot contradict. And log conversations, because in Moffatt the decisive evidence was a screenshot of what the bot actually said, the party with the record won.

Section 3

Challenge two: verifying that an agent is what it claims to be

Liability rules assume you know who transacted; on the open web, you usually do not. An inbound request claiming to be a buyer's agent is, by default, indistinguishable from a scraper, a credential-stuffing bot, or a competitor's price harvester. This identity gap is being closed by cryptography rather than policy. Cloudflare's Web Bot Auth, built on the RFC 9421 HTTP Message Signatures standard and moving through the IETF, lets an agent sign its requests against a published key so any receiving site can verify the operator deterministically (Cloudflare, 2025). A companion registry format, agent cards listing operator, purpose, and keys, aims to replace fragile IP allowlists (Cloudflare, 2025). The payment networks build on the same logic with different emphases. Visa's Intelligent Commerce program centers on verifying the agent itself, agent-specific payment tokens, step-up cardholder verification, and controls matching credential requests to authenticated instructions (Visa, 2025). Mastercard's Agent Pay pairs Agentic Tokens with verification of user intent, less who is the agent, more did the user actually authorize this (Digital Commerce 360, 2025). American Express runs a registered-agent model in a controlled environment, and backs registered-agent errors with a coverage commitment (The Financial Brand, 2026). For operators the near-term move is on the receiving side: configure your CDN or firewall to distinguish verified agents from anonymous automation, decide deliberately which tier may reach checkout or intake forms, and watch your payment provider's agent-verification rollout, because verified agent traffic is also the traffic with dispute-grade identity evidence attached.

Section 4

Challenge three: dispute evidence, mandates, records, and the chargeback gap

When an agent transaction goes wrong, the dispute turns on a question existing infrastructure was not built to answer: what did the human authorize? Card-network chargeback regimes assume a human purchaser; dispute specialists warn that agent-initiated purchases create a new class of contested charges where the cardholder truthfully says they never clicked anything (Chargebacks911, 2026). Under the major protocols, the merchant of record, the business, remains the default absorber of those disputes (Stripe, 2025). The structural answer is mandate evidence. Google's AP2 makes this explicit: three cryptographically signed mandates, Intent, Cart, and Payment, carried as W3C Verifiable Credentials, creating a tamper-evident chain from the human's instruction to the executed transaction (Google Cloud, 2025). When a dispute arises, the mandate chain shows whether the agent exceeded its authorization or executed it faithfully, converting a swearing contest into a records check. Amex's commitment to cover erroneous purchases by registered agents shows how issuers may price that evidence: protection attaches to verified, well-documented agent activity, not to agent activity in general (The Financial Brand, 2026). Service businesses should mirror this pattern even where formal mandates do not yet reach. On the selling side: timestamped logs of what an agent buyer was shown, price, scope, terms, and affirmative confirmation steps at commitment points. On the buying side, if your own agents procure on your behalf: written scope-of-authority definitions and spending limits, so you can demonstrate an agent acted outside its mandate. In every early dispute pattern, the well-documented party holds the leverage.

Section 5

Innovative solutions

The trust gap is being closed from four directions at once, and operators can borrow from each. From the standards world: signed-agent verification is being adopted as front-door infrastructure by major CDN, hosting, and commerce platforms, meaning small businesses inherit cryptographic agent identification through tools they already use rather than building it (Cloudflare, 2025). From the payments world: agent-specific tokens, step-up verification, and registered-agent programs push fraud screening to the network layer, with Visa expanding its agent-readiness programs globally through 2026 (Visa, 2025; Digital Commerce 360, 2026). From the issuer world: liability products. American Express's coverage commitment for registered-agent errors is the first mainstream example of an institution underwriting agentic mistakes, and it sketches the likely market structure, insurance and coverage attach to verified, logged, mandate-bound agent activity (The Financial Brand, 2026). Operators who keep dispute-grade records position themselves for cheaper coverage as these products spread. From the legal world: clarified doctrine. Post-Moffatt commentary converges on principal responsibility, which paradoxically helps operators by making the risk legible and therefore manageable (American Bar Association, 2024). The practical innovations that follow are contractual: terms of service that address automated purchasers explicitly, agent-use clauses in client agreements defining what each side's software may commit to, and confirmation checkpoints, a human-visible summary before any binding commitment, that create the consent evidence disputes turn on. None of these require engineering; they require a counsel review and a process decision.

Section 6

Solution framework

Organize agent-trust work into three ledgers: what your agents say, who you transact with, and what was authorized. The statements ledger covers outbound risk, the Air Canada scenario. Every client-facing agent gets a constrained knowledge base, a no-improvisation rule on price and policy, an accuracy review cadence, and durable conversation logs. The test: if a client screenshots any agent statement, would you honor it? If not, the agent should not be able to say it (BCCRT, 2024). The identity ledger covers inbound risk. Tier your traffic, verified agents, known bots, anonymous automation, using the verification signals your infrastructure already supports, and gate sensitive endpoints accordingly (Cloudflare, 2025). Extend the same discipline to your own outbound agents: as registries and signing schemes open to smaller operators, registering your agents makes your automated activity legible and trustworthy to counterparties (Visa, 2025). The authorization ledger covers dispute risk. For every agent empowered to commit resources, yours or a counterparty's, there should be a recoverable record of scope, limits, and the specific confirmation behind each commitment, modeled on AP2's intent-cart-payment chain (Google Cloud, 2025). Review all three ledgers quarterly. The framework's premise is that trust in the agentic economy is not a vibe or a brand asset; it is a set of records that either exist when a tribunal, issuer, or client asks, or do not. Air Canada's records did not (BCCRT, 2024).

Section 7

Evidence-based action plan

Days 1-30: audit your statements exposure. Inventory every place automated systems speak for your firm, site chat, intake bots, email assistants, scheduling agents. For each, verify it answers price, scope, and policy questions only from approved sources, and confirm conversation logs are retained and retrievable. Fix the single highest-risk gap first: an agent that can improvise about money. Moffatt turned on one retained screenshot; assume your next dispute will too (BCCRT, 2024). Days 31-60: put terms and verification in place. Have counsel add automated-purchaser language to your terms of service and agent-authority clauses to client agreements, who may deploy agents against whom, with what commitment power. Enable agent-verification features in your CDN, bot management, and payment stack as they ship, and decide your gating policy for unverified automation (Cloudflare, 2025; Visa, 2025). If you deploy buying agents, write their scope-of-authority documents and spending limits now. Days 61-90: build the dispute file before the dispute. Implement transaction-time logging: what the counterparty agent was shown, what was confirmed, by whom or what, when. Add a human-visible confirmation step at every binding commitment. Run one tabletop exercise, a client claims their agent was misled by your pricing page; assemble your evidence within one business day. Where the file is thin, that is your remaining build list. Issuer coverage and dispute outcomes are both converging on the same rule: documented agents are defensible agents (The Financial Brand, 2026; Chargebacks911, 2026). For adjacent evidence in this pillar, see [Pricing for Agent Buyers: How Machine-Readable Pricing Changes Negotiation and Margin](/blog/growth-pricing-for-agent-buyers-machine-readable-margin) and [The Agentic Divide: Which SMBs Are Getting Left Behind, and the Catch-Up Plan](/blog/growth-agentic-divide-smb-catch-up-plan).

FAQ

Direct answers for operators.

Who is legally responsible when an AI agent makes a mistake in a transaction?

The default is the principal, the business that deployed the agent. The Air Canada tribunal explicitly rejected the argument that a chatbot is a separate entity responsible for its own actions, awarding damages for negligent misrepresentation (BCCRT, 2024). In payment terms, the merchant of record typically absorbs disputes under current protocols (Stripe, 2025), though registered-agent coverage like Amex's is starting to shift specific cases.

How can a business verify that an AI agent is legitimate?

Through cryptographic verification rather than user-agent strings. Web Bot Auth, built on RFC 9421 HTTP Message Signatures, lets agents sign requests against published keys so receiving sites can verify the operator (Cloudflare, 2025). The card networks add payment-layer verification, Visa's agent tokens and step-up authentication, Mastercard's verified intent (Visa, 2025). Practically, most SMBs inherit these checks through their CDN and payment provider.

What records should a service business keep for agent transactions?

Three things: what your agents said (durable conversation logs), what counterparty agents were shown (timestamped price, scope, and terms), and what was authorized (confirmation events and scope-of-authority documents for any agent that can commit resources). This mirrors AP2's signed Intent, Cart, and Payment mandate chain (Google Cloud, 2025). In early disputes, the better-documented party consistently holds the leverage.

Do agent transactions increase chargeback risk?

Dispute specialists warn they create a new category of risk, because chargeback codes assume a human purchaser and cardholders can truthfully say they never clicked buy (Chargebacks911, 2026). Mitigations are emerging: mandate evidence, registered-agent programs, and issuer coverage for verified agent errors (The Financial Brand, 2026). Merchants reduce exposure by preferring verified agent traffic and logging confirmation events at every commitment point.

Joshua Agonya Pi'Rwot

Written by

Joshua Agonya Pi'Rwot

Founder, Business Growth Accelerator · Country Director, AVODA Group Uganda · EMBA

Joshua helps service-business operators turn scattered marketing into a clear path from first attention to booked call. He is Founder of Business Growth Accelerator and Country Director of AVODA Group Uganda.