What should a store do when an AI agent places a fraudulent order?
An AI shopping agent that can check out can also be pointed at fraud: stolen cards, promo abuse, inventory hoarding. The defenses are the same ones that work on human fraud, plus one new question every store needs an answer for: was this the agent misbehaving, or someone misusing the agent?
Agent fraud looks like normal fraud, faster
The fraud patterns are familiar. Card testing, where small orders probe which stolen cards still work. Promo stacking, where discount codes get combined in ways the merchant never intended. Inventory hoarding, where bots reserve limited stock. Account takeovers, where an agent logs in with stolen credentials and orders to a new address.
What changes with agents is the speed and the surface. An agent can run card tests across dozens of stores in parallel, read the checkout error messages as structured feedback, and adapt. The error message that tells a human "card declined" tells an agent "try the next card." Rate limits and velocity checks matter more, not less, in an agentic world.
First, figure out what actually happened
Before responding, classify the incident. There are three distinct cases, and they call for different responses.
Case one: agent error. The agent misread the catalog, applied the wrong discount, or ordered the wrong variant because the product data was ambiguous. This is a data quality problem on the merchant's side. Fix the feed, clarify the page, and treat the order like any customer mistake.
Case two: user misuse. A real person directed their agent to abuse a promo, test cards, or scrape and resell. The agent is the tool, the human is the fraudster. Handle it as fraud against the human: cancel, block, report.
Case three: agent misbehavior at scale. An agent framework's default behavior systematically exploits something, like retrying declined cards aggressively. This is a platform problem. The response is technical: block the agent's identifiers, tighten the rules it exploited, and report the pattern to the agent's operator.
What to log when it happens
The agent traffic log earns its keep here. For every suspicious agent order, record the agent's declared identity, the user agent string, IP addresses, the session's full request sequence with timestamps, which payment methods were attempted and in what order, and the checkout outcome. This is the evidence that separates "our checkout is broken" from "someone attacked our checkout," and it is what you hand to your payment processor when disputing chargebacks.
Keep these logs longer than your standard retention for fraud cases. Chargebacks arrive weeks later, and the agent session data is what proves the order was fraudulent rather than a fulfillment error.
Harden the checkout for agents specifically
A few controls pay for themselves. Velocity limits per session and per payment method, not just per IP, since agents rotate IPs. Declined-card attempt caps that trigger review rather than just another error message. Promo code rules that cannot be combined beyond what you explicitly allow, enforced server-side where the agent cannot see or edit them.
Consider requiring step-up verification for agent-identified sessions on high-risk orders: a new shipping address, a high-value cart, or a first-time customer. The agent can complete the verification if it is legitimate; a card-testing script cannot.
Where the liability sits
The uncomfortable question: if an agent places a fraudulent order, who is liable? The current answer is the same as for any fraud: the merchant bears the chargeback risk, and the cardholder whose card was stolen is made whole by their bank. The agent's operator is a new party in the chain, and the law has not fully caught up.
Practically, this means the merchant's fraud controls are the liability control. Document that agent traffic is subject to the same fraud screening as human traffic, keep the logs, and work with the payment processor's fraud tools. The stores that get hurt are the ones that treated agent checkouts as a novelty instead of a payment channel with the same risks as any other.
The takeaway
Do not panic about agent fraud, but do not ignore it either. Classify each incident as agent error, user misuse, or systematic misbehavior. Log everything. Harden the specific controls agents stress: velocity, card retries, and promo logic. The merchants who already run tight fraud controls will find the agentic era manageable; the ones running loose checkouts will meet their new fastest customers, the fraudsters, first.