What should a store's terms of service say about AI agent purchases?
Your terms of service were written for humans clicking buttons. AI shopping agents break the assumptions underneath them: who placed the order, who agreed to the terms, who is liable when the agent buys the wrong thing. The fix is explicit language covering agent-initiated orders, and the time to add it is before the first dispute, not after.
The liability gap nobody wrote terms for
Every terms of service assumes a human read them, or at least could have. An AI shopping agent does not read terms. It does not form intent in any legally recognized sense. It executes instructions from a user, a developer, or another agent, and somewhere in that chain an order appears on your store. When the order is wrong, the customer blames the store, the agent's operator blames the store's checkout, and the store has terms that say nothing about any of this.
This is not a theoretical problem. Agents already place real orders on real storefronts: reordering supplies, buying gifts, executing arbitrage. The volume is small today and the dispute pattern is already visible. The stores that handle it well will be the ones whose terms anticipated it. The stores that handle it badly will be writing the language under pressure, after the chargeback.
Three clauses that do the heavy lifting
First, a definition: state that orders may be placed by automated agents acting on a customer's behalf, and that the customer is responsible for orders their agents place. This closes the "I didn't click it" defense before it opens. Second, an authorization clause: by connecting an agent to the store, or by giving an agent the customer's credentials or payment details, the customer authorizes resulting orders. Third, a limitation on the store's liability for agent errors: wrong size, wrong quantity, wrong address entered by an agent is the customer's problem to solve with the agent's operator, not the store's to refund unconditionally.
Keep the language plain. Terms that read like they were written for this decade get more deference, from customers and from payment processors, than terms that pretend agents do not exist. Have counsel review the wording, but do not let counsel delete the clarity.
Agents and discount codes need a rule
Agents are tireless coupon hunters. They will try every code they can find, stack them in combinations no human would attempt, and share working codes with other agents instantly. Your terms should state the store's policy: one code per order, codes subject to change or cancellation, and orders placed with exploited or leaked codes may be cancelled. Without this, cancelling an order placed with a stacked exploit looks arbitrary. With it, it looks like policy.
This is also where your technical enforcement and your terms need to agree. If the terms say one code per order but the checkout accepts three, the terms lose. Align the code, then write the clause to describe what the code does.
Returns from agent orders follow the same rules, stated twice
State explicitly that the standard return policy applies to agent-placed orders. It sounds redundant until the first customer argues that an agent's mistaken order deserves special treatment. It does not, and the terms should say so: mistaken orders by agents are treated like mistaken orders by humans, subject to the same return window and the same restocking terms.
Consider one agent-specific addition: a short cancellation window for agent orders placed in obvious error, like duplicate submissions within seconds. Agents glitch. A five-minute self-serve cancellation window for duplicate orders costs little and prevents the disputes that cost a lot. Frame it as customer service, because it is.
Enforcement is the hard part
Terms are only as good as your ability to know an order came from an agent. That means detection: identifying agent user-agents, watching for inhuman interaction patterns, logging the signals. The stores that will enforce agent terms are the stores that can already see agent traffic in their logs. If you cannot tell which orders are agent-placed, the clauses are aspirational.
Build the visibility before you need the enforcement. Log user-agents, interaction timing, and session patterns now. When the first dispute arrives, the log is what turns "our terms cover this" into "here is the order, the agent signature, and the term it violated." Evidence beats language every time.
Review the terms every six months
Agent capabilities are moving fast enough that terms written today will have gaps in a year. Put a recurring review on the calendar: every six months, read the agent-related clauses against what agents can actually do now. The review takes an hour. The alternative is discovering the gap during a dispute, which is the most expensive possible time to discover anything.
The broader point: terms of service are a product surface now, not a legal formality. As agents become a real share of traffic, the stores with clear, current, enforced agent terms will have fewer disputes, faster resolutions, and a genuine competitive edge in the agentic channel. Write for the world that is arriving, not the one that is leaving.