Yesterday (September 22nd), six banks - ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING and NatWest - published a joint paper called Building Trust in Agentic Commerce. It sets out five principles for AI agents that shop and pay: transparency, safety, privacy and data, customer choice, and interoperability. It is also honest about the one thing those principles cannot yet settle. When an agent's transaction goes wrong, the banks write, the allocation of liability is unclear, and today's dispute processes do not involve everyone in the chain.
They are not alone in circling this. The first summit dedicated entirely to agentic commerce and payments met in Stockholm this month, and its agenda was not discovery or checkout. It was trust, identity, fraud and liability. Meanwhile the buying is starting whether the rules are ready or not: the British retailer John Lewis says AI agents now drive 2.5 percent of its search traffic, up from 0.3 percent a year ago. Adoption is moving faster than governance, and the people who run the world's payment systems have started saying so in public.
When a person buys the wrong thing, they know who to call. When an agent buys the wrong thing on a person's behalf, nobody is quite sure.
So the question deserves a serious answer. Who pays when the agent gets it wrong?
What recourse actually is
Strip the chargeback down and recourse is three things: a record of what was agreed, a way to decide who was right, and a way to make the wronged party whole. Evidence, adjudication, remedy. Card networks bundled all three into a single mechanism, and for fifty years of humans clicking buy, the bundle worked well enough.
Delegation breaks it at the first step. A consumer sets a budget and a goal, the agent executes, and a product arrives that the consumer never individually approved. The payment was authorized. The purchase, arguably, was not. The consumer's dispute has merit because they never saw the order. The merchant's defense is weak because they cannot prove intent they never witnessed.
The record that recourse depends on simply does not exist, and both sides lose the argument at once.
The stakes rose this year. Visa's consolidated dispute-monitoring program tightened its merchant threshold from 2.2 percent to 1.5 percent in April across the US, Canada, the EU and Asia Pacific, and the ratio counts events rather than value, so a disputed five dollar agent purchase weighs the same as a disputed five thousand dollar order. Among the networks, only American Express has committed to covering erroneous purchases made by registered agents on its network. Everyone else is still deciding.
There is also an honest critique aimed at our side of the industry. A merchant who moves to stablecoin rails to escape chargebacks also gives up the recourse the chargeback carried, for both sides of the trade. The critique has teeth. Independent teams are already shipping refund and arbitration layers for x402, with escrowed payments, dispute windows and neutral arbiters, because the gap is real and builders can see it.
Read the asks closely
The banks' paper is specific about what it wants. Providers should preserve an auditable record of what the customer instructed, what authority they granted, how they were authenticated, what the agent decided, and what happened after payment. Agents should identify themselves when they transact. Every relevant party should be able to join a dispute. And liability should sit wherever the error or the risk entered the transaction.
Read that list twice.
It is not a request for a larger phone bank or a faster reversal. Every item on it is an evidence requirement. The banks are describing a payment where proof is produced at the moment of the transaction rather than reconstructed weeks later from server logs and recollection. They are describing a verification rail.

Recourse by design
That is the rail we build, and the pieces are live.
Identity. An agent that can be identified can be held to account, and an agent with a reputation has something to lose. ERC-8004 gives an agent a persistent onchain identity with a track record attached, and the agents funded through our AI Builder Grants Program carry those identities into every transaction. The banks ask that agents declare themselves when they pay. On this rail, they already do.
Mandate. Authority is the second record. Two projects built through the grants program run deterministic policy checks before every payment and produces a tamper-evident evidence bundle for each transaction. Whether the customer granted this authority stops being a matter of recollection and becomes a matter of record, written at the only moment it can be trusted: before the money moves.
Evidence. Every GOAT Flow payment is verified onchain and leaves a receipt. What was requested, what was paid, when it settled, and which actor paid it. The audit trail the banks describe is not an extra system someone must remember to build. On this rail it is the byproduct of the payment itself.
Remedy. Remedies are programmable. A payment can sit in escrow until the deliverable verifies, then release or refund by rule, and a refund is an ordinary onchain payment with a receipt of its own. Verify the work, then pay is the pattern running through the businesses we fund. Micro-priced commerce shrinks the dispute surface to match: StableJack's endpoints on GOAT Flow price at half a dollar per call, so a wrong purchase costs half a dollar, and the receipt says which call it was.

Finality and recourse are different layers
We describe GOAT Flow receipts as receipts nobody can reverse, and some readers hear that as protection removed. It is the opposite: it is the separation of two things card rails fused together. Finality is a property of settlement. The ledger cannot be rewritten. Recourse is a property of the agreement above it. Evidence, adjudication, remedy.
Fuse the two, as cards did, and the only remedy is reversal, which then gets used as a weapon as often as a shield. Friendly fraud is already one of the largest dispute problems merchants face, and agent-initiated purchases will make genuine confusion and opportunistic disputes harder to tell apart, not easier. Separate the two and both get stronger. The record is incorruptible, and the remedy, whether a refund, an escrow release or an arbitration outcome, executes as a new and equally final payment with the evidence attached.
The separation runs all the way down this stack. What settles on GOAT settles on Bitcoin, so the finality under those receipts is the strongest available. And the deepest layer is itself built as a dispute process: the BitVM3 bridge design holds every withdrawal open to challenge for at least a week, with validity proven, and disputable, on Bitcoin itself. Dispute resolution was not a feature added to this system. It is the principle the system is made of, from a fifty cent API call to the exit.
One more reason this matters more for agents than for people. A person wronged in a purchase has patience, a phone and pressure to apply. An agent has none of those. A broken promise is bad for a person and worse for an agent, because the only protections an agent has are the ones written into the rail. If agents are going to carry real budgets, and the banks' paper exists because they are starting to, then the rail has to do the arguing for them.
The blueprint is running
The banks closed their paper by inviting the industry to help turn the principles into a blueprint. We think the fastest way to judge a blueprint is to run it. Merchants can sell to agents today with every payment verified and every receipt on the record, at goat.network/flow. Builders working on escrow, verification and agent identity can bring it to the grants program, where funding runs from $2,000 to $1M for the teams who ship.
Who pays when the agent gets it wrong? The party the evidence points to. That answer only works on rails where the evidence exists by default. Ours is live.


