Fraudology

La era agéntica: la alianza de Visa con OpenAI, las trampas de VAMP y la amenaza de los sitios clonados

Un gráfico de Fraud/ology #411 con el título «La era agéntica: la alianza de Visa con OpenAI, las trampas de VAMP y la amenaza de los sitios clonados», y una foto de Karisse Hendrick.

Bienvenido de nuevo a Fraudology.

En este episodio en solitario, me sumerjo en el comercio electrónico agéntico y, en concreto, en lo que ocurre cuando los agentes de compra con IA empiezan a realizar compras en nombre de los consumidores. Este es uno de esos temas que durante un tiempo sonaban muy futuristas. Hubo paneles en conferencias, muchas grandes predicciones y un montón de conversaciones del tipo “esto llegará algún día”, pero todavía no había mucho con lo que los equipos de fraude pudieran trabajar realmente.

Eso cambió cuando Visa y OpenAI anunciaron una asociación para crear infraestructura de pagos para el comercio con IA. Una vez que las capacidades de pago de Visa comiencen a integrarse en las experiencias de OpenAI, y a medida que las compras con ChatGPT y las transacciones iniciadas por IA se vuelvan más reales, los comercios van a necesitar entender los riesgos de fraude, contracargos, responsabilidad y operación que vienen con este nuevo canal.

Y es ahí donde creo que debemos desacelerar y hacernos algunas preguntas muy prácticas. ¿Quién es responsable cuando un agente de IA comete un error? ¿Qué pasa cuando un titular de tarjeta autorizó al agente, pero el agente compró algo equivocado? ¿Cómo puede un comercio demostrar que una transacción no fue fraudulenta cuando el titular de la tarjeta estuvo un paso alejado del proceso de pago? ¿Y qué sucede con la supervisión de fraude de VAMP cuando los contracargos de comercio electrónico con agentes y el fraude TC40 empiezan a aparecer de formas para las que el sistema actual no fue diseñado?

Este episodio trata realmente de dos riesgos que ya están empezando a aparecer. En primer lugar, la responsabilidad en el comercio electrónico con agentes y la responsabilidad por contracargos CNP no están preparadas para la forma en que se comportarán los agentes de compra con IA. En segundo lugar, el fraude de sitios web clonados y las estafas de compras en búsquedas con IA podrían generar una nueva ola de dolores de cabeza para el servicio de atención al cliente, problemas relacionados con TC40 y desafíos de gestión de riesgos para los equipos de comercio electrónico de las grandes empresas.

Lo que escucharás en este episodio:

  • Por qué la alianza de Visa con OpenAI hace que el comercio electrónico agente se sienta mucho más real para los comercios.
  • Cómo los agentes de compras con IA podrían crear nuevas responsabilidades por contracargos CNP y contracargos por fraude amistoso.
  • Por qué los comercios pueden tener dificultades para utilizar la evidencia contundente 3.0 cuando el titular de la tarjeta dio instrucciones a un agente en lugar de completar la compra por sí mismo.
  • Por qué la responsabilidad en el comercio electrónico basado en agentes necesita un nuevo marco antes de que las pérdidas se disparen.
  • Cómo el fraude de sitios web clonados y las estafas de compras en línea podrían empeorar cuando los agentes de IA buscan el precio más bajo.
  • Por qué el fraude TC40 y la supervisión del fraude VAMP pueden convertirse en un problema importante para los grandes minoristas.
  • Qué deberían empezar a preguntar ahora mismo los líderes de fraude a los adquirentes, las marcas de tarjetas, los equipos de atención al cliente y los equipos de TI.

Deberías escuchar este episodio si:

  • Trabajas en la prevención del fraude para comercios o en la prevención del fraude en el comercio electrónico y necesitas entender hacia dónde se dirige el comercio con agentes de IA.
  • Son responsables de los contracargos, la monitorización de VAMP, la revisión de TC40 o la estrategia de fraude CNP.
  • Trabajas en un banco, emisor, marca de tarjeta o empresa de pagos y quieres entender por qué los comercios están preocupados.
  • Están tratando de averiguar cómo el checkout agente, los pagos con IA y los pagos agénticos pueden cambiar las operaciones de fraude.
  • Quieren una perspectiva práctica sobre el fraude en el comercio con ChatGPT, las estafas de compras mediante búsquedas con IA y el riesgo de sitios clonados.
Notas del episodio y conclusiones clave

El comercio electrónico agéntico ya no es solo una conversación sobre el futuro

Durante un tiempo, el comercio agéntico se sintió como uno de esos temas de los que todo el mundo hablaba, pero nadie podía señalar con claridad qué debían hacer a continuación los equipos de fraude. Había muchas predicciones y muchas conversaciones teóricas, pero muy pocas conclusiones operativas aplicables.

El anuncio de Visa y OpenAI cambió eso para mí.

Cuando Visa dice que sus capacidades de pago se integrarán en las experiencias de OpenAI, y cuando el comercio con ChatGPT empiece a acercarse más a transacciones realmente iniciadas por la IA, esto se convierte en algo que los comercios deben tomarse en serio. Esto no significa que mañana todos los consumidores vayan a empezar a usar agentes de compra basados en IA. Pero sí significa que se están construyendo las vías, y una vez que esas vías están construidas, los problemas de fraude y contracargos suelen aparecer muy rápidamente.

La razón por la que esto es importante para el comercio electrónico con agentes es que los agentes de IA no se comportan exactamente como los humanos ni tampoco exactamente como los bots tradicionales. Pueden ser dirigidos por un consumidor, adaptarse a las instrucciones, buscar en distintos sitios web, comparar precios y completar una compra. Eso crea una nueva capa entre el titular de la tarjeta y el comerciante.

El sistema actual de contracargos no está preparado para los agentes de compra con IA

Una de mis mayores preocupaciones con el comercio electrónico basado en agentes es que el marco actual de contracargos no fue diseñado para ello. En este momento, si una transacción es sin tarjeta presente, la responsabilidad generalmente recae en el comerciante. Eso puede tener sentido en ciertos escenarios tradicionales de fraude CNP, pero se vuelve mucho más complejo cuando un agente de IA actúa en nombre de un titular de tarjeta real.

Si el titular de la tarjeta le dice a un agente que compre dos artículos y el agente compra 20, ¿qué se suponía exactamente que debía hacer el comercio? Si el agente reserva el vuelo equivocado, elige el producto incorrecto o malinterpreta las instrucciones del usuario, ¿cómo habría podido saberlo el comercio en el momento de la compra? A menos que el comercio tenga superpoderes o un psíquico sentado junto al equipo de fraude, puede que no haya ninguna forma práctica de detectar que esto va a convertirse en una disputa.

Por eso los contracargos en el comercio electrónico con agentes son tan preocupantes.

Es posible que el comercio reciba una disputa en la que el titular de la tarjeta afirme que dio instrucciones al agente, pero que cambió de opinión o que el agente realizó una compra incorrecta. Eso no encaja claramente en los flujos de trabajo actuales de fraude, fraude amistoso o de compelling evidence 3.0. Y si el comercio no puede cumplir con los requisitos de re-presentación existentes, perderá los fondos incluso si la compra fue iniciada por un agente autorizado por el titular de la tarjeta.

Esa es la brecha de responsabilidad.

Y a menos que las marcas de tarjetas, las plataformas de agentes y las redes de pago creen una estructura más clara para la responsabilidad en las compras realizadas por IA, los comercios acabarán asumiendo pérdidas que razonablemente no podrían haber evitado.

La exposición a VAMP hace que el comercio electrónico agente sea aún más arriesgado para los comercios

No se trata solo de perder contracargos individuales. La preocupación mayor es el impacto que estas disputas podrían tener en la supervisión del fraude de VAMP.

VAMP ya es un problema serio para los comercios. Los contracargos y los TC40 pueden generar una exposición financiera real, y no existe el mismo tipo de período de gracia al que los comercios podían estar acostumbrados con los programas de monitoreo anteriores de Visa. Una vez que un comercio supera el umbral, las multas y comisiones pueden acumularse rápidamente.

Ahora súmale el comercio electrónico agente por encima de eso.

Si los agentes de compras con IA generan más disputas, incluso en transacciones en las que el comercio no hizo nada malo, esos contracargos aún pueden contarse en su contra. Si las transacciones agentivas no se identifican claramente en el flujo de pago, es posible que los comercios no puedan separar esas transacciones en una categoría de riesgo diferente. Y si no existe un nuevo cambio de responsabilidad ni un proceso de representación para las transacciones iniciadas por IA, el comercio está asumiendo el riesgo de un canal que quizá ni siquiera pueda identificar.

Esa es la parte que necesita atención ahora.

Visa, Mastercard, OpenAI y cualquier otra plataforma de comercio con IA deben reflexionar sobre el lado del comerciante antes de que estas pérdidas se escalen. Si la plataforma agente comete el error, o si el consumidor autorizó al agente y luego impugna el resultado, no tiene sentido que el comerciante asuma automáticamente la responsabilidad financiera.

El sistema de contracargos nunca ha sido perfectamente justo. Pero este es un canal nuevo, y los canales nuevos necesitan reglas nuevas.

Los comercios necesitan una forma de identificar las transacciones realizadas por agentes

Otro problema es la visibilidad. En este momento, la mayoría de los comercios no tienen una forma confiable de saber si una transacción fue realizada por un humano, un bot o un agente de compras con IA.

Si no puedes identificar el tipo de transacción, no puedes diseñar una estrategia de riesgo diferente en torno a ella. No puedes enrutarla de otra manera. No puedes medir la tasa de contracargos. No puedes probar si el checkout agente se comporta de forma distinta al checkout móvil o al checkout web. No puedes separar los pagos realizados por agentes de las transacciones normales de comercio electrónico. Y no puedes crear una sólida estrategia de prevención de fraude para comercios en torno a un canal que no puedes ver.

Algunos proveedores más nuevos están empezando a trabajar en la detección de agentes de IA, pero la mayoría de los comercios que usan herramientas heredadas no tienen una forma clara de identificar las transacciones realizadas por agentes. El tiempo por sí solo puede no ayudar, porque estos agentes de IA pueden imitar el comportamiento de los consumidores. Las señales del dispositivo pueden no ser evidentes, ya que los agentes pueden usar identificadores de dispositivo reales o emuladores. Y el propio flujo de pago aún puede no indicar a los comercios que la transacción provino de un agente.

Por eso creo que eventualmente tendremos que considerar el comercio agéntico como su propio canal.

Ya pensamos en la web y en el móvil de forma diferente. Es posible que el comercio electrónico con agentes necesite el mismo tipo de tratamiento. Los agentes de IA pueden necesitar un flujo de pago distinto, un flujo de gestión de riesgos diferente y otro conjunto de señales, porque no interactúan con los sitios web de la misma manera que los humanos. Pueden alucinar sobre dónde está un botón. Pueden malinterpretar una página. Pueden elegir el producto equivocado. Pueden seguir un camino que tiene sentido para una máquina, pero no para los controles antifraude actuales de un comercio.

Hasta que los comerciantes puedan identificar el canal, seguirán atascados intentando gestionar el riesgo agéntico con herramientas que fueron creadas para un mundo diferente.

Los sitios clonados pueden convertirse en un problema mayor porque los agentes de IA están entrenados para encontrar la mejor oferta

El segundo gran riesgo en este episodio es el fraude mediante sitios web clonados.

A los estafadores siempre les han encantado las tiendas minoristas falsas, los sitios web de comercios falsos y las páginas de phishing. Eso no es nuevo. Lo que está cambiando es lo fácil que resulta clonar un sitio web y hacer que parezca funcional. La IA puede ayudar a los estafadores a duplicar páginas de productos, imágenes, procesos de pago y la presentación de la marca mucho más rápido que antes.

Ahora combina eso con agentes de compras de IA.

Si un consumidor le pide a un agente de IA que encuentre la mejor oferta para un producto, ¿para qué está optimizando el agente? A menudo, es para el precio. Y los sitios web minoristas falsos son muy buenos ofreciendo el mejor precio porque en realidad no intentan entregar el producto auténtico. Lo que intentan es robar datos de tarjetas, recopilar información personal, procesar una transacción fraudulenta o redirigir al comprador a una estafa.

Eso crea un problema muy evidente.

Un agente de IA puede encontrar lo que parece ser la versión de un producto con el precio más bajo y enviar al consumidor a un sitio clonado. El consumidor puede confiar en él porque la herramienta de IA se lo recomendó. El sitio puede parecer legítimo. El precio puede parecer increíble. Y el cliente puede creer que ha comprado al comerciante real.

Entonces el producto nunca llega, o el cliente recibe un producto falso, o se ve comprometida la información de su tarjeta.

¿Y quién se entera primero? A menudo, el equipo de atención al cliente del comerciante real.

Incluso si el comercio no procesó la transacción y no recibió los fondos, el cliente puede seguir creyendo que compró a ese comercio. Eso genera costos operativos, frustración del cliente, daño a la marca y otro problema de fraude que el comercio tiene que ayudar a resolver.

El fraude TC40 y los descriptores falsos pueden generar problemas VAMP incluso cuando la venta no fue tuya

El problema de los sitios clonados no es solo una cuestión de atención al cliente. También puede convertirse en un problema de TC40 y VAMP.

Los TC40 están vinculados a los descriptores, no solo al ID del comercio. Esto significa que, si un comerciante fraudulento utiliza un descriptor que se parece al nombre de un gran minorista, con palabras, números o modificadores adicionales, el comerciante legítimo puede ver actividad TC40 que en realidad no le corresponde.

Ese es un problema importante para los grandes minoristas.

Si un sitio falso utiliza un descriptor que comienza con el nombre de una marca real, el comerciante legítimo puede verse obligado a identificar esas transacciones y demostrar que no son suyas. En un entorno VAMP, ese factor de tiempo es importante. Los comercios necesitan saber con qué rapidez su adquirente les notificará si están en la lista VAMP, porque el reloj puede empezar a correr cuando se notifica al adquirente, no cuando el comerciante finalmente se entera.

Eso significa que los comercios deben ser proactivos.

Si eres responsable de la supervisión del fraude VAMP, habla ahora con tu adquirente. Pregunta con qué rapidez te notificarán. Pregunta qué datos TC40 recibirás. Pregunta si tendrás suficiente detalle para identificar descriptores fraudulentos. Pregunta cuál es el proceso para eliminar las transacciones que no pertenecen a tu ID de comercio.

Porque si el comercio electrónico agéntico impulsa más estafas de compras mediante búsquedas con IA y más tráfico hacia sitios clonados, los comercios pueden ver más ruido en sus datos TC40. Y si ese ruido no se elimina rápidamente, puede volverse costoso.

Los equipos de atención al cliente, TI y fraude deben prepararse juntos

Una de las conclusiones más prácticas de este episodio es que esto no puede recaer únicamente en el equipo de fraude.

Si el fraude en el comercio electrónico agente y en sitios web clonados se convierte en un problema mayor, los equipos de atención al cliente deben saber qué están viendo. Es posible que empiecen a recibir llamadas de clientes que insisten en que hicieron un pedido en tu sitio web, pero no hay ningún pedido en tu sistema. Eso resulta confuso para el cliente y frustrante para el equipo de soporte si nadie les ha explicado de antemano el problema de los sitios clonados.

Los equipos de TI también deben formar parte de la conversación, porque es posible que los sitios web falsos tengan que ser reportados, escalados y dados de baja a través de canales de DNS o de alojamiento. Los equipos legales, de protección de marca, de fraude, de atención al cliente y de seguridad pueden necesitar coordinarse rápidamente.

Y la parte de comunicación con el cliente también es importante.

Es posible que los comercios tengan que recordar a los clientes que vayan directamente al sitio web o a la aplicación oficiales, especialmente durante los periodos de compras de alto volumen, los lanzamientos de productos y las temporadas festivas. Ese mensaje no puede resolver todo el problema, pero sí puede reducir parte de la exposición.

Aquí es donde la gestión de riesgos del comerciante debe volverse interfuncional. El comercio electrónico agéntico no es solo un problema de fraude. Abarca los pagos, las devoluciones de cargo, el servicio al cliente, la protección de la marca, TI, el área legal y la experiencia del cliente.

Conclusión final:

El comercio electrónico agéntico está pasando de la teoría a la infraestructura. Y una vez que existe la infraestructura, el fraude le sigue.

La alianza de Visa con OpenAI puede ayudar a que el comercio impulsado por IA sea más sencillo y escalable, pero también plantea serias dudas sobre la responsabilidad en el comercio electrónico agéntico, la responsabilidad por compras realizadas por IA, la responsabilidad en contracargos CNP y la exposición de los comercios bajo VAMP. Al mismo tiempo, las estafas de compras mediante búsquedas con IA y el fraude de sitios web clonados podrían dirigir a los agentes de compra de IA hacia tiendas minoristas falsas que parecen legítimas, ofrecen excelentes precios y causan daños reales a consumidores y comercios.

Así que, si eres un líder de fraude en comercios, ahora es el momento de empezar a hacer preguntas incómodas. ¿Puedes identificar las transacciones gestionadas por agentes? ¿Puedes separar los pagos realizados por agentes de la actividad normal en la web y en el móvil? ¿Tus equipos de contracargos saben cómo manejar los contracargos de comercio electrónico gestionado por agentes? ¿Tu adquirente te notifica con suficiente rapidez si surgen problemas relacionados con VAMP? ¿Tu equipo puede identificar descriptores falsos en los datos TC40? ¿El servicio de atención al cliente sabe qué hacer cuando alguien llama por un pedido que no existe?

Porque este canal está llegando. La cuestión es si los comercios, emisores, adquirentes, marcas de tarjetas y plataformas de IA van a establecer las reglas antes de que las pérdidas se disparen o después.

Recursos y enlaces del episodio:

Conéctate con Karisse Hendrick | LinkedIn

  • Presentadora del pódcast Fraudology
  • Experto en ciberfraude galardonado
  • Consultor en prevención de fraudes en comercio electrónico
  • Asesor de startups, orador principal y
  • Consultor para comerciantes de Fortune 500
Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:02
Welcome to Fraudology Podcast, where we dive into the science and study of online fraud from the perspective of an e-commerce fraud fighter. I'm Karisse Hendrick.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:12
Welcome back to the Fraudology Podcast. This will be another solo episode. I think if you've been listening along in chronological order, you can guess that I've been kind of doing every other one with a guest and one on my own today. There's a topic that I want to dive into, and that is AI agentic commerce, specifically. So purchases made by AI agents in the online world. And if you work for a bank and you're like, oh, this is for merchants, hold tight because this will impact you as well. And if you're from a card brand, please listen because we need your help. Before that, I'm just going to do a reminder that the Merchant Fraud Alliance first inaugural conference. So I guess that's a double, double meaning there. So inaugural conference is October 6th and 7th in Chicago. We have some pretty optimistic goals for how many people are going to come, but we also have some really killer ambassadors that have from companies such as Booking and Best Buy and Walmart and Google and so many more that I can think of that have stepped up to be part of the planning committee and the board essentially, and have also pledged to come to the conference. So we have a great group of people that are coming already. They'll also. A lot of them will be speaking as well. We just met for a second time this past week, going through all the topics and starting to address some of the speakers. And we have, you know, someone from PlayStation, someone from Booking talking about how they're integrating AI into fighting fraud and training their analysts to utilize AI in different ways, whether it's for data analytics, reporting, dashboards, things like that. We have someone from Best Buy talking about working cross functionally with other departments. She literally is the best person, I think, that could speak to this topic. A good friend of the podcast, Holly Sandberg, is going to be talking about creating an executive score chart or scorecard for your executives and really explaining managing up and really quantifying fraud for them in ways that they understand. I had a chance to see her speak on this topic at the Assertify User conference last month, and it was really good. So those are just off the top of my head, a few of the sessions I can think of that you'll want to be there for. We're also doing an AI bootcamp on October 5, the day before the conference starts. And that's only open to people that register. You know, it's in the order you register. We're going to have about 50 slots, so I know that there's a few more spaces open. So make sure that you register soon. And if you're listening to this before July 1st, tickets are only 495 for merchants. We aren't selling vendor tickets. We have a select number of sponsor companies that are attending, but we won't be selling vendor tickets. This is for merchants only. Okay, that's enough of a plug for my conference, but that is literally all that I'm like breathing and doing right now. So I had to give a little bit of an update. I want people to show up. I want it to be as good of an experience as it can be for everyone. If you have known me at all. I try to make sure that everyone gets their time and their money's worth of anything that I work on. And this podcast is a good example. It's free and I still give out a lot of information. So, you know, just assume that the conference will be even better than a podcast episode. All right, I really am going to turn to agentic commerce now. I've, you know, I've had Robbie McDermott on the podcast talking about liability for agentic commerce. I've talked a little bit about it here and there, but I've kind of shied away from it for a few reasons. One is there was a conference in the spring that really focused a lot on agentic commerce, but there wasn't any news. It was all kind of pontification and future forward looking. And you know, the feedback I heard from almost everyone I talked to about it was there was no, there were no takeaways because we just aren't there yet. Then we saw OpenAI scrap their project. And I think, I think I made mention of that on the podcast on a solo episode a few weeks ago where they scrapped their project for, I can't remember what they called it, but it was where they had AI agents finish a purchase. So they were going to be the merchant of record. And I think they realized that liability rules as well as other issues. They didn't want to get involved, so they scrapped that project. I think also adoption was really low, so all of those things combined. I haven't really talked about it because I haven't felt like there's been a lot to say. I haven't known if it's actually going to be a thing. Yes, it's been talked about a lot. But it, you know, is going to be adopted by more than 5% of consumers. Those of them I open questions. But then an announcement came out about two weeks ago that made me think, okay, this is probably happening. I'm going to go ahead and read the LinkedIn post that I wrote about it to start just because I think I did a pretty good job of summarizing this. Last week it was announced that Visa and OpenAI are partnering to build infrastructure designed to make AI commerce secure, scalable and seamless. That's in quotations. Those are their words in this statement. Visa also said that Visa's payment capabilities will be integrated into OpenAI experiences, giving developers and merchants a streamlined way to accept Visa payments initiated by AI agents. They also said Visa will deliver the underlying global network payment tokenization authorization, agent identification and fraud monitoring infrastructure to support secure and trusted AI initiated transactions. So I'll stop there from my post and just say that, you know, the fraud monitoring isn't necessarily from the merchant perspective. It's just the general fraud monitoring that Visa does, you know, looking for card testing, that type of thing. Also on the issuer side, their fraud monitoring, I it doesn't say that Visa is doing anything new as far as fraud monitoring. So I wouldn't take that statement to mean, oh, they're going to do fraud monitoring on agentic transactions so I don't have to.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
06:39
I would not at all read in that into it. So now that Visa and you know, OpenAI, who you know is behind ChatGPT, are partnering with each other. That's a lot of power. That's a lot of brand power, but also just a lot of, you know, they're lending the visa rails to OpenAI transactions, to transactions that are initiated in ChatGPT. So some of the use cases would be, you know, if I wanted to book the best flight for the cheapest price. But I didn't want to search all of the, you know, travel agent online travel agency sites. I didn't want to use Google. I and maybe I had a little time, so maybe I had a week. I could create a prompt in ChatGPT to ask it to, you know, create an agent to look for the best Airline price from Seattle, Washington to San Francisco, California. And you know, you can set as many parameters as you want, right? Like I want my departure time to be after 10am. I want my arrival time to be before 9pm. I want, you know, a window seat, I want an aisle seat. But a lot of people aren't going to do all of those qualifiers. You can, but they may not. So you know, that opens it up to a lot of issues right. What if my, you know, and then my final prompt for that would be, find the best rate in the next week and book it on my behalf. Here's my card information. Here's, you know, my TSA pre check number or whatever you need to do, just do it for me. Others would be around, you know, sale prices, the best, you know, best deal on a sweater or a pair of shoes, or what if there's a drop coming of new sneakers. It's kind of similar to a bot, but it's different where you're directing an agent to do it for you rather than a bot, so it can adapt more. There's a lot of issues that I see with this and we're going to talk about another issue after I talk about this first one. But, from a chargeback perspective, this was really scary to me because at the end of the day, the VISA infrastructure does not support agentic e-commerce chargebacks.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:50
There's no process for them, there's no verbiage for them. There's nothing. There are chargebacks that are going through right now to merchants that are very obviously, you know, were initiated by an agent. Either the, you know, cardholder says so in their statement or the merchant can tell it was created by an agent and not a person. There's no guidance for. So the merchant is getting those chargebacks. The liability is working the way it always has where it's, if it's card not present, it's on the merchant. There's no additional liability. You know, hey, if it's, if the agent makes a mistake or it books something that the cardholder didn't want it to, or it orders 20 items instead of two, all of those different scenarios. There's no additional guidance for where liability goes. So it falls on the merchant. And I'll read what I wrote in my LinkedIn post and then I'll go a little bit further about this too. So I said there are two things I want to highlight about this announcement from the merchant perspective. Number one, and this is a little, you know, a little bit what I just said. But there are no stated changes to the chargeback liability framework for CMP transactions. This most likely means that when mistakes are made, like an agent orders the wrong thing or too much of one thing, these cardholder disputes will fall to the merchant to repay to the consumer. Even if there was nothing a merchant could have done to know it was a mistake or prevent it at the time of a transaction. The reason I said that is the whole point of the CMP liability Rules has been, well, merchants should be able to detect fraudulent transactions before they occur. So therefore they have the liability rules. In this case, it's similar to what we call friendly fraud. Right. If the cardholder information validates and it looks like the cardholder initiated the transaction, and the cardholder was involved in the transaction they initiated the agent, that type of thing, it still falls on the merchant.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
10:50
Even though there was nothing, aside of having superpowers or a psychic on hand, there's nothing they could have done to say, oh, that one order is going to come back as a chargeback, or, you know, the cardholder told the Agent to buy two, not 20, so we should cancel 18 of these. There's nothing a merchant can do. However, they're still liable. So I said, we also need to consider that more chargebacks for merchants equals a higher risk for VAMP infractions. This could mean more fines, fees, and issues with acquirers that are outside the scope of prevention for CNP merchants. So with VAMP, which man did we have a good webinar with Anoush at Visa for MFA? It was a couple weeks ago. I think it's available through About Fraud. I actually haven't asked PJ or Ronald about that, but it was recorded. I know that it was so good. And we're actually going to have a second one in August because there were just. There was so much engagement from the audience that we didn't get through everything that we needed to or wanted to or that the merchants had asked us to. Anyway, that's a side note about VAMP, but, you know, VAMP is real, and your acquirers are now managing your risk. And the more chargebacks you have, the higher risk for VAMP infractions. Vamp is not cheap. And there's no. There's no trial month. There's no safety month. That used to be that you had two to three months before the VFMPs or VDMPs would charge fines. That doesn't happen anymore. There's now, it's the first month that you go over that 1.5%, you occur $8 per TC, 40 and per chargeback. And that adds up real quick. So there's, you know, there's no wiggle room. There's no safety time. It's just instant. So it is something to be considered. But then I put my take and I said, my hope in asterisks is that visa and OpenAI rework the liability for these circumstances to require the agentic platform OpenAI in this case, to take financial liability for agent mistakes.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:56
Do I know that that is extremely optimistic and probably not likely. Yeah, I do, but I at least need to call it out. I felt the need to call it out and say, hey, merchants shouldn't be responsible for agentic mistakes. What if it's a mistake on the developer's side? You know, there's nothing a merchant could have done to stop that, but yet now they have to pay back the transaction. Doesn't make a lot of sense, doesn't seem fair, which, I mean, the chargeback system has never been fair. My grandmother used to say if I ever said something wasn't fair, she would say, you know, the fair only comes once a year, meaning that nothing's fair and the county fair is the only thing that exists. I know the chargeback system isn't fair, but we're opening a new channel. I just saw a good presentation from a startup recently where they talked about, you know, we have the e-commerce channel or the web channel, we have the mobile channel and now we're going to have the agentic channel. And the agentic channel should go through a different flow because it doesn't, you know, recognize the website in HTML format the way that human eyes do. And you know, they often will hallucinate where a button is or it will, you know, order the wrong thing because they think that button's over here or it just. Agents can't navigate websites the way that humans can. And so there needs to be a more agent friendly site where maybe humans can't understand it, but agents will know exactly, exactly what to do and where to go. I thought it was an interesting take because then also your fraud and risk decisions would be different as well if you are able to parse out the agentix transactions into their own bucket and look at the data on those. So yeah, that is something to, you know, consider. Right now we don't have an agentic channel. There is a company trying to build one right now. Visa doesn't have any way for merchants to identify in the payment flow that a transaction was initiated by an agent. Maybe that will change once their partnership with OpenAI goes through, but right now they don't. I only know of maybe two vendors on the merchant side that are really able to identify agentic orders.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:12
Most of the merchants using legacy tools, if not all of them, have no way of, you know, they've done so many tests, transactions on every different agentic site and then, you know, looked on the back end for any identifiers of what, you know, how they can tell that an order was placed through ChatGPT. And timing doesn't matter anymore because these agentic platforms are trying to mimic consumer behavior so the transactions are approved so they aren't moving fast. Otherwise they get caught up in bot detection. There's no device difference. They're using real device, you know, IDs and emulators. There's no way right now to identify it. Unless you have maybe one of two tools that are still pretty new. Yes, Sardine is one of them. I got a one on one demo from Supes, actually the CEO of Sardine, while at a conference this spring on exactly how they can detect an AI agent. And it was really fascinating. But I know of another company that is able to do that as well. But my whole point being right now there's no way to tell if it was an agentic transaction on the merchant side. And there's no additional liability shift for merchants when errors occur or when fraud occurs or anything like that. And that needs to be looked at. My other concern, and this is, this kind of, this goes hand in hand, right? Because if you don't know that an agentic transaction is coming in, you can't do anything to stop it or prevent it. There are currently no provisions for chargeback represented by a merchant. When an agent initiates a transaction on behalf of a cardholder, a cardholder can change their mind, claim fraud, or state that the wrong item was purchased. And there is no way for merchants to dispute these claims or reverse the debited funds. Merchants are currently receiving these chargebacks and are automatically losing them. Once OpenAI and visa partner up, these losses will skyrocket. My take before this partnership goes live is that it's imperative that Visa and MasterCard as well. But right now it's about Visa. At least give merchants an opportunity to prove that these purchases were not fraudulent and that the cardholder authorized their agent to make this purchase. If changes aren't made to the liability structure of CMP transactions and to the ability for merchants to dispute chargebacks, the financial losses will be astronomical. So yeah, that's some big news. But you know, if you have a Visa rep that you work with, bring this up to them, ask them what they're doing about it. I have been in touch with my contact at Visa who said, you know, this is such a new thing. They don't know if this has been considered yet, but that they were going to do their best to run it up the flagpole for consideration. I don't know if there will be any motivation to change these things if there's not a little pressure so, you know, be aware that this is the case. I already know of one merchant that lost a pretty big dollar transaction when the cardholder said I directed my agent to the purchase, but I changed my mind. That was in the cardholder documentation of the chargeback. The merchant highlighted that along with their terms of service and you know, all the other things that were required for that specific chargeback reason code. And they were given an automatic decline because this is agentic e-commerce, and it didn't fulfill the compelling evidence 3.0 requirements. You know, an agentic transaction may not even fulfill the C2. O requirements because the cardholder technically wasn't involved, but they directed it. So the cardholder is one removed from the transaction now, which makes it difficult.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:10
This episode is brought to you by Sardine. One of the things I enjoy about working closely with Sardine is the ability to learn more about identifying and preventing fraud and scams. For instance, I've learned that the best way for a bank or fintech to detect a scam is to look at the five seconds before a transaction. Most fraud in AML controls focus on the transaction itself, but it's those things immediately before it that help you stop scams. That's in the preauth signals. That's why user, device, and behavior are so crucial. In those five seconds you can identify if another user is driving that device from a remote desktop access. Or you can learn that the phone making a transaction is upside down and not actually in use. You can also identify the behavior of the person behind the device and what their true intentions are. It's those little details that all add up. For more information about this or any of the other products within Sardine, go to www. Sardine. AI to read more information or to request a one on one product.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:13
So I'd love to know your thoughts other than oh crap. If you're on the banking side, the issuer side, be aware of this. I would love for you to not forward these on to merchants when you see mention of an agent. But obviously I know you have cardholders to appease and everything else. And that's why I really do think that the agentic platform should have liability on these transactions, especially for errors. But I don't know how they would be able to do that because obviously OpenAI and any other agentic platform is going to lobby to keep playability the way it is. So that is something to be aware of as we start talking about agentic AI. Those are two concerns and two things that I think we all need to be aware of there is no liability shift for merchants. It's always on them. And there's no way for them to win those transactions because there's no provisions in the chargeback documentation about agentic transactions. Obviously, agentic commerce is moving very quickly. There wasn't even a lot to report in March, you know, so now there is right now in June. We're like, oh, okay, Visa and ChatGPT are gonna, you know, join forces. That sounds big. MasterCard has made a similar announcement, but not with a large, it's not in partnership, it's like their own thing. And I mentioned a few weeks ago another solo podcast that amex has said that if a cardholder uses their agents and their rails for a transaction, that the cardholder won't be liable for that. They don't say that it won't be turned on to the merchant. They just say that there's consumer protections on those transactions. So I don't know if they're planning to take the hit or pass those on, but, you know, the ball is moving already, is what I'm trying to say. So along that note, another issue that I see for agentic e-commerce, and this was something I thought of kind of right away when I started wrapping my head around what agentic e-commerce is, is that agents will be trained to look for the best price or they'll be, you know, trained to look for the best location or the best timing or, you know, whatever it is. If it's for concert tickets, it's the, you know, the best seating. It's the best, you know, whatever those things are, they're trained to look for those. But I would say the majority of them are looking for a deal. There are a lot of fishing websites out there, especially because of AI, because it's so easy. And Matt Vega on the podcast a month or two ago, talking about how easy it is to clone a website, he clones MasterCard's website right in front of me as we were talking and recording the podcast. He did it in about five minutes, and he was able to harvest people's information off of that. So had he made that website go live? Had he, you know, attached it to Google SEO or other search engine optimization for other browsers, he could advertise and people could think, oh, that's MasterCard's website. I have no problem putting in all of my information. But then later down the line, their identity is stolen or their credit card is used. So, you know, it's easy to make fake websites. We know that fraudsters love to create fake websites and replicate merchants. So duplicate their websites. So say, I'm not going to pick on one particular company, but like Merchant A, for whatever reason, sorry, I couldn't come up with like a creative name that wasn't real. Merchant A has, you know, sells furniture and they have, you know, proprietary photographs of all their furniture on their website. They have, you know, it's. It's their website and then it allows consumers to interact with it, to put things in their cart, to visit their cart, to, you know, then check out. Fraudsters can now duplicate not only the, they used to be able to duplicate the pictures they would copy and paste, they would scrape the websites, etc. But now they can make those functional. They can say, hey, make it possible for a cardholder to order this item and purchase this item.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:28
And then chances are they're harvesting credit card numbers and the person that you know, placed the order never gets the item. Or if they do, it's something that's really fake. It's not the real item that they thought they were ordering. Well, with agentic e-commerce, those agents are looking for the best deal possible. Those phishing websites are known for giving the best prices ever. I think we've all seen, you know, especially around drops or holidays, big purchase times. I'm sure we've all seen Facebook ads or Instagram ads for $20 Nikes or, you know, $50 airline tickets or whatever it is. You just have to click their website. Well, chances are that website isn't real and it's going to look like it's coming from Costco or United Airlines or it's going to look like it's coming from Nike themselves, but it's not. So what's going to happen is a lot of those agents are going to choose the lowest price, which is going to go to a fake website. A fake website that now has actions that can now collect credit cards, that can sometimes in some cases process credit cards. That's going to cause a lot of fraud. It's going to cause a lot of issues. The types of issues it'll cause are at your call center. You'll see more calls with people saying, hey, I ordered this item on your website, but it never came, or I got a pair of fake Nikes instead of real ones or whatever it is that is going to cause, you know, going to take time for your customer service to research it because there won't be an order on file for that cardholder.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:03
And the cardholder will be really confused because they're very certain that they made the purchase on your website. The other issue it has is for TC40s. TC40s are based on the descriptor, not the merchant ID. So if this fake company selling $20 Nikes created a website called Nike123 chances are the real Nike would get the TC40s for those. And that adds up to their VAMP very quickly. They would get the TC 40s and the chargebacks for those. Now Visa does allow a 10 day window between the time that your acquirer is notified that you're on the VAMP list. So it's a ticking clock from when your acquirer was notified, not from when you were notified. But they allow 10 days of grace for you to pull all the reporting and say oh, 430 of these were not for us, they were for a fraudulent descriptor. Um, or maybe it's, you know, 2,000 of these were for a fraudulent descriptor. It's Nike 1, 2, 3, not Nike.com.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
27:04
Sorry to Nike that I'm picking on them. It was just the easiest example I could think of. It happens to every large retailer. So I'm, no one is immune from this. So you know, when the cardholder realizes that they made an, place an order with a fake website, they're going to issue a TC40 because they want their money back. And unfortunately if you don't have the time to manually go through all of the TC data or if your acquirer doesn't provide it to you, because I know some of you are still in that boat, you can't see the printout or the, you know, the data that says this is not for us, this is for a different company that added on letters after our company name. And you know, it might be Nike DAILY sale. It doesn't have to be a number, it can be all kinds of things. But as long as it starts with Nike, they're gonna put it under Nike's, you know, account. And so it is important to dedicate some time when you get, if you are put on VAMP to look at those TC 40s and verify that they are coming for your website. But I really believe that as agentic commerce continues to grow, this is going to become a major problem because agents don't have a way of deciphering a legitimate website from a fake one. So they're just looking, if they're just looking at price, they're going to go for the $20 Nikes either because they were stolen and that's still profit for the fraudster or more likely you're not going to get those shoes ever, but your credit card is going to be stolen down the road or you were charged for those items if the fraudster was able to get a merchant account. And then that means chargebacks. So it's not going on your med, it's not going on your, you know, you, you won't be responsible for that chargeback amount. That's the good news. But for VAMP counts, those will be applied and the only way to take them out is to. Very quickly, when you're notified that you're on VAMP, look through every single CC40 or search for it. Maybe you can use ChatGPT for this. Actually, you know, look for any descriptor that isn't yours and make sure they subtract those from the total. However, it is challenging because acquirers are sitting on these notices.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:21
They're not always providing them to the merchant within just a couple days. So it is important to talk to your acquirer and say, hey, if I get on the VAMP list and if you're going to find me, how quickly do you notify merchants of that? I need to be notified within two to three business days of when you're notified because I need to be able to highlight these transactions for Visa that shouldn't be under our name. So that's my big overview. But I found an article that talks about this too. And, you know, this has been kind of my. So what I just talked about was kind of my take on it and like, what I thought would happen. And this article from the Guardian actually says that I'm right. And like I always say, when it comes to fraud, I don't like to be right necessarily. I don't like to be called the fraud psychic. It's just, you know, those of us that have been in fraud for a long time, we know the cause and effect of it and we know, you know what's going to happen if you change something upstream and how it's going to impact the downstream. So this article is titled Cloned Sites, which is just what I was talking about. The shopping scams that led ChatGPT to fake stores, or that lead ChatGPT to fake stores. Buyers are ripped off, assuming online stores were genuine, because they are recommended by an AI tool. You want to buy a new bag and you ask ChatGPT for help. You always liked Russell and Bromley, so you asked ChatGPT what is popular there at the moment. The AI assistant gives you a crossbody shoulder, casual, informal options with the prices listed beside them. You click through from the sources to what looks like the official Russell and Bromley site and buy your new bag, which is conveniently on sale. The item will never arrive, however, you have handed money over to a scammer and your bank details have been harvested through an elaborate fraud where fake sites are created to look convincingly like real retailers. Ask Silver, a scam checking service, says clone sites have been showing up in search results on ChatGPT. The ones it has seen are rip offs off of Russell and Bromley and furniture retailer Dunelm. This must be in the UK because those are brands I'm not familiar with, Anna Jones of Ask Silver says. In this instance it looks like scammers are taking advantage of the fact that Russell and Bromley went into administration in January of 2026 and was absorbed by Next.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:45
So there is no longer an official Russell and Bromley website, but potential customers will likely still be searching for it. Louise Baxter, the head of scams team at National Trading Standards, said people should not assume a website is genuine just because it is recommended by an AI tool. And that's the same for Internet browsers as well. When they come back with results. You can't assume that all of those websites are real either. Consumers are increasingly turning to AI tools to ask for advice and recommendations, but criminals are adapting just as quickly. The fact that scam websites can appear in AI generated results is worrying and a stark reminder that fraudsters will exploit any new technology that helps them reach potential victims, she said. The Ask Silver research asked ChatGPT a general question. What are the popular Russell and Bromley purses and bags? The results include details and prices of different bags, trends and what bag was good for what occasion. Among the sources for the answer were two fraudulent Russell and Bromley sites. These sites look credible. In one case there are huge discounts, up to 80% offered on a bag. In reality, it is likely that if you buy something, fraudsters will make off with your money. The cloned website will often have a similar address to one that you may expect a legitimate store to have. Ask Silver identified the Russell Bromley official and Russell Bromley London, Russell Bromley Online UK and Russell Dash and Dash Bromley as some of the names of the fake sites. The legitimate Russell and Bromley store sits within the next website, so there isn't actually a Russell and Bromley website anymore dedicated to them. What you can do when shopping online, watch out for clone sites by looking at their address. Legitimate UK sites will often use .co.uk or .com. In the US it would be you know .com or maybe .co.us. Sometimes and beware of extra words in the title such as official or deals. Fraudulent sites will often only take payment by bank transfer, which is an immediate red flag and have large discounts on them. So large fees on them. Go directly to retailers websites when you can rather than following the sources. That's my big suggestion. A spokesperson for Dunelm said we encourage our customers to only engage with our official website, www.dunelm.com or via the official Dunelm app. He said that when the retailer became aware of a fraudulent site, it worked hard to ensure its removal as soon as possible. If you find that you have handed over your financial details, reported bank and report fraud, that's in the uk. There's not really a place to report fraud here in the US like that. Next, which brought Russell and Bromley in January, said that it was aware of the situation and had been working to have the sites closed down. A spokesperson for ChatGPT said it had removed the fraudulent websites from its search index. Users of the AI tool can report sites that violate its policies through this form that requires consumers to notice that it's fake and that's, you know, the onus shouldn't be on them, in my opinion.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:57
This article and its headline were amended on 12 June to remove the suggestion made by Silver that the large language model powering ChatGPT may have been poisoned. This is a specific term that applies to the manipulation of AI training data rather than AI simply providing false research results and that is it. So basically the website said what I was saying, but just a little bit more because you know, we're aware of the VAMP program and having received those TC 40s from those fake sites can be really detrimental and can add up and then you can be fined for them. But also the impact on your customer service is big. You know, they're expecting their item and they are mad at you. They're not mad at some scammer. They want their money back. Well, they can't get it back from you, it's going to be a lot of headaches. So if I were a fraud leader now for an enterprise e-commerce, I would first notify customer service that this may be happening and explain what's happening. You know that there are most likely scam websites out there, you know, that are depicting and look very legitimate to be your website. You know, let them know that's happening. Contact your IT department to have them try to take it down through the DNS servers. That can take a little time but they can, you know, do what they can there and then the other thing is, you know, really encourage your consumers as much as you can through messaging and other, you know, maybe creative ways. You know, maybe you meet them on social media, maybe you meet them, you know, you meet them where they are.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
36:30
Right. So it's important to educate your consumers that they need to be going to your official website. The challenge is going to be that ChatGPT and other, you know, large language models are going to keep directing their consumers to the lowest price. It would be very good if they had the same type of thing that Google put in place when they had this problem, which is a registry for the legitimate websites and not allowing the fake websites to do much. But the combination of being able to clone a website along with these large language models looking for the best deals tells me that this is going to be a real big problem for e-commerce merchants in the next few months and ongoing years. Again, you won't receive a chargeback for them because it'll be on a different M ID if they did charge their card. But you will receive customer service complaints and you will most likely receive TC 40s that you don't deserve. So those are just two of the things from Regenta Commerce that are impacting e-commerce fraud today or that will impact e-commerce commerce fraud. I would love to hear from you if you feel like I'm missing anything or if you have any questions or comments about the two topics that I shared today.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:46
That's it. That's really all that I wanted to talk about today. We might take a break next week for the U. S. holiday of the Fourth of July. I have not decided yet, but that's a possibility. So if you don't see a new episode next week, that's why. And then the next episode's going to be with a really good guest. You're not going to want to miss it. We're going to talk all about marketplace places and market volatility and how market volatility impacts marketplaces in their fraud and abuse. It'll be really interesting. We've already had a pre-call and I had a lot of fun geeking out and it's someone that's a friend of mine that I think you guys will all enjoy learning from and hearing from too.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:29
So you have that to look forward to either next week or the week after. I hope that you are enjoying a great summer if you are in the Northern hemisphere, and I will look forward to speaking with you more next week.