Fraudology

A Era Agente: Parceria da Visa com a OpenAI, Armadilhas do VAMP e a Ameaça de Sites Clonados

Um gráfico do Fraud/ology nº 411 com o título “A Era Agêntica: a parceria da Visa com a OpenAI, armadilhas do VAMP e a ameaça de sites clonados”, e uma foto de Karisse Hendrick.

Bem-vindo de volta ao Fraudology.

Neste episódio solo, vou mergulhar no comércio eletrônico agentivo e, especificamente, no que acontece quando agentes de compras com IA começam a fazer compras em nome dos consumidores. Este é um daqueles temas que por muito tempo soou como algo muito voltado para o futuro. Havia painéis em conferências, muitas grandes previsões e inúmeras conversas do tipo “isso vai chegar um dia”, mas ainda não havia muito com o que as equipes de fraude pudessem realmente trabalhar.

Isso mudou quando a Visa e a OpenAI anunciaram uma parceria para criar infraestrutura de pagamentos para o comércio com IA. À medida que os recursos de pagamento da Visa começarem a ser integrados às experiências da OpenAI e que as compras pelo ChatGPT e as transações iniciadas por IA se tornarem mais concretas, os comerciantes vão precisar entender os riscos de fraude, estorno, responsabilidade e operação que acompanham esse novo canal.

E é aí que eu acho que precisamos desacelerar e fazer algumas perguntas bem práticas. Quem é responsável quando um agente de IA comete um erro? O que acontece quando o portador do cartão autorizou o agente, mas o agente comprou a coisa errada? Como um comerciante prova que uma transação não foi fraudulenta quando o portador do cartão estava um passo afastado do checkout? E o que acontece com o monitoramento de fraude VAMP quando estornos de comércio eletrônico com agentes e fraudes TC40 começam a aparecer de maneiras para as quais o sistema atual não foi projetado?

Este episódio é, na verdade, sobre dois riscos que já começaram a aparecer. Primeiro, a responsabilidade em comércio eletrônico com agentes e a responsabilidade por chargebacks CNP não estão preparadas para a forma como os agentes de compras com IA vão se comportar. Segundo, fraudes com sites clonados e golpes em buscas de compras com IA podem criar uma nova onda de dores de cabeça para o atendimento ao cliente, problemas com TC40 e desafios de gestão de risco para equipes de comércio eletrônico de grandes empresas.

O que você vai ouvir neste episódio:

  • Por que a parceria da Visa com a OpenAI torna o comércio eletrônico agente muito mais real para os lojistas.
  • Como agentes de compras de IA podem criar novas responsabilidades de estornos CNP e estornos por fraude amigável.
  • Por que os comerciantes podem ter dificuldade em usar evidências contundentes 3.0 quando o portador do cartão instruiu um agente em vez de concluir a compra pessoalmente.
  • Por que a responsabilidade no comércio eletrônico com agentes precisa de um novo framework antes que as perdas aumentem.
  • Como fraudes em sites clonados e golpes de compras online podem piorar quando agentes de IA buscam o menor preço.
  • Por que a fraude TC40 e o monitoramento de fraude VAMP podem se tornar um grande problema para grandes varejistas.
  • O que os líderes de fraude devem começar a perguntar agora aos adquirentes, às bandeiras de cartão, às equipes de atendimento ao cliente e às equipes de TI.

Você deve ouvir este episódio se você:

  • Trabalha na prevenção de fraudes para lojistas ou na prevenção de fraudes em comércio eletrônico e precisa entender para onde o comércio com agentes de IA está caminhando.
  • São responsáveis por chargebacks, monitoramento VAMP, análise de TC40 ou estratégia de fraude CNP.
  • Trabalha em um banco, emissor, bandeira de cartão ou empresa de pagamentos e quer entender por que os comerciantes estão preocupados.
  • Estão tentando entender como o checkout agente, os pagamentos com IA e os pagamentos agentes podem mudar as operações de fraude.
  • Quer uma perspectiva prática sobre fraudes em comércio com ChatGPT, golpes em compras via busca com IA e riscos de sites clonados.
Notas do episódio e principais aprendizados

O comércio eletrônico agentivo deixou de ser apenas uma conversa sobre o futuro

Durante um tempo, o comércio agente parecia ser um daqueles temas de que todo mundo falava, mas ninguém conseguia realmente indicar o que as equipes de fraude precisavam fazer em seguida. Havia muitas previsões e muitas conversas teóricas, mas pouquíssimos desdobramentos práticos.

O anúncio da Visa e da OpenAI mudou isso para mim.

Quando a Visa diz que seus recursos de pagamento serão integrados às experiências da OpenAI, e quando o comércio via ChatGPT começar a se aproximar de transações realmente iniciadas por IA, isso se torna algo que os comerciantes precisam levar a sério. Isso não significa que todos os consumidores passarão a usar agentes de compras com IA amanhã. Mas significa que a infraestrutura está sendo construída e, uma vez que essa infraestrutura esteja pronta, problemas de fraude e estornos geralmente aparecem muito rapidamente.

O motivo pelo qual isso é importante para o e-commerce agentivo é que os agentes de IA não se comportam exatamente como humanos nem exatamente como bots tradicionais. Eles podem ser orientados por um consumidor, adaptar-se às instruções, pesquisar em vários sites, comparar preços e concluir uma compra. Isso cria uma nova camada entre o titular do cartão e o comerciante.

O sistema atual de chargebacks não está preparado para agentes de compras com IA

Uma das minhas maiores preocupações com o e-commerce baseado em agentes é que a estrutura atual de chargeback não foi criada para isso. Hoje, se uma transação é feita sem a presença física do cartão, a responsabilidade geralmente recai sobre o comerciante. Isso pode fazer sentido em certos cenários tradicionais de fraude CNP, mas fica muito mais complicado quando um agente de IA age em nome de um titular de cartão real.

Se o titular do cartão disser a um agente para comprar dois itens e o agente comprar 20, o que exatamente o comerciante deveria fazer? Se o agente reservar o voo errado, escolher o produto errado ou entender mal as instruções do usuário, como o comerciante poderia saber disso no momento da compra? A menos que o comerciante tenha superpoderes ou um vidente sentado ao lado da equipe de prevenção a fraudes, talvez não haja uma forma prática de detectar que isso vai se tornar uma contestação.

É por isso que os estornos em comércio eletrônico com agentes são tão preocupantes.

O comerciante pode receber uma contestação em que o titular do cartão afirma que deu instruções ao agente, mas depois mudou de ideia ou o agente fez a compra errada. Isso não se encaixa bem nos fluxos de trabalho atuais de fraude, fraude amigável ou de compelling evidence 3.0. E, se o comerciante não conseguir atender aos requisitos atuais de reapresentação, perderá os valores, mesmo que a compra tenha sido iniciada por um agente autorizado pelo titular do cartão.

Essa é a lacuna de responsabilidade.

E, a menos que as bandeiras de cartão, as plataformas agentivas e as redes de pagamento criem uma estrutura mais clara para a responsabilidade em compras feitas por IA, os comerciantes acabarão arcando com prejuízos que não poderiam razoavelmente ter evitado.

A exposição ao VAMP torna o comércio eletrônico agente ainda mais arriscado para os lojistas

Isso não se trata apenas de perder estornos individuais. A preocupação maior é o que essas disputas podem causar ao monitoramento de fraude do VAMP.

O VAMP já é um problema sério para os comerciantes. Estornos e TC40s podem gerar uma exposição financeira real, e não existe o mesmo tipo de período de carência ao qual os comerciantes podem estar acostumados em programas anteriores de monitoramento da Visa. Quando um comerciante ultrapassa o limite, as multas e taxas podem se acumular rapidamente.

Agora coloque o comércio eletrônico agente por cima disso.

Se agentes de compras com IA gerarem mais disputas, mesmo em transações em que o comerciante não fez nada de errado, esses chargebacks ainda podem contar contra o comerciante. Se as transações agentivas não forem claramente identificadas no fluxo de pagamento, os comerciantes podem não conseguir separar essas transações em uma categoria de risco diferente. E se não houver um novo modelo de responsabilidade ou processo de contestação específico para transações iniciadas por IA, o comerciante estará assumindo o risco de um canal que talvez nem consiga identificar.

Essa é a parte que precisa de atenção agora.

Visa, Mastercard, OpenAI e qualquer outra plataforma de comércio com IA precisam considerar o lado do comerciante nisso antes que essas perdas aumentem de escala. Se a plataforma agente cometer o erro, ou se o consumidor tiver autorizado o agente e depois contestar o resultado, não faz sentido que o comerciante assuma automaticamente a responsabilidade financeira.

O sistema de chargeback nunca foi perfeitamente justo. Mas este é um novo canal, e novos canais precisam de novas regras.

Os comerciantes precisam de uma forma de identificar transações agentivas

Outro problema é a visibilidade. Hoje, a maioria dos lojistas não tem uma forma confiável de saber se uma transação foi feita por um humano, um bot ou um agente de compras com IA.

Se você não consegue identificar o tipo de transação, não consegue criar uma estratégia de risco diferente para ela. Você não consegue roteá-la de forma diferente. Você não consegue medir a taxa de chargeback. Você não consegue testar se o checkout agente se comporta de forma diferente do checkout em dispositivos móveis ou do checkout na web. Você não consegue separar pagamentos feitos por agentes das transações normais de comércio eletrônico. E você não consegue criar uma estratégia sólida de prevenção a fraudes para lojistas em um canal que você não consegue enxergar.

Alguns fornecedores mais recentes estão começando a trabalhar na detecção de agentes de IA, mas a maioria dos comerciantes que usam ferramentas legadas não tem uma forma clara de identificar transações realizadas por agentes. O tempo, por si só, pode não ajudar, porque esses agentes de IA podem imitar o comportamento do consumidor. Os sinais do dispositivo podem não ser óbvios, pois os agentes podem usar IDs de dispositivo reais ou emuladores. E o próprio fluxo de pagamento ainda pode não indicar aos comerciantes que a transação veio de um agente.

É por isso que acho que talvez eventualmente precisemos considerar o comércio agêntico como um canal próprio.

Já pensamos na web e no mobile de forma diferente. O comércio eletrônico com agentes pode precisar do mesmo tipo de tratamento. Agentes de IA podem precisar de um fluxo de checkout diferente, um fluxo de risco diferente e um conjunto diferente de sinais, porque eles não interagem com sites da mesma forma que os humanos. Eles podem alucinar onde um botão está. Podem interpretar mal uma página. Podem escolher o produto errado. Podem seguir um caminho que faz sentido para uma máquina, mas não para os controles de fraude atuais de um lojista.

Até que os comerciantes consigam identificar o canal, eles ficarão presos tentando gerenciar o risco agente com ferramentas que foram criadas para um mundo diferente.

Os sites clonados podem se tornar um problema ainda maior porque os agentes de IA são treinados para encontrar a melhor oferta

O segundo grande risco neste episódio é a fraude de sites clonados.

Os fraudadores sempre adoraram sites de varejo falsos, sites de comerciantes falsos e sites de phishing. Isso não é novidade. O que está mudando é a facilidade de clonar um site e fazê-lo parecer funcional. A IA pode ajudar fraudadores a duplicar páginas de produtos, imagens, experiências de checkout e a apresentação da marca muito mais rapidamente do que antes.

Agora combine isso com agentes de compras de IA.

Se um consumidor pede a um agente de IA para encontrar a melhor oferta em um produto, para que exatamente esse agente está otimizando? Muitas vezes, é pelo preço. E sites falsos de varejo são muito bons em oferecer o melhor preço porque não estão realmente tentando entregar o produto de verdade. Eles estão tentando roubar dados de cartão, coletar informações pessoais, processar uma transação fraudulenta ou direcionar o comprador para um golpe.

Isso cria um problema muito óbvio.

Um agente de IA pode encontrar o que parece ser a versão de menor preço de um produto e enviar o consumidor para um site clonado. O consumidor pode confiar nele porque a ferramenta de IA o recomendou. O site pode parecer legítimo. O preço pode parecer incrível. E o cliente pode acreditar que comprou do comerciante verdadeiro.

Então o produto nunca chega, ou o cliente recebe um produto falsificado, ou as informações do seu cartão são comprometidas.

E quem é o primeiro a saber disso? Muitas vezes, é a equipe de atendimento ao cliente do verdadeiro comerciante.

Mesmo que o comerciante não tenha processado a transação nem recebido os fundos, o cliente ainda pode acreditar que comprou desse comerciante. Isso gera custo operacional, frustração do cliente, dano à marca e mais um problema de fraude que o comerciante precisa ajudar a resolver.

Fraude TC40 e descritores falsos podem criar problemas de VAMP mesmo quando a venda não foi sua

O problema dos sites clonados não é apenas uma questão de atendimento ao cliente. Ele também pode se tornar um problema de TC40 e VAMP.

Os TC40s estão vinculados a descritores, não apenas ao ID do comerciante. Isso significa que, se um comerciante fraudulento usar um descritor que se pareça com o nome de um grande varejista, com palavras, números ou modificadores extras adicionados, o comerciante legítimo pode ver atividades de TC40 que na verdade não pertencem a ele.

Esse é um grande problema para grandes varejistas.

Se um site falso usar um descritor que começa com o nome de uma marca real, o comerciante legítimo pode ter que identificar essas transações e provar que não são dele. Em um ambiente VAMP, esse timing é importante. Os comerciantes precisam saber com que rapidez o seu adquirente irá notificá-los se eles estiverem na lista VAMP, porque o relógio pode começar a contar quando o adquirente é notificado, e não quando o comerciante finalmente fica sabendo disso.

Isso significa que os comerciantes precisam ser proativos.

Se você for responsável pelo monitoramento de fraude VAMP, fale com o seu adquirente agora. Pergunte com que rapidez você será notificado. Pergunte quais dados TC40 você receberá. Pergunte se terá detalhes suficientes para identificar descritores fraudulentos. Pergunte qual é o processo para remover transações que não pertencem ao seu ID de comerciante.

Porque, se o comércio eletrônico agente gerar mais golpes de compras em buscas com IA e mais tráfego para sites clonados, os lojistas poderão ver mais ruído em seus dados TC40. E, se esse ruído não for removido rapidamente, isso pode sair caro.

As equipes de atendimento ao cliente, TI e prevenção a fraudes precisam se preparar juntas

Uma das lições mais práticas deste episódio é que isso não pode ficar apenas com a equipe de fraude.

Se o comércio eletrônico agente e a fraude com sites clonados se tornarem um problema maior, as equipes de atendimento ao cliente precisam saber o que estão vendo. Elas podem começar a ouvir clientes insistindo que fizeram um pedido no seu site, mas não há nenhum pedido registrado no seu sistema. Isso é confuso para o cliente e frustrante para a equipe de suporte se ninguém tiver explicado antecipadamente o problema dos sites clonados.

As equipes de TI também precisam fazer parte da conversa, porque sites falsos podem precisar ser denunciados, escalados e derrubados por meio de canais de DNS ou de hospedagem. As áreas jurídica, de proteção de marca, fraude, atendimento ao cliente e segurança podem todas precisar se coordenar rapidamente.

E a parte de comunicação com o cliente também é importante.

Os lojistas podem precisar lembrar os clientes de acessarem diretamente o site ou o aplicativo oficial, especialmente durante períodos de alto volume de compras, lançamentos de produtos e temporadas de feriados. Essa mensagem não resolve todo o problema, mas pode reduzir parte da exposição.

É aqui que a gestão de risco do comerciante precisa se tornar multifuncional. O comércio eletrônico agentic não é apenas uma questão de fraude. Ele envolve pagamentos, estornos, atendimento ao cliente, proteção de marca, TI, jurídico e a experiência do cliente.

Conclusão final:

O comércio eletrônico agente está passando da teoria para a infraestrutura. E, uma vez que a infraestrutura existe, a fraude vem em seguida.

A parceria da Visa com a OpenAI pode ajudar a tornar o comércio impulsionado por IA mais fácil e escalável, mas também levanta questões sérias sobre responsabilidade em e-commerce agentivo, responsabilidade por compras feitas por IA, responsabilidade por chargebacks CNP e exposição dos comerciantes sob o VAMP. Ao mesmo tempo, golpes em compras via busca por IA e fraudes com sites clonados podem direcionar agentes de compras de IA para lojas virtuais falsas que parecem legítimas, oferecem ótimos preços e causam danos reais para consumidores e comerciantes.

Portanto, se você é um líder de prevenção a fraudes em um estabelecimento comercial, agora é a hora de começar a fazer perguntas incômodas. Você consegue identificar transações agentic? Consegue separar pagamentos agentic da atividade normal na web e no mobile? Suas equipes de chargeback sabem como lidar com chargebacks de e-commerce agentic? Seu adquirente avisa você com rapidez suficiente se surgirem problemas relacionados ao VAMP? Sua equipe consegue identificar descritores falsos em dados TC40? O atendimento ao cliente sabe o que fazer quando alguém liga sobre um pedido que não existe?

Porque esse canal está chegando. A questão é se os lojistas, emissores, adquirentes, bandeiras de cartão e plataformas de IA vão estabelecer as regras antes que as perdas aumentem, ou depois.

Conecte-se com Karisse Hendrick | LinkedIn

  • Apresentadora do podcast Fraudology
  • Especialista em ciberfraude premiado(a)
  • Consultor em Prevenção de Fraudes em Comércio Eletrônico
  • Consultor de startups, palestrante principal e
  • Consultor para comerciantes da Fortune 500
Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:02
Welcome to Fraudology Podcast, where we dive into the science and study of online fraud from the perspective of an e-commerce fraud fighter. I'm Karisse Hendrick.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:12
Welcome back to the Fraudology Podcast. This will be another solo episode. I think if you've been listening along in chronological order, you can guess that I've been kind of doing every other one with a guest and one on my own today. There's a topic that I want to dive into, and that is AI agentic commerce, specifically. So purchases made by AI agents in the online world. And if you work for a bank and you're like, oh, this is for merchants, hold tight because this will impact you as well. And if you're from a card brand, please listen because we need your help. Before that, I'm just going to do a reminder that the Merchant Fraud Alliance first inaugural conference. So I guess that's a double, double meaning there. So inaugural conference is October 6th and 7th in Chicago. We have some pretty optimistic goals for how many people are going to come, but we also have some really killer ambassadors that have from companies such as Booking and Best Buy and Walmart and Google and so many more that I can think of that have stepped up to be part of the planning committee and the board essentially, and have also pledged to come to the conference. So we have a great group of people that are coming already. They'll also. A lot of them will be speaking as well. We just met for a second time this past week, going through all the topics and starting to address some of the speakers. And we have, you know, someone from PlayStation, someone from Booking talking about how they're integrating AI into fighting fraud and training their analysts to utilize AI in different ways, whether it's for data analytics, reporting, dashboards, things like that. We have someone from Best Buy talking about working cross functionally with other departments. She literally is the best person, I think, that could speak to this topic. A good friend of the podcast, Holly Sandberg, is going to be talking about creating an executive score chart or scorecard for your executives and really explaining managing up and really quantifying fraud for them in ways that they understand. I had a chance to see her speak on this topic at the Assertify User conference last month, and it was really good. So those are just off the top of my head, a few of the sessions I can think of that you'll want to be there for. We're also doing an AI bootcamp on October 5, the day before the conference starts. And that's only open to people that register. You know, it's in the order you register. We're going to have about 50 slots, so I know that there's a few more spaces open. So make sure that you register soon. And if you're listening to this before July 1st, tickets are only 495 for merchants. We aren't selling vendor tickets. We have a select number of sponsor companies that are attending, but we won't be selling vendor tickets. This is for merchants only. Okay, that's enough of a plug for my conference, but that is literally all that I'm like breathing and doing right now. So I had to give a little bit of an update. I want people to show up. I want it to be as good of an experience as it can be for everyone. If you have known me at all. I try to make sure that everyone gets their time and their money's worth of anything that I work on. And this podcast is a good example. It's free and I still give out a lot of information. So, you know, just assume that the conference will be even better than a podcast episode. All right, I really am going to turn to agentic commerce now. I've, you know, I've had Robbie McDermott on the podcast talking about liability for agentic commerce. I've talked a little bit about it here and there, but I've kind of shied away from it for a few reasons. One is there was a conference in the spring that really focused a lot on agentic commerce, but there wasn't any news. It was all kind of pontification and future forward looking. And you know, the feedback I heard from almost everyone I talked to about it was there was no, there were no takeaways because we just aren't there yet. Then we saw OpenAI scrap their project. And I think, I think I made mention of that on the podcast on a solo episode a few weeks ago where they scrapped their project for, I can't remember what they called it, but it was where they had AI agents finish a purchase. So they were going to be the merchant of record. And I think they realized that liability rules as well as other issues. They didn't want to get involved, so they scrapped that project. I think also adoption was really low, so all of those things combined. I haven't really talked about it because I haven't felt like there's been a lot to say. I haven't known if it's actually going to be a thing. Yes, it's been talked about a lot. But it, you know, is going to be adopted by more than 5% of consumers. Those of them I open questions. But then an announcement came out about two weeks ago that made me think, okay, this is probably happening. I'm going to go ahead and read the LinkedIn post that I wrote about it to start just because I think I did a pretty good job of summarizing this. Last week it was announced that Visa and OpenAI are partnering to build infrastructure designed to make AI commerce secure, scalable and seamless. That's in quotations. Those are their words in this statement. Visa also said that Visa's payment capabilities will be integrated into OpenAI experiences, giving developers and merchants a streamlined way to accept Visa payments initiated by AI agents. They also said Visa will deliver the underlying global network payment tokenization authorization, agent identification and fraud monitoring infrastructure to support secure and trusted AI initiated transactions. So I'll stop there from my post and just say that, you know, the fraud monitoring isn't necessarily from the merchant perspective. It's just the general fraud monitoring that Visa does, you know, looking for card testing, that type of thing. Also on the issuer side, their fraud monitoring, I it doesn't say that Visa is doing anything new as far as fraud monitoring. So I wouldn't take that statement to mean, oh, they're going to do fraud monitoring on agentic transactions so I don't have to.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
06:39
I would not at all read in that into it. So now that Visa and you know, OpenAI, who you know is behind ChatGPT, are partnering with each other. That's a lot of power. That's a lot of brand power, but also just a lot of, you know, they're lending the visa rails to OpenAI transactions, to transactions that are initiated in ChatGPT. So some of the use cases would be, you know, if I wanted to book the best flight for the cheapest price. But I didn't want to search all of the, you know, travel agent online travel agency sites. I didn't want to use Google. I and maybe I had a little time, so maybe I had a week. I could create a prompt in ChatGPT to ask it to, you know, create an agent to look for the best Airline price from Seattle, Washington to San Francisco, California. And you know, you can set as many parameters as you want, right? Like I want my departure time to be after 10am. I want my arrival time to be before 9pm. I want, you know, a window seat, I want an aisle seat. But a lot of people aren't going to do all of those qualifiers. You can, but they may not. So you know, that opens it up to a lot of issues right. What if my, you know, and then my final prompt for that would be, find the best rate in the next week and book it on my behalf. Here's my card information. Here's, you know, my TSA pre check number or whatever you need to do, just do it for me. Others would be around, you know, sale prices, the best, you know, best deal on a sweater or a pair of shoes, or what if there's a drop coming of new sneakers. It's kind of similar to a bot, but it's different where you're directing an agent to do it for you rather than a bot, so it can adapt more. There's a lot of issues that I see with this and we're going to talk about another issue after I talk about this first one. But, from a chargeback perspective, this was really scary to me because at the end of the day, the VISA infrastructure does not support agentic e-commerce chargebacks.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:50
There's no process for them, there's no verbiage for them. There's nothing. There are chargebacks that are going through right now to merchants that are very obviously, you know, were initiated by an agent. Either the, you know, cardholder says so in their statement or the merchant can tell it was created by an agent and not a person. There's no guidance for. So the merchant is getting those chargebacks. The liability is working the way it always has where it's, if it's card not present, it's on the merchant. There's no additional liability. You know, hey, if it's, if the agent makes a mistake or it books something that the cardholder didn't want it to, or it orders 20 items instead of two, all of those different scenarios. There's no additional guidance for where liability goes. So it falls on the merchant. And I'll read what I wrote in my LinkedIn post and then I'll go a little bit further about this too. So I said there are two things I want to highlight about this announcement from the merchant perspective. Number one, and this is a little, you know, a little bit what I just said. But there are no stated changes to the chargeback liability framework for CMP transactions. This most likely means that when mistakes are made, like an agent orders the wrong thing or too much of one thing, these cardholder disputes will fall to the merchant to repay to the consumer. Even if there was nothing a merchant could have done to know it was a mistake or prevent it at the time of a transaction. The reason I said that is the whole point of the CMP liability Rules has been, well, merchants should be able to detect fraudulent transactions before they occur. So therefore they have the liability rules. In this case, it's similar to what we call friendly fraud. Right. If the cardholder information validates and it looks like the cardholder initiated the transaction, and the cardholder was involved in the transaction they initiated the agent, that type of thing, it still falls on the merchant.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
10:50
Even though there was nothing, aside of having superpowers or a psychic on hand, there's nothing they could have done to say, oh, that one order is going to come back as a chargeback, or, you know, the cardholder told the Agent to buy two, not 20, so we should cancel 18 of these. There's nothing a merchant can do. However, they're still liable. So I said, we also need to consider that more chargebacks for merchants equals a higher risk for VAMP infractions. This could mean more fines, fees, and issues with acquirers that are outside the scope of prevention for CNP merchants. So with VAMP, which man did we have a good webinar with Anoush at Visa for MFA? It was a couple weeks ago. I think it's available through About Fraud. I actually haven't asked PJ or Ronald about that, but it was recorded. I know that it was so good. And we're actually going to have a second one in August because there were just. There was so much engagement from the audience that we didn't get through everything that we needed to or wanted to or that the merchants had asked us to. Anyway, that's a side note about VAMP, but, you know, VAMP is real, and your acquirers are now managing your risk. And the more chargebacks you have, the higher risk for VAMP infractions. Vamp is not cheap. And there's no. There's no trial month. There's no safety month. That used to be that you had two to three months before the VFMPs or VDMPs would charge fines. That doesn't happen anymore. There's now, it's the first month that you go over that 1.5%, you occur $8 per TC, 40 and per chargeback. And that adds up real quick. So there's, you know, there's no wiggle room. There's no safety time. It's just instant. So it is something to be considered. But then I put my take and I said, my hope in asterisks is that visa and OpenAI rework the liability for these circumstances to require the agentic platform OpenAI in this case, to take financial liability for agent mistakes.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
12:56
Do I know that that is extremely optimistic and probably not likely. Yeah, I do, but I at least need to call it out. I felt the need to call it out and say, hey, merchants shouldn't be responsible for agentic mistakes. What if it's a mistake on the developer's side? You know, there's nothing a merchant could have done to stop that, but yet now they have to pay back the transaction. Doesn't make a lot of sense, doesn't seem fair, which, I mean, the chargeback system has never been fair. My grandmother used to say if I ever said something wasn't fair, she would say, you know, the fair only comes once a year, meaning that nothing's fair and the county fair is the only thing that exists. I know the chargeback system isn't fair, but we're opening a new channel. I just saw a good presentation from a startup recently where they talked about, you know, we have the e-commerce channel or the web channel, we have the mobile channel and now we're going to have the agentic channel. And the agentic channel should go through a different flow because it doesn't, you know, recognize the website in HTML format the way that human eyes do. And you know, they often will hallucinate where a button is or it will, you know, order the wrong thing because they think that button's over here or it just. Agents can't navigate websites the way that humans can. And so there needs to be a more agent friendly site where maybe humans can't understand it, but agents will know exactly, exactly what to do and where to go. I thought it was an interesting take because then also your fraud and risk decisions would be different as well if you are able to parse out the agentix transactions into their own bucket and look at the data on those. So yeah, that is something to, you know, consider. Right now we don't have an agentic channel. There is a company trying to build one right now. Visa doesn't have any way for merchants to identify in the payment flow that a transaction was initiated by an agent. Maybe that will change once their partnership with OpenAI goes through, but right now they don't. I only know of maybe two vendors on the merchant side that are really able to identify agentic orders.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
15:12
Most of the merchants using legacy tools, if not all of them, have no way of, you know, they've done so many tests, transactions on every different agentic site and then, you know, looked on the back end for any identifiers of what, you know, how they can tell that an order was placed through ChatGPT. And timing doesn't matter anymore because these agentic platforms are trying to mimic consumer behavior so the transactions are approved so they aren't moving fast. Otherwise they get caught up in bot detection. There's no device difference. They're using real device, you know, IDs and emulators. There's no way right now to identify it. Unless you have maybe one of two tools that are still pretty new. Yes, Sardine is one of them. I got a one on one demo from Supes, actually the CEO of Sardine, while at a conference this spring on exactly how they can detect an AI agent. And it was really fascinating. But I know of another company that is able to do that as well. But my whole point being right now there's no way to tell if it was an agentic transaction on the merchant side. And there's no additional liability shift for merchants when errors occur or when fraud occurs or anything like that. And that needs to be looked at. My other concern, and this is, this kind of, this goes hand in hand, right? Because if you don't know that an agentic transaction is coming in, you can't do anything to stop it or prevent it. There are currently no provisions for chargeback represented by a merchant. When an agent initiates a transaction on behalf of a cardholder, a cardholder can change their mind, claim fraud, or state that the wrong item was purchased. And there is no way for merchants to dispute these claims or reverse the debited funds. Merchants are currently receiving these chargebacks and are automatically losing them. Once OpenAI and visa partner up, these losses will skyrocket. My take before this partnership goes live is that it's imperative that Visa and MasterCard as well. But right now it's about Visa. At least give merchants an opportunity to prove that these purchases were not fraudulent and that the cardholder authorized their agent to make this purchase. If changes aren't made to the liability structure of CMP transactions and to the ability for merchants to dispute chargebacks, the financial losses will be astronomical. So yeah, that's some big news. But you know, if you have a Visa rep that you work with, bring this up to them, ask them what they're doing about it. I have been in touch with my contact at Visa who said, you know, this is such a new thing. They don't know if this has been considered yet, but that they were going to do their best to run it up the flagpole for consideration. I don't know if there will be any motivation to change these things if there's not a little pressure so, you know, be aware that this is the case. I already know of one merchant that lost a pretty big dollar transaction when the cardholder said I directed my agent to the purchase, but I changed my mind. That was in the cardholder documentation of the chargeback. The merchant highlighted that along with their terms of service and you know, all the other things that were required for that specific chargeback reason code. And they were given an automatic decline because this is agentic e-commerce, and it didn't fulfill the compelling evidence 3.0 requirements. You know, an agentic transaction may not even fulfill the C2. O requirements because the cardholder technically wasn't involved, but they directed it. So the cardholder is one removed from the transaction now, which makes it difficult.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
19:10
This episode is brought to you by Sardine. One of the things I enjoy about working closely with Sardine is the ability to learn more about identifying and preventing fraud and scams. For instance, I've learned that the best way for a bank or fintech to detect a scam is to look at the five seconds before a transaction. Most fraud in AML controls focus on the transaction itself, but it's those things immediately before it that help you stop scams. That's in the preauth signals. That's why user, device, and behavior are so crucial. In those five seconds you can identify if another user is driving that device from a remote desktop access. Or you can learn that the phone making a transaction is upside down and not actually in use. You can also identify the behavior of the person behind the device and what their true intentions are. It's those little details that all add up. For more information about this or any of the other products within Sardine, go to www. Sardine. AI to read more information or to request a one on one product.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:13
So I'd love to know your thoughts other than oh crap. If you're on the banking side, the issuer side, be aware of this. I would love for you to not forward these on to merchants when you see mention of an agent. But obviously I know you have cardholders to appease and everything else. And that's why I really do think that the agentic platform should have liability on these transactions, especially for errors. But I don't know how they would be able to do that because obviously OpenAI and any other agentic platform is going to lobby to keep playability the way it is. So that is something to be aware of as we start talking about agentic AI. Those are two concerns and two things that I think we all need to be aware of there is no liability shift for merchants. It's always on them. And there's no way for them to win those transactions because there's no provisions in the chargeback documentation about agentic transactions. Obviously, agentic commerce is moving very quickly. There wasn't even a lot to report in March, you know, so now there is right now in June. We're like, oh, okay, Visa and ChatGPT are gonna, you know, join forces. That sounds big. MasterCard has made a similar announcement, but not with a large, it's not in partnership, it's like their own thing. And I mentioned a few weeks ago another solo podcast that amex has said that if a cardholder uses their agents and their rails for a transaction, that the cardholder won't be liable for that. They don't say that it won't be turned on to the merchant. They just say that there's consumer protections on those transactions. So I don't know if they're planning to take the hit or pass those on, but, you know, the ball is moving already, is what I'm trying to say. So along that note, another issue that I see for agentic e-commerce, and this was something I thought of kind of right away when I started wrapping my head around what agentic e-commerce is, is that agents will be trained to look for the best price or they'll be, you know, trained to look for the best location or the best timing or, you know, whatever it is. If it's for concert tickets, it's the, you know, the best seating. It's the best, you know, whatever those things are, they're trained to look for those. But I would say the majority of them are looking for a deal. There are a lot of fishing websites out there, especially because of AI, because it's so easy. And Matt Vega on the podcast a month or two ago, talking about how easy it is to clone a website, he clones MasterCard's website right in front of me as we were talking and recording the podcast. He did it in about five minutes, and he was able to harvest people's information off of that. So had he made that website go live? Had he, you know, attached it to Google SEO or other search engine optimization for other browsers, he could advertise and people could think, oh, that's MasterCard's website. I have no problem putting in all of my information. But then later down the line, their identity is stolen or their credit card is used. So, you know, it's easy to make fake websites. We know that fraudsters love to create fake websites and replicate merchants. So duplicate their websites. So say, I'm not going to pick on one particular company, but like Merchant A, for whatever reason, sorry, I couldn't come up with like a creative name that wasn't real. Merchant A has, you know, sells furniture and they have, you know, proprietary photographs of all their furniture on their website. They have, you know, it's. It's their website and then it allows consumers to interact with it, to put things in their cart, to visit their cart, to, you know, then check out. Fraudsters can now duplicate not only the, they used to be able to duplicate the pictures they would copy and paste, they would scrape the websites, etc. But now they can make those functional. They can say, hey, make it possible for a cardholder to order this item and purchase this item.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
24:28
And then chances are they're harvesting credit card numbers and the person that you know, placed the order never gets the item. Or if they do, it's something that's really fake. It's not the real item that they thought they were ordering. Well, with agentic e-commerce, those agents are looking for the best deal possible. Those phishing websites are known for giving the best prices ever. I think we've all seen, you know, especially around drops or holidays, big purchase times. I'm sure we've all seen Facebook ads or Instagram ads for $20 Nikes or, you know, $50 airline tickets or whatever it is. You just have to click their website. Well, chances are that website isn't real and it's going to look like it's coming from Costco or United Airlines or it's going to look like it's coming from Nike themselves, but it's not. So what's going to happen is a lot of those agents are going to choose the lowest price, which is going to go to a fake website. A fake website that now has actions that can now collect credit cards, that can sometimes in some cases process credit cards. That's going to cause a lot of fraud. It's going to cause a lot of issues. The types of issues it'll cause are at your call center. You'll see more calls with people saying, hey, I ordered this item on your website, but it never came, or I got a pair of fake Nikes instead of real ones or whatever it is that is going to cause, you know, going to take time for your customer service to research it because there won't be an order on file for that cardholder.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
26:03
And the cardholder will be really confused because they're very certain that they made the purchase on your website. The other issue it has is for TC40s. TC40s are based on the descriptor, not the merchant ID. So if this fake company selling $20 Nikes created a website called Nike123 chances are the real Nike would get the TC40s for those. And that adds up to their VAMP very quickly. They would get the TC 40s and the chargebacks for those. Now Visa does allow a 10 day window between the time that your acquirer is notified that you're on the VAMP list. So it's a ticking clock from when your acquirer was notified, not from when you were notified. But they allow 10 days of grace for you to pull all the reporting and say oh, 430 of these were not for us, they were for a fraudulent descriptor. Um, or maybe it's, you know, 2,000 of these were for a fraudulent descriptor. It's Nike 1, 2, 3, not Nike.com.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
27:04
Sorry to Nike that I'm picking on them. It was just the easiest example I could think of. It happens to every large retailer. So I'm, no one is immune from this. So you know, when the cardholder realizes that they made an, place an order with a fake website, they're going to issue a TC40 because they want their money back. And unfortunately if you don't have the time to manually go through all of the TC data or if your acquirer doesn't provide it to you, because I know some of you are still in that boat, you can't see the printout or the, you know, the data that says this is not for us, this is for a different company that added on letters after our company name. And you know, it might be Nike DAILY sale. It doesn't have to be a number, it can be all kinds of things. But as long as it starts with Nike, they're gonna put it under Nike's, you know, account. And so it is important to dedicate some time when you get, if you are put on VAMP to look at those TC 40s and verify that they are coming for your website. But I really believe that as agentic commerce continues to grow, this is going to become a major problem because agents don't have a way of deciphering a legitimate website from a fake one. So they're just looking, if they're just looking at price, they're going to go for the $20 Nikes either because they were stolen and that's still profit for the fraudster or more likely you're not going to get those shoes ever, but your credit card is going to be stolen down the road or you were charged for those items if the fraudster was able to get a merchant account. And then that means chargebacks. So it's not going on your med, it's not going on your, you know, you, you won't be responsible for that chargeback amount. That's the good news. But for VAMP counts, those will be applied and the only way to take them out is to. Very quickly, when you're notified that you're on VAMP, look through every single CC40 or search for it. Maybe you can use ChatGPT for this. Actually, you know, look for any descriptor that isn't yours and make sure they subtract those from the total. However, it is challenging because acquirers are sitting on these notices.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
29:21
They're not always providing them to the merchant within just a couple days. So it is important to talk to your acquirer and say, hey, if I get on the VAMP list and if you're going to find me, how quickly do you notify merchants of that? I need to be notified within two to three business days of when you're notified because I need to be able to highlight these transactions for Visa that shouldn't be under our name. So that's my big overview. But I found an article that talks about this too. And, you know, this has been kind of my. So what I just talked about was kind of my take on it and like, what I thought would happen. And this article from the Guardian actually says that I'm right. And like I always say, when it comes to fraud, I don't like to be right necessarily. I don't like to be called the fraud psychic. It's just, you know, those of us that have been in fraud for a long time, we know the cause and effect of it and we know, you know what's going to happen if you change something upstream and how it's going to impact the downstream. So this article is titled Cloned Sites, which is just what I was talking about. The shopping scams that led ChatGPT to fake stores, or that lead ChatGPT to fake stores. Buyers are ripped off, assuming online stores were genuine, because they are recommended by an AI tool. You want to buy a new bag and you ask ChatGPT for help. You always liked Russell and Bromley, so you asked ChatGPT what is popular there at the moment. The AI assistant gives you a crossbody shoulder, casual, informal options with the prices listed beside them. You click through from the sources to what looks like the official Russell and Bromley site and buy your new bag, which is conveniently on sale. The item will never arrive, however, you have handed money over to a scammer and your bank details have been harvested through an elaborate fraud where fake sites are created to look convincingly like real retailers. Ask Silver, a scam checking service, says clone sites have been showing up in search results on ChatGPT. The ones it has seen are rip offs off of Russell and Bromley and furniture retailer Dunelm. This must be in the UK because those are brands I'm not familiar with, Anna Jones of Ask Silver says. In this instance it looks like scammers are taking advantage of the fact that Russell and Bromley went into administration in January of 2026 and was absorbed by Next.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:45
So there is no longer an official Russell and Bromley website, but potential customers will likely still be searching for it. Louise Baxter, the head of scams team at National Trading Standards, said people should not assume a website is genuine just because it is recommended by an AI tool. And that's the same for Internet browsers as well. When they come back with results. You can't assume that all of those websites are real either. Consumers are increasingly turning to AI tools to ask for advice and recommendations, but criminals are adapting just as quickly. The fact that scam websites can appear in AI generated results is worrying and a stark reminder that fraudsters will exploit any new technology that helps them reach potential victims, she said. The Ask Silver research asked ChatGPT a general question. What are the popular Russell and Bromley purses and bags? The results include details and prices of different bags, trends and what bag was good for what occasion. Among the sources for the answer were two fraudulent Russell and Bromley sites. These sites look credible. In one case there are huge discounts, up to 80% offered on a bag. In reality, it is likely that if you buy something, fraudsters will make off with your money. The cloned website will often have a similar address to one that you may expect a legitimate store to have. Ask Silver identified the Russell Bromley official and Russell Bromley London, Russell Bromley Online UK and Russell Dash and Dash Bromley as some of the names of the fake sites. The legitimate Russell and Bromley store sits within the next website, so there isn't actually a Russell and Bromley website anymore dedicated to them. What you can do when shopping online, watch out for clone sites by looking at their address. Legitimate UK sites will often use .co.uk or .com. In the US it would be you know .com or maybe .co.us. Sometimes and beware of extra words in the title such as official or deals. Fraudulent sites will often only take payment by bank transfer, which is an immediate red flag and have large discounts on them. So large fees on them. Go directly to retailers websites when you can rather than following the sources. That's my big suggestion. A spokesperson for Dunelm said we encourage our customers to only engage with our official website, www.dunelm.com or via the official Dunelm app. He said that when the retailer became aware of a fraudulent site, it worked hard to ensure its removal as soon as possible. If you find that you have handed over your financial details, reported bank and report fraud, that's in the uk. There's not really a place to report fraud here in the US like that. Next, which brought Russell and Bromley in January, said that it was aware of the situation and had been working to have the sites closed down. A spokesperson for ChatGPT said it had removed the fraudulent websites from its search index. Users of the AI tool can report sites that violate its policies through this form that requires consumers to notice that it's fake and that's, you know, the onus shouldn't be on them, in my opinion.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:57
This article and its headline were amended on 12 June to remove the suggestion made by Silver that the large language model powering ChatGPT may have been poisoned. This is a specific term that applies to the manipulation of AI training data rather than AI simply providing false research results and that is it. So basically the website said what I was saying, but just a little bit more because you know, we're aware of the VAMP program and having received those TC 40s from those fake sites can be really detrimental and can add up and then you can be fined for them. But also the impact on your customer service is big. You know, they're expecting their item and they are mad at you. They're not mad at some scammer. They want their money back. Well, they can't get it back from you, it's going to be a lot of headaches. So if I were a fraud leader now for an enterprise e-commerce, I would first notify customer service that this may be happening and explain what's happening. You know that there are most likely scam websites out there, you know, that are depicting and look very legitimate to be your website. You know, let them know that's happening. Contact your IT department to have them try to take it down through the DNS servers. That can take a little time but they can, you know, do what they can there and then the other thing is, you know, really encourage your consumers as much as you can through messaging and other, you know, maybe creative ways. You know, maybe you meet them on social media, maybe you meet them, you know, you meet them where they are.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
36:30
Right. So it's important to educate your consumers that they need to be going to your official website. The challenge is going to be that ChatGPT and other, you know, large language models are going to keep directing their consumers to the lowest price. It would be very good if they had the same type of thing that Google put in place when they had this problem, which is a registry for the legitimate websites and not allowing the fake websites to do much. But the combination of being able to clone a website along with these large language models looking for the best deals tells me that this is going to be a real big problem for e-commerce merchants in the next few months and ongoing years. Again, you won't receive a chargeback for them because it'll be on a different M ID if they did charge their card. But you will receive customer service complaints and you will most likely receive TC 40s that you don't deserve. So those are just two of the things from Regenta Commerce that are impacting e-commerce fraud today or that will impact e-commerce commerce fraud. I would love to hear from you if you feel like I'm missing anything or if you have any questions or comments about the two topics that I shared today.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
37:46
That's it. That's really all that I wanted to talk about today. We might take a break next week for the U. S. holiday of the Fourth of July. I have not decided yet, but that's a possibility. So if you don't see a new episode next week, that's why. And then the next episode's going to be with a really good guest. You're not going to want to miss it. We're going to talk all about marketplace places and market volatility and how market volatility impacts marketplaces in their fraud and abuse. It'll be really interesting. We've already had a pre-call and I had a lot of fun geeking out and it's someone that's a friend of mine that I think you guys will all enjoy learning from and hearing from too.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:29
So you have that to look forward to either next week or the week after. I hope that you are enjoying a great summer if you are in the Northern hemisphere, and I will look forward to speaking with you more next week.