News

When an AI Agent Makes the Wrong Purchase, Who Pays? Design the Answer Before You Deploy

When an autonomous agent buys the wrong thing, liability lands on whoever cannot prove who approved what. Card networks are already asking the question. Before deployment, put confirmation gates on every money-moving step, define named approvers and spending limits, and keep an append-only audit trail that survives review.

Key facts

Liability triggerCard networks are asking who bears the cost when an agent purchases incorrectly
Required controlConfirmation gate before any money-moving action
Spending limitsPer-task and per-day caps enforced by policy
Approval recordNamed approver captured with the action, not just the outcome
Audit trailAppend-only log of prompts, tool calls, approvals and results
Take-overHuman can pause or take over a running agent
DeploymentPlugsky cloud, your VPC, on-prem or air-gapped

TL;DR

  • Agentic commerce makes 'who approved this?' a liability question.
  • If your agent cannot prove approval, you have built a liability, not a worker.
  • Gate every money-moving step with a confirmation and a named approver.
  • Append-only logs turn disputes into evidence.
  • Design the answer before you deploy, not during the incident review.

How it works, step by step

  1. List every action your agent can take that moves money or creates obligations.
  2. Classify each action by reversibility and set a spend threshold for approval.
  3. Insert a confirmation gate that waits for a named human approver.
  4. Enforce per-task and per-day spending caps in policy, not in prompts.
  5. Write an append-only audit entry for every approval and action.
  6. Give operators a take-over control to pause or stop a running agent.
  7. Test the dispute path: replay a bad purchase and produce the approval record.
1List every actionyour agent can takethat moves money or2Classify eachaction byreversibility and3Insert aconfirmation gatethat waits for a4Enforce per-taskand per-dayspending caps in5Write anappend-only auditentry for every6Give operators atake-over controlto pause or stop a

Try it yourself

Open the agent workflow designer →

The new liability question in agentic commerce

Card networks have started asking the question every agent builder must answer: when an autonomous agent buys the wrong item, who absorbs the cost? The Financial Brand covered the debate, and the uncomfortable part is that most agent stacks cannot answer it. If your logs show the outcome but not the instruction and the approval, you cannot reconstruct responsibility when a customer, auditor or regulator asks.

Why speed multiplies mistakes

Agents transact faster than human review cycles. A mistyped quantity, a stale supplier list or an ambiguous instruction can repeat across dozens of orders before anyone notices. The damage is not a single bad purchase; it is systematic. Reviewing a weekly report is too slow when the agent has already placed the orders. Approvals must sit inline, at the moment the risky step is about to execute.

Approval gates on every money-moving step

Define the actions that require a human: payments above a threshold, new payees, refunds, contract terms, bulk orders. A confirmation gate should pause the run, present the exact action and its rationale, and wait for a named approver. Spend caps add a second layer so a runaway loop fails closed. In Plugsky agents, these gates are part of the run, not bolted on afterwards.

The append-only audit trail

Approval matters only if it is recorded. Keep an append-only log of the goal, plan, each tool call, the approver's identity, the decision and the result. Store it in your jurisdiction with configurable retention. When a dispute arrives months later, the log should answer four questions without human memory: what was requested, what the agent did, who approved it, and what policy applied.

Designing the answer before deployment

Write the liability answer into the product: approval policy, evidence trail, escalation path and incident runbook. Then test it by simulating a wrong purchase and proving you can reconstruct the decision chain. Teams that can produce that record negotiate disputes as process failures. Teams that cannot, absorb the cost — and the trust damage.

Honest comparison

CapabilityPlugsky agent stackCustom agent codeChatbot with tools
Approval gatesInline confirmation before risky actionsUsually custom-builtRarely present
Spending capsPolicy-enforced per task and per dayCustom middlewareNo
Approver identityCaptured with each decisionIf logged at allNo
Audit trailAppend-only, replayableApplication logsChat history only
Take-over controlPause and resume a runCustomNo
Data residencyIn-region deployment optionsYour infrastructureProvider-dependent

Frequently asked questions

Who is legally responsible when an agent buys the wrong thing?

Responsibility depends on jurisdiction and contract, but practically it lands on the operator who cannot prove authorization. Approval records and audit logs are what shift a dispute from assumption to evidence.

Do approval gates slow agents down?

Gates only apply to the actions you classify as risky. Routine steps run autonomously; payments and irreversible actions wait for a named approver, which is exactly where delay is desirable.

What counts as a money-moving action?

Payments, transfers, refunds, new payees, contract acceptance, bulk orders and anything that creates a financial obligation. Classify by reversibility, not by amount alone.

Can we enforce hard spending limits?

Yes. Caps belong in policy outside the model, so a prompt injection cannot talk its way past them. Per-task and per-day limits both fail closed when exceeded.

How long should audit logs be retained?

Retention is configurable and should match your regulatory and contractual requirements. Store logs in your chosen jurisdiction so the evidence stays under your control.

Can we try approval gates before production?

Yes. The Plugsky Playground Beta lets you watch an agent plan and pause for confirmation before risky actions, with no install required.

How do we get started with agents?

Start on the free plan with plugsky-micro and plugsky-lite, or use the 14-day full-access trial for the paid tiers. See the live pricing page for current plans.

Cite this page

Plugsky (2026). “When an AI Agent Buys Wrong, Who Pays?”. Plugsky. Available at: https://plugsky.com/news/ai-agent-accountability-approval (last updated 2026-09-25).