Of everything said about AI agents and money this year, one line stands apart for being an actual commitment rather than a principle. American Express announced in April that it will protect eligible customers from charges caused by AI agent error, provided a Card Member authorized a registered agent and that agent sent Amex the customer's authenticated purchase intent. That's a real company naming a real condition under which it eats the loss. Most of what else has been published this year on agent liability is still a framework, a set of principles, or a call for someone to figure this out.
Only part of it, and the boundary it draws matters more than the headline.
Amex Agent Purchase Protection is scoped to a specific failure: a registered, verified agent, operating with a Card Member's authenticated intent, that still gets the transaction wrong, buying the wrong item, picking the wrong merchant, duplicating an order, or spending outside the customer's stated limits. That's a genuinely useful thing to cover. It's also a narrow one. Every condition in it assumes the agent is who it claims to be, doing what it was actually told to do, just doing it imperfectly.
None of Amex's public terms address what happens when that assumption fails: an agent that's been compromised and is no longer under the customer's control, or one that's drifted outside the boundaries it was actually authorized to operate within. Those aren't edge cases dreamed up for this piece. They're the two scenarios every bank paper on agent liability this year has named as the hard problem.
We wrote in September about six global banks agreeing that AI agent liability should sit where the risk or error was introduced, while noting that a shared principle isn't a mechanism until someone puts a number on it in a real product. Amex's commitment is the first concrete instance of exactly that principle in the wild: liability assigned, in advance, to a named party, for a named category of failure. That's real progress on the easy half of the problem.
The hard half is still sitting exactly where it was. A properly authorized agent that makes an honest mistake now has an answer. A hijacked agent, or one that quietly exceeds what it was actually asked to do, does not, at Amex or anywhere else with a public commitment on the record. The first mover on agent liability drew its line at the same place everyone else has been circling, rather than past it.
It matters that Amex's commitment is a card-rail story specifically. Muse doesn't only shop with cards. It also connects directly to bank accounts through Plaid, read-only for now, to check balances and transactions on a customer's behalf, and Meta has said it wants to go further. There is no Amex-equivalent commitment anywhere in that part of the chain. No bank, aggregator, or agent platform has published a public condition under which it will make a customer whole if an agent connected to their actual bank account gets something wrong, let alone if it's compromised.
Card networks had decades of dispute rules, chargeback rights, and network-level liability shifts to build on before Amex ever wrote a line about agents. Open finance doesn't have that foundation yet. It's being asked to answer the harder version of this question, an agent with standing access to an actual account rather than a card number, with none of the infrastructure cards already had in place.
Losing a phone freezes a card in one tap, across every merchant and institution that card touches, instantly. Losing control of an agent has no equivalent. Today, a customer who suspects their agent has been compromised revokes access one connected institution at a time, on whatever timeline each of those institutions happens to support. There's no single action that cuts off a compromised agent everywhere it has standing access at once, because no single institution can see everywhere that access actually reaches.
That's not a gap Amex, or any single card network, bank, or platform, can close alone, and it's worse on the open finance side of the chain than the card side. A card network administers its own rails end to end; it could theoretically build a kill switch across everything it touches. Open finance has no equivalent single administrator. A compromised agent's standing access runs through whichever bank, aggregator, and platform happen to be connected, each with its own revocation process and none with visibility into the others. As Simon Taylor put it in Fintech Brainfood this week, somebody needs to build the button.
The gap discussed in this article - no liability commitment for agents connected to bank accounts, no shared view of where a compromised agent's access actually reaches - is a version of the same problem this blog keeps describing: open finance runs on participants that no single institution can fully see or vouch for alone. Card networks could eventually patch this themselves because they own the rails end to end. Open finance can't, because no single bank, aggregator, or platform owns the whole chain a customer's agent actually touches. That's precisely the layer Invela exists to build: accrediting every participant in that chain, monitoring their risk continuously rather than once, and settling in advance where liability sits when, not if, one of them fails.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.
Get your Invela Risk Indicator score and a benchmark against industry peers.
Sign up now
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.