Biometric Payments: Who's Liable When AI Agents Buy for You?
Quick answer
How secure are passkeys for online payments at checkout?
Passkeys are much safer than passwords at checkout. Your phone keeps a private key that never leaves the device, and a fingerprint, face scan or PIN unlocks it, so there is no password to steal or trick out of you. What they cannot show is whether you meant to approve a specific AI purchase.
Picture this: you set up an AI shopping assistant to reorder household basics when you run low. One Tuesday morning, it buys you $340 worth of supplements you didn't ask for, because you once clicked "interested" on a wellness article. Your phone's fingerprint reader approved the payment. Technically, the system worked perfectly. So whose fault is that?
Visa is rolling out passkeys, phone-based identity checks that replace passwords at checkout, but the real gap isn't security anymore. It's whether anyone can prove you actually authorized what an AI assistant just bought on your behalf.
Visa just made a significant move. The company is expanding what are called payment passkeysa system that lets your phone's fingerprint reader, face scan, or PIN replace the old "enter your password / check your email for a code" checkout dance, across Asia Pacific, into online shopping in India, and now into live AI-assisted payment pilots in Europe. A real test transaction was completed in Germany: an AI agent made a purchase, and a passkey on the user's device approved it.
That last sentence deserves a second read. An AI made the purchase. The human's phone said yes.
Passkey Payments: Why They're Actually Good News
Let's be fair: passwords at checkout are terrible. Not "inconvenient" terrible, actually dangerous terrible. The one-time codes texted to your phone (you know, "your verification code is 847291, never share this") can be intercepted. Fake checkout pages trick people into typing their passwords every single day. This is how billions of dollars get stolen annually from ordinary people, not just corporations.
Starts at 00:21 — this story3:34
Watch this story, in under a minute
A new briefing every weekday — three stories, three minutes.
Subscribe on YouTubePasskeys fix this specific problem well. Here's how they work in plain English: instead of storing a password on a website's server, where it can be hacked, your phone holds a private digital key that never leaves your device. When you check out, your phone and the payment system do a quick handshake to confirm it's really your device. Your fingerprint or face scan just unlocks that handshake. Nobody can steal a password that doesn't exist.
According to Biometric Update, Visa's system lets cardholders approve online payments using whatever security feature their phone already has, fingerprint, face recognition, a PIN, even a swipe pattern. You're not learning new technology. You're using the thing you already do to unlock your phone every morning.
That's genuinely good. The old system had real holes. This plugs them. This article is part of a series, start with Face Match Not Proof Biometric Assurance Deepfakes.
Here's Where Passkey Payment Security Breaks Down
The problem isn't the technology. The technology works. The problem is the question the technology doesn't answer.
A passkey confirms who you are. It does not confirm what you meant to do.
Those two things used to be the same. When you typed in your password and clicked "confirm purchase," the act of doing it was the proof you intended it. You were present. You were in the loop. Now, increasingly, you might not be, because an AI assistant is acting on your behalf, and your phone's passkey is just... approving whatever it decided.
Nearly half of American shoppers are already using AI for at least some part of their purchasing decisions. By next holiday season, millions more will be using AI agents that can complete purchases entirely on their own. McKinsey projects this kind of AI-assisted commerce could touch up to $1 trillion in U.S. retail revenue by 2030. That is not a distant future scenario. That is the system being built right now, this year, in live pilots.
And the infrastructure for who's responsible when something goes wrong isn't ready.
"The focus is no longer on whether a user is authenticated; instead it shifts to understanding who authorized the agent, what permissions it holds, whether it is acting within intent, and whether that intent can be independently verified." Analysis via FIME, on the trust gap in AI-driven commerce
Read that again slowly. It's not asking "did we confirm the shopper's identity?" That part is solved. It's asking: did the person actually tell the AI it could do this specific thing? And can anyone prove it after the fact?
Right now, mostly: no. Previously in this series: Your Face Is Being Scanned At The Grocery Store And A Tiny S.
The AI-Driven Chargeback Nobody Planned For
Here's the scenario that should be keeping payment lawyers very busy. An AI agent, working within the parameters you set weeks ago, makes a purchase you'd consider way outside what you intended. You call your bank and dispute the charge. The bank looks at the transaction log: your passkey approved it. The AI platform says: our agent acted within the permissions granted. The merchant says: we got a valid payment, we shipped the goods. You're left going, "but I didn't actually mean to buy that."
Who eats the loss? Nobody has a clear answer yet.
The chargeback rules that currently exist were written assuming a human being pressed the buy button. They were not written for a situation where a software agent pressed it, operating on a general approval you gave six weeks ago during setup. AI2Work's analysis of agentic commerce flags this directly: when an autonomous agent makes a purchase a customer later disputes, the liability chain, meaning who is legally responsible, is entirely unclear. And smaller merchants are expected to absorb a disproportionate share of the early-stage risk while the industry figures it out.
Some smart people are working on this. Mastercard has developed what they call Verifiable Intenta framework where AI agents are issued credentials (think: a digital permission slip) that cryptographically link every transaction back to a specific human-approved mandate. The mandate can include: allowed types of stores, spending limits, and expiration windows. The agent can only buy within those rails, and every transaction carries proof of what the human actually authorized.
That's a genuinely good idea. Mastercard's Verifiable Intent framework essentially creates a receipt for your intent, not just your identity. The problem, as PYMNTS.com notes, is that most companies haven't upgraded to meet it yet. A pilot working beautifully in a controlled test and an ecosystem of thousands of merchants all correctly implementing intent verification are two very different things.
Why This Matters to You Specifically
- ⚡ Your phone approval means more than you thinkWhen you unlock a passkey at checkout, that may soon count as approving AI purchases you weren't directly watching happen
- 📊 Dispute rules haven't caught upThe chargeback system (your "I didn't authorize that" protection) was built for humans clicking buttons, not AI agents acting on old permissions
- 🔍 Setup screens matter nowThe permissions you grant an AI assistant during initial setup are effectively a blank check until the industry standardizes intent verification
- 🔮 The standards are being written right nowGroups including Visa are actively working on authentication and liability frameworks for AI-driven commerce, which means the rules could look very different in 18 months
What You Can Actually Do About This Today
You don't need to panic. You don't need to avoid AI shopping tools entirely. But you do need to treat the setup screen of any AI assistant like a contract, because functionally, it is one.
When an AI shopping tool asks you to set your preferences, spending limits, and approved categories, take that seriously. That's not a convenience feature. That's the only instruction your AI agent will have when it's making decisions without you in the room. Set hard spending caps. Be specific about what types of purchases it's allowed to complete versus what it should only suggest and wait for your confirmation. Most AI tools, even today, let you require a separate approval step for purchases above a certain amount, use it. Up next: That 99 Face Match Unlocking Your Bank Fraudsters Just Found.
If you ever wonder whether a charge on your statement was something you actually authorized versus something an AI agent decided on its own, that's a legitimate dispute, and one worth making. The industry needs the paper trail of those disputes to accelerate building clearer rules.
Here's a useful thing to watch for: when a payment app or AI assistant asks you to set up passkeys, check whether it also shows you a clear summary of what your AI is permitted to buy. If that screen doesn't exist, if it's just "approve everything" with no limits, that's a yellow flag about how seriously that company has thought through the liability question.
Passkeys solve the password theft problem, and that's a real win. But your bigger job now is making sure you understand what you're pre-approving when you hand an AI assistant the ability to shop on your behalf. The phone check proves it's you. Nothing yet proves it's what you meant.
If you've ever wondered whether an online transaction was really authorized by you or just technically attributed to you, that's the exact gap this whole industry is scrambling to close before AI-assisted shopping becomes the default. CaraComp exists for exactly this kind of "wait, is that really me?" question, whether it's a face, a profile, or a payment. The useful thing to do right now, before any of this is fully sorted, is stay skeptical of "set it and forget it", and read the permissions screen like someone who knows it matters.
The payment industry is spending enormous energy solving the question of "is this really you?" Passkeys, biometrics (your fingerprint, your face, the body stuff uniquely yours), cryptographic keys, all pointed at proving identity. That problem is basically solved.
The problem nobody has fully solved yet is quieter and more personal: did you actually mean to do that?
And in a world where an AI agent can make a purchase while you're asleep, your phone unlocked, your old permissions still active, the gap between "proven identity" and "genuine intent" is exactly the space where a trillion dollars of commerce is about to be decided. The question worth asking before your AI assistant gets its own passkey approval is simple: whose intention, exactly, is being verified?
Biometric Payments and Biometric Security: What's Actually Being Verified
Biometric payments are transactions that use biological characteristics, a fingerprint, a face scan, a voice pattern, even palm biometrics, instead of a password to confirm who is paying. Biometric security in this context means locking the payment step to your body rather than something you can forget or someone can steal, like an old-fashioned PIN written on a sticky note. That's a real improvement over passwords, and it's why biometric payments have spread so fast at checkout. But biometric security only answers one question: is this the right person's finger, face, or voice? It says nothing about whether that person meant to authorize this specific purchase, made by an AI agent, at this specific moment.
Biometric Payment Solutions for Agentic Commerce
Payment companies are now racing to build biometric solutions that work for both humans and the AI agents acting for them. A biometric payment used to mean a simple, one-time check: scan your fingerprint, approve the charge, done. Now the same fingerprint scan can also be read as blanket approval for a whole string of future purchases an agent makes on your behalf, sometimes weeks later. That shift is why banks, card networks, and merchants are all rethinking what a single biometric payment should actually be allowed to authorize.
How Biometric Authentication Differs From Biometric Data Consent
Biometric authentication confirms identity at the moment of payment. It is a yes-or-no check: does this fingerprint or face match the person on file? Biometric data, the underlying fingerprint pattern, voiceprint, or facial map, is what gets stored and compared to make that check possible, and consumers rarely see how long it's kept or who else can access it. Biometric recognition systems are generally good at the matching part; they are not designed to confirm intent, permission scope, or whether an AI agent is acting within the boundaries a person actually set.
Biometric payments enable shoppers to skip typing passwords, and that convenience is genuine. A fingerprint or face scan takes a second; a remembered password with a texted code takes much longer, and it's more exposed to theft along the way. For a human standing at checkout, biometric payments are a clear upgrade over passwords in almost every practical sense. The open question is what happens once that same fast, one-touch approval is asked to cover purchases a person never personally reviewed.
Merchant systems that accept biometric payments generally don't distinguish between a person tapping their own fingerprint at checkout and a passkey approving a purchase an AI agent initiated on a stored permission. To the merchant, both look identical: a valid biometric payment came through, so the transaction is treated as authorized and the goods ship. That is exactly the gap Mastercard's Verifiable Intent framework and similar biometric technology efforts are trying to close, by attaching proof of what was actually authorized to the payment itself, not just proof of whose body approved it.
Biometric payment systems will keep expanding into more of everyday commerce, from groceries to travel bookings to recurring subscriptions. That expansion makes sense: biometric authentication is faster and generally harder to steal than a password, and most consumers already prefer it. But as more of that authentication happens silently, in the background, on behalf of an AI agent rather than a person actively checking out, the industry's task shifts from proving identity to proving intent, and biometric solutions alone, however well designed, were never built to answer that second question by themselves.
Voice Biometric Payments: A Growing Piece of the Picture
Voice is becoming a bigger part of biometric payments as more people manage accounts through smart speakers and voice assistants. A voice payment works the same basic way as a fingerprint or face scan: your voiceprint is compared against the one on file, and if it matches, the payment goes through. Voice biometric payments raise the same underlying question as any other biometric payment method, confirming whose voice it is says nothing about whether that person actually meant to authorize an AI agent to place this specific order on their behalf.
Banks and payment providers are investing heavily in biometric payment infrastructure because the payment experience it offers is simply faster for accounts of every kind, from checking accounts to store cards to subscription services. A payments system that recognizes your fingerprint, face, or voice can approve a purchase in under a second, compared with the many seconds a typed password and texted code usually take. That speed is a real win for services ranging from grocery delivery to travel booking to bill payment, and it explains why so many merchants have adopted biometric payment methods at checkout.
Still, speed and security are not the same thing as certainty about intent. A biometric payment can confirm a person's identity in a fraction of a second while telling merchants nothing about whether an AI agent's specific purchase decision matches what that person actually wanted. This is why payment companies, banks, and merchants are now looking past authentication alone toward systems that can also verify permission and intent, not just identity, for every transaction that touches a stored account.
As biometric payments become the default way to complete transactions across banking apps, retail checkouts, and subscription services, the market for tools that verify intent, not just identity, is likely to grow alongside it. Merchants, card networks, and banks each have an incentive to close that gap, since disputed AI-driven purchases create costs and customer-trust problems for all three. Expect more banking apps and payment services to add clearer permission screens next to their biometric payment setup, showing customers exactly what an AI agent is allowed to buy before a single biometric payment authorizes anything.
For everyday shoppers, the practical takeaway is straightforward: a biometric payment method is a strong replacement for a password, but it is not automatically proof that you approved every individual purchase made under it. Review the permissions tied to your stored biometric data the same way you'd review a recurring subscription. Recognition of your face, fingerprint, or voice is only the first half of a safe payment; the second half, proof of intent, is still being built by the payment industry, one framework at a time.
Frequently asked questions
What are biometric payments?
Biometric payments let a fingerprint reader, face scan, or PIN on your phone replace passwords and one-time codes at checkout. Visa's version, called payment passkeys, is expanding across Asia Pacific, into online shopping in India, and into live AI-assisted payment pilots in Europe, including a test transaction completed in Germany.
Are biometric payments safer than passwords?
Yes, in the sense that they remove weaknesses like texted one-time codes, which can be intercepted, and fake checkout pages that trick people into typing passwords. Passwords at checkout have caused billions of dollars in losses annually, so replacing that step with a fingerprint or face scan closes a major security gap.
Who is liable when an AI agent makes a purchase using biometric payments?
That's unresolved. In the Germany test transaction, an AI agent made a purchase and a passkey on the user's device approved it, meaning the system worked as designed. But whether that proves the human actually authorized what the AI bought is the real gap, not the security of the fingerprint or face scan itself.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore News
Deepfake Impersonation: Cloned Voice Drains €95M From Bank
A familiar voice on the phone is no longer proof of anything. One reported bank heist shows how deepfake impersonation works, and the simple habit that stops it.
digital-forensicsDeepfake Video Detection: Fake Doctors Fool 3 in 4 People
Scammers are cloning real doctors' faces and voices to sell fake health products. Our eyes and ears can't catch it anymore, so here is what actually works.
privacyPlayStation Age Verification: Chat Now Costs a Face Scan
PlayStation is putting messages and voice chat behind an age check. Before your family shares a face scan or ID, here is what to ask.
