Stripe and OpenAI launch AI payments: the big question of responsibility

Stripe and OpenAI launch AI payments: the big question of responsibility

AI agents can now execute payments completely autonomously. An operational revolution which masks a major legal void. In the event of fraud or litigation, the impasse can be total.

Since 2025, Stripe, Coinbase and OpenAI have each launched their own protocol allowing artificial intelligence agents to execute payments completely autonomously, without human validation. An agent can now book a service, pay a supplier, pay for a subscription, alone, in a few seconds. This is presented as an obvious efficiency gain. It is also, and this is the subject that no one is really talking about yet, a system which can legally decide to pay without knowing legally who is responsible for its decision.

The first reflex is therefore oriented cybersecuritybecause how can you prevent an agent from being hacked or hijacked. This is a real subject, widely covered, and security teams are making rapid progress on it. But there is one question that remains almost entirely open. Indeed, the day an agent executes a fraudulent payment, manipulated by an instruction hidden in an email or a document that he treated as legitimate, who is responsible?

The candidates for liability are however plural, among them the developer who designed the agent, the company which deployed and configured it, the supplier of the language model or even the payment platform which executed the transaction. Today, no one can say with certainty who is responsible, and it is precisely this void that should worry much more than just the technical challenge.

One might believe it to be a simple delay in the law on technology, as happens regularly. But this void is deeper than that. The national strategy for means of payment 2025-2030 published by the Banque de France does not mention AI agents once. This is not negligence. This is explained simply by the fact that at the time this document was written, the subject did not yet exist on this scale. European law is not better off because the payment services regulation (DSP3/PSR) regulates human service providers or identified legal entities, not systems that decide without direct intervention. The AI ​​Act classifies artificial intelligence systems by level of risk, but where exactly does an agent who executes financial transactions on its own initiative fit in? The question remains, to date, without a clear answer.

It is therefore legitimate to question how a judge faced with this question could rule in the current state of the law. This is undoubtedly the most revealing question that can be asked on this subject because what would a French court decide, today, with existing law, if such a dispute were submitted to it?

Three legal regimes could be mobilized, and none really corresponds. Common law civil liability would require proving identifiable human fault, which becomes particularly difficult in the face of an algorithmic decision chain. Liability for defective products could apply if we consider the agent as a product, but this regime was designed for classic objects or software, not for systems that evolve and make decisions autonomously. The contractual regime, finally, would depend on clauses which, in the vast majority of cases, have simply not been drafted to cover this specific scenario.

The likely result would be a case-by-case decision, without clear doctrine, with potentially different solutions for very similar cases. This takes us back to the very definition of a legal vacuum, not the total absence of applicable law, but the absence of a predictable response.

This is not the first time that the law finds itself in this situation. At the start of electronic commerce, in the 1990s, judges had to stretch existing notions, sale, mandate, to cover situations that no one had anticipated, before a specific framework was constructed years later. History repeats itself, just faster, and with potentially greater sums at stake in each transaction.

Three paths are now emerging. We could wait for new European regulations at the risk of arriving too late, extend existing regimes such as the GDPR to the AI ​​decision-making chain, or even let the market impose its own standards of proof.

There is no obvious answer. But as AI agents manage an increasing share of financial flows, the question of who is accountable for their decisions cannot go unanswered indefinitely. The debate deserves to be opened now, by jurists, regulators and lawyers, before the first case forces it to be opened urgently.

Leave a Reply

Your email address will not be published. Required fields are marked *