Legal development

New York's financial regulator turns its attention to agentic commerce

    As AI agents move from answering questions to executing purchases and arranging financing on their own—sometimes with limited real-time human oversight—the question of who is responsible when something goes wrong has started to draw regulatory attention. Speaking at the New York Federal Reserve's Innovation Conference on June 26, New York Department of Financial Services (the Department) acting Superintendent Kaitlin Asrow signaled that her agency is watching the rise of agentic commerce closely and is working through how its long-standing consumer protections should apply. Asrow came to the role from inside the Department, where she led its research and innovation division, and she previously advised the Federal Reserve on fintech and related policy. For retailers, lenders, banks, and the fintechs building these tools, her remarks offer an early read on how one of the country's most influential state financial regulators is likely to approach this technology.

    Key takeaways

    • Liability and consumer protection gaps in agentic transactions: Asrow flagged inherent and unresolved risks as consumers begin using AI agents to transact autonomously, including by drawing on payment credentials such as a card. She did not specify a single mechanism, and in practice these arrangements can take more than one form, from a regulated firm offering an agent-enabled product to a consumer connecting an outside agent to an existing account. Her remarks do not point to any one structure but rather to the Department’s interest in how consumer protections carry into transactions that no human directly approves. Left unaddressed, the chargeback, dispute, and liability gaps that agentic transactions can create could expose banks to large-scale consumer redress demands. As agents gain the ability to act autonomously and transact on a customer's behalf, the Department is focused on where responsibility rests when a transaction goes awry, how to preserve the consumer protections and payment flows that the financial system has relied on for decades, and how to layer this new capability onto that existing foundation.
    • Supervisory discomfort with autonomous execution: Asrow acknowledged that transactions executed without active human approval sit uneasily with regulators’ traditional instincts and expectations. The central question for her agency is how to keep consumers protected across the full life of such a transaction, and the Department’s attention will center on whether firms have appropriate systems and governance in place.
    • No single blueprint for AI development: Asrow cautioned expecting a one-size-fits-all standard, noting that there is no single correct way to deploy agentic AI, although there are many ways to get it wrong. The message for firms is that the Department expects sound controls rather than adherence to a fixed template.

    Where accountability is likely to land

    A regulated firm answering for its own compliance is nothing new. What agentic commerce unsettles is who the responsible party is when the autonomous agent, rather than the consumer, initiates the transaction and how that responsibility is shared across the chain. The Department has not settled its expectations for allocation of agentic transaction liability. Its broader track record, however, offers a strong hint about the likely direction. In guidance issued earlier in her tenure, the Department made clear that a regulated firm remains responsible for the cyber risk posed by its third-party vendors and cannot delegate its compliance obligations away. The same logic is likely to extend to agentic commerce: The entity offering the product or service—not the software that arranged it—will be expected to answer for the outcome.

    Suppose an agent enrolls the consumer in an installment plan or opens a credit line on the consumer's behalf, and the transaction later gives rise to a dispute, an error, or a disclosure failure. Whether the terms were favorable is beside the point. Because the agent is not itself a regulated entity and owes the consumer no fiduciary duty, the Department is likely to look to the licensed lender, merchant, or other regulated entity behind the product rather than to the software that made the selection.

    The reading raises a practical question of reach. The Department supervises the financial institutions it licenses, not merchants, so even though the merchant is often the party presenting terms at checkout, the Department leverage runs through the regulated entity in the chain, whether it is the card issuer, the lender, or a licensed provider. The likely result is that the Department expects that regulated entity to ensure required disclosures reach the consumer even when an agent or an automated interface sits between them, rather than asserting authority over the merchant directly. No such requirement has been proposed for agent-driven transactions, so this remains a forward-looking expectation rather than a present rule, but it is a natural extension of the Department’s consumer-protection philosophy.

    Why this matters

    For retailers and other merchants, the exposure is more indirect. The Department does not supervise merchants, so its expectations reach merchants mainly through their banks and lender partners and the contracts that govern those relationships. A merchant that presents financing at checkout should expect its regulated partners to push disclosure and dispute-handling obligations down by contract, even where an agent completes the purchase. For service providers that use AI to automate transactions, the message is that automation is unlikely to dilute existing consumer-protection obligations. The transparency and disclosure duties that attach to an offer should be assumed to follow that offer into an automated channel.

    For banks and card issuers, the exposure is most direct, because they are the regulated entities the Department can actually reach. The immediate pressure point sits in the dispute and chargeback machinery. Existing frameworks were built around transactions initiated by people, and an agent acting on standing instructions strains familiar assumptions about authorization and consumer consent. Institutions that clarify now how agent-initiated transactions fit within their liability and error-resolution processes will be better positioned if regulators begin asking pointed questions.

    For fintechs and platforms enabling agentic transactions, the governance point is the one to take seriously. Asrow's emphasis on systems and controls, rather than on a prescribed product design, suggests firms will have room to innovate but will be expected to document how they manage the risks. The way a platform allocates liability between itself and its customers is likely to attract scrutiny.

    For businesses operating across multiple states, the New York signal is worth reading in a wider context. As federal consumer-protection oversight has pulled back, state regulators have moved to fill the space, and a posture staked out in New York often shapes expectations well beyond its borders.

    The broader state trend

    Asrow's remarks fit a pattern of state regulators asserting themselves as federal supervision recedes. In one of her early actions after taking the acting role, the Department issued guidance making clear that banks remain responsible for the cyber risk posed by their third-party vendors, guidance that reinforces the nondelegation principle likely to inform the Department’s approach to agentic commerce. Other states have moved in parallel, with Rhode Island, for instance, writing its own cybersecurity requirements for nonbank financial companies, extending to new entrants the kind of obligations regulators have long placed on banks. That same instinct, holding the regulated firm accountable as activity shifts to new technologies and new players, is likely to drive state treatment of agentic commerce. Agentic commerce looks poised to become another area where state-level expectations develop ahead of any national standard.

    What to do now

    Firms and merchants active in payments, retail financing, or building agentic capabilities may want to take several practical steps while the regulatory posture takes shape:

    • Map where liability sits across your agentic transaction flows, and review customer agreements to confirm that authorization, consent, and responsibility for agent-initiated activity are clearly allocated.
    • Confirm that automated sales and checkout tools deliver the same transaction disclosures a human representative would be required to provide, with equal prominence, rather than burying them.
    • Review the audit trails behind any automated decision-making, since the Department already expects covered entities to maintain audit trails, and extend that same discipline to automated decisions arranged for an agent-represented customer.
    • Assess your governance and controls for agent-driven transactions, since the Department has signaled that the adequacy of systems and oversight will be a focal point.
    • Track developments in New York and other active states, and assume that expectations may develop unevenly across jurisdictions before any national standard emerges.

    This is an early signal rather than a rule, but it is a meaningful one. The Department is still building its position, the allocation of liability in agentic commerce remains unsettled, and state regulators are moving quickly to shape the space. We will continue to monitor the Department’s approach and related developments across the states.

    The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
    Readers should take legal advice before applying it to specific issues or transactions.

    Key Contacts