top of page

Visa Just Created a Customer That Consumer Protection Law Cannot See

The Consumer Protection Act, the National Credit Act, and FSCA regulations were designed for human buyers. Visa's ChatGPT integration introduces an autonomous AI agent as the commercial actor — and none of those frameworks adequately address what happens when it acts, errs, or is manipulated.



Sign up for my Substack daily AI newsletter here.


See my AI Training course portfolio for corporate Business Leaders here.




On 11 June 2026, Visa announced it had linked its payment infrastructure directly to ChatGPT, enabling AI agents to recommend retail products and execute financial transactions without human intervention at the point of purchase. The mechanics are precise. A user pre-authorises the ChatGPT environment with specific spending parameters. When the AI agent decides on a purchase, it generates a single-use payment token through the Visa network.


The token is transmitted via API to the merchant’s backend systems. The transaction settles through Visa’s payment rails. Visa’s Chief Product and Strategy Officer, Jack Forestell, noted that initial rollouts include human approval steps — a notification prompting the user to confirm before the token settles — while consumer trust in the system is established. That guardrail is a launch condition, not an architectural limit. The entire value proposition of the integration is a trajectory toward removing human presence from the point of decision entirely, and the governance questions it raises are not diminished by the existence of a temporary approval prompt.


This is commercially significant and technically impressive. It is also something that South Africa’s consumer protection, credit, and financial services regulatory frameworks were not designed to govern — and the gap between what the technology enables and what the law addresses is not a future problem. It is a current one.


CONTEXT AND BACKGROUND

South Africa’s consumer protection architecture rests on three primary pillars. The Consumer Protection Act of 2008 protects consumers in the purchase of goods and services, establishing rights of disclosure, cooling-off periods, protection against unfair terms, and remedies for defective goods. The National Credit Act of 2005 governs credit agreements, requiring affordability assessments, disclosure of terms, and protection against reckless lending. The Financial Advisory and Intermediary Services Act governs the provision of financial advice and intermediary services, requiring that advice be appropriate, disclosed, and provided by a fit and proper person.


Each of these frameworks rests on a foundational assumption: the consumer is a natural person who can be informed, who can read and understand terms, who can make a decision, and who can exercise the rights the law provides. The Visa-ChatGPT integration introduces a commercial actor that satisfies none of those assumptions. The AI agent is not a natural person. It cannot be deceived in the legal sense because it does not have beliefs or expectations that can be falsified. It cannot give informed consent because it does not have subjective experience of the terms it is accepting. It cannot exercise the right to a cooling-off period because it does not experience the passage of time between purchase decision and regret. It cannot receive a written record of the transaction in the way Section 26 of the CPA contemplates — if the receipt is transmitted to an LLM profile, the question of whether that satisfies the retailer’s obligation to provide a sales record to the consumer is not answered by the statute. And it cannot be the beneficiary of consumer protection rights because it is not the consumer — it is acting on behalf of one, in circumstances where the consumer may not have reviewed the specific transaction before it was executed.


South Africa does have a legislative framework that acknowledges automated commercial actors. The Electronic Communications and Transactions Act of 2002 recognises electronic agents in Sections 21 through 25, stating explicitly that a contract can be formed by an electronic agent and a natural person and that a human is bound by the actions of their electronic agent. That recognition is significant — it means the law is not entirely silent on this commercial actor. What it means is that the law recognises a version of this actor that bears almost no resemblance to the one Visa has now deployed. ECTA was written for predictable, pre-programmed software scripts of the early internet era — an automated stock reorder system, a price comparison bot, a rule-based checkout integration. It was never designed for a non-deterministic large language model with hallucination risks, prompt injection vulnerabilities, and reasoning that cannot be fully predicted from its inputs. The governance gap is not that the law does not see AI agents at all. It is that the law sees a version of them that no longer describes what they actually are.


INSIGHT AND ANALYSIS

The governance gap takes three distinct forms, each of which requires a different regulatory response.


The first is the disclosure problem. The CPA requires that suppliers disclose material terms to consumers before or at the time of the transaction. When an AI agent executes a purchase on behalf of a user, the disclosure mechanism the law assumes — a human reading terms, confirming understanding, and proceeding — does not occur. The agent processes terms programmatically. Whether that constitutes adequate disclosure under the CPA, or satisfies a retailer’s obligation to provide a formal sales record under Section 26, are questions the law cannot answer. While ECTA historically recognised electronic agents, its 2002 framework was built for predictable, pre-programmed software scripts — not the non-deterministic, fluid reasoning of an LLM open to downstream manipulation. The cooling-off provisions of the CPA add a further complication: Section 16 provides a five-day cooling-off right for transactions resulting from direct marketing. If an AI agent scrapes the web, identifies a product, and purchases it, whether that constitutes direct marketing to the consumer — and therefore whether the five-day right applies — is a question the statute does not address.


The second is the liability chain problem. When a human consumer buys a defective product and seeks redress, the liability chain is relatively well-defined: supplier, retailer, manufacturer, as specified in the CPA. When an AI agent buys a defective product, the chain extends further. The agent acted within the user’s defined parameters. The agent’s reasoning was shaped by the LLM’s training data and inference. The payment token was provided by Visa. The transaction was processed by the merchant. If the product fails to meet the parameters defined in the user’s original instruction to the agent — and the agent navigates the return process autonomously — each step of that process involves actors whose legal responsibilities in an agentic transaction are not defined. ECTA binds the human principal to the actions of their electronic agent. It does not assign liability among the chain of parties whose systems, models, and rails enabled the transaction. The CPA provides remedies for the consumer against the supplier. It does not define how those remedies operate when the contracting party was an algorithm acting within pre-defined parameters that the consumer approved in advance and the specific transaction the consumer did not review.


The third is the manipulation problem, which the article identifies as prompt injection — the possibility that a malicious actor could manipulate the AI agent’s reasoning to purchase from a fraudulent vendor or authorise an inflated transaction. Visa’s fraud detection models provide a layer of protection at the payment rail. They do not address the manipulation of the agent’s decision-making before it reaches the payment stage. ECTA binds the human to their agent’s actions — but it does not address the scenario in which the agent’s reasoning was compromised before it acted. If a user’s AI agent is manipulated through a prompt injection attack into executing an unauthorised transaction, the question of whether the user retains rights under the ECT Act, whether Visa bears any responsibility for the downstream consequences of a compromised agent token, and whether the CPA’s protections against unconscionable conduct apply to a transaction executed through a corrupted agent reasoning layer, are all open.


I have previously written about the governance failures that emerge when organisations deploy agentic AI without the frameworks required to define ownership, accountability, and recourse when autonomous agents act in ways that produce unintended consequences. The Visa-ChatGPT integration is the most concrete consumer-facing example yet of that gap — the compliance frameworks adequate for human-operated digital commerce are not adequate for agent-operated digital commerce, and the organisations that discover this in the context of a disputed transaction, a regulatory inquiry, or a consumer complaint will be doing so without the clarity that a properly designed governance framework would have provided.


The Visa-ChatGPT integration is the most concrete example yet of that gap at the consumer-facing level. The compliance frameworks that were adequate for human-operated digital commerce are not adequate for agent-operated digital commerce — and the organisations that discover this in the context of a disputed transaction, a regulatory inquiry, or a consumer complaint will be doing so without the clarity that a properly designed governance framework would have provided.


IMPLICATIONS

For South African boards and executives, the Visa-ChatGPT integration raises governance questions across three domains that most current AI strategy frameworks have not addressed.


For financial services organisations — banks, insurers, payment processors, and financial advisers — the integration raises the question of whether existing FSCA authorisations and regulatory permissions extend to services provided to or through AI agents acting on behalf of clients. When a financial adviser recommends a product to a human client, FAIS requires that the advice be appropriate, disclosed, and based on an analysis of the client’s needs. When an AI agent acting on behalf of a client executes a financial transaction, the question of whether FAIS requirements have been satisfied — whether the agent’s decision constitutes advice, whether the user’s pre-authorisation of the agent constitutes informed consent to the advice, and whether the agent’s reasoning is subject to the same appropriateness standards as human financial advice — is not yet resolved.


For retailers and e-commerce operators, the integration changes both the nature of the customer and the architecture required to serve them. Retailers using headless commerce architectures — where the payment and inventory backend is decoupled from the front-end website — are best positioned to process agent payloads cleanly. Their systems can receive the agent’s API call, confirm stock levels, validate the payment token, and settle the transaction in milliseconds without requiring the agent to navigate a visual interface.


Traditional multi-page checkout storefronts with mandatory account creation and CAPTCHA verification introduce failure points that agentic transactions cannot accommodate. The CPA’s requirements for fair marketing and honest product representation apply to agent-mediated purchases — but demonstrating CPA compliance in a transaction where the human consumer never directly experienced the marketing, the product description, or the checkout terms is a question that neither the statute nor any regulatory guidance currently answers.


For all organisations that deploy or integrate with AI agent systems, the prompt injection attack surface is the most immediately actionable security governance question. Current cybersecurity frameworks were designed for human-operated interfaces. Extending them to cover agent manipulation requires understanding a threat model in which the target is an AI reasoning engine operating autonomously within financial parameters rather than a human user navigating a screen.


CLOSING TAKEAWAY

South Africa’s Electronic Communications and Transactions Act recognised the concept of an electronic agent in 2002 — a provision that was forward-thinking for its time and entirely inadequate for the present. The electronic agent ECTA recognised was a predictable script executing a pre-defined task. The electronic agent Visa has now connected to its payment infrastructure is a non-deterministic large language model capable of browsing the open web, reasoning across merchant catalogues, generating payment tokens, and initiating returns — and capable of being manipulated through its reasoning layer in ways that ECTA’s drafters could not have anticipated.


The Consumer Protection Act, the National Credit Act, and the Financial Advisory and Intermediary Services Act have not yet caught up. The governance gap this creates belongs to the FSCA, the National Consumer Commission, the National Credit Regulator, and the boards of every South African organisation that is either deploying AI agents on behalf of its customers or receiving transactions initiated by AI agents acting on behalf of someone else’s. The technology has arrived. The governance response cannot wait for the first disputed agentic transaction to make the absence of a framework visible.


Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net



 
 
 

Comments


Leveraging AI in Human Resources ​for Organisational Success
CTU Training Solutions webinar

bottom of page