Consumer protection law defines a consumer as a person acting outside a trade or profession. Your purchasing agent is not a person, and everything it does is trade. That definition predates software that can hold a card, and no regulator has replaced it. It's one of five cross-border questions nobody has settled.

Here are all five: why each is hard, and what the competing answers look like. None have a vendor answer yet, ours included.

The questionOne answerThe competing answer
Whose consumer rules attach abroadThe buyer's home rulesWhat the merchant could see
Who the law treats as the buyerThe company whose card it isThe company, inside the authority it granted
What a limit governs after conversionThe approved amountThe settled amount
Whether one country's record satisfies another's regulatorA signed record travelsA record is only as good as its home law
Where the record has to liveWhere the decision was madeWhere the law over the people named reaches

Which country's consumer rules apply when no consumer clicked buy?

Nobody has settled it. Consumer protection attaches to a consumer, and a company's procurement agent is not one under any definition in force. The open case is the other one: a personal assistant buying across a border for an individual, where the buyer is a consumer and the order came from software.

Cross-border consumer rules generally attach where a merchant directed its activity. That test assumes a website with a language and a currency, read by a human before buying. An agent comparing forty vendors and taking the cheapest reads none of it.

So either the agent counts as a tool, like a browser, and the buyer's home rules follow the purchase, or the transaction gets judged on what the merchant could see. The proposed "supervised digital agent" category, a third legal frame sitting between software tool and person, is one way that question gets settled.

Who does the law treat as the buyer when software places the order?

The company whose card it is, in every card programme running today. That holds while an agent buys inside its own company's policy. It gets harder when one company's agent buys from another's, or when a single agent buys for several principals, because the name on the transaction and the party that decided to buy stop being the same.

Contract law's answer for humans is about authority rather than identity. If the seller reasonably believed the buyer had authority, the deal stands, even where the buyer went past what the employer allowed internally.

What a merchant can reasonably believe about software it has never dealt with is the open part. Treat the agent as a tool and every purchase binds the company, which is what the rails can express today. Treat it as a delegate with scoped authority and purchases outside that scope don't bind.

Can a limit checked at authorization hold when the currency converts later?

Only up to the conversion. A cross-currency purchase is approved in one currency and settles in another, at a rate that isn't fixed at approval. A limit satisfied when the purchase was approved can be exceeded by the time the statement lands. Whose problem that difference is has never been argued out.

For a person on a business trip that gap is a rounding error. For an agent buying in several currencies every day, the same drift lands on every line.

Govern the approved amount and your policy is exact when it's checked, with the statement free to come in higher. Govern the settled amount and it's exact on the statement, which means it could never stop anything while the merchant was waiting.

Will a record produced in one country satisfy a regulator in another?

There's no general answer. A supervisor in one country can ask for a record held under another country's law, and what counts as a record was written for bank books and human signatures. Signed mandates of the kind AP2, Google's Agent Payments Protocol, defines give you a tamper-evident artifact. Whether a supervisor elsewhere treats it as proof is separate.

Underneath that sits a residency problem, and it arrives first. An approval record worth keeping names the person who approved, when, and what they were shown. That's personal data, and the EU restricts moving it out of the bloc under GDPR. Where agent payment records live and how long they're kept covers the retention half.

Keep one record in one place and some regulator ends up reading a foreign document. Keep a copy per jurisdiction and you hold several records that have to agree.

What holds up while these stay open?

The controls that don't depend on which way the arguments go. A limit on one agent's purchasing instrument means the same thing whether the law calls that agent a tool or a delegate. A record of who approved a purchase is worth keeping before anyone rules on what makes it admissible.

Shatale gives each agent its own scoped virtual card, enforces the policy you set at the authorization moment, escalates purchases above your thresholds to a person, and keeps an immutable per-agent record of every decision. A purchase outside policy is blocked or escalated for approval while the merchant waits.

None of that settles the five questions above. They stay open for us and for every other vendor in this category, and a vendor who answers them in a sales call is describing a product decision as a legal one.

Rain launched the Agentic Payments Alliance on 18 August 2026 with 26 founding members, Remitly among them, and named regulatory advocacy as part of its early work. Advocacy is what a group does about a question nobody has answered.

What to ask

FAQ

Which country's law applies when an AI agent buys across a border?

There's no settled answer. A card transaction counts as cross-border when the issuer's country differs from the acquirer's, which is a fact about two banks and says nothing about which consumer or contract rules attach. For a company's purchases the contract with the merchant usually governs.

Is a purchase made by an AI agent a consumer purchase?

Not when a company's agent buys for the company. Consumer protection attaches to a person acting outside a trade or profession, and a procurement agent fails that test on both counts. The unsettled case is a personal assistant buying for an individual across a border.

Does a spending limit still work if the agent buys in another currency?

It applies to whichever amount your provider evaluates. A cross-currency purchase is approved in one currency and settles in another at a rate that isn't fixed at approval, so the two amounts can differ. Ask which of them your limit governs.

Is anyone regulating cross-border AI agent payments yet?

There's no rulebook written specifically for agent-initiated cross-border payments. Existing payment and data protection rules apply as written, and they were written for humans placing orders. The Agentic Payments Alliance, launched in August 2026 with 26 founding members, names regulatory advocacy as part of its early work.


What changes at the transaction level once an agent's purchase crosses a border is covered in cross-border agent payments. Early access is free for publishers.

Shatale is the control layer for AI-agent payments. Its authorization architecture is the subject of European patent application EP26194994.5 (filed; priority 28 July 2026).