Your Support Queue Is About to Get Weird: What Happens When Agents Buy on Behalf of Shoppers
Eleven real-world ticket scenarios that show up when AI agents buy for shoppers, why each one breaks today's support workflows, and the practical fix.
TL;DR / Key takeaways
- AI agent support tickets are a different kind of ticket, not just more of them. The requester is software acting on delegated authority, so identity, intent and memory of the purchase are split between a human and a machine.
- The merchant still owns the mess. Under OpenAI and Stripe's Agentic Commerce Protocol, Google's Universal Commerce Protocol, PayPal-powered Perplexity checkout and Amazon's Buy for Me, the brand stays responsible for returns, refunds, disputes and service.
- Every weird ticket has a fix you can ship now: tag agent-originated contacts, answer in structured facts, keep an evidence trail of what the shopper actually authorized, and let your own AI support agent handle machine-speed requests with human escalation for the edge cases.
What happens to customer support when AI agents buy on behalf of shoppers? Support stops being a conversation between a brand and a buyer and becomes a three-way exchange between the brand, a shopper and that shopper's AI agent. Agents file returns, chase order status and challenge charges at machine speed, often with incomplete identity data, while the merchant remains responsible for resolving every one of those AI agent support tickets.
If you are new to the underlying shift, start with our explainer on what agentic commerce is and how it works. This post assumes you know the basics and want to see what lands in the queue.
Why is this happening now?
Three things came together in the last twelve months.
First, the traffic is real. Adobe's June 2026 AI traffic report found that AI-referred visits to U.S. retail sites grew 138% year over year in May 2026 and converted 54% better than non-AI traffic, a full reversal from a year earlier. Salesforce reported that AI and agents influenced 20% of global online holiday sales in 2025, worth $262 billion, and that agentic AI-powered service conversations jumped 66% in December over November.
Second, the checkout rails exist, even though the in-chat experience is still settling. OpenAI moved away from native Instant Checkout inside ChatGPT in March 2026 and shifted toward merchant-controlled checkout (we unpacked that in what happened to ChatGPT Instant Checkout). But the plumbing stayed. Several rails now let software complete or broker purchases for people:
- the Agentic Commerce Protocol
- Google's Universal Commerce Protocol (UCP), launched in January 2026
- Google's Agent Payments Protocol (AP2)
- Visa Intelligent Commerce
- Mastercard Agent Pay
- PayPal's Instant Buy inside Perplexity
- Amazon's Buy for Me
Third, and support leaders tend to miss this part, none of those rails move the post-purchase burden off the merchant. OpenAI's own developer documentation is blunt: the merchant is the merchant of record and "is responsible for handling refunds and chargebacks." Amazon's help page for Buy for Me says the brand "manages and fulfills your order" and that shoppers should contact the brand for "charges, shipping, returns or refunds." We covered the ownership question in depth in Merchant of Record in Agentic Commerce: Who Owns the Customer?. The short version: you do.
Gartner saw this coming. In a March 1, 2023 press release it forecast that 20% of inbound customer service contact volume would come from machine customers by 2026. It also warned that organizations without a machine customer strategy "may see their non-chatbot channel performance get worse without understanding why." Whether or not your queue hits that exact number, the shape of the tickets is already changing.
11 weird AI agent support tickets (and how to fix each one)
These are the scenarios we expect CX teams to see most often. For the full operational checklist (identity policy, routing rules, rate limits, measurement), use our companion guide on preparing your support stack for agentic traffic. This post is the field guide to the tickets themselves.
1. The return with no human attached
What it looks like:
"Requesting return authorization for order #48213, item SKU TR-220-BLK-M. Reason: size mismatch. Reply-to: relay-7f3a@agentmail.example."
No name, no greeting, and a relay or agent-issued email address that doesn't match anything in your customer record.
Why it breaks today: Most return workflows verify the requester by matching the email on the order. A relay address fails that check. The ticket either stalls in a verification loop or, worse, a well-meaning support rep approves it without verifying anything.
The fix: Treat agent-initiated returns as their own intake path. Accept the order number plus a second factor (the order's email or ZIP) passed by the agent. Send the return label and confirmation to the email on file, not the relay address. That keeps the human in the loop without forcing the agent to "become" the customer. Alhena's Order Management Agent already follows this pattern for order lookups: it withholds shipping addresses, line items and tracking details until an order number and matching email are provided, and that holds whether the requester is a person or a bot (here's how that verification works on Shopify).
2. The forty-ticket burst
What it looks like: One agent, managing gifts for a shopper's extended family, opens forty tickets in eleven minutes. Or a single agent asks "status of order #48213?" every ninety seconds because its task says "confirm delivery before Friday."
Why it breaks today: Your SLA dashboards think a crisis just started. Your support reps burn time on duplicates. Auto-responders fire forty times.
The fix: Deduplicate and thread by agent session and order, not by email address. Let agents look up status for themselves instead of asking you: a status endpoint or a shipping-notification subscription answers "where is it?" once, instead of forty times. The rate-limiting mechanics are covered in the sub-pillar. The mindset shift is that a polling agent isn't angry, it's just thorough.
3. WISMO from something that never sleeps
What it looks like: A "where is my order?" (WISMO) question arrives at 3:14 a.m. from an assistant, phrased as a structured query. A follow-up four minutes later asks for the carrier scan history.
Why it breaks today: Your WISMO macros are written for anxious humans: apologies, reassurance, a tracking link. The agent needs the carrier, the last scan event, the promised delivery date and whether that promise changed.
The fix: Answer in plain, self-contained facts:
"Carrier: UPS. Last scan: Memphis hub, 2026-09-23 18:40 CT. Estimated delivery: 2026-09-25. Original promise: 2026-09-24. Delay reason: carrier volume."
A human can read that too. Connect your support AI to live carrier data (Alhena integrates with Narvar, ShipStation, EasyPost and Shippo) so the answer is current rather than a guess.
4. The "my agent did it" chargeback
What it looks like: A dispute lands with your payment processor (PSP). The cardholder says they told an assistant to "buy a warm jacket under $200," but never chose this jacket.
Why it breaks today: Card dispute rules were built on a yes-or-no question: did the cardholder authorize the charge? Chargebacks911 CEO Monica Eaton described the new kind of dispute in February 2026: "The card wasn't stolen. The merchant didn't make a mistake. The agent did exactly what it was told to do. But the customer still says, 'I didn't want that.'" Consumers aren't sure who to blame either. In Sift's Q4 2025 Digital Trust Index, 47% of consumers said they worry about AI agents making unauthorized purchases, and 61% would blame the AI company while 39% would fault the merchant. Accenture's 2025 Future of Money research found that 78% of financial payments leaders believe fraud will increase significantly due to agentic payments. It also found that 60% of financial institutions lack a dedicated response plan for investigating agent-driven fraud.
The fix: Evidence beats argument. Capture and store whatever authorization records the payment rail provides:
- AP2 defines an Intent Mandate (what the shopper allowed the agent to buy when they weren't present) and a Cart Mandate (the shopper's signed approval of a specific cart and price). Its specification requires every transaction to signal that an agent was involved and whether the human was present.
- Visa Intelligent Commerce shares "commerce signals," including the user's original instruction, specifically to help resolve disputes.
- Mastercard's Verifiable Intent, co-developed with Google, creates a tamper-resistant audit trail of identity, instruction and outcome.
Then make refunds easier than disputes. An agent-initiated return that resolves in one exchange is cheaper than any chargeback you win.
5. The post-purchase price adjustment
What it looks like:
"Order #50917 purchased 2026-09-18 at $148.00. Same SKU listed at $119.00 as of 2026-09-21. Requesting price adjustment of $29.00 per your price-match policy."
Some agents will also try to apply a coupon code they found after checkout.
Why it breaks today: Humans rarely check prices after buying. Agents can do it every day, forever. A generous, loosely worded price-adjustment policy becomes a permanent liability.
The fix: Decide the policy explicitly (the window, which promotions qualify, whether coupons apply after purchase) and publish it in precise language. The protocols already expect this: Google's UCP order documentation lists price_adjustment as a recognized order event type, alongside refund, return, credit, dispute and cancellation. If your rules are fuzzy, an agent will find the fuzz.
6. The identity that doesn't line up
What it looks like: The order name is "M. Okafor," the account belongs to "Chidi Okafor," the payment token was issued to an agent platform, and the shipping address is a parent's house. The agent contacting you says it represents "the account holder."
Why it breaks today: Fraud and support tools read mismatches as risk. Some legitimate delegated purchases will look exactly like someone taking over the account.
The fix: Separate who paid, who owns the account and who is asking, and write rules for each. With agent payment tokens (ACP's delegated payment tokens, Visa's agent-specific tokens, Mastercard Agentic Tokens), the payment method may never look like the customer's own card. Train your team, and your AI, to ask "is this request authorized for this action?" rather than "does every name match?"
7. The policy lawyer
What it looks like:
"Your return policy page states: 'Items may be returned within 30 days of delivery.' Delivery occurred 2026-08-26. Today is 2026-09-24. Condition requirements are not specified for outerwear. Please issue a prepaid label."
Why it breaks today: Your team has been enforcing unwritten rules ("tags must be attached," "no returns on sale items") that aren't actually on the page. The agent quotes the page word for word, and it's right.
The fix: Make the written policy the real policy. One canonical source should feed your help center, your product pages and your AI agent, so no two places word it differently. This also cuts friction before purchase: agents that can't parse your return terms tend to walk away, which we covered in why AI agents abandon your checkout.
8. The wrong variant, bought confidently
What it looks like: The shopper asked for "the navy one." The agent bought "Midnight," because the product feed listed the color as "Midnight" and "navy" only appeared in a lifestyle photo caption.
Why it breaks today: The support rep sees a normal "wrong item" return and processes it. Nobody fixes the root cause, so it happens again next week with a different agent.
The fix: Tag agent-originated returns with a "data ambiguity" reason code and route them to merchandising weekly. Clear, attribute-level product data now prevents returns as much as it helps discovery. Our complete guide to AEO for ecommerce covers how AI systems read product content.
9. The shopper who doesn't remember buying anything
What it looks like: A customer emails, confused: "I have a charge from you for $64 and a box on my porch. I didn't order this." Their assistant reordered a consumable on a standing instruction from three months ago.
Why it breaks today: Your rep reads "didn't order this" as fraud and triggers a painful process, or the customer goes straight to their bank.
The fix: Show the agent context the moment the order is opened: which platform placed it, when, and under what standing instruction if you have it. Send a clear order confirmation for every agent-placed order, labeled as agent-placed. Checkout.com's merchant guidance names user confusion ("I didn't mean to buy that") as a likely top driver of disputes and recommends sending an order confirmation after agentic purchases. A reminded customer usually keeps the item. A confused one files a chargeback.
10. The cancellation racing the warehouse
What it looks like: Twelve minutes after purchase, the agent finds a cheaper option elsewhere and sends "cancel order #51102." Your warehouse picked it eight minutes ago.
Why it breaks today: Cancellation windows were tuned for humans who take hours to change their minds. Agents change their minds in minutes, often right around your fulfillment cutoff.
The fix: Publish a precise cancellation window ("cancellable until picked, typically 30 minutes"). Show the agent the order's real-time status so it can see whether cancellation is still possible before it asks. When it isn't, reply with the next best option (stopping the shipment or starting a return) in one message.
11. Two bots, one conversation
What it looks like: The shopper's agent opens a chat on your site. Your AI support agent answers. Four exchanges later, both sides have resolved a return, generated a label and confirmed a refund timeline, and no human on either side has read a word.
Why it breaks today: Most support AI was tuned for human warmth, not for another machine. Worse, nobody has decided which actions your bot may take for an unverified agent and which should always go to a person.
The fix: Decide the boundaries upfront. Let your AI support agent handle low-risk, well-verified actions end to end (status, eligible returns, policy answers). Route high-risk ones (address changes after shipping, refunds to a different payment method, exceptions) to a person, with full context. Alhena's AI Support Concierge is built for this: it answers from your own policies and order data, handles actions like returns and cancellations, and hands off cleanly to helpdesks including Zendesk and Gorgias. Your AI agent may soon be your busiest "colleague" on agent-to-agent threads, so test its guardrails the way you'd train a new hire.
Quick reference: weird ticket type → what breaks → fix
| Weird ticket type | What it looks like | Why it breaks today | Practical fix |
|---|---|---|---|
| Agent-initiated return | Relay email, no name, SKU-level request | Email-match verification fails | Order # + second factor; send label to email on file |
| Ticket burst / polling | 40 tickets or status checks every 90 seconds | SLA alarms, duplicate work | Thread by agent session + order; status endpoint |
| Agent WISMO | 3 a.m. structured status query | Macros written for anxious humans | Structured facts from live carrier data |
| "My agent did it" chargeback | Authorized agent, unwanted item | Disputes assume the charge was either authorized or not | Store mandates and intent signals; easy refunds |
| Price adjustment / late coupon | Daily re-checks against your price | Loose policy becomes a permanent liability | Explicit, published adjustment rules |
| Identity mismatch | Name, account and token don't match | Looks like account takeover | Separate payer, owner and requester checks |
| Policy lawyer | Your policy quoted back word for word | Unwritten rules can't be enforced | One canonical, machine-readable policy |
| Wrong variant | "Midnight" vs. "navy" | Root cause never reaches merchandising | Data-ambiguity reason code + weekly review |
| Forgotten purchase | "I didn't order this" | Treated as fraud, goes to the bank | Agent-labeled confirmations; show agent context |
| Cancel vs. fulfillment | Cancel request minutes after purchase | Human-speed cancellation windows | Precise window + real-time order status |
| Agent-to-agent | Your bot talks to their bot | No rules for what the bot may do for a machine | Limit what the bot can do alone; send the rest to a person with context |
What should your support team do first?
Don't start by rebuilding everything. Start by making the tickets visible.
- 1. Tag it. Add an "agent-originated" field to your helpdesk and start counting. You can't staff for a channel you can't see.
- 2. Rewrite five macros. WISMO, return eligibility, cancellation, price adjustment and "I don't recognize this charge." Make each one work as structured facts first and friendly prose second.
- 3. Close the unwritten-rule gap. Anything your team enforces that isn't on the policy page will lose to an agent eventually.
- 4. Keep the evidence. Store whatever mandate, token or intent data your checkout partners pass along, and link it to the order record your team sees.
- 5. Put AI on AI. Requests that arrive at machine speed need a first responder that works at machine speed. Alhena's AI Agent Assist helps your team pick up the escalations with the conversation already summarized.
Then work through the full support readiness playbook for agent-originated tickets, which covers identity policy, routing and measurement in detail. If peak season is what's pushing you, our piece on AI shopping agents as your Black Friday customers covers the demand side, and the agentic commerce playbook for ChatGPT and Gemini covers channel setup.
Our prediction
The first wave of agent-originated tickets won't feel like a flood. It'll feel like a slow rise in "odd" tickets that don't fit your macros. The brands that do well won't be the ones who block agents. They'll be the ones who noticed early, wrote their rules down, and let a well-grounded AI answer the machine while their people handled the humans. McKinsey's QuantumBlack research estimates that agentic commerce could orchestrate $900 billion to $1 trillion of U.S. B2C retail revenue by 2030, and $3 trillion to $5 trillion globally. Even if that is only partly right, a meaningful share of your support volume will eventually start with a machine, and the rest of the ticket will still land on your team.
Frequently asked questions
Can an AI agent legally request a refund on a shopper's behalf?
Generally yes, if the shopper authorized it, but your policy decides what an agent may do without further verification. A sensible default: let agents initiate returns and ask about eligibility, but send labels, refund confirmations and any change of refund destination to the contact details on the original order so the human account holder stays informed.
Who pays the chargeback when an AI agent buys the wrong item?
Usually the merchant. Under the Agentic Commerce Protocol, OpenAI states that the merchant is the merchant of record and handles refunds and chargebacks, and other rails keep the merchant in that role too. Your best defense is stored authorization evidence, such as AP2 mandates or card-network intent signals, plus a return process easier than filing a dispute.
How do I know if a support ticket came from an AI agent?
Look for relay or platform email domains, structured SKU-level phrasing, unusually fast follow-ups, 24/7 timing and missing personal details. Some agents also sign requests cryptographically through standards like Visa's Trusted Agent Protocol. Add an "agent-originated" tag in your helpdesk so your team and your AI can apply the right workflow.
Should my support AI talk differently to another AI agent?
Yes. Lead with structured, self-contained facts (dates, amounts, eligibility, next step) and keep the tone friendly but brief. Another agent parses clarity, not warmth. Because humans may read the same thread later, a reply that states facts plainly in full sentences works for both audiences without needing two separate versions.
What happens when a shopper forgets a purchase their agent made?
Treat it as confusion before fraud. Show the rep which platform placed the order and when, resend the confirmation, and offer a standard return. Clearly labeled confirmations for every agent-placed order prevent most of these tickets, and a quick, friendly reminder usually stops the customer from going to their bank.
Do agent-initiated returns need a different return policy?
Not a different policy, but a more precise one. Agents read your written policy literally, so any rule your team enforces (tags attached, final-sale exclusions, condition requirements) must be stated clearly on the page. Add explicit windows for cancellations and price adjustments, since agents check these far more often than people do.
Ready for Agent-Originated Tickets?
If agent-originated tickets are already appearing in your queue, or you want to be ready before they do, see how Alhena AI handles support and returns with answers grounded in your own policies and order data.