Is It Safe to Give ChatGPT My Credit Card? Six Banks Just Said the Rules Are Not Written Yet

Picture the moment. You type into ChatGPT: find me a replacement filter for my vacuum and just buy it. Then you stop, fingers over the keyboard, and type a different question instead: is it safe to give ChatGPT my credit card? That second question is one of the phrases Google now finishes for you. People are asking it because AI companies have spent a year telling them the chatbot can shop.
On Tuesday, September 22, six banks answered a version of it. Bank of America, Capital One, NatWest, ING, Commonwealth Bank of Australia and New Zealand’s ASB published a joint paper warning that AI shopping agents bring “potential for higher rates of scams, fraud and disputes” — and that the rules for who pays when an agent gets it wrong are not written yet. We read all 13 pages today, counted what is in them, and lined them up against the federal rules that already protect your card.
The short answer. Paying for your ChatGPT subscription with a card on the Billing page is an ordinary online subscription: safe, with the usual federal card protections. Typing a card number into a chat message is not — it sits in your chat history like anything else you type. Letting an AI agent spend for you is the part nobody has settled.
The banks’ paper, counted on September 23, 2026: 5 principles, 16 numbered recommendations, the word “should” 28 times, “must” 0 times, “refund” 0 times. It calls itself “voluntary and non-binding.” Until that changes, the protection you have is the one in your wallet: a credit card caps fraud losses at $50 by federal law; a debit card can cost you $500 or everything if you report late.
Can ChatGPT actually buy things for you today?
Less than you have been told. The feature that made the headlines had a short life, and the one that replaced it has not shipped to consumers.

On September 29, 2025, OpenAI launched Instant Checkout for U.S. users buying from Etsy sellers, with subscribers able to “pay with their card on file.” By the Associated Press’s account, it was “prone to errors, was not widely adopted by merchants who balked at a 4% transaction fee and was retired in March.”
Then, on June 10, 2026, Visa said it had embedded its payment network inside ChatGPT, so an agent could buy at any merchant that takes Visa, with “spending limits, required approval steps and a list of approved merchants.” Neither company gave a launch date. Google, for its part, announced a Universal Cart on May 19 with Google Pay checkout “soon” at Nike, Sephora, Target, Ulta Beauty and Walmart.
So the honest state of play on September 23: the chatbot is very good at finding things and mostly hands you to the store to pay. The banks are warning about the next step before most people have taken it. That is the useful moment to set your own rules.
What six banks put in writing on September 22

The paper, Building Trust in Agentic Commerce, is short and careful. Its most useful paragraph is a list of things banks say some AI shopping services already do. Quoted exactly, some providers are:
“requesting consumer card details and entering them directly into websites, prioritizing payment methods with lower protections, and not complying with payment processing standards and payment scheme rules.”
— Building Trust in Agentic Commerce, Principle 2 (Safety), page 8
Read that list slowly, because each item maps to a choice you control. An agent that asks you to type your card number is the first item. An agent that nudges you toward a bank transfer or a stored-value wallet instead of a card is the second. The paper also names the motive: agents “may prioritize products, payment methods or other services that deliver the best financial outcomes for their providers (e.g. higher commissions, lower token costs).”
And it is blunt about the part readers care most about. When things go wrong, “there is unclear and inefficient allocation of liability, and disputes processes do not involve all relevant parties.” In other words: if an agent buys the wrong thing, today nobody has agreed whose problem that is.

Here is the line no news segment will read to you. We counted the paper’s own verbs. Its 16 recommendations use “should” 28 times and “must” not once. The word “refund” does not appear; “chargeback” appears once, as a merchant worry. That is not a criticism — a first paper from a group of competitors is supposed to be polite. It is a timing signal: the banks promise a second paper with the actual frameworks; until then, nothing in this one changes what happens to your money this month.
If the agent gets it wrong, the card you used decides who pays
Federal consumer credit and electronic-transfer rules were written decades before AI agents, but they still set the floor. We read the current text on eCFR today. The key sentences:
| How you paid | Someone else misuses it | The purchase itself is wrong |
|---|---|---|
| Credit card | Your loss is capped at the lesser of $50 or the amount charged (12 CFR 1026.12(b)) | Billing-error dispute for goods “not delivered as agreed” — in writing, within 60 days of the statement (1026.13) |
| Debit card | $50 if you report within 2 business days of learning of it; up to $500 after; unlimited after 60 days from the statement (1005.6) | No federal right for a wrong item. Your bank’s policy decides |
| Bank transfer, Zelle | Same debit limits, if someone else started the transfer | No federal right to pull back a transfer you authorized |
| Gift card, crypto | No federal cap | No federal right |
Federal floor only, read September 23, 2026. Card networks and banks often promise more in their own terms. This is not legal advice.

Now the uncomfortable part, and the reason the banks wrote their paper. The $50 cap protects you against “unauthorized use,” which the regulation defines as use by someone “who does not have actual, implied, or apparent authority.” The debit rule is sharper still: it does not treat as unauthorized a transfer made by “a person who was furnished the access device” by you. If you gave an agent your card and told it to shop, a mistake it makes may not be “unauthorized” at all. No regulator has said how these words apply to software. Until one does, the billing-error dispute on a credit card is the only federal tool that fits “it bought the wrong thing” — and it has a 60-day clock.
Let’s put a number on it. Say an agent buys the wrong $400 air purifier and the store refuses the return. On a credit card, you have a written dispute right, and while it is open the $400 is the bank’s money, not yours. On a debit card, the $400 left your checking account the moment it was charged, and whether you see it again depends on your bank’s goodwill. Same purchase, same mistake; the difference is which piece of plastic you handed over.
The one thing never to type into a chat box

A card number typed into a chat message is just text. It sits in your conversation history, it can be copied from a shared link or a screenshot, and depending on your settings it may be used to improve the model. That is exactly the “requesting consumer card details” practice the banks flagged, and no legitimate checkout needs it. The real ones hand the store an encrypted token, not your number: OpenAI described its own as “only authorized for specific amounts and specific merchants with the user’s permission.”

It has happened before on a smaller scale. On March 24, 2023, OpenAI disclosed a bug that may have shown other users the name, email, payment address, card type, last four digits and expiration date of 1.2% of ChatGPT Plus subscribers active during a nine-hour window. OpenAI said full card numbers “were not exposed at any time” — precisely because they were never stored in the chat. Keep it that way.
A safer habit. Ask the chatbot the money question without the identifiers. “I owe $4,200 at 24% and $1,100 at 19%; I can pay $300 a month; which first?” gets you the same answer as pasting a statement — and costs you nothing if the chat ever leaks. More on this in our beginner’s guide to ChatGPT.
Two short segments worth watching
A note on what we left out. A YouTube search for this week’s bank warning surfaces clips posted within a day by channels with a few dozen views and no identifiable newsroom. On a topic about fraud, the source matters as much as the message.
What to do with this
- Never type a full card number, bank account number or Social Security number into any chatbot. If you already did, delete the chat and call the number on the back of your card for a replacement.
- Use a credit card, never debit, for anything an AI touches — subscriptions included. The $50 cap and the 60-day dispute right are the whole reason.
- Turn on a text or app alert for every charge. The debit clock starts when you learn of a problem; the credit clock starts with the statement. Alerts shorten both.
- If your issuer offers virtual card numbers, use one with a limit for any agent or new shopping app, and delete it when you are done.
- Say no if an agent steers you to a bank transfer, Zelle, gift card or crypto. The banks named that exact move. Those rails have no federal “wrong item” right.
- Keep the receipt of what you asked. Screenshot the request and the confirmation. A billing-error dispute is a written argument; the chat is your evidence.
- Know where your card lives: chatgpt.com → Settings → Billing for the web subscription; Apple or Google settings if you subscribed in the app. Our cancellation guide walks both screens.
What to watch next. The banks say a second paper will turn these principles into protocols and standards. When it lands, look for three words that are missing today: must, refund and liable. And if OpenAI and Visa announce a launch date for agent purchases in ChatGPT, check whether it defaults to “approve every purchase” — Visa’s own product chief said in June he expects most early transactions to still need human approval. We will update this page when either happens.
If you want to go deeper
- What is an “AI agent,” exactly? A chatbot that can take actions, not just answer. Our plain-English explainer: Agentic AI, and how it differs from generative AI.
- Can the price an agent sees be different from mine? Yes, and in some states that is now regulated. See is it illegal to charge different prices for the same product.
- What if the charge is an AI subscription you did not expect? Start with why am I being charged for Google AI Pro and what AI really costs per month.
Questions people type about ChatGPT and their credit card
Is it safe to give ChatGPT my credit card?
For paying your own ChatGPT subscription on the Billing page, it is an ordinary online subscription with the same federal card protections as any other. Typing a card number into a chat message is not safe: the text is stored in your chat history like everything else you type. And letting an AI agent spend on your behalf is still an unsettled area; six banks said on September 22, 2026 that liability when an agent goes wrong is unclear. If you try it, use a credit card, not debit.
Can ChatGPT buy things for you?
Not in the way the headlines suggested, as of September 23, 2026. OpenAI’s Instant Checkout, launched September 29, 2025 for U.S. Etsy sellers, was retired in March 2026, according to the Associated Press. Visa announced on June 10, 2026 that it had plugged its network into ChatGPT so an agent could buy at any merchant that accepts Visa, with spending limits and approvals, but neither company has announced a consumer launch date. Today ChatGPT mostly finds products and sends you to the store to pay.
Has ChatGPT ever leaked credit card information?
Partially, once. OpenAI said on March 24, 2023 that a bug may have exposed payment details of 1.2% of ChatGPT Plus subscribers active during a nine-hour window: name, email, payment address, card type, the last four digits and the expiration date. OpenAI said full card numbers were not exposed at any time.
How do I remove my credit card from ChatGPT?
The card that pays for your subscription lives under Settings, then Billing, on chatgpt.com. If you bought the plan in the iPhone or Android app, the card is held by Apple or Google, not OpenAI, and you manage it there. If you ever pasted a card number into a chat, delete that conversation and call your card issuer for a new number; deleting the chat does not un-share the number.
Is it safe to give ChatGPT financial information?
Share the question, not the identifiers. "I owe $4,200 at 24% and can pay $300 a month, which card first?" gets you the same math as pasting a statement, without handing over account numbers, your address or your card digits. Never share full card numbers, account and routing numbers, your Social Security number, or passwords in any chatbot.
Who is responsible if an AI agent buys the wrong thing?
Nobody has settled it. The six banks’ paper says that when things go wrong "there is unclear and inefficient allocation of liability." Your strongest existing tool is a credit card billing-error dispute: federal rules (12 CFR 1026.13) cover goods not delivered as agreed, if you write to the card issuer within 60 days of the statement that shows the charge. Debit cards have no equivalent federal right for a wrong item.
Is a debit card or credit card safer for AI shopping?
A credit card. If someone else uses a credit card without authority, federal law caps your loss at $50. On a debit card the cap is $50 only if you report within two business days of learning of the loss, rises to $500 after that, and can be unlimited if you miss 60 days from the statement. And while a credit card dispute is pending the money is the bank’s; on debit it has already left your account.
Sources
- Building Trust in Agentic Commerce, ASB, Bank of America, Capital One, Commonwealth Bank of Australia, ING, NatWest (PDF), published September 22, 2026
- NatWest Group press release, September 22, 2026
- 12 CFR 1026.12, liability for unauthorized use (Regulation Z)
- 12 CFR 1026.13, billing error resolution (Regulation Z)
- 12 CFR 1005.6, liability for unauthorized transfers (Regulation E)
- 12 CFR 1005.2(m), definition of unauthorized transfer (Regulation E)
- OpenAI, “Buy it in ChatGPT,” September 29, 2025
- Associated Press via Euronews, Visa and ChatGPT, June 11, 2026
- Google, “Introducing the Universal Cart,” May 19, 2026
- OpenAI, “March 20 ChatGPT outage,” March 24, 2023
- All documents fetched and read September 23, 2026. Word counts are ours.
Keep reading
- AI scams targeting seniors, and the safe word that beats them
- AI Scam Watch: September 2026
- What happens if you say yes on a scam call
- How to tell if a Facebook ad is fake
- How to tell if a phone call is AI
- How do I talk to a real person
- How to turn off AI on Amazon
- Is ChatGPT Plus still worth it?
- Is GPT-6 Astra free?
- When to use agentic AI, and when not to
- Do health insurance companies use AI to deny claims?
- The Briefing · AI Price Tracker · FAQ · Ask a question
About the author. Prof. H teaches robotics and AI and writes The Briefing, a weekly read on what AI is doing to ordinary bills, benefits and rights. Every document in this piece was fetched and read on the date shown. This is general information, not legal or financial advice. Corrections and questions: ask here.
Prof.’s H Newsletter
One short email a month, with the numbers in it
What actually moved in AI hiring, AI prices, and the scams aimed at older Americans. Counted here, dated, and linked to the source. One email a month, and your address goes nowhere else.