Stripe updated its Services Agreement on 28 September, and one new clause is aimed at everyone wiring AI agents into payments. Section 1.7 of the General Terms now reads: "If User uses an AI Agent to access the Stripe Services, User is solely responsible for each action initiated by or through the AI Agent." The terms apply to new users and new services immediately and to existing users from 6 January 2027.
If an agent in your stack can create refunds, issue payouts, change prices or touch customer records through Stripe, this is the clause that decides who carries the loss when it gets something wrong.
What the new clause says
The agreement defines an AI Agent broadly: "software, computer or other automated technology capable of independently or semi-independently acting as User's delegate, proxy, intermediary, or agent in transactional activity." That covers a Claude or GPT agent calling the Stripe API through an MCP server, a coding agent with your secret key in its environment, and an automation tool acting on a webhook.
Section 1.7 also has users acknowledge that AI Agents are "electronic agents" under the US Uniform Electronic Transactions Act, and that actions they initiate are legally binding on the user. In plain terms: "the agent did it, not me" is not a defence Stripe will accept.
According to Stripe's support note, the update also consolidates the Stripe Atlas terms and adds specific Service Terms for Agentic Commerce, Billing, Financial Connections, Payments, Payouts, Stablecoin Treasury, Managed Payments and Next-Day Settlement. Where you run Stripe's Agentic Commerce services, the Service Terms put the responsibility on you to make sure your own user agreement and agent disclosures accurately describe who does what in an agent-made transaction.
The dates that matter
28 September 2026: the new terms apply to new users and to Stripe services you start using from now on.
7 November 2026: Connect platforms with Custom, Express or Dashboard-less connected accounts must notify those accounts of the change and its 6 January effective date, per Stripe's support note.
6 January 2027: the General Terms changes, and Service Terms changes that materially affect existing services, apply to existing users.
Stripe says most users need do nothing: continuing to use Stripe after the effective date counts as acceptance. The only alternative it offers is closing your account before that date.
Why this is more than boilerplate
Payment platforms have always held merchants responsible for their own API calls. What is new is that Stripe has named AI agents explicitly and tied them to electronic-agent law. That closes an argument some merchants might have tried after an agent issued a mistaken refund or a runaway payout loop: that the action was not authorised by any person.
It also moves risk down the chain. If you build a product that lets customers connect an agent to their Stripe account, your customers carry that liability to Stripe, and they will look to your terms to see whether any of it comes back to you.
What to actually do
1. List every agent that can reach Stripe. Include MCP servers, coding agents with access to .env files, Zapier or n8n workflows and internal scripts driven by an LLM. For each, write down which API key it uses.
2. Replace secret keys with restricted keys. Stripe's restricted API keys let you grant read-only or per-resource permissions. An agent that summarises revenue needs read access to charges, not the ability to create refunds or payouts.
3. Put a human in front of money-moving actions. Refunds above a threshold, payouts, price changes and subscription cancellations should need a confirmation step. Most agent frameworks support tool-level approval; turn it on.
4. Log agent actions separately. Tag agent-initiated requests with metadata or an idempotency key prefix so you can reconstruct what happened. If there is a dispute, you will want the prompt and the tool call next to the Stripe event.
5. If you run Connect, diarise 7 November. Draft the notice to connected accounts now. If your product exposes agents to connected accounts, update your own terms and disclosures so they reflect the new allocation of responsibility.
6. Check your own customer terms. If your SaaS lets users trigger payment actions through an AI feature, make sure your agreement says who is responsible for those actions, and that it matches what Stripe now expects.
The bottom line
Stripe has written down what was always implied: an AI agent using your account is you. From 6 January 2027 that binds every existing user. Use the next three months to audit which agents hold Stripe keys, narrow their permissions, add approval steps for anything that moves money, and, if you run Connect, send your notice before 7 November.
This post is general information about Stripe's published terms, not legal advice. Check the agreement that applies in your country and speak to a lawyer about your own obligations.