Stripe's new terms make AI agent actions legally binding on you

Stani Mihov
Founder & CEO
·

TL;DR
What changed:
If you let an AI agent use Stripe for you, you are "solely responsible" for everything it does, and its actions are "legally binding on User."
An AI agent counts even when it works through other tools you cannot see or control.
Data that Stripe returns to you, including Radar data, cannot be sold, used to train a model that substitutes for Stripe, or be the only basis for decisions about a customer.
Stripe can suspend an account when a violation is reasonably likely, and insolvency now covers the reasonable likelihood of events such as being unable to pay debts.
Data incidents that could affect Stripe must be reported within 48 hours, and included support is now "standard technical support."
The new terms apply now to new users and from January 6, 2027 to existing users.
What to do: List every AI tool and integration that holds a Stripe API key and what it can do, and add the 48-hour Stripe notice to your incident response plan.
The change
On September 28, 2026, Stripe updated the General Terms of its Services Agreement, the contract every business on Stripe accepts when it opens an account. The previous version was dated November 18, 2025, and Stripe keeps earlier versions on its prior versions page.
According to Stripe's update notice, the new terms apply immediately to users who sign up on or after September 28, 2026. For existing users, the changes to the General Terms take effect on January 6, 2027, and continuing to use Stripe after that date means accepting them. No signature or action is needed.
The notice's list of the most notable changes starts with a new section on AI agents. The General Terms also changed in several places that the list does not mention, covering how Stripe data can be used, when Stripe can suspend or terminate an account, how fast data incidents must be reported, and what support is included.
What changed
AI agents. A new Section 1.7 says that if a user lets an AI agent access Stripe, the user "is solely responsible for each action initiated by or through the AI Agent," and that those actions "are legally binding on User."
Stripe Output Data. A new Section 4.7 limits data returned by Stripe's services to the user's "own internal business purposes," and bans selling it or using it to train models that substitute for Stripe.
Suspension and termination. Stripe can now suspend an account when it reasonably believes the user is "reasonably likely to violate" a law or requirement, and a new definition of "Insolvency Event" covers the "reasonable likelihood" of events such as being unable to pay debts.
Data incidents. A data incident "reasonably likely to impact" Stripe must be reported within 48 hours, with three specific details. The old clause said to notify Stripe "immediately."
Support. The support included with every account changed from "basic business and technical support" to "standard technical support."
What counts as an AI agent
The definition is broad. An AI Agent is any software or automated technology that is "capable of, designed for, or employed for the purpose of independently or semi-independently acting as User's delegate, proxy, intermediary, or agent in any transactional activity." It includes technology that works through other systems, APIs, or agents, "whether or not User has direct control over or visibility into each intermediate system in the chain."
In practice, that covers an AI assistant connected to a Stripe account with an API key, a coding agent that runs Stripe commands, and a third-party tool that hands a task to another tool that then calls Stripe. If the chain ends in a refund, a price change, or a new payment link, the contract treats the result as the user's own action.
Section 1.7 also says an AI agent counts as an "electronic agent" under the Uniform Electronic Transactions Act, a US law under which automated systems can complete binding transactions. The existing Section 3, which did not change in this update, already said Stripe "is entitled to rely on any instruction or action taken within User's Stripe Account." The new section makes the same point about AI agents in so many words. HubSpot took a similar line for its own agents in September, when it made customers answer for what its AI agents do.
New limits on the data Stripe returns to you
"Stripe Output Data" is any data a user receives that "has been produced or returned by or through the Services," including Stripe Radar Data, the output of Stripe's fraud screening. The new Section 4.7 limits its use to the user's own internal business purposes and says it must not be used:
as "the sole input" into decisions about starting, ending, or refusing a business relationship with a customer
as a factor in a person's eligibility for credit, insurance, housing, or employment
to discriminate, or to take an "adverse action" as defined in the Fair Credit Reporting Act
in a way that counts as a prohibited AI practice under the EU AI Act
to "develop, test, validate, train, enhance or deploy" machine learning models that substitute for, or are substantially similar to, Stripe's services
Users also may not sell, rent, transfer, or otherwise share Output Data, and must delete it "promptly upon Stripe's reasonable written request." For a team that automatically blocks or drops customers based on a Radar result alone, the first item is the one to check.
More ways to suspend or terminate an account
Section 10.1 already let Stripe suspend an account immediately in a range of situations. The update widens several of them:
Stripe may suspend if it reasonably believes the user "has violated, or is reasonably likely to violate," a law or requirement. The old text said "will violate."
A "Financial Provider directive" is now a suspension trigger, alongside Financial Provider Terms.
Failing to provide requested User Information, such as compliance or financial details, now counts, not only failing to respond to the request promptly.
Stripe can terminate for cause if the user has an Insolvency Event and the law allows termination, or if the law, a Governmental Authority, or a Financial Provider directs Stripe to do so.
The insolvency trigger now has a definition. The old terms listed "a User Insolvency Event" as a reason to suspend without defining it. The new definition covers "the occurrence or reasonable likelihood" of events such as being unable to pay debts, an involuntary bankruptcy petition that is not dismissed within 30 days, or formal negotiations to restructure debts with creditors, and it also applies when the same happens to a material subsidiary. For a company in financial difficulty, the trigger can be the likelihood of these events, not only the events themselves. Google made a similar move in September when it added new triggers for suspension and termination to its cloud terms.
Other changes in the same update
Data incident reports. The old clause required users to notify Stripe "immediately" of any unauthorized access to, disclosure of, or loss of personal data on their systems that was provided to or used by Stripe. The new Section 4.3 applies to a data incident "reasonably likely to impact" Stripe or its affiliates, sets a limit of 48 hours after becoming aware of it, and requires the type of personal data involved, the categories and potential number of people or records affected, and the status of the investigation and remediation.
Support. The phrase "basic business and technical support" became "standard technical support." Optional paid support plans are still offered.
Notice of changes to the service. Stripe could already skip notice of a change that reduces functionality if notice would create a security risk for Stripe. That exception now covers a security risk "for Stripe, its users, or its Financial Providers."
Force majeure. The list of events outside a party's control now includes a "cyberattack or other harmful third-party interference with information systems, including through the use of artificial intelligence." Payment obligations to Stripe are still not excused.
Preview features. Stripe's liability for Preview Services was capped at $1,000. It is now the lesser of $1,000 and the fees the user paid in the previous 12 months.
Why this matters
Stripe is where a SaaS company's revenue moves: subscriptions, refunds, invoices, and payouts. More of that work now runs through automation, from AI assistants with API access to agents inside other tools, and the new General Terms settle who carries the result. It is the user, whether or not anyone approved the action, and whether or not anyone could see every system in the chain.
The other changes point the same way. Data from Stripe comes with new limits on how it can be used, a data incident has a 48-hour reporting clock, and suspension can turn on what Stripe believes is likely rather than on what has happened. For existing accounts, all of it takes effect on January 6, 2027 without a signature. That is the pattern behind most hidden risks in vendor legal changes: the contract changes while the product looks the same, as it did when Meta rewrote its privacy policy around agentic AI.
Potential impact
For a company that runs payments on Stripe, the update raises five practical questions:
Which AI tools, agents, and integrations hold a Stripe API key, and what can each of them do, such as issuing refunds, changing prices, or creating payment links?
Is each key limited to the permissions that tool actually needs?
Does any automated process block or drop customers based only on Stripe Radar data or other Stripe output?
Does your incident response plan include a notice to Stripe within 48 hours, with the three details the new clause requires?
If you run a Connect platform with Custom or Express accounts, have you notified those accounts by November 7, 2026, as Stripe's notice asks?
Our guide on how to monitor vendor terms of service covers a repeatable way to answer questions like these each time a vendor updates its terms.
How Venpo detected it
Venpo monitors Stripe's legal documents as part of vendor contract monitoring. It flagged the new General Terms on September 28 and separated the substantive changes from a long list of rewording and renumbering. Every quote in this article was checked against the inserted and deleted text in the redline and against the live page. The full redline is on the Stripe change page, and every monitored Stripe document is listed on the Stripe vendor profile.
Business outcome
Teams that track Stripe got a plain-English list of the changes more than three months before they apply to existing accounts. That leaves time to review which agents and tools can act in the account, check automations that rely on Radar results, and add the 48-hour Stripe notice to the incident plan. The alternative is learning about Section 1.7 after an agent issues refunds that nobody approved.
Key takeaway
Stripe's September 28 update puts every action an AI agent takes in a Stripe account on the user, limits how Stripe data can be used, and lets suspension turn on likelihoods. The notice highlights the AI agent section, while the rest of the changes sit in the redline, which is why the reliable way to catch them is to track the terms every time they change.
The change
On September 28, 2026, Stripe updated the General Terms of its Services Agreement, the contract every business on Stripe accepts when it opens an account. The previous version was dated November 18, 2025, and Stripe keeps earlier versions on its prior versions page.
According to Stripe's update notice, the new terms apply immediately to users who sign up on or after September 28, 2026. For existing users, the changes to the General Terms take effect on January 6, 2027, and continuing to use Stripe after that date means accepting them. No signature or action is needed.
The notice's list of the most notable changes starts with a new section on AI agents. The General Terms also changed in several places that the list does not mention, covering how Stripe data can be used, when Stripe can suspend or terminate an account, how fast data incidents must be reported, and what support is included.
What changed
AI agents. A new Section 1.7 says that if a user lets an AI agent access Stripe, the user "is solely responsible for each action initiated by or through the AI Agent," and that those actions "are legally binding on User."
Stripe Output Data. A new Section 4.7 limits data returned by Stripe's services to the user's "own internal business purposes," and bans selling it or using it to train models that substitute for Stripe.
Suspension and termination. Stripe can now suspend an account when it reasonably believes the user is "reasonably likely to violate" a law or requirement, and a new definition of "Insolvency Event" covers the "reasonable likelihood" of events such as being unable to pay debts.
Data incidents. A data incident "reasonably likely to impact" Stripe must be reported within 48 hours, with three specific details. The old clause said to notify Stripe "immediately."
Support. The support included with every account changed from "basic business and technical support" to "standard technical support."
What counts as an AI agent
The definition is broad. An AI Agent is any software or automated technology that is "capable of, designed for, or employed for the purpose of independently or semi-independently acting as User's delegate, proxy, intermediary, or agent in any transactional activity." It includes technology that works through other systems, APIs, or agents, "whether or not User has direct control over or visibility into each intermediate system in the chain."
In practice, that covers an AI assistant connected to a Stripe account with an API key, a coding agent that runs Stripe commands, and a third-party tool that hands a task to another tool that then calls Stripe. If the chain ends in a refund, a price change, or a new payment link, the contract treats the result as the user's own action.
Section 1.7 also says an AI agent counts as an "electronic agent" under the Uniform Electronic Transactions Act, a US law under which automated systems can complete binding transactions. The existing Section 3, which did not change in this update, already said Stripe "is entitled to rely on any instruction or action taken within User's Stripe Account." The new section makes the same point about AI agents in so many words. HubSpot took a similar line for its own agents in September, when it made customers answer for what its AI agents do.
New limits on the data Stripe returns to you
"Stripe Output Data" is any data a user receives that "has been produced or returned by or through the Services," including Stripe Radar Data, the output of Stripe's fraud screening. The new Section 4.7 limits its use to the user's own internal business purposes and says it must not be used:
as "the sole input" into decisions about starting, ending, or refusing a business relationship with a customer
as a factor in a person's eligibility for credit, insurance, housing, or employment
to discriminate, or to take an "adverse action" as defined in the Fair Credit Reporting Act
in a way that counts as a prohibited AI practice under the EU AI Act
to "develop, test, validate, train, enhance or deploy" machine learning models that substitute for, or are substantially similar to, Stripe's services
Users also may not sell, rent, transfer, or otherwise share Output Data, and must delete it "promptly upon Stripe's reasonable written request." For a team that automatically blocks or drops customers based on a Radar result alone, the first item is the one to check.
More ways to suspend or terminate an account
Section 10.1 already let Stripe suspend an account immediately in a range of situations. The update widens several of them:
Stripe may suspend if it reasonably believes the user "has violated, or is reasonably likely to violate," a law or requirement. The old text said "will violate."
A "Financial Provider directive" is now a suspension trigger, alongside Financial Provider Terms.
Failing to provide requested User Information, such as compliance or financial details, now counts, not only failing to respond to the request promptly.
Stripe can terminate for cause if the user has an Insolvency Event and the law allows termination, or if the law, a Governmental Authority, or a Financial Provider directs Stripe to do so.
The insolvency trigger now has a definition. The old terms listed "a User Insolvency Event" as a reason to suspend without defining it. The new definition covers "the occurrence or reasonable likelihood" of events such as being unable to pay debts, an involuntary bankruptcy petition that is not dismissed within 30 days, or formal negotiations to restructure debts with creditors, and it also applies when the same happens to a material subsidiary. For a company in financial difficulty, the trigger can be the likelihood of these events, not only the events themselves. Google made a similar move in September when it added new triggers for suspension and termination to its cloud terms.
Other changes in the same update
Data incident reports. The old clause required users to notify Stripe "immediately" of any unauthorized access to, disclosure of, or loss of personal data on their systems that was provided to or used by Stripe. The new Section 4.3 applies to a data incident "reasonably likely to impact" Stripe or its affiliates, sets a limit of 48 hours after becoming aware of it, and requires the type of personal data involved, the categories and potential number of people or records affected, and the status of the investigation and remediation.
Support. The phrase "basic business and technical support" became "standard technical support." Optional paid support plans are still offered.
Notice of changes to the service. Stripe could already skip notice of a change that reduces functionality if notice would create a security risk for Stripe. That exception now covers a security risk "for Stripe, its users, or its Financial Providers."
Force majeure. The list of events outside a party's control now includes a "cyberattack or other harmful third-party interference with information systems, including through the use of artificial intelligence." Payment obligations to Stripe are still not excused.
Preview features. Stripe's liability for Preview Services was capped at $1,000. It is now the lesser of $1,000 and the fees the user paid in the previous 12 months.
Why this matters
Stripe is where a SaaS company's revenue moves: subscriptions, refunds, invoices, and payouts. More of that work now runs through automation, from AI assistants with API access to agents inside other tools, and the new General Terms settle who carries the result. It is the user, whether or not anyone approved the action, and whether or not anyone could see every system in the chain.
The other changes point the same way. Data from Stripe comes with new limits on how it can be used, a data incident has a 48-hour reporting clock, and suspension can turn on what Stripe believes is likely rather than on what has happened. For existing accounts, all of it takes effect on January 6, 2027 without a signature. That is the pattern behind most hidden risks in vendor legal changes: the contract changes while the product looks the same, as it did when Meta rewrote its privacy policy around agentic AI.
Potential impact
For a company that runs payments on Stripe, the update raises five practical questions:
Which AI tools, agents, and integrations hold a Stripe API key, and what can each of them do, such as issuing refunds, changing prices, or creating payment links?
Is each key limited to the permissions that tool actually needs?
Does any automated process block or drop customers based only on Stripe Radar data or other Stripe output?
Does your incident response plan include a notice to Stripe within 48 hours, with the three details the new clause requires?
If you run a Connect platform with Custom or Express accounts, have you notified those accounts by November 7, 2026, as Stripe's notice asks?
Our guide on how to monitor vendor terms of service covers a repeatable way to answer questions like these each time a vendor updates its terms.
How Venpo detected it
Venpo monitors Stripe's legal documents as part of vendor contract monitoring. It flagged the new General Terms on September 28 and separated the substantive changes from a long list of rewording and renumbering. Every quote in this article was checked against the inserted and deleted text in the redline and against the live page. The full redline is on the Stripe change page, and every monitored Stripe document is listed on the Stripe vendor profile.
Business outcome
Teams that track Stripe got a plain-English list of the changes more than three months before they apply to existing accounts. That leaves time to review which agents and tools can act in the account, check automations that rely on Radar results, and add the 48-hour Stripe notice to the incident plan. The alternative is learning about Section 1.7 after an agent issues refunds that nobody approved.
Key takeaway
Stripe's September 28 update puts every action an AI agent takes in a Stripe account on the user, limits how Stripe data can be used, and lets suspension turn on likelihoods. The notice highlights the AI agent section, while the rest of the changes sit in the redline, which is why the reliable way to catch them is to track the terms every time they change.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
