Why AI Startups Get Flagged as High-Risk Merchants and How to Pass Payment Underwriting

Why AI Startups Get Flagged as High-Risk Merchants and How to Pass Payment Underwriting
By Carl Anderson September 20, 2026

An AI startup high risk merchant account application can receive extra scrutiny because card-not-present sales, recurring or usage-based billing, free-trial conversion, digital fulfillment, and automated fraud can increase financial exposure. Approval prospects improve when the company clearly documents its product, pricing, customer consent, refunds, fraud controls, processing history, and realistic transaction profile.

“High-risk” is not a judgment about whether an AI company is legitimate. It is an underwriting assessment of potential fraud, disputes, refunds, fulfillment obligations, regulatory exposure, and losses the acquirer could ultimately have to absorb.

Nor is every AI company automatically high-risk. A contracted enterprise AI platform billing established businesses quarterly can look very different from a public generative-AI application offering instant free trials, anonymous signup, stored cards, and uncapped usage.

AI Startup High Risk Merchant Account: What Underwriters Actually See

An acquiring bank or processor needs to understand what is being sold, when customers are charged, how the service is delivered, how long financial obligations remain outstanding, and what happens when customers dispute or request refunds.

Several characteristics common to AI products can make that analysis harder.

100% card-not-present payments

Many self-serve AI companies never see a physical card. Card-not-present processing places more responsibility on authentication, fraud screening, account verification, and evidence showing who authorized a transaction.

That does not make CNP commerce unacceptable. It means the merchant should be able to explain its fraud controls and transaction flow.

Instant but subjective digital fulfillment

AI output may be delivered in seconds, yet disputes over quality can still be subjective. A customer may acknowledge receiving generations or API responses while arguing that the service failed to perform as advertised.

Precise product descriptions, usage records, timestamps, and realistic marketing claims make fulfillment easier to explain.

Free trials and recurring billing

A trial can create a dispute when the customer remembers “free” but not the conversion date, subscription price, or cancellation deadline.

That makes free trial negative option billing risk relevant to both compliance and underwriting. The risk is especially visible when a card is collected during signup and the first paid charge occurs later without another customer action.

Usage-based AI billing

An AI company might charge a base subscription plus tokens, API calls, images, GPU time, agent actions, or credits. The resulting charge may differ substantially from one billing period to another.

Customers can challenge token counts, compromised API-key usage, unexpected overages, internal employee consumption, auto-recharges, or expensive model selection. The underwriter wants evidence that the company can reconstruct the bill.

Public signup and API access

Open registration makes customer acquisition easy, but poorly protected payment flows can also be automated by attackers.

The payment layer should therefore sit beside strong AI API authentication, rate limiting, and abuse controls rather than being treated as a separate problem.

AI business traitWhat an underwriter may seeWhat helps explain the risk
CNP subscriptionsRemote recurring transactionsConsent records and fraud controls
Free-trial conversionPotential billing surpriseClear conversion terms and cancellation
Usage billingVariable transaction amountsMetering records, alerts and invoices
Instant digital deliverySubjective fulfillment disputesAccess and usage evidence
Public signupAutomated payment abuseVelocity and account controls
New companyLittle processing historyFinancials and realistic forecasts

These are examples of risk questions, not universal approval criteria.

Free Trials That Roll Into Paid Plans Receive Extra Scrutiny

A strong trial flow tells the customer, before payment credentials are submitted, how long the trial lasts, what happens when it ends, the amount and frequency of subsequent billing, and how to cancel.

The company should retain the version of the offer accepted, consent timestamp, confirmation message, notices sent, and cancellation outcome.

The FTC position in 2026

The widely discussed 2024 FTC “Click-to-Cancel” amendments should not be presented as current binding law.

The Eighth Circuit vacated those amendments on July 8, 2025. In February 2026, the FTC formally restored the pre-2024 Negative Option Rule. That older rule is much narrower and principally addresses prenotification plans involving merchandise. 

In March 2026, the FTC opened a new Advance Notice of Proposed Rulemaking concerning negative-option practices; that proceeding is a proposal-stage process, not a final replacement rule.

The FTC’s current Negative Option Rule materials should therefore be checked rather than relying on articles that still describe the vacated 2024 amendments as effective.

Separately, the federal Restore Online Shoppers’ Confidence Act remains relevant to covered online consumer transactions. ROSCA requires clear disclosure of material terms before billing information is obtained, express informed consent before charging through a negative-option feature, and simple mechanisms for stopping recurring charges.

Network subscription rules are a separate obligation

Visa’s April 2026 rules require a simple cancellation procedure for recurring transactions and at least an online cancellation procedure when the order was originally accepted online. 

Visa also requires notification at least seven days before a recurring transaction when a trial, introductory offer, or promotional period is ending, including the subsequent transaction amount/date and an easy cancellation mechanism.

Mastercard separately requires clear subscription terms and affirmative acceptance in e-commerce. For digital goods and services with a trial lasting longer than seven days, its June 2026 Transaction Processing Rules require a reminder between three and seven days before the trial ends.

FTC law, ROSCA, Visa rules, Mastercard rules, and the merchant agreement are different sources of obligation. One should not be described as another.

Why Card-Testing Attacks Hit AI Products

Card testing attacks on AI products become possible when bots can repeatedly reach signup, account-verification, card-storage, trial, or payment endpoints.

Attackers may submit stolen or generated payment credentials to determine which cards are usable. PCI SSC describes this activity as account testing, payment-account enumeration, card testing, or BIN attacks.

A processor may consequently see:

  • very high authorization velocity;
  • unusually high decline volume;
  • many cards associated with the same account;
  • repeated low-value attempts;
  • suspicious device or IP patterns;
  • geographic inconsistencies.

A high decline rate alone does not prove fraud. Integration errors, legitimate issuer declines, retries, or customer mix can also affect approvals. What matters is whether the merchant can investigate and explain the pattern.

Useful mitigations include server-side rate limits, CAPTCHA or adaptive challenges, email/account verification, device and IP velocity controls, limits on cards per account, account-creation controls, fraud scoring, risk-based 3-D Secure, and delayed high-cost activation for suspicious accounts.

None guarantees that card testing will stop.

Hypothetical example

A public AI trial launches on Monday. Bots begin creating accounts and generate thousands of card authorization attempts overnight. Most decline.

The processor sees extreme authorization volume, multiple cards per account, low-value tests, and geographically inconsistent traffic.

The company blocks the affected path, introduces verified signup, card/account/IP velocity rules, and higher-friction activation for suspicious traffic. It then documents the incident, affected dates, remediation, and subsequent authorization patterns.

That is much stronger underwriting evidence than simply saying, “The declines were bots.”

Merchant Account for AI Company: Build an Underwriting Package

When applying for a merchant account for an AI company, founders should make the transaction understandable without requiring the reviewer to reverse-engineer the product.

Current processor underwriting documentation confirms that business model, billing practices, processing history, financial stability, refunds, disputes, free trials, and sharp changes in volume can all be relevant to risk review.

These SaaS underwriting requirements vary by acquirer, but a useful package commonly includes:

CategoryEvidence to prepareWhy it helps
EntityFormation records, EIN/TIN, ownership, ID and bank evidence where requestedKYB and ownership verification
ProductWorking website, demo, screenshots, product explanationMakes fulfillment understandable
PricingPlans, usage rates, trial and overage termsExplains charge amounts
PoliciesTerms, privacy, refunds and cancellationShows complaint handling
ProcessingPrior statements, volume, refunds, disputesProvides historical evidence
FraudControls and incident-response processExplains CNP exposure
FinancialBank statements or financials if requestedShows capacity for obligations
ForecastMonthly volume and average/maximum ticketsDefines expected exposure

Not every processor requests every item.

The pricing page matters

For self-service billing, show the plan price, billing frequency, included usage, overage methodology, trial duration, renewal mechanics, and cancellation process.

“Contact us” is perfectly reasonable for enterprise pricing, but an underwriter reviewing card processing still needs the actual order form or checkout terms used for those customers.

Make AI deliverables concrete

Claims such as “unlimited AI,” “guaranteed revenue,” or “fully autonomous profits” can create obvious questions if the service actually has limits or results cannot be guaranteed.

Explain what customers receive, what usage is included, which restrictions apply, when access starts, and what circumstances may produce refunds.

Terms of Service should address billing, recurring authorization, trials, cancellation, refunds, acceptable use, suspension, and service limitations. Qualified counsel should determine the actual legal language.

A categorical “all sales final” sentence is not a substitute for procedures covering duplicate charges, technical failure, fraud reports, mistaken purchases, or billing errors.

Processing History Replaces Assumptions With Evidence

An established merchant can provide available processor statements showing transaction volume, average ticket, maximum ticket, refunds, disputes, and unusual events.

Some underwriters may ask for six or more months, but there is no universal six-month requirement.

A startup without history should instead provide realistic projections, contracts where available, funding or bank information when requested, customer pipeline evidence, and a staged rollout plan.

Do not inflate forecasts to appear more successful.

Suppose the application estimates $50,000 per month at a $50 average ticket, but the merchant immediately processes $500,000 with $2,000 transactions. Those numbers are illustrative, but the principle matters: a legitimate business can still trigger review when actual processing no longer resembles the approved profile.

Notify the processor before a major product launch, enterprise contract, large price change, or sudden geographic expansion where it materially changes the processing profile.

Chargeback Ratio for Subscription SaaS: There Is No Universal 1% Rule

Searching for a single chargeback ratio for subscription SaaS produces misleading answers because card networks and processors do not all use the same metric.

Visa’s VAMP, Mastercard’s monitoring programs, and a processor’s contractual risk controls are separate frameworks.

Visa VAMP in the U.S. in 2026

Visa consolidated its prior Visa Fraud Monitoring Program and Visa Dispute Monitoring Program framework into the Visa Acquirer Monitoring Program, or VAMP, for covered activity.

Visa defines its VAMP ratio using specified TC40 fraud reports plus TC15 disputes divided by TC05 settled card-not-present VisaNet transactions.

As of September 2026, Visa’s published U.S. Excessive Merchant threshold is at least 1.50% (150 basis points) plus at least 1,500 monthly fraud-and-dispute events, effective April 1, 2026, when the acquirer itself is not already identified Above Standard or Excessive.

Visa’s enumeration measure is separate. Its published thresholds are at least 20% enumerated authorizations and at least 300,000 enumerated authorization transactions, counting identified approved and declined attempts. This is not a “20% decline-rate rule.”

The current Visa Acquirer Monitoring Program framework should be checked whenever an article cites a VAMP number because thresholds and implementation dates can change.

Mastercard is different

Mastercard’s current framework separately identifies the Excessive Chargeback Program and Excessive Fraud Merchant program. Its Security Rules calculate chargeback basis points using chargebacks received in a calendar month divided by Mastercard transactions from the preceding month, multiplied by 10,000.

The current public Merchant Edition routes ECM and HECM identification criteria to Mastercard’s Data Integrity Monitoring Program materials rather than publishing the numeric criteria directly in that section. 

Therefore, this article does not invent or copy an old third-party threshold. Merchants should confirm current criteria with their acquirer through Mastercard’s merchant rules and compliance-program materials.

Most importantly, an acquirer can impose contractual or risk controls before a merchant reaches a formal network monitoring threshold.

“I’m below Visa’s threshold” does not mean the processor is contractually required to keep the account open.

Reduce AI Subscription Disputes Before They Become Chargebacks

AI businesses should design billing records so finance and support can reconstruct a charge without searching several systems.

For usage billing, retain the applicable pricing version, metered units, billing-period boundaries, credits, overages, and invoice calculation. Give customers dashboards, spending alerts, and appropriately designed caps where offered.

Operational logs can help establish access and usage, but do not copy sensitive prompts, API keys, or card information into dispute files unnecessarily. Privacy-conscious prompt and response logging practices are especially useful when payment evidence is being connected to AI activity.

Other dispute controls include recognizable descriptors, confirmation emails, required renewal notices, clear receipts, a cancellation route, responsive support, and documented refund decisions.

Common AI-specific dispute sources include trial confusion, overages, compromised API keys, forgotten subscriptions, duplicate billing, unused credits, failed cancellation, model-output dissatisfaction, and unrecognized employee usage within business accounts.

Not every dispute is fraud.

Why an Underwriter May Ask for a Rolling Reserve

A reserve is money held to cover potential future losses such as refunds and disputes. Processor documentation describes reserves as a risk-management tool, not proof that the merchant is dishonest.

Possible arrangements include rolling reserves, fixed reserves, delayed funding, upfront funding, or combinations depending on the provider and agreement.

There is no responsible universal statement such as “AI businesses receive a 10% six-month reserve.”

Ask in writing about the percentage or balance target, hold duration, release method, reserve cap, review date, reduction conditions, post-termination hold, and rights of setoff.

Volume Caps and Ongoing Underwriting

Approved monthly volume, average ticket, and maximum ticket describe the expected transaction profile. They are not the same thing as technical limitations inside the billing application.

Sharp volume changes can prompt further review.

The same principle applies to material business changes. A company originally approved for an AI writing subscription should not assume that approval automatically extends to a marketplace, financial product, gambling functionality, adult content, crypto activity, or another materially different service.

Underwriting continues after activation.

What to Do if an Aggregator Freezes or Terminates the Account

If an aggregator places a hold or restriction, first identify exactly what happened: reserve, delayed payout, processing suspension, documentation review, or termination.

Then preserve processing statements, transaction history, refund information, disputes, fulfillment evidence, support records, and authorization data. Stop an active fraud attack, but preserve relevant logs.

Respond through the provider’s official process with the documents requested and a concise root-cause explanation.

If the account is terminated, the next application should accurately disclose the prior processor, closure date, reason given, processing history, outstanding reserve, and any fraud or dispute incident.

Do not create a shell company, disguise the AI product, choose a false business type, or hide the termination.

Termination does not automatically mean MATCH

Mastercard’s current MATCH Pro rules require additions when a qualifying termination occurs while specified MATCH conditions exist. They do not say that every merchant-account closure automatically becomes a MATCH record. Mastercard also states that an acquirer may onboard a merchant appearing in MATCH Pro after conducting the required risk assessment.

A merchant questioning a listing can contact the relevant acquirer through legitimate correction or removal procedures. Mastercard’s August 2026 rules require acquirers to respond to removal requests and provide information concerning their listings.

Recovery package after termination

Bring the next underwriter the termination notice, processing history, root-cause analysis, updated fraud controls, current dispute information, revised trial and cancellation flow, refund plan, bank or financial records requested, and any existing reserve details.

Remediation supported by evidence is more useful than blaming the previous provider.

Five AI Underwriting Scenarios

  • Free-trial SaaS: An AI copywriting service sees complaints after a seven-day trial converts. It improves checkout disclosure, consent evidence, notification scheduling, cancellation, and confirmation records.
  • Public API attack: Bots target the card-setup flow. Engineering adds account verification, payment velocity limits, adaptive challenges, and suspicious-activation controls, then documents the before-and-after authorization pattern.
  • Usage-billing disputes: Customers receive unexpected API overages. The company introduces usage dashboards, alerts, administrative limits, detailed invoices, and reproducible metering.
  • New startup: There is no processing history. The application instead contains clear product evidence, realistic volume assumptions, financial information requested by underwriting, and a staged rollout.
  • Aggregator termination: The founder discloses the closure, explains the incident, supplies historic statements, and documents corrective controls instead of attempting to hide the account history.

Myth vs. Reality

MythMore accurate reality
Every AI company is automatically high-riskRisk depends on the actual business and transaction profile
Under 1% chargebacks means you are safeNetworks and processors use different metrics and limits
Approval is permanentMonitoring continues after onboarding
Failed card tests do not matterEnumeration activity can itself trigger monitoring
“No refunds” eliminates disputesPoor complaint handling can push customers toward disputes
A free trial is low-risk because the first charge is $0Conversion and stored-card activity create separate exposure
A reserve means fraud is suspectedReserves are financial risk controls

Frequently Asked Questions

Why is my AI startup considered high risk?

Usually because one or more characteristics—CNP transactions, recurring billing, variable charges, digital fulfillment, limited history, fraud exposure, or customer disputes—create additional underwriting uncertainty. The processor’s assessment is company-specific.

What documents are needed for an AI merchant account?

Prepare legal-entity and ownership documents, bank verification, product and website evidence, pricing, trial and billing terms, refund/cancellation policies, processing history when available, fraud-control documentation, expected volume, and financial information if requested.

Does a free trial increase underwriting risk?

It can. The concern is usually the later conversion, customer consent, cancellation mechanics, and potential billing complaints rather than the mere existence of a free period.

Why do AI signup pages attract card testing?

Public, automated signup paths can give attackers repeated access to payment authorization or card-verification functionality unless adequate controls are applied.

Can a high decline rate hurt underwriting?

A sudden or unexplained decline spike can trigger questions, especially when paired with unusual authorization velocity. A high decline rate alone does not prove fraud.

What chargeback ratio is too high?

There is no universal percentage for every merchant. Visa VAMP, Mastercard programs, processor contracts, event counts, and regional rules differ.

Does Visa still use the old VDMP threshold as the current U.S. standard?

No. Current U.S. monitoring should be evaluated under VAMP rather than treating historical VDMP/VFMP threshold charts as the active framework.

How much reserve should an AI startup expect?

There is no universal AI reserve. The percentage, duration, cap, and release conditions are provider- and account-specific.

Can I get another merchant account after termination?

Potentially, but approval is not guaranteed. Accurate disclosure of the termination, supporting history, and documented remediation gives the new underwriter a reliable basis for evaluating the business.

Make the AI Business Easy to Underwrite

The strongest AI startup high risk merchant account application makes the company easy to understand and easy to monitor.

That means a concrete product, transparent prices, documented trial conversion, reproducible usage billing, reliable refund and cancellation processes, effective card-testing defenses, realistic volume projections, adequate financial evidence, and an honest processing history.

The objective is not to convince an underwriter that risk does not exist. It is to show where the risk comes from, how it is measured, and how the company manages it.