THE MARGIN / Chargebacks & Risk

EMV liability shift:
who eats card-present
fraud in 2026

A dipped or tapped chip card and a swiped one look identical at the register -- until a counterfeit-fraud chargeback lands, and the network rules decide who pays based on whose equipment was behind the times. Here's how the liability actually moves, and where fuel dispensers stand after a decade of delays.

13 min readโ€ขPublished August 2026โ€ขBy the MidPay desk

Quick answer

Since October 1, 2015, US card networks (Visa, Mastercard, American Express, Discover) shifted counterfeit-card fraud liability to whichever party in a transaction has the least EMV-compliant technology. If a merchant's terminal can't read a chip card and the transaction gets swiped or keyed instead, and it turns out to be counterfeit fraud, the merchant eats the chargeback instead of the issuer. If the merchant has a working EMV terminal but the issuer hasn't put a chip on the card, liability stays with the issuer. Contactless (tap) transactions carry the same protection as contact chip when they run through the EMV kernel. The one long-running exception was automated fuel dispensers, whose deadline Visa and Mastercard delayed three times -- October 2017, then October 2020, then April 16, 2021 -- before it finally took effect; there is no further scheduled delay as of 2026. This is the card-present counterpart to the card-not-present liability shift we cover in 3-D Secure: liability shift vs conversion cost.

Card-not-present fraud gets most of the attention because it's the faster-growing exposure, a gap we covered in full in e-commerce's true blended rate and 3-D Secure's liability shift. But the card-present side has its own liability framework, one that's been in force for a decade and still catches merchants who fell behind on hardware or who fall back to a swipe out of habit. The EMV chip liability shift decides, transaction by transaction, who absorbs a counterfeit-fraud chargeback when a physical card gets used at a physical terminal -- and the answer depends entirely on whose equipment was the weaker link.

What the EMV liability shift actually is

EMV -- named for its original backers Europay, Mastercard, and Visa -- is the global chip standard that replaced the static magnetic stripe with a microprocessor generating a unique cryptogram for every transaction, making a cloned counterfeit card far harder to produce. In the US, the major card networks coordinated a single date, October 1, 2015, after which the financial consequence of accepting a counterfeit card shifted onto whichever party in the transaction chain hadn't upgraded to chip-reading or chip-issuing technology. The U.S. Payments Forum's white paper on the shift puts the mechanism plainly: beginning in October 2015, "that liability will shift to the merchants in certain cases unless they have replaced or upgraded their card acceptance and processing systems to use chip-enabled devices."

It's important to be precise about what this is and isn't. It is not a law and not a mandate -- there's no fine or penalty for a merchant who never installs an EMV terminal. It is a reallocation of who wins a chargeback dispute when counterfeit fraud occurs, and for a merchant running any real volume, losing that reallocation repeatedly is its own real cost, showing up the same way any other chargeback does, which we cover more broadly in chargebacks as a hidden tax.

How liability assignment actually works

The rule is often summarized as "the least-EMV-compliant party eats the loss," and that's the right mental model, but the mechanics run through a few concrete scenarios:

The U.S. Payments Forum frames the tie-break the same way: "the party supporting the most secure technology for each fraud type will prevail in a chargeback; and in case of a technology tie, the fraud liability... generally is expected to remain as it is today -- with the issuer." In practice, that means a merchant only takes on new exposure when their side of the transaction is demonstrably behind the card's capability, not simply because fraud happened somewhere in their store.

Card capabilityTerminal / read methodWho eats counterfeit-fraud liability
Chip-enabled cardEMV terminal, chip read correctlyIssuer -- both sides met the standard
Chip-enabled cardNo EMV terminal, or chip read fails and falls back to swipe/keyMerchant -- merchant's side was the weaker link
No chip on card (magstripe-only)EMV terminal available, card is swiped because it has no chipIssuer -- issuer's side was the weaker link
Chip-enabled card, contactlessTerminal reads contactless via EMV kernel (tap)Issuer -- contactless-EMV carries the same protection as contact chip
Chip-enabled cardNo EMV terminal AND no chip on card (technology tie)Issuer -- ties default to pre-2015 liability, which sat with the issuer

This is a liability-assignment reference built from network-rule descriptions, not a numeric trend -- there's no reliable, consistently reported year-over-year dataset on how often each scenario occurs, so we built a decision table instead of fabricating a chart around a number we couldn't verify.

Fuel dispensers: the exception that took six years to close

Automated fuel dispensers (AFDs) were carved out of the original October 2015 deadline because retrofitting an entire pump island's payment hardware is a far bigger job than swapping a countertop terminal -- new secure card readers, updated point-of-sale integration, sometimes new pump housings entirely, across tens of thousands of locations nationwide. The card networks pushed the AFD liability shift date multiple times in response to industry pressure over the pace of that retrofit work: the deadline moved from its original October 2017 target to October 2020, and then Mastercard and Visa each separately extended it a final time to April 16, 2021, giving fuel retailers roughly three and a half extra years beyond the original date to complete the upgrade.

That April 16, 2021 date has passed, and it is the deadline currently in force -- fuel retailers still running magstripe-only pumps have been exposed to the same liability-shift logic as any other card-present merchant since that date. We did not find a credible source describing any further scheduled delay of the AFD deadline as of 2026; if you operate fuel dispensers and haven't confirmed your equipment's EMV status, that's worth verifying directly with your equipment vendor or acquirer rather than assuming an extension is still pending, since the extension era is over.

Automated fuel dispenser EMV liability shift: delay timeline, 2015-2021 Timeline chart showing the original card-present EMV liability shift taking effect October 2015, followed by three delays to the automated fuel dispenser deadline specifically: from October 2017 to October 2020, then to the final effective date of April 16, 2021. Automated fuel dispenser (AFD) liability shift: delay timeline Oct 2015 general shift All other card-present takes effect Oct 2017 AFD original target Delayed (retrofit pace too slow) Oct 2020 2nd AFD target Delayed again by both networks Apr 16, 2021 final effective date In effect no further delay found
Source: U.S. Payments Forum, "Understanding the 2015 U.S. Fraud Liability Shifts"; Digital Transactions, "Mastercard Also Extends EMV Liability Shift for Fuel Pumps" (May 2020); Visa's published AFD liability-shift bulletin. The general card-present EMV liability shift took effect October 1, 2015. The automated fuel dispenser deadline was pushed from an original October 2017 target to October 2020, and then Mastercard and Visa separately extended it a final time to April 16, 2021 -- the date currently in effect.

The fallback swipe is the trap. A chip-capable card run through a working EMV terminal protects the issuer's liability -- reading that same chip as a magstripe swipe hands the risk straight back to the merchant.

Chip-and-PIN vs chip-and-signature in the US

The EMV standard supports two cardholder verification methods at the point of sale: chip-and-PIN, where the customer enters a PIN to authorize the transaction, and chip-and-signature, where a signature (or increasingly, nothing at all under a network's no-signature-required threshold) stands in for verification. Most other developed markets moved to chip-and-PIN as the default; the US rollout leaned overwhelmingly toward chip-and-signature, largely because US card issuers and merchants prioritized speed of adoption and customer familiarity over the additional fraud reduction PIN verification offers. That choice doesn't change liability-shift eligibility either way -- both verification methods qualify as EMV chip transactions for liability-shift purposes -- but chip-and-PIN does provide stronger protection against a specific fraud type (a lost or stolen physical card being used by someone other than the cardholder) that chip-and-signature and no-CVM transactions don't address as well, since the chip itself only proves the physical card was present, not that the person holding it is the legitimate cardholder.

Contactless and tap-to-pay: same protection, different gesture

Contactless "tap" transactions run through the same EMV kernel as a dipped chip transaction -- the card and terminal exchange the same type of cryptographic authentication, just over a short-range wireless connection instead of a physical contact interface. That means a contactless EMV transaction carries the identical liability-shift protection as a contact chip transaction: if the terminal reads the card's EMV contactless application correctly, the transaction qualifies for the same "both parties compliant" outcome, and counterfeit-fraud liability stays with the issuer. The liability exposure only appears when a terminal can't complete a contactless or contact chip read and falls back to swipe or manual key entry -- the tap gesture itself isn't a weaker technology tier, it's a different interface to the same chip standard.

For merchants weighing whether to prioritize contactless-capable hardware, this is a practical argument in its favor beyond the checkout-speed benefit: a terminal that reliably completes contactless reads reduces how often staff or customers default to swiping out of frustration with a slow or failed chip dip, which is exactly the fallback moment that strips liability protection.

What merchants should actually do

  1. Confirm your terminals are actually EMV-certified and activated, not just chip-capable hardware sitting unconfigured -- some older deployments have chip readers installed but never fully enabled in the processor's system, which doesn't earn liability protection until it's live.
  2. Fix chronic chip-read failures instead of tolerating the swipe fallback. If staff routinely swipe because the chip reader is slow, damaged, or poorly maintained, every one of those transactions is exposed to shifted liability if it turns out to be counterfeit fraud -- the fallback, not the fraud itself, is what moves the risk onto you.
  3. Enable and encourage contactless where your terminal supports it -- it carries full liability-shift protection and reduces how often a failed or slow chip dip pushes a transaction to swipe.
  4. If you operate fuel dispensers and haven't verified your pumps are EMV-active since the April 16, 2021 deadline, treat that as an open compliance gap, not a future project -- the delay window has closed.
  5. Train staff on why the chip matters, not just how to use it -- a swipe habit formed for speed during a busy shift is the single most common way an otherwise-compliant merchant loses liability protection transaction by transaction.

How this differs from the card-not-present liability shift

The EMV shift is a card-present framework: it only governs transactions where a physical card is dipped, tapped, or swiped at a physical terminal, and it only addresses counterfeit-card fraud specifically. Online and phone sales sit entirely outside its scope, because there's no physical card or terminal read to evaluate in the first place. That's where 3-D Secure's liability shift takes over, moving liability for card-not-present fraud to the issuer only when cardholder authentication completes successfully -- a mechanism we cover in full in 3-D Secure: the liability shift vs the conversion cost, including why it doesn't cover the non-fraud disputes that make up most CNP chargeback queues. A merchant selling both in-store and online is managing two separate liability frameworks, not one -- the EMV rules protect the register, the 3DS rules protect the checkout page, and neither substitutes for the other. The broader cost stack behind online fraud exposure, including how chargebacks and fraud-tooling spend layer on top of card-not-present interchange, is covered in e-commerce's true blended rate.

Frequently asked questions

Who is liable for fraud if a merchant doesn't have an EMV terminal?

Since October 1, 2015, liability for counterfeit-card fraud shifts to whichever party in the transaction has the least EMV-compliant technology. If a merchant swipes or manually keys a chip-enabled card instead of reading the chip -- because their terminal isn't EMV-capable or they fell back to the magstripe -- and that transaction turns out to be counterfeit fraud, the merchant absorbs the chargeback instead of the card-issuing bank.

Does the EMV liability shift apply to fuel dispensers?

Yes, since April 16, 2021. Visa and Mastercard both delayed the automated fuel dispenser (AFD) liability shift multiple times -- originally set for October 2017, pushed to October 2020, then to April 16, 2021 -- to give fuel retailers more time to retrofit pumps with EMV-capable readers. That final date has passed and is in effect; there is no further scheduled delay as of 2026.

Is contactless tap-to-pay covered by the EMV liability shift?

Yes, when the contactless transaction runs through the EMV kernel on the card and terminal -- which nearly all US contactless cards and modern terminals do. A tap transaction processed via the EMV contactless application carries the same fraud-liability protection as a contact chip transaction. It is the magstripe fallback, not the tap itself, that strips the protection.

What's the difference between the EMV liability shift and the 3-D Secure liability shift?

The EMV shift governs card-present transactions -- a physical card dipped, tapped, or swiped at a terminal -- and moves counterfeit-fraud liability to whichever party has the weaker technology. The 3-D Secure shift governs card-not-present transactions -- an online or phone sale where no physical card is presented -- and moves fraud liability to the issuer only when authentication completes successfully. They cover different channels and different fraud types, and a merchant selling both in-store and online needs to manage both separately.

Key takeaways

  • Since October 1, 2015, counterfeit-fraud liability on card-present transactions shifts to whichever party -- merchant or issuer -- has the least EMV-compliant technology.
  • Falling back to swipe or manual key entry on a chip-enabled card strips liability protection even if the terminal is technically EMV-capable -- the fallback itself is the exposure, not just missing hardware.
  • Fuel dispensers were delayed three times (Oct 2017 โ†’ Oct 2020 โ†’ Apr 16, 2021) before the shift took effect; that date has passed with no further scheduled delay found as of 2026.
  • Contactless/tap transactions carry the same liability-shift protection as contact chip when read through the EMV kernel -- tap is not a weaker technology tier.
  • EMV liability governs card-present fraud only; card-not-present fraud runs on a separate framework covered by 3-D Secure's liability shift, not this one.

Sources & how to verify

The October 1, 2015 US liability-shift date and the least-EMV-compliant-party mechanism, including the technology-tie default to issuer liability, are drawn from the U.S. Payments Forum's "Understanding the 2015 U.S. Fraud Liability Shifts". The automated fuel dispenser delay timeline (original October 2017 target, extension to October 2020, and the final April 16, 2021 effective date) is drawn from Digital Transactions' reporting on Mastercard's AFD extension and Payments Dive's coverage of the card networks' fuel-dispenser deadline changes; verify current AFD compliance status directly with your acquirer or equipment vendor, since we did not locate a credible source describing any further scheduled delay beyond April 2021. General EMV mechanics, chip-and-PIN vs chip-and-signature context, and contactless-EMV liability parity are consistent with EMV Connection's overview of the fraud liability shift.

Get your terminal fleet checked for EMV and contactless

Send us your current equipment lineup and we'll confirm whether your terminals are fully EMV-active and contactless-ready, or whether a swipe fallback is quietly leaving you exposed.

Talk to MidPay โ†’ Need new hardware? See our terminal options.