What Is EMV and Why Do Chip Cards Matter?
EMV chip cards generate a one-time code per transaction, which is why they killed card cloning. Here is what the 2015 liability shift means for you.
By Gray Merchants Team

- EMV chip cards generate a one-time use security code for every transaction, which is why copied transaction data can't be reused to clone a card the way it could with a magnetic stripe.
- The October 2015 US liability shift moved fraud liability to whichever party is less EMV-capable, so a merchant running swipe-only hardware absorbs the loss when a chip card is used fraudulently.
- The networks did not shift identical liability: Visa shifted counterfeit fraud only, while Mastercard, American Express, and Discover shifted both counterfeit and lost-or-stolen fraud.
- Federal Reserve Bank of Kansas City research found card-present fraud losses declined for issuing banks but increased for merchants and cardholders, meaning EMV moved cost as much as it eliminated it.
- In 2022, 87.5% of US in-person card payments involved a chip and 19.7% were contactless, per Federal Reserve data. Contactless is part of the EMV family, not a less secure alternative to it.
So what is EMV? It's the global chip-card standard behind every card you insert or tap instead of swipe. EMVCo describes it as a set of open, global technology specifications that make secure contact and contactless payments work anywhere in the world (EMVCo). The name comes from Europay, Mastercard and Visa, the three networks that originated it, though the standard is now owned collectively by six card networks.
Why the Chip Beat the Magstripe
Here's the entire security argument in one sentence. A magnetic stripe holds static data, the same numbers every single time, so anyone who copies that stripe can make a working clone of your card. A chip doesn't work that way. It validates the card's authenticity and generates a one-time use security code for every transaction, which is specifically what stops counterfeit, lost, and stolen fraud (EMVCo).
Copy the data from one chip transaction and you get a code that's already been used. It's worthless for the next one. That single design choice is why card cloning collapsed as an attack once chip terminals became standard.
EMVCo itself is owned collectively by six member organizations: American Express, Discover, JCB, Mastercard, UnionPay, and Visa (EMVCo). That shared ownership is why a chip card issued in one country works in a terminal on the other side of the world. Globally, 97% of card-based transactions now run on EMV chip (EMVCo).
The October 2015 Liability Shift, and the Part Most Guides Get Wrong
On October 1, 2015, the US card networks changed who pays when a chip card gets used fraudulently at a merchant who can't accept chips. Before that date, issuing banks generally absorbed counterfeit fraud losses. After it, liability shifted to whichever party was less EMV-capable. If a customer presents a chip card and the merchant only has a swipe terminal, the merchant now eats the fraud loss.
Here's the nuance almost every explainer skips: the networks did not all shift the same kind of liability. Visa shifted counterfeit fraud liability only. Mastercard, American Express, and Discover shifted both counterfeit and lost-or-stolen fraud liability. That means the exact same fraudulent transaction can land differently depending on which network's card was used, which matters a great deal if you're trying to work out why one chargeback stuck and another didn't.
One correction worth making, since it circulates widely: this was a card network rule change, not a PCI Security Standards Council mandate. PCI DSS and EMV are separate things solving separate problems. PCI DSS governs how you protect cardholder data. EMV governs how the card proves it's genuine at the point of sale.
What Actually Happened to Fraud After EMV
This is where the honest version differs from the marketing version. The card networks published impressive counterfeit-fraud reduction figures in the years after 2015, and counterfeit fraud at chip-enabled merchants did genuinely fall.
But research from the Federal Reserve Bank of Kansas City complicates that story in a way merchants should know about. Their payments research found that card-present fraud loss rates declined for issuing banks while increasing for merchants and cardholders. The losses didn't simply vanish. A meaningful share of them moved onto the people now holding the liability, which is exactly what a liability shift is designed to do.
So the fair summary is this: EMV worked as designed at making card cloning impractical, and it also moved a real cost from banks onto merchants. Both things are true. Any guide telling you only the first half is selling you something.
Where EMV Actually Stands in US Transactions Today
The most rigorous US numbers come from the Federal Reserve's payments study, which discloses its methodology rather than citing a vendor estimate. In 2022, in-person payments made up 63.8% of general-purpose card payments by number. Of those in-person payments, 87.5% involved the use of a chip, 29.1% used chip and PIN (a form of two-factor authentication), and 19.7% were contactless (Federal Reserve, 2024).
That 87.5% figure is the practical answer to "is chip standard yet?" Yes, overwhelmingly, for in-person payments. The contactless number is the one still climbing fast.
Contactless Is EMV Too
A common misunderstanding: tap-to-pay isn't a separate technology competing with chip. Contactless is part of the EMV specification family, covered by EMVCo's own contactless chip specifications (EMVCo). A contactless tap uses the same cryptographic principle as an inserted chip, generating transaction-specific data rather than transmitting static card details.
Practically, that means a terminal supporting contactless is EMV-compliant for liability purposes on those transactions. It's not a security downgrade from inserting the card.
What This Means When You're Buying Terminals
If you're choosing POS systems or replacing terminals today, the EMV question is mostly settled: buy chip-capable, and buy contactless-capable alongside it. The liability exposure of running swipe-only hardware is real, and given how few in-person transactions still run on stripe alone, a non-chip terminal is a liability you're choosing to hold for no benefit.
What's worth actually checking with your provider: whether the terminal is certified for all the networks you accept (certification is per-network, not universal), and whether contactless is enabled by default or something you have to turn on. Plenty of merchants have contactless-capable hardware sitting with the feature switched off.
Worth noting for card-not-present businesses: EMV addresses in-person card authenticity specifically. It does nothing for online transactions, where the card is never physically present. That's a separate problem, handled by tools like 3D Secure and tokenization.
Frequently Asked Questions
What does EMV stand for?
Europay, Mastercard, and Visa, the three networks that originally developed the standard. It's now managed by EMVCo, which is owned collectively by six card networks including those three.
Is a chip card actually safer than a magstripe?
For counterfeit fraud, substantially. A chip generates a one-time code per transaction, so copied transaction data can't be reused to make a working clone. A magstripe holds the same static data every time, which is exactly what makes cloning possible.
Am I liable for fraud if I don't have a chip terminal?
Generally yes, for in-person transactions where a chip card was presented. Since October 2015, liability falls on whichever party is less EMV-capable, and that's the merchant if the terminal can't read chips.
Does the liability shift work the same across all card networks?
No, and this trips up a lot of merchants. Visa shifted counterfeit fraud liability only, while Mastercard, American Express, and Discover shifted both counterfeit and lost-or-stolen fraud liability.
Does EMV protect my online transactions?
No. EMV secures in-person transactions by proving the physical card is genuine. Online payments need different tools, primarily 3D Secure for authentication and tokenization for protecting stored card data.
Is contactless less secure than inserting the chip?
No. Contactless is part of the EMV specification family and uses the same transaction-specific cryptography rather than transmitting static card data.
Setting up in-person payments and want terminals that won't leave you holding avoidable liability? Apply free for a 24 to 48 hour decision, or talk to a specialist about the right hardware for your setup.
Gray Merchants Team
Gray Merchants is a payment ISO that places merchant accounts across every risk level, from low-risk retail and e-commerce to 67+ high-risk verticals. The editorial team writes on high-risk merchant accounts, chargeback defense, MATCH/TMF remediation, and ACH processing, whether you are new, scaling, switching processors, or rebuilding after a decline.