> The credit card companies literally have no control over who can charge us.
That's not quite true. The card network can refuse a merchant for any reason, constantly making bogus charges would probably be a good reason for the network to refuse them and that's likely to be the result. Of course you don't see if your bogus charge was reflective of 0.01% of the charges from this merchant or 99.9%
However as I've explained on HN a few times there's an important distinction between two separate payment card processes: Authorization and Settlement.
Authorization is the one with PINs and online referral and even getting a call from your bank about "possible fraud". Authorization protects the bank from fraud by customers (you're a necessary evil to them) and merchants by automatically collecting evidence that both authorized this to happen. Once upon a time that meant taking an "impression" and a few merchants still do that, today it may mean redirecting customers to a half-arsed HTTPS site or an EMV PIN terminal.
Settlement moves money. The merchant tells the network that they want $85.26 from card #1234567890 and usually that will just result in them receiving $85.26
These two systems aren't tied together. If there are two authorizations against your card this week for $20.00 and $35.26 but also three settlements for $19.86, $209.42 and $20.00 respectively, it's likely no alarm bells go off, this is fine, you pay $249.28
One reason it is this way is that while Settlement is essential to the idea in the first place (if the merchants don't get money what's the point?), Authorization is dozens of extra things tacked on over time and so each has to be optional or the system would fail.
This means important safeguards in Authorization don't actually safeguard you, only your issuer (in your case Amex)
For example: Modern Authorization schemes are replay resistant. When you pay with an EMV card the merchant gets a one-time "cryptogram" that isn't reusable. Buying a $5 product, walking out of the store, then realising you needed two, so you go back and buy another $5 product results in two entirely different cryptograms for the two Authorizations. The store can't present a third Authorization because it would need a new cryptogram.
BUT Settlement isn't replay resistant. When (not if, this really happens) an IT mistake results in running all the Settlement for a merchant twice, customers just all get charged twice, again no flags are raised automatically, it will take until either somebody confesses their error or more likely angry customers start calling their issuers to complain.
For individuals the only advice is: Check your statements, demand that line items you can't explain be reversed, and try to pick an issuer who is on your side.