3-D Secure, now in version 2, is the protocol that inserts an additional check between checkout and approval. Depending on the calculated risk, the issuing bank asks the cardholder for confirmation, through an app or a code, before authorizing.
The most important effect isn't technical, it's about liability. In a successfully authenticated transaction, the fraud dispute becomes the issuer's responsibility, not the seller's. This is what's called the liability shift.
The cost is friction. Every extra step in the checkout drags down conversion, and that's why the sensible decision isn't to turn 3DS on or off for everything, but to apply it by risk tier: suspicious transactions or high-ticket ones go through authentication, the rest go straight through.