Banks are warning that artificial intelligence agents capable of selecting products and making purchases could create new fraud, payment, and data-protection risks unless consumer safeguards develop alongside the technology.
A group including NatWest, Bank of America, ING, Capital One, Commonwealth Bank of Australia, and ASB Bank has set out principles for the development of agentic commerce as technology companies expand the role of AI assistants in online shopping.
The concern is emerging as AI tools move beyond answering product questions and towards taking actions on behalf of users. Companies including OpenAI, Anthropic, Google, and Meta are developing assistants that can help consumers search, compare, choose, and ultimately transact.
Retailers are responding because AI-generated recommendations may become another route to customer acquisition. John Lewis said this month that searches arriving from AI agents had increased from 0.3% of traffic a year earlier to 2.5%, showing how quickly shopping behaviour can change while the technology remains at an early stage.
The banking group said customers are interested in the convenience offered by AI shopping agents but remain uncertain about accountability. Its report said: “Consumers are unclear if AI will act in their interests.”
Risks identified include agents requesting card information and entering it directly into merchant websites, recommending payment methods with weaker protections, or making purchasing decisions that do not reflect a consumer’s intended limits. Fraudsters could also attempt to exploit the additional layer between the consumer and merchant.
The banks want policymakers and technology providers to consider disclosure requirements when an AI system is involved in a transaction, greater transparency around how recommendations are generated, stronger protection of customer data, and interoperability between services.
The proposals raise a wider question for financial services: who carries responsibility when software is authorised to act but makes a fraudulent or unintended transaction possible? Existing payments regulation generally assumes that a consumer, merchant, bank, or authorised payment provider can be identified at each stage. Agentic systems add another decision-making layer that may operate across several providers.
The issue is distinct from conventional card fraud but emerges while payment losses are already substantial. UK card-fraud losses reached £594.9m in 2025, illustrating the financial incentive criminals already have to exploit weaknesses in digital payment journeys.
Agentic commerce could also create conduct risk. A shopping assistant may rank products using commercial relationships, platform incentives, personal data, or proprietary recommendation models that are not obvious to the customer. Undisclosed commercial influence could undermine trust even where no fraud occurs.
Retailers may need to adapt fraud controls and website architecture as automated purchases increase. A transaction initiated by an AI agent can generate different behavioural signals from one made manually by a customer, reducing the usefulness of systems that rely heavily on navigation, typing patterns, device behaviour, or conventional bot detection.
Banks face a related challenge when determining whether payments are genuinely authorised. Consumers may give an AI agent broad permission to make purchases while expecting it to stay within conditions around price, merchant, product type, delivery, or payment method. Translating those instructions into controls recognisable by payment systems is more complex than approving a conventional card transaction.
Disputes could become more complicated as well. A consumer might approve the use of an agent but dispute a particular transaction because the system misunderstood a preference or exceeded an intended limit. Payment providers would then need evidence showing which instructions were given, how they were interpreted, and which party controlled each stage of the transaction.
The sector is still at the standards-setting stage rather than facing mass adoption of fully autonomous purchasing. That creates an opportunity to design consumer protection into the infrastructure before agentic shopping becomes routine, but technology, banking, retail, and regulation are developing at different speeds.
The expansion of agentic commerce will therefore depend on payment architecture and accountability as well as AI capability. Shopping agents can reduce friction, but banks are signalling that liability, data access, authorisation, and fraud prevention need to be resolved before autonomous purchasing becomes a routine part of ecommerce.




You must be logged in to post a comment.