Please, rotate your device

Mobile apps and games

Banks warn about the risks of shopping with AI agents

Artificial intelligence is moving beyond finding products and comparing prices. AI agents are beginning to select sellers, complete checkouts and make payments on behalf of consumers. Banks, however, warn that customer protection is not developing as quickly as the technology.

NatWest, Bank of America, ING, Capital One, ASB Bank and Commonwealth Bank of Australia have outlined joint principles for the development of agentic commerce. According to Reuters, the institutions are concerned about scams, payment-data exposure and uncertainty over who is responsible when an AI agent makes the wrong purchase.

What shopping with an AI agent means

A conventional chatbot can search for a product, compare specifications and recommend several options. An AI agent can be given broader authority: it may choose a seller, add an item to the basket, enter a delivery address, apply a discount code and complete the payment.

A customer might, for example, ask an agent to find a particular smartphone below a specified price and order it for delivery before a certain date.

This model is known as agentic commerce. It can make shopping more convenient, but it also transfers decisions that were previously made by the customer to an algorithm.

OpenAI, Anthropic, Google and Meta are developing shopping capabilities for their AI services, while retailers are trying to ensure that their products appear in agents’ recommendations.

What the banks are concerned about

Existing consumer-protection rules were generally created for transactions that people review and approve themselves. When an autonomous agent completes an order, determining where a mistake occurred and who should be responsible becomes more complicated.

The banks highlighted several potential risks:

  • the agent could select the wrong product or seller;

  • it could spend more than the customer intended;

  • payment information could be passed to a merchant insecurely;

  • the agent could choose a payment method with weaker protection;

  • scammers could create offers designed to influence AI recommendations;

  • customers might not know where to request a refund;

  • it may be unclear whether the agent is always acting in the buyer’s best interests.

One particular concern involves agents requesting card details and entering them directly on merchants’ websites. Payment information may then pass through several systems, leaving the customer unsure where it is stored and who can access it.

An agent could choose a less protected payment method

Payment methods do not all offer the same protection. Some provide a mechanism for disputing a transaction when goods are not delivered, while others may give the customer fewer options.

If an AI agent prioritizes speed, price or checkout convenience, it could choose an option that benefits the merchant but offers weaker protection to the buyer.

The customer might also fail to notice that the agent has accepted a subscription, an additional service, automatic renewal or another condition displayed during checkout.

Who is responsible when the agent makes a mistake?

When a customer personally confirms a payment, the usual path is relatively clear: they can contact the merchant, bank or payment provider.

An AI-initiated purchase can involve more parties, including the model developer, agent platform, online store, payment processor and issuing bank.

If the agent orders the wrong item, exceeds the customer’s budget or purchases from a fraudulent seller, it may be difficult to determine whether the error belongs to the user, the algorithm, the platform or the merchant.

Banks therefore argue that customers must know in advance what an agent is allowed to do and where they can seek help if something goes wrong.

What the banks are proposing

The institutions plan to discuss their proposals with policymakers. Their suggested principles include:

  • clear disclosure whenever an AI agent is involved in a transaction;

  • explanations of why an agent selected a particular product, seller or payment method;

  • stronger safeguards for card and personal data;

  • freedom to choose between different AI-commerce services;

  • interoperability between agents, merchants and payment systems;

  • clear allocation of responsibility;

  • the ability for a person to approve or cancel a purchase.

Before money is taken, the customer should be able to see the final price, merchant, payment method, delivery terms and return conditions, particularly for expensive or unusual transactions.

Payment networks are developing safeguards

Visa is building Visa Intelligent Commerce, which is intended to support agent verification, protected payment credentials, spending limits, authentication and approval requirements.

Mastercard is pursuing a similar approach through Agent Pay. Controlled agentic transactions in Europe already use tokenization, passkeys and Verifiable Intent, which links an agent’s action to the customer’s explicit authorization. Mastercard described the first European implementations in an official overview of trusted agentic commerce.

These systems are designed to avoid giving an agent an ordinary card number. Instead, the agent receives protected payment credentials governed by specific rules and limits.

How to shop more safely with AI agents

Until common standards are established, customers should retain control over the final stage of a purchase.

Before allowing an agent to make payments, it is sensible to:

  • set a maximum amount for each transaction;

  • require approval before any money is taken;

  • avoid entering primary card details directly into a chat;

  • use a virtual card or a separate spending limit;

  • check the merchant, final price and return conditions;

  • prevent the agent from creating subscriptions without permission;

  • keep receipts, order confirmations and the agent’s activity history;

  • prevent the agent from changing the payment method without approval.

For expensive products, reservations and recurring payments, final human confirmation remains the safer option.

Why this matters

Shopping may become a standard feature of AI assistants. Instead of merely recommending a product, an agent could complete the entire task on the customer’s behalf.

That convenience requires users to give an algorithm access to their money, personal information and purchasing decisions. The future of agentic commerce will therefore depend not only on accurate recommendations but also on clear limits, secure payment infrastructure and defined responsibility when mistakes occur.

Until those protections become standard, AI is better used to find and compare products while the customer retains responsibility for reviewing and confirming the final purchase.