Drooid Logo
Back to story perspectives

Full Breakdown

Banks Call for Safeguards as AI-Powered Shopping Agents Expand

By Drooid · · How we work

Core Event – September 22 Report Highlights Risks of “Agentic Commerce”

On September 22, a coalition of six banks — NatWest, Bank of America, ING, ASB Bank, Capital One, and Commonwealth Bank of Australia — released a joint paper, “Building Trust in Agentic Commerce.” The report warns that AI agents that can search, select, and complete purchases may increase exposure to scams, fraud, and data-privacy breaches. The banks propose principles for developers, merchants, and regulators, including mandatory disclosure of AI involvement, greater transparency of decision-making algorithms, and auditable records of consumer instructions, authorizations, and transaction outcomes.

Background & Context – Growing Role of AI in Online Shopping

Technology firms such as OpenAI, Google, Anthropic, and Meta are promoting chat-based assistants that act as shopping aides. British retailer John Lewis reported that product searches originating from AI agents rose from 0.3 % to 2.5 % of its website traffic within a year, indicating rapid adoption.

Timeline

  • September 22 – Banks publish the “Building Trust in Agentic Commerce” paper and outline proposed safeguards.

Data & Statistics – Early Indicators of Market Shift

  • John Lewis AI-driven search share: 0.3 % -> 2.5 % in one year.
  • Bank-identified risk scenarios: agents requesting full card details, entering them directly on merchant sites, and steering shoppers toward payment methods with weaker consumer protections.

Official Statements & Responses – Banks’ Proposed Safeguards

The banks argue that AI development outpaces existing consumer-protection standards. Their paper calls for:

1. Disclosure Requirements – Transactions must indicate when an AI agent participated.

2. Transparency of Decision Logic – Providers should explain how agents prioritize products and payment options, including any sponsored placements.

3. Auditable Transaction Trails – Records should capture the consumer’s original instruction, delegated authority limits, the agent’s decision process, and the final payment outcome.

4. Data-Privacy Safeguards – Limits on collection, storage, and sharing of personal and financial information used by agents.

5. Choice and Interoperability – Consumers and merchants should be free to select among AI agents, digital wallets, and payment services without unreasonable restrictions.

The principles are voluntary and nonbinding; a follow-up document will explore concrete protocols.

Why It Matters – Potential Consumer Harm and Legal Complexity

If an AI agent exceeds a shopper’s budget, selects the wrong product, or routes payment through a less protected method, the consumer may face financial loss and limited recourse. Existing chargeback protections may not apply cleanly when the agent, rather than the consumer, initiates the transaction. Determining liability will require clear evidence of the agent’s authorized scope, the data used in its decision, and the party responsible for any breach. The ability of agents to request and store card credentials raises additional privacy concerns.

Conflicting Reports & Gaps – No Consensus on Implementation Timeline

The proposals are voluntary, and the report does not specify a timetable for adoption or regulatory enforcement. No competing industry standards were identified, leaving a gap in how quickly the safeguards might become practice.

What’s Next – Ongoing Development of Auditable Intent Systems

Payment networks are already working on solutions aligned with the banks’ recommendations. Mastercard is developing a “Verifiable Intent” system to create auditable records of consumer permissions, while Visa’s “Intelligent Commerce” initiative aims to embed credentials, controls, and authentication into AI-initiated purchases. The banks plan to present their principles to policymakers, but concrete regulatory action remains pending.