Drooid Logo
Back to story perspectives

Full Breakdown

Banks Warn AI Shopping Agents Could Heighten Scams, Fraud and Privacy Risks

By Drooid · · How we work

Core Event: Six Global Banks Release Joint Principles on Agentic Commerce

On September 22, a coalition of six major banks—NatWest Group, Bank of America, ING Group, ASB Bank (New Zealand), Capital One and Commonwealth Bank of Australia—published a principles paper titled “Building Trust in Agentic Commerce.” The report warns that AI-driven shopping agents, which can select products, enter payment details and complete purchases without direct human oversight, may increase scams, fraud and data-privacy breaches. The banks propose safeguards to be discussed with policymakers.

Background & Context

Technology firms including OpenAI, Anthropic, Google and Meta are promoting AI chatbots that act as personal shopping assistants. Retailers are already adapting; British department store John Lewis reported AI-originated searches rose to 2.5 % of its site traffic in September, up from 0.3 % a year earlier. The banks note that consumer enthusiasm for “agentic commerce” is outpacing the development of industry standards and consumer-protection frameworks.

Data & Statistics

  • John Lewis AI-originated traffic: 2.5 % (September) vs. 0.3 % (previous year).
  • Banks involved: NatWest Group, Bank of America, ING Group, ASB Bank, Capital One, Commonwealth Bank of Australia.

Official Statements & Responses

The paper cites concerns that AI agents may purchase the wrong item, exceed spending limits or expose users to scams. Two technical risks are highlighted: (1) agents requesting and directly entering customers’ card details on merchant sites, and agents steering shoppers toward payment methods with weaker consumer protections.

To address these risks, the banks propose:

  • Mandatory disclosure whenever an AI agent participates in a transaction.
  • Greater transparency about how agents make product-selection and payment-method decisions.
  • Safeguards to protect customer data, including secure handling of payment credentials.
  • Interoperability standards that let consumers and merchants choose among AI-powered services without lock-in.

The report stresses that without such measures, consumers may be uncertain whom to contact when an automated purchase goes wrong, and merchants could face disputed transactions without clear liability.

Why It Matters

If AI agents autonomously complete purchases, the traditional audit trail linking a cardholder to a specific transaction can become fragmented. Scammers could exploit agents by presenting fake storefronts or manipulating product data, leading to unauthorized charges that are difficult to trace. Existing dispute-resolution mechanisms are ill-suited to a multi-party chain that includes the user, the AI-service provider, the retailer and the payment processor. Clear rules on disclosure, data handling and liability are therefore essential as the technology scales.

Verbatim Quotes

  • “When you peel back the onion, it really comes down to ensuring you have the right guardrails and observability in place,” — Kiran Vuppu, U.S. chief information officer at TD Bank.

What’s Next

The banks intend to bring their proposals to policymakers for discussion, aiming to shape regulations that address disclosure, transparency, data security and interoperability for AI-driven e-commerce. No specific legislative timetable has been announced.