· Ashan Hettiarachchi

AI Shopping Agents: Convenience vs. Security Risks

What “agentic commerce” actually means

Agentic commerce is the industry phrase for AI agents that act on a shopper’s behalf. Instead of you browsing a site, comparing prices, and tapping “Buy,” an AI agent:

  • searches across retailers
  • chooses a product
  • decides how to pay
  • completes the purchase

OpenAI, Anthropic, Google, and Meta are all pushing chatbots as shopping tools. Retailers, for their part, are racing to influence what those bots recommend.

The shift is already visible in traffic. British retailer John Lewis said in September that searches coming from AI agents had jumped to 2.5% of search activity, up from 0.3% a year earlier — and the trend is accelerating.


Who issued the warning

The principles come from six banks that sit in the middle of everyday payments:

  • NatWest (UK)
  • Bank of America (US)
  • Capital One (US)
  • ING (Netherlands)
  • ASB Bank (New Zealand)
  • Commonwealth Bank of Australia

They published a shared framework for “trusted agentic commerce,” focused on five areas: transparency, safety, privacy and data, choice, and interoperability.

NatWest framed the project as banks using their place in the payments ecosystem — connecting consumers, businesses, and merchants — to set foundations before the technology scales.


Why banks are nervous

The banks are not saying AI shopping should be banned. Their report says customers are enthusiastic and keen to switch it on.

The problem is trust and liability.

The report put consumer anxiety in plain language: people are unclear whether AI will act in their interests. They worry an agent will buy the wrong thing, spend too much, or lose their money to scams and fraud. They also do not know whether they will be protected, or whom to call if a purchase goes wrong.

That last point matters. Traditional card networks, banks, and retailers already have established dispute processes. An AI agent sitting between the shopper and the merchant blurs who did what — and who pays when it fails.


The specific risks they flagged

1. Card details in the wrong hands

An AI agent may ask a customer for card details and type them into a website. That is a new attack surface. If the agent is compromised, impersonated, or poorly designed, payment data can leak or be reused without the shopper noticing.

2. Weaker payment rails

Agents might steer users toward payment methods that are faster or cheaper for a merchant or platform, but that offer thinner consumer protections than a standard card transaction. Convenience can quietly replace chargeback rights.

3. New social-engineering scams

Bad actors could impersonate a shopping agent or a merchant, compromise a real agent, or invent new social-engineering scripts that feel like a helpful assistant. “Your AI bought this for you” is a powerful cover story.

4. Unclear liability

When a purchase is wrong, overpriced, or fraudulent, dispute processes may not include every party in the chain: the model provider, the agent platform, the retailer, the payment network, and the bank. The banks say allocation of liability is currently unclear and inefficient.

5. Data privacy

Shopping agents need preferences, budgets, addresses, and payment information. That is a rich profile. Without hard safeguards, the same data that makes an agent useful can be reused, shared, or exposed.


What the banks want policymakers to consider

The group plans to take proposals to policymakers. Among them:

Proposal Why it matters
Disclose when an AI agent is in the transaction Shoppers should know a bot, not a person, initiated or completed the buy.
Explain how the agent decided Why this product, this merchant, this price, this payment method?
Protect customer data Limit what agents can store, share, and reuse.
Let consumers and merchants choose their tools No lock-in to a single AI shopping platform.
Make systems interoperable Agents, banks, and retailers should work across vendors, not inside walled gardens.

In short: label the bot, show the reasoning, lock down the data, and keep the market open.


What this means for shoppers

If you start letting an assistant buy things for you, treat it like you would treat a stranger with your wallet.

Practical habits that match the banks’ concerns:

  • Prefer agents that use tokenized or bank-mediated payments instead of raw card numbers.
  • Set hard spending limits and require confirmation above a threshold.
  • Check whether the payment method still gives you chargebacks or authorized-push-payment protections.
  • Read what data the agent stores and whether it can shop without asking.
  • Keep a paper trail: which agent, which merchant, which authorization.

The technology will keep getting better at sounding helpful. That is exactly why the banks want disclosure and auditability baked in now, not after the first wave of holiday-season losses.


The bigger picture

This is a familiar pattern. A new interface appears between the customer and their money. Adoption races ahead. Protections lag. Banks, who still eat a large share of fraud losses and still run the rails, try to write the rules before the damage becomes systemic.

Agentic shopping could be genuinely useful — especially for routine reorders, comparison-heavy purchases, and people who hate checkout flows. It could also become a high-speed way to drain accounts if agents can spend, if merchants can influence recommendations, and if nobody can say who authorized what.

The banks’ message on September 22, 2026 was not “stop.” It was “slow down the unprotected version.”

Customers want the convenience. Banks want the liability map drawn before the bots start tapping “Pay” at scale.


Further reading


This post is an original summary and analysis for blog use. It is not a copy of the Reuters article. Facts are drawn from public reporting dated September 22, 2026.