Major Banks Warn AI Shopping Agents Pose Fraud and Privacy Risks
A coalition including Bank of America and NatWest says agentic commerce is outpacing consumer protections and creating new vulnerabilities.

A coalition of six major financial institutions has issued a warning that AI-powered shopping agents are introducing significant risks around fraud, scams, and data privacy — and that the technology is advancing faster than existing consumer protections can address.
The group, which includes NatWest, Bank of America, ING, Capital One, New Zealand's ASB Bank, and Commonwealth Bank of Australia, released a report Tuesday outlining principles for how agentic commerce should be developed. The term refers to AI systems that autonomously select and purchase products on behalf of consumers.
New vulnerabilities in automated purchasing
The banks identified several specific threats created by AI shopping agents. One concern centers on agents that collect customer payment card details and submit them to third-party merchant sites, creating potential exposure points for data breaches. The report also noted that AI agents might prioritize payment methods that carry weaker consumer protection mechanisms.
Beyond technical vulnerabilities, the banks warned that bad actors could compromise or impersonate both AI agents and merchants. Social engineering attacks could also evolve to exploit the automated nature of these systems, the coalition said.
A core problem identified in the report is ambiguity around liability when transactions go wrong. "When things go wrong, there is unclear and inefficient allocation of liability, and disputes processes do not involve all relevant parties across the value chain," the banks stated.
Why it matters
As technology giants including OpenAI, Anthropic, Google, and Meta position AI chatbots as shopping assistants, and retailers actively work to influence these systems' recommendations, the infrastructure for agentic commerce is being built without clear regulatory guardrails. British retailer John Lewis reported that searches originating from AI agents jumped from 0.3% to 2.5% of total traffic in a single year — a signal that adoption is accelerating even as fundamental questions about consumer protection remain unresolved. The banks' intervention represents an unusual preemptive move by financial institutions to shape regulation before problems become widespread.
Proposed regulatory framework
The coalition plans to bring several specific proposals to policymakers. These include requiring disclosure when an AI agent participates in a transaction, mandating transparency into how agents make purchasing decisions, and implementing stronger data security measures.
The banks also advocated for preserving consumer and merchant choice over which AI commerce platforms they use, and called for interoperability standards that would allow competing systems to work together seamlessly.
Consumer adoption remains mixed
Despite the technology's rapid development, consumer comfort with AI shopping remains uneven. Research from PYMNTS Intelligence found that while half of American consumers reported using some form of AI assistance in retail purchases, only about one in four said they would be comfortable allowing an AI agent to handle both product selection and payment execution independently.
The warning arrives as U.S. banking regulators have begun incorporating AI oversight into standard bank examinations, though no comprehensive AI-specific regulatory framework has been established. Banking examiners are now questioning lenders about their governance of AI technology in higher-risk applications.
These details were first reported by Reuters and Quartz.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call