The next target for online scammers may not be your bank account directly, but the AI agent you trust to spend from it.
Six major banks are warning that agentic commerce could create new opportunities for fraud, scams and data breaches as AI systems gain authority to select products, interact with merchants and complete purchases on consumers' behalf.
Bank of America, Capital One, ING Group, NatWest, Commonwealth Bank of Australia and ASB Bank have responded with a joint set of principles intended to make these transactions safer.
That is because an AI shopping agent can become more than another piece of software: it may hold sensitive information and be authorized to act on a user's behalf. The banks warn that attackers could compromise or impersonate agents and merchants, while consumers could also face weaker payment protections or unclear responsibility when an agent makes a mistake.
Where banks see the biggest risks
The six banks are not necessarily against the use of AI agents in online commerce. Their central argument, however, is that AI's rapid integration into the sector is outpacing the protections in place — a warning that also underpins the recent AI slowdown debates.
According to the banks' report, consumers are enthusiastic about using AI agents to make shopping easier, but many remain “unclear if AI agents will act in their interests” when carrying out retailing activities.
These activities include how an agent selected a product, why it chose one merchant or payment method over another, or what happens if the agent makes a purchase the consumer did not intend.
That lack of clarity matters more when an AI moves beyond recommendations and starts taking action. An agent that can search for a product is one thing; an agent that can choose the seller, handle payment information, and complete the transaction on a customer's behalf has considerably more authority — and therefore creates more opportunities for fraud, scams, privacy breaches, and disputes.
AI shopping is moving faster than its safeguards
The warning comes as AI agents gain more autonomy and move closer to handling real transactions rather than simply recommending products.
At the same time, AI companies and retailers are still working out who gets access to the data and infrastructure that make these systems useful. Retailers want AI agents to bring customers to their products, but they also want control over their customer relationships and the data generated during those interactions. The recent dispute between Amazon and Meta over Meta's Muse agent shows how quickly that tension can turn into a fight over access, privacy, and security.
Agentic commerce is continuing to expand through partnerships between AI companies, retailers and payment providers even as responsibility, consumer protections and data-sharing rules remain unsettled.
What the banks want to change
The six banks propose five principles for safer agentic commerce:
- Transparency: Consumers should know when an AI agent is acting on their behalf and why it made a particular choice.
- Safety: Agents should have safeguards that reduce unauthorized transactions, manipulation and fraud.
- Privacy & Data: Users should retain control over sensitive information shared between agents, merchants, and payment providers.
- Choice: Consumers should be able to control permissions, payment methods and how much authority an agent receives.
- Interoperability: Systems should work across merchants and payment providers without weakening security or consumer protections.
In practice, that means consumers should know when an AI is acting for them, understand what it is allowed to do, control its permissions, and see a reliable record of instructions, authentication, and transactions if something goes wrong.
For consumers, the practical takeaway is fairly simple: an AI agent should not get a blank cheque just because it can shop on your behalf. The more control an agent has, the more important it is to limit that authority, keep an auditable trail of what it did, and ensure a clear path to challenge a transaction when it gets something wrong.
There is one important catch: these are “voluntary and non-binding” principles, not new regulations. That means much of the protection these banks are calling for still depends on what AI companies, retailers, payment firms, and regulators actually agree to implement.
Other news: ShinyHunters claims it breached FBI systems by exploiting an Oracle PeopleSoft zero-day, allegedly gaining access to internal services and stealing sensitive employee and job applicant data.





