← All posts / Industry

Six Global Banks Draw a Red Line Around AI Shopping Agents

NatWest, Bank of America, ING, ASB, Capital One and Commonwealth Bank warn that agentic commerce is outpacing consumer protections — and they want mandatory disclosure when an AI bot touches a transaction.

Six Global Banks Draw a Red Line Around AI Shopping Agents

The world’s biggest AI labs are racing to turn chatbots into checkout buttons. On Tuesday, six major banks on three continents fired back with a warning: the race is moving faster than the guardrails.

NatWest and Bank of America, joined by ING, New Zealand’s ASB Bank, US lender Capital One and Commonwealth Bank of Australia, published a report arguing that deploying AI agents for online shopping could heighten the risk of scams, fraud and data-privacy breaches — and they set out a set of principles for developing the technology responsibly.

The collision course

Technology companies including OpenAI, Anthropic, Google and Meta are increasingly promoting AI chatbots as shopping tools, envisioning a future in which shoppers delegate product selection and even the purchase itself to an AI agent acting on their behalf. Retailers, meanwhile, are racing to influence chatbot recommendations, treating the agent as the new storefront shelf.

The consumer signal suggests this is no longer speculative. British retailer John Lewis reported in September that search traffic originating from AI agents had risen to 2.5% of the total, up from 0.3% a year earlier — an eightfold increase, and accelerating. When almost one in forty searches at a century-old department store starts inside a chatbot, agentic commerce has left the demo stage.

The banks acknowledge this enthusiasm. Their report notes that customers are keen to adopt agentic commerce, and the institutions themselves have every commercial incentive to enable it. But they warn that the technology is advancing faster than industry standards and consumer protections — a gap that historically has been filled by fraudsters first and regulators second.

“Consumers are unclear if AI will act in their interests”

The report’s bluntest language is reserved for the trust deficit. “Consumers are unclear if AI will act in their interests,” it states. “They are concerned that AI agents may buy the wrong thing or spend too much – or even worse, lose their money to scams and fraud. They are not sure whether they will be protected or who they will need to go to if things go wrong.”

That last clause is the legally dangerous one. When a human clicks “buy,” liability chains are well understood: card networks, chargeback rules, consumer protection law. When an autonomous agent completes a transaction under opaque instructions, every link in that chain becomes an argument. Was the agent acting on the customer’s intent? Who vouches for the agent’s identity? If it was impersonated or manipulated, whose loss is it?

The specific hazards the banks flag are concrete rather than hypothetical. One: AI agents soliciting customers’ payment card details and entering them directly into websites — turning the agent into an uncontrolled intermediary holding raw credentials. Two: agents steering shoppers toward payment channels that offer weaker protections, the digital equivalent of being walked to the alley behind the store.

What the banks want

The coalition plans to take a series of proposals to policymakers. The headline measure is mandatory disclosure when an AI agent is involved in a transaction — a “bot was here” flag that would let banks, merchants and regulators distinguish human purchases from delegated ones in real time.

They are also calling for greater transparency over how AI agents make decisions, and for safeguards protecting customer data flowing through agent ecosystems. Two further principles aim at market structure rather than fraud: consumers and merchants should remain free to choose which AI-powered e-commerce services they use, and different agent systems should be interoperable — a pointed rejection of any future in which one lab’s assistant holds a tollbooth position over commerce.

Why this lands now

The banking intervention arrives at a moment when agentic commerce is being pushed hard from both sides of the transaction. OpenAI and its peers are shipping shopping-capable agents; payment networks have spent the past year building agent-to-agent protocols; retailers are optimizing for chatbot visibility the way they once optimized for search engines. Everyone is building the machinery. Almost nobody has answered the question the banks just asked: who pays when the machinery misfires?

It is also a turf assertion. Banks sit on the loss data, the fraud models and the regulatory relationships. By publishing principles before regulators write rules, the six institutions position themselves as co-authors of the coming regime rather than subjects of it — and implicitly put the AI labs on notice that consumer protection will not simply be a prompt-engineering problem.

The likeliest near-term outcome is exactly what the report is designed to produce: a seat at the table when disclosure mandates and agent-identity standards get drafted. The John Lewis numbers suggest the table needs to be set quickly. Agentic commerce grew eightfold in a year at one retailer; fraud tools, refund rules and disclosure regimes do not move nearly that fast.

For the AI industry, the message from the world’s payment custodians is uncomfortable but simple: bots that shop are welcome, bots that shop in the dark are not.