
AI agents that can search for products and make purchases on your behalf promise convenience. But some of the world's biggest banks say the technology also creates new opportunities for scams, fraud, data breaches and misuse of personal information.
Imagine telling an AI assistant: “Find me the best Mac under $1,000 and buy it.”
Instead of simply recommending a few models, the AI searches stores, compares prices, selects one, enters your payment information and completes the transaction—all without you visiting the retailer.
This emerging model, known as agentic commerce, could dramatically change online shopping. But giving AI the ability to act—and spend money—also creates an entirely new layer of cybersecurity and privacy risk.
Bank of America, Capital One, ING, NatWest, Commonwealth Bank of Australia and ASB Bank are now calling for common safeguards around the technology. In a new paper on trusted agentic commerce, the banks highlight risks ranging from compromised AI agents and impersonation to payment fraud, excessive data collection and breaches.
AI shopping doesn't necessarily mean giving a chatbot unlimited access to your bank account.
Agentic commerce covers a spectrum of automation. At one end, an AI might find products while you make the final purchasing decision. Further along, you might tell the agent what you want and approve the purchase before it executes it.
At the most autonomous end, an agent could identify a need and make the purchase without asking you again.
The banks warn that risks may increase as agents gain greater autonomy. Unlike traditional ecommerce, these systems can make decisions, enter payment credentials and execute purchases while the customer isn't present.
That raises a fundamental cybersecurity question: What happens if someone manipulates the thing you've authorized to spend your money?
The report warns that agentic commerce could lead to higher rates of scams, fraud and payment disputes.
Some services, for example, could request customers' card information and enter those details directly into websites. Others could steer transactions toward payment methods offering weaker protections.
Criminals, meanwhile, could develop attacks specifically aimed at the agents themselves.
The banks explicitly warn of attackers compromising or impersonating AI agents or merchants, alongside new forms of social engineering.
An attacker who compromises a shopping agent could gain something considerably more powerful than a stolen password: a trusted intermediary that already has permission to act for its owner.
The danger isn't purely theoretical at the architectural level. Agentic payment systems already have to account for threats such as manipulated checkout information and abuse or reuse of payment authorizations. Security guidance for the Agent Payments Protocol (AP2), for example, explicitly treats agents and the language models behind them as potential attackers when designing its threat model.
Authorization therefore becomes critical.
If you ask an AI agent to “buy these groceries every Friday,” does that mean it can spend $50? $500? Can it buy from any merchant? Can it substitute products? Can it change the delivery address? And how long does that permission remain valid?
The banks argue that consumers should be able to see and manage exactly what authority they have delegated to an AI agent. Payment credentials and purchase authorizations should also be handled through secure, auditable mechanisms, with authentication available when necessary.
That could become a key security distinction between ordinary chatbots and agents: a mistaken chatbot answer may mislead you, but an autonomous agent with payment authority can potentially act on the mistake.
There is another problem that doesn't require anyone to hack the AI at all: privacy.
Today's online stores already collect considerable amounts of information about customers. AI agents could produce an even richer trail.
According to the banks, agentic commerce could generate data including conversational prompts, decision logs, purchase intentions and transaction details.
Consider what that might reveal over time.
You might tell an assistant you're looking for an anniversary present for your spouse, medication for an embarrassing problem, baby products before you’ve told friends you're expecting, cheaper groceries when money is tight, or flights because you're planning to leave town.
A traditional retailer may know what you eventually purchased. An AI assistant could potentially know why you wanted it, what alternatives you considered, what constraints you have and what you intend to do next.
That context makes the information particularly sensitive.
The banks identify potential privacy failures such as:
In other words, the question isn't merely whether an AI shopping service can keep your credit card number secure.
Consumers may also need to know what happens to the conversations surrounding a transaction:
The banks' proposed principle is that services and merchants should access only the information needed to perform their functions, while additional uses or sharing should depend on consent.
Agentic shopping also further complicates the answer to one of the oldest questions in payment security: who is responsible when something goes wrong?
If someone steals your card number and makes a fraudulent purchase, established processes exist for investigating and disputing the transaction.
But what if your legitimate AI agent makes a purchase you didn't intend?
What if the agent misunderstands your instructions? What if someone manipulates it? What if a fraudulent merchant deceives the agent rather than you? Or what if the AI technically followed the permission you gave it, but behaved in a way you never expected?
The banks acknowledge that liability remains unclear in parts of the emerging ecosystem. They argue that dispute mechanisms should include all relevant parties, with responsibility reflecting where the error or risk was introduced.
Keeping auditable records of consumers’ instructions to agents, their authentication, the agent’s decisions and the ultimate outcome could be crucial when investigating fraud.
AI agents could make online shopping remarkably convenient. Ask for what you need, set a budget and let software handle everything else.
But consumers should be cautious about how much authority they surrender along the way.
Before allowing an AI service to make purchases, check what permissions it receives, whether spending or merchant restrictions are available, how payment information is handled and whether permissions can easily be revoked. Avoid giving an agent broader access than it needs.
The same principle applies to personal information. Think carefully about what you tell an AI assistant connected to shopping, payments or other accounts. A casual conversation can contain information far more revealing than the transaction it eventually produces.
And continue monitoring bank and card statements even when an agent handles the shopping. Alerts for purchases and unusual account activity can provide an important second line of defense.
On topic:
AI hacks system and accesses personal data in reported breach
SpaceX wants customer data from failed startups as AI fodder
AI hallucinated a nuclear threat. The US military nearly responded
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts