+
AI shopping agents are about to move the most important moment in digital commerce away from the visible checkout page and into an invisible chain of software permissions. That shift can make buying faster. It can also make a disputed transaction much harder to explain, because the person, the agent, the merchant, the bank and the payment network may each hold a different version of what was authorized.
A group of major banks has now put that problem into unusually direct language. NatWest, Bank of America, ING, Capital One, Commonwealth Bank of Australia and ASB Bank warned that autonomous shopping tools could increase scams, fraud and data privacy failures unless standards and consumer protections catch up. Their concern is not that artificial intelligence can recommend a bad pair of shoes. It is that an agent may receive payment credentials, choose a merchant, select a payment method and complete a purchase while the consumer is absent from the final decision.
The immediate headline is about safety. The deeper financial story is about control. In ordinary electronic commerce, the checkout concentrates evidence. A customer sees the product, price, merchant and payment method, then confirms the purchase. Agentic commerce separates those steps across systems and time. The instruction might be given in the morning, the product selected in the afternoon and the payment executed after a price condition is met. The financial system must prove that the completed transaction still matches the original intention.
This creates a new competitive layer between the consumer and every merchant. The company that controls the agent can influence what is discovered, which offers are compared, how consent is collected, which payment rail is preferred and what evidence survives a dispute. AI shopping agents therefore do not simply automate checkout. They turn authorization, liability and distribution into software architecture.
The banking warning is arriving before mass adoption
The banks’ intervention matters because their role begins after a recommendation becomes a financial claim. A technology company can optimize for a completed task. A bank must decide whether the transaction was authorized, whether fraud controls were applied and whether the customer is entitled to reimbursement. Those obligations make financial institutions sensitive to ambiguity that may look harmless during a product demonstration.
Reuters reported on September 22 that the bank group wants disclosure when an agent participates, clearer explanations of how recommendations are made, stronger data safeguards, consumer choice and interoperability. The report also highlighted a practical warning: an agent might request card details directly or steer a user toward a payment method with weaker protections.
That distinction is essential. Two purchases of the same item at the same price can leave the consumer with different rights depending on whether payment uses a card, a bank transfer, a wallet balance or another rail. A recommendation engine that ranks payment methods is therefore making a risk allocation decision, even if the interface describes it as convenience.
The commercial trend is already measurable at the discovery stage. Reuters cited John Lewis saying that searches originating from AI agents had risen from 0.3 percent to 2.5 percent within a year. Search traffic is not completed spending, and the figure comes from one retailer. Yet the direction is important. Agents are beginning to influence the top of the purchasing funnel before the payment standards needed at the bottom are fully settled.
The transition resembles the earlier migration from browser checkout to mobile wallets, but the agency is different. A wallet generally stores credentials and waits for a person to approve a transaction. As MIT Sloan’s explanation of agentic systems makes clear, an agent can plan and act with limited supervision. In commerce, that means it can interpret a goal, search across sellers, negotiate constraints and decide when a purchase qualifies. The payment instrument is no longer only stored inside software. It is exposed to software judgment.
An agentic purchase contains five separate decisions
The phrase “the agent bought it” compresses a long sequence into one sentence. A reliable system needs to preserve at least five distinct decisions.
- Intent. What did the consumer actually request? “Buy a safe child seat” is not the same instruction as “buy model X from merchant Y for no more than a stated amount.”
- Delegation. Which choices may the agent make without returning to the consumer? That can include seller, color, delivery speed, substitution and price tolerance.
- Authentication. How does the system prove that the person granting authority controls the relevant account and payment credential?
- Execution. Which merchant, item, price, payment method and delivery terms were ultimately selected?
- Evidence. What durable record connects the original intent to the completed payment if the consumer later disputes it?
Conventional checkout often handles these decisions in a compressed human session. The shopper is authenticated, sees a cart and clicks a button. Agentic commerce can distribute the same decisions across multiple agents, merchant systems and payment providers. Every handoff creates a point where meaning can change.
Suppose a customer asks an agent to buy noise cancelling headphones under a fixed budget from a reputable seller, with delivery before a flight. The agent finds an unfamiliar marketplace seller offering a lower price and faster delivery. Is that within the mandate? The answer depends on what “reputable” meant, which evidence the agent used and whether the consumer delegated seller selection. If the headphones are counterfeit, the dispute is not only about payment authorization. It is also about whether the agent fulfilled a qualitative instruction.
This is why Google’s Agent Payments Protocol uses signed mandates. An intent mandate can specify price limits, timing and other conditions before the person leaves the transaction. A later cart mandate captures what the merchant is actually offering. The design attempts to create a cryptographic bridge between an open ended request and a specific purchase.
The protocol addresses a real weakness in existing payment messages. Card networks are excellent at transmitting an amount, merchant identity and credential. They are not designed to explain the natural language instruction that caused a machine to choose that merchant. Agentic commerce needs both layers: payment authorization and proof of delegated intent.
Authentication cannot prove that the agent made a good decision
A common error is to treat authentication as a complete answer. Strong authentication can show that a consumer approved an agent, enrolled a credential or confirmed a particular transaction. It cannot prove that the agent correctly interpreted the instruction.
This separates identity risk from decision risk. Identity risk asks whether an attacker took control of the account or credential. Decision risk asks whether authorized software bought the wrong product, exceeded a hidden preference or selected an unsafe seller. The second category can exist without any account takeover.
Visa’s infrastructure illustrates how payment networks are adapting. The Visa Intelligent Commerce developer documentation describes agent specific payment tokens and controls intended to align purchase actions with authenticated user instructions. Tokenization can prevent an agent from receiving the underlying card number and can restrict the credential to a defined context. That reduces credential theft and makes an agent easier to revoke.
Tokenization does not decide whether the chosen product was appropriate. It proves that a particular agent used a constrained payment credential. The distinction matters for liability. If a criminal steals a token and uses it outside its permitted scope, the control failed. If the authorized agent uses the token within scope but purchases an unsuitable product, the payment control may have worked exactly as designed while the commercial outcome still failed.
A mature system therefore needs layered consent rather than a single approval switch. The consumer should be able to define monetary limits, merchant categories, geography, delivery windows, substitution rules and conditions that always require fresh confirmation. The agent should not infer unlimited financial authority from permission to search.
This is also why transaction level visibility must remain available. A customer needs a readable explanation of what the agent chose and why. A bank needs machine readable evidence that the agent was authorized. A merchant needs proof that the presented credential was valid. These are related records, but they are not interchangeable.
Fraud liability will follow the quality of the evidence
Agentic commerce will produce new arguments around an old question: who should bear the loss when a transaction goes wrong? The answer will depend less on whether artificial intelligence was involved than on what each participant could observe and prevent.
If an attacker impersonates the consumer and enrolls an agent, the failure resembles account takeover. If a legitimate agent is manipulated by a malicious product page, the failure resembles a corrupted decision process. If the merchant misrepresents the item, existing chargeback and consumer law concepts may still apply. If the agent ignores a clear spending limit, the agent provider may face a direct claim. If the bank authorizes a payment after risk signals should have triggered a block, the issuer’s controls become relevant.
These cases require a common audit trail. Without one, every party can present a technically accurate but incomplete story. The agent can show a user instruction. The merchant can show a valid token. The issuer can show successful authentication. The consumer can show that the delivered item violated the request. Liability becomes expensive when evidence is fragmented.
The open AP2 documentation identifies authorization, authenticity and accountability as core problems. Its use of verifiable credentials is economically important because it can lower the cost of resolving disputes. A signed mandate does not prevent every error, but it can establish which constraints existed and whether the final cart matched them.
That can change fraud economics. Payment networks invest heavily in scoring transactions because fast authorization reduces losses and false declines. Agentic commerce adds behavioral information that could improve those models. A payment message might indicate whether the user was present, whether the agent acted under a standing mandate, how narrowly the merchant was authorized and whether the final purchase required confirmation.
The same information can create privacy risk. A detailed mandate may reveal preferences, timing, health needs, travel plans or household routines. The best fraud evidence is often the most sensitive commercial data. Systems need to prove that conditions were satisfied without exposing the entire conversation to every participant. The reserve and access questions discussed in our analysis of MiCA’s stablecoin reserve rule show the same broader principle: changing the payment instrument never removes risk, but relocates it across balance sheets and institutions.
This is one reason banks are asking for safeguards before volume becomes large. Once merchants and agents build around a convenient but weak evidence model, improving it becomes costly. The industry learned this lesson from card security, identity verification and online advertising. Standards adopted early can prevent a market from normalizing avoidable risk.
Recommendation bias becomes a financial conflict
An AI shopping agent appears to work for the consumer. Its economics may point elsewhere. Retailers can pay for placement, platforms can favor preferred partners and payment providers can subsidize the rail they want the agent to choose. If these incentives are not visible, the agent can turn a purchasing mandate into a distribution auction.
Traditional search advertising at least separates many sponsored results from organic results. An autonomous agent may return only one answer. The consumer sees the outcome rather than the ranking process, which makes disclosure more important and more difficult.
The conflict has three layers. First, the agent can influence which merchant wins. Second, it can influence which payment method funds the transaction. Third, it can shape post purchase behavior, including returns, warranties and subscription cancellation. A provider that controls all three can collect fees at multiple points while claiming to optimize convenience.
This is not merely an antitrust concern. It changes expected losses for banks and consumers. A payment method with weaker dispute rights may be cheaper for the merchant or agent platform. A seller with higher commissions may receive more visibility despite greater fraud risk. The software’s commercial objective can therefore determine the financial protection attached to the purchase.
The experience of digital wallets offers a useful comparison. Our analysis of Apple Pay’s India distribution challenge showed that acceptance, regulation and local payment habits can matter as much as technology. Agentic commerce adds another gatekeeper above the wallet. The winning payment method may be the one most easily invoked by agents, not the one most familiar to consumers.
Data compounds the advantage. An agent that sees the consumer’s conversations, calendar, email, location and spending history can make better recommendations than a merchant that sees only a visit. That can improve relevance. It can also make switching harder because the most valuable asset is not the payment token. It is the accumulated context used to interpret intent.
The checkout becomes a contest over standards
Payment networks understand that the new layer can either reinforce their position or route around it. Visa has described Intelligent Commerce Connect as a network and token vault agnostic connection for agents, merchants and commerce platforms. Google has positioned AP2 as an open protocol. Mastercard, wallets, processors and identity providers are building related capabilities.
The strategic prize is not one shopping application. It is the grammar used by machines to describe consent, carts, credentials and disputes. A standard that becomes widely adopted can influence which evidence merchants accept and which controls issuers expect.
Interoperability is therefore both a safety issue and a market structure issue. A consumer should be able to use one agent without being forced into a single payment provider. A merchant should not need a separate integration for every agent. A bank should be able to assess risk using consistent signals. If one platform controls the entire chain, it can improve coordination while also creating dependence.
The tension resembles the settlement problem explored in our analysis of Circle’s Arc network and USDC settlement. Infrastructure becomes strategically powerful when it defines the asset, transaction rules and access path at the same time. Agentic commerce can produce a similar concentration around identity and intent rather than around the settlement asset.
Open standards do not automatically guarantee open markets. Implementations can differ, certification can become restrictive and the largest platforms can shape extensions. Yet open mandates provide a better starting point than proprietary records that a consumer or bank cannot independently verify.
Who gains and who absorbs the new cost
| Participant | Potential gain | New risk or cost | Evidence it needs |
|---|---|---|---|
| Consumer | Less search and checkout friction | Wrong purchase, overspending, privacy loss | Readable mandate, reasons and revocation history |
| Agent provider | Control of discovery and transaction flow | Liability for interpretation and steering | Signed intent and decision log |
| Merchant | Higher conversion and access to automated demand | Bot fraud, returns and platform dependence | Verified agent identity and cart approval |
| Bank or issuer | More contextual fraud signals | Ambiguous authorization and dispute cost | Token scope, authentication and mandate match |
| Payment network | New token and trust services | Pressure from alternative rails and standards | Interoperable transaction credentials |
The table shows why adoption will not be driven by convenience alone. Every participant gains efficiency only if evidence reduces the new disputes created by delegation. Otherwise the system converts time saved at checkout into cost spent on complaints, fraud reviews and returns.
Merchants may face a particularly difficult tradeoff. Agents can deliver customers with strong purchase intent, but they can also weaken the merchant’s direct relationship. Brand design, loyalty programs and cross selling matter less when a machine compares products through structured data. Retailers may need to optimize for agent readability while protecting themselves from automated scraping, fake agents and manipulated demand.
Banks could become more valuable because consumers trust them to resolve errors. They could also be pushed into a narrow funding and dispute role while technology platforms control discovery. The warning from the bank group is therefore both a consumer protection intervention and a strategic claim: regulated institutions want a voice in the standards governing delegated spending.
The privacy dimension connects with our analysis of TikTok’s privacy settlement as a governance test. Compliance cannot be reduced to a promise that data is secure. It requires limits on collection, use, sharing and retention. An agent may need rich context to perform well, but the payment network does not need the entire context to authorize a purchase.
Three scenarios for agentic commerce
Scenario one: tokenized agents become a normal wallet feature
In the constructive scenario, payment networks and open protocols converge on a common model. Consumers create agent specific tokens with clear limits. Merchants receive proof that a purchase matches a signed mandate. Banks see whether the user was present and which constraints applied. Disputes use a shared audit trail.
Adoption grows first in low risk, repetitive categories such as groceries, household supplies and travel rebooking. Consumers retain confirmation for unusual merchants, large purchases and regulated products. The agent becomes another controlled interface to existing payment rails rather than an unbounded financial actor.
This outcome favors large networks because they already connect issuers and merchants, but it also gives specialist agents room to compete. The key is portability. A consumer can change agents without reentering raw card details or losing all transaction protections.
Scenario two: platforms build closed commerce loops
In the concentration scenario, major technology platforms combine the agent, marketplace, wallet and advertising system. Purchases are smooth because one company controls identity, recommendations and payment. Merchants accept the system to reach demand, while banks receive only the final transaction.
Fraud may be manageable inside each closed loop, but competition weakens. Sponsored recommendations become difficult to distinguish from independent advice. Smaller merchants pay for access. Alternative payment methods struggle to appear. Consumer context becomes a durable moat.
This outcome could trigger regulatory intervention around disclosure, data portability and self preference. It would also increase operational concentration. An outage or policy change at one agent platform could affect discovery and payment across many merchants at once.
Scenario three: fraud and disputes slow autonomy
In the cautious scenario, early systems generate enough wrong purchases, scams and unclear disputes that banks restrict agent initiated payments. Consumers must confirm most transactions. Merchants treat autonomous traffic as higher risk. Insurers and processors charge more for weak evidence.
Agentic commerce still develops, but as assisted shopping rather than autonomous buying. Agents compare products and prepare carts while people remain present for payment. The convenience gain is smaller, yet the legal and operational model stays closer to conventional checkout.
This would not represent a failure of the technology. It would show that delegated financial authority requires more than capable models. Trust grows when controls, incentives and liability are understandable.
What would invalidate the central thesis
The argument that agentic commerce creates a new liability layer would weaken if consumers continue to approve every material purchase in real time. In that case, agents improve search and cart preparation without taking meaningful payment authority. Existing wallet and card protections would remain central.
The thesis would also weaken if a common mandate standard becomes widely adopted before autonomous volume grows. Strong, portable evidence could make agent initiated transactions easier to resolve than ordinary online payments. Banks might then treat agent context as an improvement rather than a new ambiguity.
A third invalidation would come from merchant behavior. If leading retailers refuse autonomous checkout and require direct confirmation, agents may remain discovery tools. John Lewis traffic would then indicate a new referral channel, not a new payment architecture.
Investors and operators should watch four indicators. The first is the share of agent traffic that reaches completed purchases. The second is whether issuers distinguish agent initiated transactions in authorization and dispute data. The third is whether standards support portable mandates across agents and networks. The fourth is who pays when an authorized agent makes an incorrect choice.
Loss allocation will reveal the real market structure. If consumers absorb most errors, adoption may face a trust ceiling. If agent providers offer strong guarantees, their cost of capital and fraud controls become important. If banks and networks absorb losses, they will demand greater control over agent enrollment and transaction evidence.
The Block2Learn assessment
AI shopping agents are likely to become useful because search is expensive. Consumers already delegate product discovery to marketplaces, review systems and recommendation engines. Allowing software to complete a tightly constrained purchase is a logical next step.
The mistake would be to treat permission as a one time consent screen. Delegation must be narrow, inspectable and revocable. A secure credential should identify the agent, limit its authority and preserve proof of the consumer’s constraints. Recommendation incentives should be disclosed. Payment protections should not silently weaken because an agent chose the rail.
The strongest architecture separates roles. The agent interprets the goal. The merchant commits to the cart. The consumer or standing mandate approves defined conditions. The payment network tokenizes the credential. The bank evaluates financial risk. No single participant needs the entire conversation, and no participant should be able to rewrite the evidence after the transaction.
This structure will not eliminate disputes. It can make them cheaper and fairer. The relevant question is not whether the agent acted autonomously. It is whether every action can be traced to authority that a person could understand before granting it.
Agentic commerce therefore moves the competition beyond model quality. The winning systems will not merely find products quickly. They will demonstrate that delegated intent survived recommendation, checkout and payment without becoming someone else’s commercial objective.
The banks’ warning is timely because standards are still fluid. Once a payment architecture scales, convenience makes it difficult to reverse. Building transparent mandates, scoped tokens and portable evidence now is less expensive than repairing consumer trust after autonomous spending becomes normal.
The bot may soon hold the card. The consumer must still hold the authority.
Continue through the Block2Learn Learning Path
Understanding agentic commerce requires more than following product announcements. It requires a working knowledge of digital payments, tokenization, fraud controls, platform incentives, data governance and market concentration.
The Block2Learn Learning Path develops those foundations in sequence. Free Start introduces the language of markets and technology. Foundation builds the principles of risk and capital allocation. The Investor Operating System turns those principles into a repeatable method for evaluating uncertain systems. The Crypto Layer extends the analysis into wallets, settlement networks and programmable value.
The objective is not to predict which shopping agent wins. It is to identify where authority sits, which participant captures the economics and who absorbs the loss when the software is wrong. Information is abundant. Structure is rare.
This article is provided solely for informational and educational purposes and does not constitute financial or investment advice, a recommendation, or an offer or solicitation to buy or sell any financial instrument or digital asset. See our Financial Disclaimer.
This article was generated with the support of AI and reviewed by the Editorial Team. For more information, see our Terms of Service.

