Six of the world's biggest consumer banks have put the AI industry on notice: the shopping agents that OpenAI, Anthropic, Google and Meta are racing to put in front of consumers are moving faster than the safeguards meant to protect the people using them. On Tuesday, NatWest, Bank of America, ING, Capital One, Commonwealth Bank of Australia and New Zealand's ASB Bank jointly published a principles paper, titled "Building Trust in Agentic Commerce," warning that AI agents that buy on a shopper's behalf raise fresh risks of scams, fraud and data-privacy breaches, and that the banks intend to take a set of proposals directly to regulators.

The paper's diagnosis is blunt. "Consumers are unclear if AI will act in their interests," the banks wrote, according to Reuters. "They are concerned that AI agents may buy the wrong thing or spend too much โ€” or even worse, lose their money to scams and fraud. They are not sure whether they will be protected or who they will need to go to if things go wrong."

Card numbers typed into strangers' websites

The most concrete warning concerns how some agents handle payment data today. The banks flagged providers that ask customers for their card details and then key those numbers directly into third-party merchant websites, bypassing the tokenization layers card networks have spent years building. They also warned that agents may steer users toward payment methods that carry weaker consumer protections, and, as Cryptopolitan reported from the paper, may promote products or payment options that earn their providers a larger cut even when those are not the best value for the shopper.

Criminals are the other half of the problem. According to PYMNTS, the report warns that bad actors could compromise or impersonate AI agents and merchants, or develop new forms of social engineering aimed at the software rather than the human. And when a purchase goes wrong, nobody is clearly on the hook. "When things go wrong, there is unclear and inefficient allocation of liability, and disputes processes do not involve all relevant parties across the value chain," the banks wrote.

The group organized its response around five principles: transparency, safety, privacy and data protection, customer choice, and interoperability. The headline proposal for policymakers is disclosure, requiring that every party to a transaction be told when an AI agent is involved and on whose behalf it is acting. The banks also want greater visibility into how agents rank options and reach decisions, including sponsored placements; secure and auditable handling of payment credentials; the ability for consumers to view and revoke the authority they delegate to an agent; and liability that falls where the risk or error was introduced. The principles are voluntary, and the banks say a second paper on implementation will follow.

The traffic is already arriving

The warning lands as agentic shopping moves from demo to real traffic. British retailer John Lewis said this month that searches originating from AI agents had risen to 2.5% of its total, up from 0.3% a year earlier, and that the trend was accelerating, Reuters reported.

Consumers remain far more comfortable letting AI browse than letting it pay. PYMNTS Intelligence research cited alongside the report found that 50% of Americans say they have made a retail purchase with help from AI and 22% begin product research with an AI tool, but just 24% are willing to let an agent both shop and pay. "The change stops as the agent gets closer to the money," that report concluded.

The banks were careful not to cast themselves as opponents of the technology. "Customers need confidence that payments are secure, their data is protected and they remain in control," said Hans Overeem, global head of Payments and Cash Management at ING, adding that the bank was pleased to work with peers "to help establish common principles for transparency, security, privacy and customer choice, and help shape the future of agentic commerce." NatWest Chief Payments Officer Mark Brant struck a similar note: "customers need to trust that they remain in control of how payments are made and that their money is safe."

Why It Matters

Banks sit at the point where an agent's decision turns into money leaving an account, which means they absorb the fraud losses, the chargebacks and the angry customer calls when something breaks. That makes this paper less a philosophical statement than a claim on the rulebook. By asking regulators to mandate agent disclosure and to allocate liability to whoever introduced the risk, the banks are trying to ensure that AI platforms, not card issuers, carry the cost when an agent is fooled by a fake storefront or spends more than its owner intended.

It also builds on work the card networks have already done. Visa and Mastercard have built "know your agent" frameworks to verify which bots are allowed to transact; the banks are now pushing on the layer above that, covering consumer disclosure, decision transparency and dispute handling. The payments industry is signaling that agentic commerce will not scale on screen-scraping and pasted card numbers. For AI labs, that means integrating with bank and network rails rather than working around them.

With members across the US, UK, Europe, Australia and New Zealand, the coalition also hands policymakers in several jurisdictions a ready-made template.

What to Watch

The next milestones are the banks' promised second paper on implementation and their conversations with policymakers, where agent disclosure is the most likely proposal to gain traction first. Watch whether other lenders and payment firms sign on, as the group has invited merchants, technology providers and financial institutions to help turn the principles into standards. The sharpest test will be how the AI companies respond: whether OpenAI, Google, Anthropic and Meta adopt disclosure and credential-handling rules voluntarily, or wait for regulators to impose them, will shape who pays when an AI shopping agent gets it wrong.

“Customers need confidence that payments are secure, their data is protected and they remain in control.”
— Hans Overeem, Global Head of Payments and Cash Management, ING
2.5%
John Lewis searches from AI agents (0.3% a year ago)
6
Banks behind the principles
50%
Americans who bought with AI help
24%
Willing to let an agent shop and pay