Mr. Latte News


Banks are starting to worry about AI shopping agents: the hardest problem for agents is authority, not intelligence

This English page is a machine translation of the Korean original, so some phrasing may read awkwardly.

Six banks have issued joint principles and warned of fraud and privacy risks as AI agents begin shopping and paying on people's behalf.

Read the original at Reuters ↗

A chatbot that gets an answer wrong leaves behind bad information. An agent with permission to buy things actually spends my money.

Six banks, NatWest, Bank of America, ING, Capital One, New Zealand's ASB, and Australia's Commonwealth Bank, released joint principles for "agentic commerce" on September 22. Agentic commerce means shopping where AI agents choose products and pay on someone's behalf. Reuters reported that the banks warned about fraud, privacy breaches, and consumer protection.

The risks the banks identified are specific. An agent might take a customer's card details and enter them directly into a website, or steer them toward payment methods with weaker safeguards. The five principles cover transparency, safety, privacy and data, choice, and interoperability.

At British department store John Lewis, the share of search traffic coming through AI agents grew from 0.3% to 2.5% in a year.

That is still a small share, but the pace at which AI is entering the buying process deserves attention.

Should every payment require human approval, then? That would reduce the benefits of having an agent do the shopping.

But "buy whatever suits my taste" cannot be enough to grant unlimited authority, either.

There is no guarantee that AI will always interpret what I mean by a "reasonable price" or a "trustworthy seller."

The solution is to enforce the limits of that delegation in the payment system, rather than trying to get AI to perfectly reproduce my thinking.

For example, someone might say, "Buy a product that meets these conditions by the end of this week for no more than 100,000 won, including shipping. Exclude used items and overseas sellers." The agent finds a product and pays within those limits. If an order falls outside them, it stops and asks again.

Writing those conditions in a prompt is not enough.

Payment tokens or virtual cards for agents need limits on the amount, validity period, and merchants. At payment authorization, the system must check whether the actual order matches the user's instructions.

Visa has made payment tokens for agents available to developers. These replace actual card numbers and come with a feature that checks whether a payment matches purchase instructions authenticated by the user. Stripe's card issuing tool, Stripe Issuing, also lets developers set spending limits and decide in real time whether to authorize a payment.

What happens after the purchase matters, too.

The system needs a connected record of the conditions the user approved, the product the agent chose, and what was actually paid for.

That makes it possible to find the evidence needed for cancellations, refunds, and disputes when something goes wrong.

In March, Mastercard and Google also introduced Verifiable Intent, a technology that links a user's instructions to an agent's payment through a verifiable record. But a cancel payment button alone does not reverse an already authorized transaction. The product also needs to connect to the seller's order cancellation and refund processes.

There seems to be a business opportunity here.

An authorization management service for AI shopping agents.

With a single API, shopping apps and agent developers could store a user's purchase conditions, check the rules just before payment, and request approval only for orders that fall outside those conditions.

Users would see "what was bought and why" and "whether it can still be canceled." The service could start with repeat purchases or small purchases, where clear conditions are easier to set.

Even if card networks and payment providers supply the tokens, someone still has to turn a user's words into enforceable rules and apply them across agents, stores, and payment methods.

The payments industry also sees differing platform protocols, refunds, and dispute handling as problems to solve. That could be an opening for an independent service.

Before giving AI a card, ask these questions.

How much can it decide on my behalf? And who will enforce those limits, and how?

Sources

  1. NatWest Group: Global banks collaborate on principles for trusted agentic commerce, September 22, 2026.
  2. Reuters: Banks warn AI shopping bots raise scam, fraud, data privacy risks, September 22, 2026. The original was cross-checked against the reprint in Global Banking & Finance Review.
  3. Visa Developer: Visa Intelligent Commerce, accessed September 23, 2026.

A question to think about

If AI buys things for me, what should come first: recommendation quality or spending limits?

Get new posts by RSS

Add the feed address to your RSS reader to follow new posts.

Open feed ↗