My phone buzzed with an approval ping for a purchase I hadn’t made. You feel that tiny shock—because that ping could be an AI agent spending your money while you sleep. I spent the next hour trying to untangle how a cheerful assistant became a silent spender.
At a suburban bank branch last week, a teller told me customers were frantic about mysterious charges.
Six global banks, including Bank of America and Capital One, have put that panic into paper. Their report, Building Trust in Agentic Commerce, says agentic shopping — AI agents that act on your behalf — carries “risks spanning transparency, safety, privacy & data, choice, and interoperability” that rise when the agents get more autonomy.
Think of a polished assistant that feels helpful but behaves like a shoplifter in a tuxedo: smooth, persuasive, and quietly bending rules. The banks warn those assistants might favor certain products or payment rails because of commission structures or token-cost tradeoffs, not because it’s what you actually want.
Are AI shopping agents safe?
Short answer: not yet. The report flags higher potential for scams, fraud, and disputes as agents act with greater independence. Meta’s Muse assistant — which Shopify planned to use for agentic checkout — recently had a zero-day that could let attackers hijack the agent and exploit any granted permissions. Amazon even asked Muse to stop interacting with its site after concerns about identity and account handling, and that kind of incident illustrates the practical gaps between marketing copy and real-world resilience.
When I asked shoppers in a mall whether they’d let an AI spend their money, most laughed and shook their heads.
You and I both know why: consumers are unclear whether an AI will act in their interest. The banks quote people worried an agent will buy the wrong item, overspend, or hand over account access to a scam. Ron Johnson, the former Apple Stores executive, told TechCrunch he thinks AI will make online research better but won’t change the essential need to physically experience some products — a blunt reminder that product discovery and trust aren’t the same thing.
That mistrust isn’t merely sentimental. It’s practical. If an agent is allowed to pay, reconcile returns, and manage credentials, a single breach or misstep can cascade into lost funds, contested charges, and damaged merchant relationships.
Can AI agents be trusted with payments?
The banks say not until systems, rules, and protections catch up. Agentic commerce can centralize highly sensitive data — payment tokens, account credentials, and transaction histories — and a breach would be costly for both consumers and merchants. They also call out incentive misalignment: an agent might steer you to a product or payment method because it’s cheaper to compute or more lucrative for a partner, not because it’s best for you.
On a conference call between banks and payments firms, the mood shifted from hype to caution.
The consortium doesn’t close the door on agentic commerce — they call it a “promise” that could become a mainstream transaction model. But they put the burden on industry players to build trust through standards, policies, and consumer protections that are currently as brittle as an old password.
The group plans a follow-up paper detailing how to implement five principles — transparency, safety, privacy and data, choice, and interoperability — into practical guardrails. If you work at a merchant, a gateway, or a wallet provider, that document will matter; regulators, too, will be watching how banks and Big Tech reconcile convenience with liability.
I’ve seen the product demos, read the white papers, and watched executives smile onstage. You should be skeptical until the trust scaffolding is in place. Will banks and platforms build protections fast enough to make handing your wallet to an AI feel like progress rather than peril?