Banks are moving to put guardrails around AI shopping agents before they become a mainstream way to pay online, warning that the technology could amplify fraud, privacy breaches and disputes over who is liable when something goes wrong.
Banks Push Rules for AI Shopping Agents

The intervention matters because agentic shopping could shift more of the checkout process away from consumers and merchants toward opaque software intermediaries that can handle card data, choose payment routes and make purchases autonomously. That raises the stakes for payment security, customer consent and data governance at a time when technology companies are racing to turn AI assistants from search tools into commerce engines.
In a report released by a group including NatWest, Bank of America, ING, ASB Bank and Capital One, banks said consumers were enthusiastic about AI-enabled shopping but did not know whether the agent would act in their best interest. They warned that shoppers could end up buying the wrong product, spending too much, or losing money to scams if agents are manipulated by bad actors or direct users to weaker payment protections.
The lenders also highlighted a more structural concern: AI agents may request card details and enter them directly into websites, increasing the risk of credential theft and making it harder for banks and card networks to distinguish legitimate purchases from fraud. That is a familiar risk in digital payments, but one that could become harder to manage if software agents initiate transactions at scale and across platforms.
The banks want policymakers and industry groups to consider new rules, including mandatory disclosure when an AI agent is involved in a transaction, clearer transparency over how these systems make decisions, stronger security standards for customer data and interoperability between competing e-commerce AI systems. They also argued that consumers and merchants should retain the freedom to choose which AI commerce services they use, a signal that banks do not want a few large tech platforms controlling the plumbing of online shopping.
For investors, the issue lands at the intersection of payments, e-commerce and AI infrastructure. Financial institutions such as JPMorgan, Bank of America and Capital One have strong incentives to shape the rules early, because higher fraud rates can lift chargebacks, compliance costs and losses tied to unauthorized transactions. Payment processors and wallets including PayPal also face the prospect of more friction and more expensive risk controls if AI shopping grows without clear standards. On the other side, Amazon and other online merchants could benefit if AI agents drive more checkout volume, but they would also bear the cost of answering disputes, protecting customer data and proving that purchases were authorized.
There is already evidence that the shift is beginning. John Lewis said in September that searches from AI agents had risen to 2.5% from 0.3% a year earlier, a rapid change from a tiny base that suggests early adoption is accelerating. That is still small in absolute terms, but it shows retailers are already competing to influence chatbot recommendations, setting up a broader contest over who controls product discovery and the transaction itself.
The policy debate is likely to intensify as AI commerce moves from novelty to routine. Banks are effectively arguing that the rails of online shopping need the same kind of trust framework that underpins card payments and open banking: clear authorization, traceability and liability. Whether regulators adopt those principles quickly will help determine whether AI shopping bots become a convenience layer or a new vector for fraud.
| Entity | Gains | Losses |
|---|---|---|
| Banks | ▲stronger controls | ▼higher fraud risk |
| Consumers | ▲faster shopping | ▼privacy exposure |
| Tech platforms | ▲more commerce data | ▼tougher regulation |
| Merchants/payments firms | ▲potential volume growth | ▼more disputes and costs |

