Artificial intelligence is beginning to change online shopping from a process controlled directly by consumers into one in which software can search, compare, recommend and eventually purchase products on their behalf. The attraction is clear: an AI agent can process large amounts of information quickly and potentially complete routine purchases with little human involvement. But giving software the authority to make transactions also changes the nature of the risks surrounding online commerce.
Major banks are increasingly concerned that existing fraud controls and consumer protections were designed for transactions initiated by people, not autonomous systems. Banks including NatWest, Bank of America, ING, Capital One, ASB Bank and Commonwealth Bank of Australia have warned that the rapid development of AI shopping agents could create new opportunities for scams, payment fraud and misuse of personal information. Their concern is not that AI shopping itself is inherently unsafe, but that the technology is advancing faster than the rules and security systems needed to control it.
The shift is already becoming visible in online retail. One major British retailer reported that searches originating from AI agents had risen from 0.3 percent to 2.5 percent within a year. Payment companies are also developing systems that allow AI agents to transact using controlled credentials and spending limits. This suggests that agent-based commerce is moving beyond experimentation and towards real financial transactions, making the unresolved security questions more significant.
AI Creates a New Target for Online Scams
The most important difference between conventional online shopping and agent-based commerce is that the person making the purchase may no longer be the system interacting directly with the merchant. An AI agent can interpret a consumer’s request, search multiple websites, compare products and make a selection according to its instructions. That creates another point at which misleading information can influence the transaction.
Fraudsters could potentially exploit this process by creating websites, product listings or offers designed specifically to appeal to AI systems. A fraudulent merchant does not necessarily need to persuade a human shopper if its website can be made attractive to an automated recommendation system. An agent searching for the lowest price, for example, could encounter a fake retailer offering an unusually cheap product and interpret that offer as an attractive result.
This creates a problem because traditional fraud detection often asks whether the person conducting a transaction is genuine and whether that person is authorized to make the purchase. Agent-based commerce introduces additional questions: whether the AI agent itself is legitimate, whether it is acting within the user’s instructions and whether the transaction accurately reflects what the consumer intended.
Security specialists have already identified this as a developing problem. Fraudsters can manipulate online content and commercial information in ways designed to influence automated systems. The result could be a new form of fraud in which both the fraudulent merchant and the shopping process are increasingly optimized through automation.
The danger is particularly serious when the AI agent has permission to complete a purchase without obtaining a separate confirmation at the final stage. A human shopper might notice an unfamiliar website, an unrealistic price or suspicious payment request before pressing a purchase button. An automated system may be less capable of recognizing those warning signs unless such safeguards have been specifically built into it.
Payment Credentials Increase the Consequences
The risks become greater when AI agents are given access to payment information. To make autonomous shopping genuinely convenient, an agent needs some method of completing transactions. That can involve stored payment credentials, virtual cards, payment tokens or other forms of authorization.
The financial industry is therefore developing systems that restrict what an AI agent can do. Virtual payment credentials can be designed with spending limits, restrictions on particular merchants and other controls so that an agent does not receive unrestricted access to a customer’s financial account. These measures can reduce exposure, but they also demonstrate that traditional payment authorization is not sufficient for autonomous transactions.
The central issue is intent. When a person enters card information and confirms a purchase, there is usually a direct connection between the consumer and the transaction. When an AI agent performs the same action, the system may have interpreted a broader instruction made earlier. If the agent purchases the wrong product, selects an unsuitable seller or spends more than the customer expected, determining responsibility becomes considerably harder.
The problem extends to disputes. If a conventional card transaction is unauthorized, consumers generally know which bank or payment provider to contact. With agent-based purchases, several parties may be involved, including the AI provider, the merchant, the payment company and potentially another technology platform connecting the agent to the retailer. Clear rules about liability will therefore become increasingly important as autonomous transactions grow.
Personal Data Could Become More Valuable to AI Agents
Privacy represents another major concern because a shopping agent can become much more useful when it knows more about the consumer. A system that understands previous purchases, preferred brands, household requirements, spending limits and delivery information can make more personalized decisions. But the same information can create a detailed picture of a person’s behaviour.
An ordinary shopping platform may learn what a customer buys from that particular service. An AI agent operating across multiple retailers could potentially observe a much wider range of purchasing activity. If that information is combined with other data available to the agent, the resulting profile could become substantially more detailed than the information held by any individual retailer.
The risk is not limited to intentional misuse. Data can be exposed through weak security, excessive permissions, compromised accounts or poorly controlled connections between AI agents and commercial platforms. Recent disputes between major technology and retail companies over AI agents accessing shopping websites have highlighted concerns about how such systems interact with customer credentials and protected information.
This is why privacy protection cannot be treated as a secondary issue in agent-based commerce. The more authority an AI system receives, the more important it becomes to restrict the information it can access and retain. Consumers need meaningful control over which information an agent can use and which services it can access.
Retailers Are Also Fighting for Control
AI shopping creates a separate commercial problem for retailers because the traditional relationship between search, advertising and purchasing could change. Today, retailers compete for visibility by appearing prominently in search results, advertising products and encouraging consumers to browse their websites. An AI agent could reduce much of that browsing by presenting consumers with a small number of recommendations.
This gives retailers a strong incentive to influence how AI systems evaluate products. If an agent becomes the primary gateway to online shopping, being recommended by the agent could become more valuable than attracting a consumer directly to a website.
That creates another potential source of conflict. Consumers expect an AI shopping agent to act according to their interests, while retailers naturally want their own products to receive attention. If commercial relationships influence recommendations without adequate disclosure, consumers may struggle to understand why one product was selected over another.
The emergence of different approaches among major retailers demonstrates that the industry itself has not reached a common position. Some platforms are developing systems that allow AI agents to complete purchases, while others are restricting autonomous agents from accessing their services. The disagreement reflects unresolved questions about security, commercial control, data access and responsibility.
Consumer Protection Must Catch Up With Autonomous Commerce
The banks’ warning ultimately points to a wider regulatory problem. Existing consumer protection systems were largely developed around transactions in which people directly interact with merchants and payment providers. AI agents introduce an intermediary capable of making decisions and acting on instructions without continuous human supervision.
The solution is unlikely to be simply banning autonomous shopping. The technology could provide genuine benefits by helping consumers compare prices, find products, track orders and complete routine purchases more efficiently. The challenge is creating sufficient safeguards before consumers begin giving AI agents broad financial authority.
Banks have proposed greater transparency when an AI agent is involved in a transaction, clearer information about how agents make decisions and stronger protections for consumer data. These measures address different parts of the same problem: consumers need to know when software is acting for them, what authority it has and who is responsible when something goes wrong.
The development of agent-based payment systems is also creating pressure for stronger identity and authorization standards. A secure system needs to establish not only that a transaction is genuine, but also that the AI agent is acting for the correct person and within the limits that person established.
AI shopping is therefore creating a new stage in the evolution of electronic commerce. The technology is moving the consumer from being the direct operator of a transaction to becoming the person who delegates the transaction to software. That delegation can make shopping faster and more convenient, but it also transfers important decisions to systems that can be manipulated, misunderstood or given excessive access.
The banks’ concerns highlight why fraud protection and privacy safeguards need to evolve alongside the technology rather than after it becomes widespread. The success of agent-based commerce will depend not only on whether AI can find and purchase the right product, but on whether consumers can trust the system with their money, personal information and purchasing authority.
(Adapted from StarNewsGlobal.com)









