Banks including NatWest, Bank of America, ING and Capital One have warned that AI agents making purchases for consumers could increase scams, fraud and data-privacy breaches unless standards and protections catch up.

Technology companies are promoting a future in which a chatbot does more than recommend a toaster. An “agentic” shopping system could search retailers, compare products, choose an offer and complete payment with limited human involvement. That sounds useful because online shopping has somehow turned buying socks into a research project involving fourteen tabs and a newsletter pop-up.

It also means giving software authority over money, identity and card information. The banks’ report says consumers are unsure whether an agent will act in their interests, who is responsible if it buys the wrong product and whether existing protection applies when a transaction goes wrong.

This is not a claim that every AI shopping tool is fraudulent. The banks are stakeholders in the payment system and may also be protecting their position as technology companies enter commerce. Their concerns are nevertheless concrete: agents may request card details and type them directly into websites, choose payment methods with weaker safeguards or be manipulated by scammers.

The technology is already entering British shopping

Reuters reported that John Lewis said searches reaching its website from AI agents rose from 0.3% to 2.5% in a year. That remains a small share, but the increase shows the behaviour is moving beyond demonstrations.

OpenAI, Anthropic, Google and Meta are among companies developing shopping capabilities. Retailers are trying to make their products visible and attractive to the systems that generate recommendations. The familiar battle for the top of a search page is becoming a battle to enter the robot’s shortlist.

Editorial illustration of bank security analysts monitoring AI-commerce transaction alerts

That creates a new conflict of interest. Does the agent recommend the best product for the customer, the retailer paying for prominence, the payment method producing a commission or the service that owns the agent? A friendly conversational answer can hide commercial incentives more effectively than a banner advert labelled “sponsored”.

The banks want disclosure whenever an AI agent participates in a transaction, greater transparency about how decisions are made, stronger data safeguards and freedom for consumers and merchants to choose interoperable services. Those are sensible starting principles, although enforcement will matter more than a badge nobody reads.

What happens when the bot buys badly

Ordinary online purchases contain several relationships: consumer, retailer, marketplace, card issuer, payment processor and sometimes a delivery platform. An autonomous agent adds another actor that may select the seller, accept terms and transmit payment information.

If it orders the wrong size, the answer may be a normal return. If it buys from a fake retailer, reveals card details or chooses a bank transfer that lacks card protections, responsibility becomes much less obvious. The technology company may say it followed instructions; the bank may say the customer authorised payment; the merchant may not exist anywhere beyond a copied logo and an optimistic tracking page.

British consumers have valuable protections for certain card purchases, including potential Section 75 coverage on qualifying credit-card transactions. Chargeback may help in other cases, although it is a card-scheme process rather than the same statutory right. An AI agent should not quietly route a customer away from a protected method because another option is faster or more profitable.

Consent also needs attention. Permission to “find me the cheapest laptop” is not necessarily permission to create accounts, share an address across unfamiliar websites or accept subscriptions hidden in checkout terms. Good systems should set clear spending caps, require confirmation before payment and show the merchant, product, total price, delivery terms and payment method.

How to use shopping agents safely now

Do not give an unproven agent unrestricted access to a primary bank account or store card details in a service whose security and liability terms you have not checked. Prefer tools that stop before payment and let you complete checkout directly with a known retailer.

Use a strong unique password and multi-factor authentication. Set bank alerts and review transactions. Avoid authorising bank transfers to unfamiliar sellers simply because a chatbot found a remarkable price. A remarkable price remains one of fraud’s favourite costumes.

Check who operates the agent, whether recommendations are sponsored, where data is stored and how to revoke access. Keep confirmation emails and screenshots of the agent’s instructions. If something goes wrong, contact the merchant and payment provider quickly.

Retailers have responsibilities too. A checkout should make it obvious when instructions arrive through an automated agent, preserve an itemised record and allow a disputed order to be paused quickly. Banks, technology companies and merchants also need a shared process for tracing what the agent was told, what it decided and what information it transmitted. Without that audit trail, every participant can point elegantly at the next participant while the customer’s money performs the disappearing act.

For more practical digital-safety reporting, visit OutOut’s Technology section.

The OutOut verdict

AI can remove genuine drudgery from shopping. It can compare specifications without becoming emotionally attached to the first product photographed beside a fern. But convenience should not require handing a persuasive autocomplete machine the household card and wishing it personal growth.

The minimum rule is simple: the agent must reveal whose interests it serves, ask before spending, preserve the consumer’s payment protections and leave an audit trail. Until that exists, let the bot research. Keep the final click human.

Sources