AI assistants are officially moving from window shopping to swiping your credit card, though exact capabilities still depend on where you live and what platform you use.
The move toward full automation has spooked a coalition of six banking giants, including Bank of America, NatWest and ING, who issued a joint warning that autonomous commerce is leaving current regulations in the dust. The financial sector isn’t worried about algorithms suggesting a nice pair of shoes. The anxiety kicks in when the bot selects the item, chooses the card, fills in the checkout details and completes the purchase completely on autopilot.
UK retailer John Lewis noted in September that AI agents drove 2.5% of its site traffic, compared to 0.3% a year prior. A metric that highlights the immediate challenge: consumers are already sending algorithms to shop for them today, but the policy rulebook on who takes the blame for a rogue transaction is virtually blank.
Where Things Go Wrong
The banking report skips vague industry worries to outline specific ways this tech breaks down.
An algorithm could order the wrong variant, double up on quantities or blow through a budget cap. Scammers could also hijack these tools using fake storefronts, deceptive product data or prompt exploits engineered to fool machine logic. Security drops further if software feeds card details into unvetted checkout flows or picks payment options that strips away buyer protection. Ultimately, this creates authorisation disputes between store and shopper.
This authorisation mismatch is where things get messy. Software can sign off on a payment while the actual cardholder insists, with good reason, that they never clicked buy. According to the banks, consumers will be left playing an impossible guessing game over who is on the hook when an automated transaction goes wrong, with no legal clarity to sort it out.
More from Artificial Intelligence
- The Gender Gap In AI Adoption May Be About Caution, Not A Lack Of Interest
- What Are The Real-World Risks Of AI Hallucinations?
- If OpenAI Goes Public, Will That Validate Or Burst The AI Bubble?
- Experts Comment: What If AI Isn’t The Threat To Education We Think It Is?
- Healthcare Isn’t Europe’s Biggest AI Adopter, But It Is Seeing The Best Returns
- Quite Contrary: AI Will Replace Certain Jobs, According To Philip Huthwaite
- UK SMEs Have Increased AI Spend By 1,000% – But Is It Actually Paying Off?
- UK Startups Are Stuck Between ChatGPT Demos And Production AI
So Who’s Actually Liable?
There’s no unified rulebook for who takes the financial hit when an AI shopper goes rogue. Blame will depend on context: whether spending limits were respected, whether platforms spotted the fraud or where credentials were stored.
The real trouble is that software mediation turns the clean separation between authorised payments and fraud into a grey area. A user might give an agent permission to buy essentials, only for the bot to pick a dodgy merchant, inflate the cost or choose a payment route the user hasn’t signed off on.
Why Banks Are Worried About This More Than Tech Companies Are
Big tech loves to paint agentic commerce as a bulletproof shopping miracle where algorithms scout products and settle checkouts in seconds, while merchants are rushing to optimise their stores for bot eyes.
Banks see things differently because they pick up the tab when everything goes wrong. They fund fraud investigations and refund claims, often covering losses triggered by security lapses at third-party AI platforms or marketplaces they have no ties to.
Worse still, traditional visibility dissolves here. While standard card processing offers clear audit trails, an AI purchase ropes in a lengthy lineup of intermediaries including the user, agent vendor, retailer, marketplace and payment processor. This complexity buries the truth about whether a transaction was legitimately approved or manipulated. Since existing dispute protocols can’t rope in every party involved, banks are sounding the alarm for definitive rules before machine-driven shopping takes over completely.
Banks aren’t against AI shopping, especially since their own data shows customers are keen to use it. Instead, they’re pressing for a pragmatic timeline: building protections while the technology scales up, instead of scrambling to clean up the mess after major fraud hits.
Their proposed safety checklist is refreshingly practical: mandatory bot name tags, clear insight into how algorithms make purchasing choices, tighter data security, clear rules on who pays when things go south, dispute networks that actually rope in every company involved, interoperability so agents from different providers don’t operate in closed loops, and, importantly, an easy way to pull an agent’s access the moment you stop trusting it with your card.
