A consortium of banks is pushing policymakers for mandatory disclosure rules as agentic commerce tools create new vectors for scams and data breaches.
AI shopping agents, the kind that browse, compare, and buy things on your behalf, are getting good enough that your bank is officially worried. On September 22, 2026, a consortium that includes Bank of America, NatWest, ING, New Zealand’s ASB Bank, and Capital One released a joint report flagging that the rise of agentic commerce tools is creating meaningful new risks around fraud, scams, and consumer data privacy.
The core concern is not that AI shopping bots exist. It’s that they’ve arrived faster than the rules designed to protect people from them.
What the banks are actually saying #
The banks are specifically asking policymakers to require disclosure whenever an AI agent is involved in a financial transaction. Beyond disclosure, the group is pushing for greater transparency in how AI shopping tools make decisions, and for stronger standards around how customer data is handled when these agents are operating.
One of the more specific risks the report highlights involves payment security. AI shopping agents, in their current form, may directly request and enter card details during automated checkout flows, or steer users toward payment methods that are less secure than what they’d choose themselves. The banks also flagged the ambiguity problem: when an AI agent completes a transaction that goes wrong, it’s genuinely unclear who is responsible. Is it the consumer, the platform hosting the agent, the AI developer, or the retailer? Existing consumer protection frameworks weren’t written with that question in mind.
Consumers are enthusiastic but nervous #
Research from the Consumer Bankers Association and Forrester surveys cited in the context of this report found a significant share of people are reluctant to let AI agents complete transactions autonomously. The sticking points are predictable: potential errors, a sense of lost control, and the nagging question of what happens if the bot buys the wrong thing, or worse, exposes payment details to a bad actor.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The banks’ report acknowledges consumer enthusiasm for the category. The concern isn’t that people don’t want this technology. It’s that wanting it and being adequately protected while using it are currently two different things.
Why banks are getting involved at all #
Banks sit at the end of every transaction. When an AI agent facilitates a fraudulent purchase, the dispute lands in the bank’s lap. Fraud costs, chargebacks, and the reputational exposure that comes from customers losing money through products they thought were safe all run through the banking system.
The report positions these banks as participants in ongoing conversations with legislative bodies, not as bystanders waiting for rules to arrive.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our