Hero image for Major Banks Warn AI Shopping Bots Enable New Scams
By AI Tool Briefing Team

Major Banks Warn AI Shopping Bots Enable New Scams


On September 22, six major banks — NatWest, Bank of America, ING, Capital One, New Zealand’s ASB Bank, and Commonwealth Bank of Australia — published Building Trust in Agentic Commerce, a joint paper warning that AI shopping agents fraud risk is growing faster than the rules built to catch it. Not “someday might be a problem.” Now. According to the banks’ announcement, some agents are already typing customers’ card numbers straight into checkout pages — including pages that turn out to be phishing sites — with no human in the loop to notice something’s wrong.

Six months ago, we covered Shopify’s agentic storefronts going live inside ChatGPT, Gemini, Copilot, and Google AI Mode as a genuine breakthrough — full purchase flows completing inside a chat window, no browser tab required. We wrote about what it meant for merchants, for Google’s ad business, for the shape of the funnel. We did not ask who eats the loss when the agent gets it wrong. Six banks just asked that question, together, in public.

Quick Summary: What Happened

DetailInfo
AnnouncedSeptember 22, 2026
WhoNatWest, Bank of America, ING, Capital One, ASB Bank, Commonwealth Bank of Australia
WhatJoint principles paper, “Building Trust in Agentic Commerce”
Core warningAI shopping agents are outpacing fraud, liability, and data-privacy protections
Sharpest risk flaggedAgents entering card details directly into storefronts, including phishing sites, with the customer cut out of the loop
StatusVoluntary principles, not regulation. Banks plan to bring proposals to policymakers and publish a second paper on implementation

Bottom line: The same agentic-checkout capability this site covered as a distribution win in March is now the subject of a coordinated bank warning about scams, unclear liability, and data exposure — and nobody has actually fixed any of it yet.

What Actually Happened

Six banks don’t coordinate a joint publication on a whim. Building Trust in Agentic Commerce lays out five principles the banks say need to exist before agentic commerce can be trusted at scale: transparency, safety, privacy and data protection, customer choice, and interoperability. Reasonable-sounding, almost boilerplate — until you read what prompted them.

The specific failure mode the banks are worried about: an AI shopping agent enters a customer’s saved card details into a merchant’s checkout flow on the customer’s behalf. That’s the entire pitch of agentic commerce — no manual re-entry, no friction. It’s also, per the banks, a problem the moment the “merchant” is actually a spoofed storefront designed to look like one. A human might pause at a URL that looks slightly off. An agent optimizing for “complete the purchase” has no particular reason to.

Hans Overeem, ING’s global head of Payments and Cash Management, put the ask plainly: “Customers need confidence that payments are secure, their data is protected and they remain in control.” Mark Monaco at Bank of America framed the harder problem underneath that: “Building confidence among consumers, merchants and financial institutions will require thoughtful approaches to identity, authorization, fraud prevention, liability management and customer protection.” Five nouns in that sentence, and liability is the one nobody has actually solved.

That’s not a rhetorical concern. Per the banks’ own reporting on the launch, “when things go wrong, there is unclear and inefficient allocation of liability, and disputes processes do not involve all relevant parties across the value chain.” Translation: if an agent gets phished, or a merchant’s agent-facing API gets spoofed, or a purchase decision goes sideways, there’s no settled answer for whether the bank, the AI platform, the merchant, or the customer is on the hook. Chargeback rules were written for a human tapping “confirm.” Nobody wrote the version for an autonomous agent doing it instead.

Which Banks Signed the Warning?

  1. NatWest — UK retail and commercial bank, co-author of the principles paper.
  2. Bank of America — largest US bank by assets in the coalition; Mark Monaco represented BofA in the announcement.
  3. ING — Dutch multinational bank; global head of payments Hans Overeem is the paper’s most-quoted voice.
  4. Capital One — US card issuer, adding a payments-fraud angle given how much of agentic commerce runs through stored card credentials.
  5. ASB Bank — New Zealand’s third-largest bank, the coalition’s only non-US/UK/EU/Australia voice.
  6. Commonwealth Bank of Australia — Australia’s largest bank by market cap, rounding out a genuinely global six-bank coalition.

That spread matters. This isn’t one nervous regional bank. It’s institutions across four continents converging on the same warning independently enough to co-author a paper about it.

Why This Matters

Consumer appetite for agentic shopping is already real, which is exactly what makes the timing of this warning uncomfortable. Survey data cited alongside the banks’ report and reported by PYMNTS found that half of American consumers say they’ve made a retail purchase with some kind of AI assistance, and 22% now start their product research with an AI tool. But only about 24% said they’d trust an agent to handle both the shopping and the paying, autonomously, without them watching. Note that gap: people are fine letting AI do the browsing. They get nervous the moment it reaches for the wallet. That’s a US consumer survey, not a global one — the gap could look different in markets with stronger built-in payment protections, but the shape of the hesitation (research: yes, payment: not yet) tracks with what you’d expect from any new payment rail.

The volume is real too. British retailer John Lewis reported, per Reuters coverage picked up by Yahoo Finance, that search traffic arriving from AI agents rose from 0.3% to 2.5% of its total over the past year. That’s roughly an eightfold jump at one retailer, in twelve months, for a channel that functionally didn’t exist as a meaningful line item a year ago. Multiply that trajectory across every Shopify merchant now running agentic storefronts, and “we’ll figure out the fraud model later” stops being a reasonable posture.

This is also where the March story and the September story connect directly. Agentic checkout was sold as friction removal — the entire value proposition is that the agent skips the steps a human would normally slow down for. Compare a browser session, where you’d notice a shipping address that got auto-filled wrong, to an agentic one, where the human isn’t watching the screen at all. Every step a human would have paused on to catch a mistake, a scam, or a bad address is a step the agent now completes without asking. The banks aren’t objecting to that convenience. They’re pointing out that removing friction and removing the fraud checks that lived inside that friction turned out to be the same move.

What Are the Banks Proposing to Regulators?

  1. Mandatory disclosure — consumers should be told, explicitly, whenever an AI agent is the one executing a transaction on their behalf, not just recommending one.
  2. Transparency into agent decision-making — some visibility into why an agent picked the product, merchant, or payment method it did, rather than a black-box “trust us.”
  3. Stronger data-protection safeguards — specific measures to keep the payment and personal data an agent handles from leaking to whatever storefront it’s transacting with.
  4. Preserved customer and merchant choice — the banks want assurance that agentic platforms won’t lock customers or merchants into a single provider’s ecosystem.
  5. Interoperability — competing agent platforms and payment rails need to work together, not fragment into incompatible silos that make fraud monitoring harder across the board.

Notice what’s missing from that list: liability. The banks named it as the core problem in their own language, then didn’t put a concrete liability framework into their five proposals. That’s not an oversight — it’s the hardest question in the room, and the one where six competing banks are least likely to agree with each other, let alone with OpenAI, Google, and Shopify.

What Are Your Options Now

If you shop using an AI agent, don’t assume the protections you get from a normal card swipe automatically carry over. Check whether your bank or card issuer has published guidance on agent-initiated purchases, and be skeptical of any agent that offers to store and auto-submit your card details to storefronts you haven’t personally vetted.

If you run an e-commerce storefront, the fraud surface just expanded. A spoofed version of your checkout flow, built specifically to catch agent traffic rather than human traffic, is now a viable attack — because an agent has fewer of the visual and contextual cues a human shopper uses to sniff out something wrong. Worth revisiting your fraud detection posture with agent traffic specifically in mind, not just bot traffic in general.

If you’re building on agentic checkout infrastructure, this paper is a preview of what regulators will eventually ask for, even though the principles themselves are voluntary. Building disclosure and audit logging into an agent’s transaction flow now is cheaper than retrofitting it after a rule forces you to.

If you’re a financial institution not yet in this coalition, six competitors just moved first on setting the terms of this conversation. Waiting for a seventh mover’s version of this paper means reacting to a framework built without your input.

The Bigger Picture

Card fraud has been through a liability fight like this before, and it’s worth remembering how that one actually got resolved. When US card networks rolled out chip terminals, they didn’t just ship better hardware — they redrew who eats the loss. Starting in October 2015, card networks shifted counterfeit-fraud liability onto whichever party, issuer or merchant, hadn’t upgraded to chip-capable equipment. The effect was immediate and measurable: businesses that completed the switch saw counterfeit fraud losses drop 47% within a year, and adopters were down 87% by 2019. That wasn’t better technology alone doing the work. It was better technology paired with a rule that made someone specific pay for not using it.

Agentic commerce doesn’t have that rule yet. It has five principles and a promise that the liability paper is coming later. That’s the real gap this week’s warning exposes, and it’s narrower than “AI moves faster than its safeguards.” It’s specifically about who has a financial reason to fix agent-checkout fraud once everyone agrees it exists. The chip shift worked because Visa and Mastercard could point at a specific party and say: you pay if you don’t upgrade. Nobody has drawn that line for agentic commerce — not the bank whose card got charged, not the AI platform that ran the agent, not the merchant whose storefront got spoofed. Diffuse liability tends to produce diffuse urgency.

Publishing principles ahead of regulation is its own tell. It’s the same move payment networks made ahead of PSD2 in Europe: get to the table first, shape the framework before a legislature writes one without you in the room. Voluntary principles aren’t nothing — they signal where the industry expects binding rules to eventually land. But the 2015 shift became more than a suggestion because it carried a hard deadline and a dollar figure attached to non-compliance. A paper with five principles and no liability line is the industry drafting the easy chapters first and leaving the expensive one for later.

Our Take

We think the banks are right about the problem and soft on the solution. Card-in-checkout fraud, unclear liability, agents that can’t tell a phishing storefront from a real one — these are concrete, current risks, not hypothetical ones, and it’s genuinely useful that six banks across four continents said so on the record instead of waiting for a headline-grabbing fraud incident to force the conversation.

But five principles that carefully avoid naming a liability framework is a coalition agreeing on the easy 80% and leaving the hard 20% for the “second paper” they’ve promised on implementation. Disclosure and transparency are good defaults and cost the industry very little to adopt. Deciding who actually pays when an agent gets scammed is the fight that determines whether this framework means anything, and that’s the fight nobody in this paper picked.

Also worth saying plainly: several of these same banks are actively building or partnering on agentic payment products of their own. Publishing consumer-protection principles while shipping the products that create the risk isn’t hypocrisy exactly — it’s the position every fintech ends up in eventually. But it’s worth watching whether the proposals these banks bring to regulators end up shaping rules that favor incumbent payment rails over newer agentic platforms. That’s not a conspiracy theory. It’s just what self-interested actors tend to do when they get to write the first draft.

Frequently Asked Questions

Which banks warned about AI shopping agent fraud?

NatWest, Bank of America, ING, Capital One, ASB Bank (New Zealand), and Commonwealth Bank of Australia co-authored a September 22, 2026 principles paper, Building Trust in Agentic Commerce, warning that AI shopping agents are creating fraud, liability, and privacy risks faster than protections are catching up.

What specific risk are the banks most worried about?

The banks flagged AI shopping agents that enter a customer’s saved card details directly into a checkout page without the customer reviewing it first — including cases where that page turns out to be a phishing storefront rather than a legitimate merchant.

Who is liable if an AI shopping agent is tricked into an unauthorized purchase?

There’s no settled answer yet. The banks’ own report says liability allocation is currently “unclear and inefficient,” and that dispute processes don’t involve every party in the transaction chain — the bank, the AI platform, and the merchant. Resolving that is expected to be the subject of a follow-up implementation paper.

Are these bank principles legally binding?

No. The five principles — transparency, safety, privacy and data protection, customer choice, and interoperability — are voluntary. The coalition plans to bring proposals based on them to regulators and policymakers, but no binding rule currently exists.

How does this relate to Shopify’s agentic storefronts?

Shopify’s agentic storefronts, which let customers complete purchases inside ChatGPT, Gemini, Copilot, and Google AI Mode, launched in March 2026 as a capability breakthrough. This September’s bank warning addresses the fraud and trust risks in that same category of agentic checkout, which weren’t the focus of coverage at launch.

How many consumers are already using AI shopping agents?

Survey data cited alongside the banks’ report found that 50% of American consumers have made a retail purchase with some form of AI assistance, and 22% now begin product research with an AI tool. Only about 24% said they’d trust an agent to handle both shopping and payment autonomously — this data reflects US consumers specifically, not a global figure.

What are the banks asking regulators to require?

Five things: mandatory disclosure when an AI agent executes a transaction, transparency into how agents make purchasing decisions, stronger data-protection safeguards, preserved customer and merchant choice of platform, and interoperability between competing agentic commerce systems.


Last updated: September 23, 2026. Sources: ING — Global banks collaborate on principles for trusted agentic commerce · Building Trust in Agentic Commerce (principles paper) · PYMNTS — Banks Say Consumers Unsure AI Agents Are on Their Side · Yahoo Finance — Banks warn AI shopping agents outpace fraud protections · InstaMed — EMV: Chipping Away at Fraud, One Year Post Liability Shift.

Related reading: Shopify Agentic Storefronts: The E-Commerce Funnel Breaks · Plugin4Shell: The RCE Bug Hitting 4 AI Coding Agents · AI Agents Explained · AI Safety and Privacy Guide · Best AI Tools for E-Commerce