Grok 4.7 Ships After 5 Delays, SpaceX Data Inside
On September 22, six major banks — NatWest, Bank of America, ING, Capital One, New Zealand’s ASB Bank, and Commonwealth Bank of Australia — published Building Trust in Agentic Commerce, a joint paper warning that AI shopping agents fraud risk is growing faster than the rules built to catch it. Not “someday might be a problem.” Now. According to the banks’ announcement, some agents are already typing customers’ card numbers straight into checkout pages — including pages that turn out to be phishing sites — with no human in the loop to notice something’s wrong.
Six months ago, we covered Shopify’s agentic storefronts going live inside ChatGPT, Gemini, Copilot, and Google AI Mode as a genuine breakthrough — full purchase flows completing inside a chat window, no browser tab required. We wrote about what it meant for merchants, for Google’s ad business, for the shape of the funnel. We did not ask who eats the loss when the agent gets it wrong. Six banks just asked that question, together, in public.
Quick Summary: What Happened
Detail Info Announced September 22, 2026 Who NatWest, Bank of America, ING, Capital One, ASB Bank, Commonwealth Bank of Australia What Joint principles paper, “Building Trust in Agentic Commerce” Core warning AI shopping agents are outpacing fraud, liability, and data-privacy protections Sharpest risk flagged Agents entering card details directly into storefronts, including phishing sites, with the customer cut out of the loop Status Voluntary principles, not regulation. Banks plan to bring proposals to policymakers and publish a second paper on implementation Bottom line: The same agentic-checkout capability this site covered as a distribution win in March is now the subject of a coordinated bank warning about scams, unclear liability, and data exposure — and nobody has actually fixed any of it yet.
Six banks don’t coordinate a joint publication on a whim. Building Trust in Agentic Commerce lays out five principles the banks say need to exist before agentic commerce can be trusted at scale: transparency, safety, privacy and data protection, customer choice, and interoperability. Reasonable-sounding, almost boilerplate — until you read what prompted them.
The specific failure mode the banks are worried about: an AI shopping agent enters a customer’s saved card details into a merchant’s checkout flow on the customer’s behalf. That’s the entire pitch of agentic commerce — no manual re-entry, no friction. It’s also, per the banks, a problem the moment the “merchant” is actually a spoofed storefront designed to look like one. A human might pause at a URL that looks slightly off. An agent optimizing for “complete the purchase” has no particular reason to.
Hans Overeem, ING’s global head of Payments and Cash Management, put the ask plainly: “Customers need confidence that payments are secure, their data is protected and they remain in control.” Mark Monaco at Bank of America framed the harder problem underneath that: “Building confidence among consumers, merchants and financial institutions will require thoughtful approaches to identity, authorization, fraud prevention, liability management and customer protection.” Five nouns in that sentence, and liability is the one nobody has actually solved.
That’s not a rhetorical concern. Per the banks’ own reporting on the launch, “when things go wrong, there is unclear and inefficient allocation of liability, and disputes processes do not involve all relevant parties across the value chain.” Translation: if an agent gets phished, or a merchant’s agent-facing API gets spoofed, or a purchase decision goes sideways, there’s no settled answer for whether the bank, the AI platform, the merchant, or the customer is on the hook. Chargeback rules were written for a human tapping “confirm.” Nobody wrote the version for an autonomous agent doing it instead.
That spread matters. This isn’t one nervous regional bank. It’s institutions across four continents converging on the same warning independently enough to co-author a paper about it.
Consumer appetite for agentic shopping is already real, which is exactly what makes the timing of this warning uncomfortable. Survey data cited alongside the banks’ report and reported by PYMNTS found that half of American consumers say they’ve made a retail purchase with some kind of AI assistance, and 22% now start their product research with an AI tool. But only about 24% said they’d trust an agent to handle both the shopping and the paying, autonomously, without them watching. Note that gap: people are fine letting AI do the browsing. They get nervous the moment it reaches for the wallet. That’s a US consumer survey, not a global one — the gap could look different in markets with stronger built-in payment protections, but the shape of the hesitation (research: yes, payment: not yet) tracks with what you’d expect from any new payment rail.
The volume is real too. British retailer John Lewis reported, per Reuters coverage picked up by Yahoo Finance, that search traffic arriving from AI agents rose from 0.3% to 2.5% of its total over the past year. That’s roughly an eightfold jump at one retailer, in twelve months, for a channel that functionally didn’t exist as a meaningful line item a year ago. Multiply that trajectory across every Shopify merchant now running agentic storefronts, and “we’ll figure out the fraud model later” stops being a reasonable posture.
This is also where the March story and the September story connect directly. Agentic checkout was sold as friction removal — the entire value proposition is that the agent skips the steps a human would normally slow down for. Compare a browser session, where you’d notice a shipping address that got auto-filled wrong, to an agentic one, where the human isn’t watching the screen at all. Every step a human would have paused on to catch a mistake, a scam, or a bad address is a step the agent now completes without asking. The banks aren’t objecting to that convenience. They’re pointing out that removing friction and removing the fraud checks that lived inside that friction turned out to be the same move.
Notice what’s missing from that list: liability. The banks named it as the core problem in their own language, then didn’t put a concrete liability framework into their five proposals. That’s not an oversight — it’s the hardest question in the room, and the one where six competing banks are least likely to agree with each other, let alone with OpenAI, Google, and Shopify.
If you shop using an AI agent, don’t assume the protections you get from a normal card swipe automatically carry over. Check whether your bank or card issuer has published guidance on agent-initiated purchases, and be skeptical of any agent that offers to store and auto-submit your card details to storefronts you haven’t personally vetted.
If you run an e-commerce storefront, the fraud surface just expanded. A spoofed version of your checkout flow, built specifically to catch agent traffic rather than human traffic, is now a viable attack — because an agent has fewer of the visual and contextual cues a human shopper uses to sniff out something wrong. Worth revisiting your fraud detection posture with agent traffic specifically in mind, not just bot traffic in general.
If you’re building on agentic checkout infrastructure, this paper is a preview of what regulators will eventually ask for, even though the principles themselves are voluntary. Building disclosure and audit logging into an agent’s transaction flow now is cheaper than retrofitting it after a rule forces you to.
If you’re a financial institution not yet in this coalition, six competitors just moved first on setting the terms of this conversation. Waiting for a seventh mover’s version of this paper means reacting to a framework built without your input.
Card fraud has been through a liability fight like this before, and it’s worth remembering how that one actually got resolved. When US card networks rolled out chip terminals, they didn’t just ship better hardware — they redrew who eats the loss. Starting in October 2015, card networks shifted counterfeit-fraud liability onto whichever party, issuer or merchant, hadn’t upgraded to chip-capable equipment. The effect was immediate and measurable: businesses that completed the switch saw counterfeit fraud losses drop 47% within a year, and adopters were down 87% by 2019. That wasn’t better technology alone doing the work. It was better technology paired with a rule that made someone specific pay for not using it.
Agentic commerce doesn’t have that rule yet. It has five principles and a promise that the liability paper is coming later. That’s the real gap this week’s warning exposes, and it’s narrower than “AI moves faster than its safeguards.” It’s specifically about who has a financial reason to fix agent-checkout fraud once everyone agrees it exists. The chip shift worked because Visa and Mastercard could point at a specific party and say: you pay if you don’t upgrade. Nobody has drawn that line for agentic commerce — not the bank whose card got charged, not the AI platform that ran the agent, not the merchant whose storefront got spoofed. Diffuse liability tends to produce diffuse urgency.
Publishing principles ahead of regulation is its own tell. It’s the same move payment networks made ahead of PSD2 in Europe: get to the table first, shape the framework before a legislature writes one without you in the room. Voluntary principles aren’t nothing — they signal where the industry expects binding rules to eventually land. But the 2015 shift became more than a suggestion because it carried a hard deadline and a dollar figure attached to non-compliance. A paper with five principles and no liability line is the industry drafting the easy chapters first and leaving the expensive one for later.
We think the banks are right about the problem and soft on the solution. Card-in-checkout fraud, unclear liability, agents that can’t tell a phishing storefront from a real one — these are concrete, current risks, not hypothetical ones, and it’s genuinely useful that six banks across four continents said so on the record instead of waiting for a headline-grabbing fraud incident to force the conversation.
But five principles that carefully avoid naming a liability framework is a coalition agreeing on the easy 80% and leaving the hard 20% for the “second paper” they’ve promised on implementation. Disclosure and transparency are good defaults and cost the industry very little to adopt. Deciding who actually pays when an agent gets scammed is the fight that determines whether this framework means anything, and that’s the fight nobody in this paper picked.
Also worth saying plainly: several of these same banks are actively building or partnering on agentic payment products of their own. Publishing consumer-protection principles while shipping the products that create the risk isn’t hypocrisy exactly — it’s the position every fintech ends up in eventually. But it’s worth watching whether the proposals these banks bring to regulators end up shaping rules that favor incumbent payment rails over newer agentic platforms. That’s not a conspiracy theory. It’s just what self-interested actors tend to do when they get to write the first draft.
NatWest, Bank of America, ING, Capital One, ASB Bank (New Zealand), and Commonwealth Bank of Australia co-authored a September 22, 2026 principles paper, Building Trust in Agentic Commerce, warning that AI shopping agents are creating fraud, liability, and privacy risks faster than protections are catching up.
The banks flagged AI shopping agents that enter a customer’s saved card details directly into a checkout page without the customer reviewing it first — including cases where that page turns out to be a phishing storefront rather than a legitimate merchant.
There’s no settled answer yet. The banks’ own report says liability allocation is currently “unclear and inefficient,” and that dispute processes don’t involve every party in the transaction chain — the bank, the AI platform, and the merchant. Resolving that is expected to be the subject of a follow-up implementation paper.
No. The five principles — transparency, safety, privacy and data protection, customer choice, and interoperability — are voluntary. The coalition plans to bring proposals based on them to regulators and policymakers, but no binding rule currently exists.
Shopify’s agentic storefronts, which let customers complete purchases inside ChatGPT, Gemini, Copilot, and Google AI Mode, launched in March 2026 as a capability breakthrough. This September’s bank warning addresses the fraud and trust risks in that same category of agentic checkout, which weren’t the focus of coverage at launch.
Survey data cited alongside the banks’ report found that 50% of American consumers have made a retail purchase with some form of AI assistance, and 22% now begin product research with an AI tool. Only about 24% said they’d trust an agent to handle both shopping and payment autonomously — this data reflects US consumers specifically, not a global figure.
Five things: mandatory disclosure when an AI agent executes a transaction, transparency into how agents make purchasing decisions, stronger data-protection safeguards, preserved customer and merchant choice of platform, and interoperability between competing agentic commerce systems.
Last updated: September 23, 2026. Sources: ING — Global banks collaborate on principles for trusted agentic commerce · Building Trust in Agentic Commerce (principles paper) · PYMNTS — Banks Say Consumers Unsure AI Agents Are on Their Side · Yahoo Finance — Banks warn AI shopping agents outpace fraud protections · InstaMed — EMV: Chipping Away at Fraud, One Year Post Liability Shift.
Related reading: Shopify Agentic Storefronts: The E-Commerce Funnel Breaks · Plugin4Shell: The RCE Bug Hitting 4 AI Coding Agents · AI Agents Explained · AI Safety and Privacy Guide · Best AI Tools for E-Commerce