Banks are warning that using artificial intelligence (AI) agents for online shopping may heighten the risk of scams, fraud, and data privacy violations for consumers. This caution comes from a report by financial institutions including Bank of America, Capital One, NatWest in the UK, ASB Bank in New Zealand, and Commonwealth Bank of Australia. They expressed that, despite the excitement surrounding AI shopping agents, the technology’s risks could outstrip existing consumer protections and industry norms.
The report indicates that consumers are uncertain about whether AI will prioritize their best interests. They have concerns that AI agents might make incorrect purchases, overspend, or, even worse, lead them to lose money through scams and fraud. There’s also confusion about what protections are available or whom to contact when things go awry.
As tech companies increasingly introduce sophisticated AI agents, consumers can now utilize them as shopping aids, tracking products and even completing purchases independently.
In September, British retailer John Lewis noted a rise in searches initiated by AI agents, from 0.3% last year to 2.5% this year, showing considerable growth in AI-driven traffic.
The banks’ report underscores several risks associated with using AI agents, such as the potential for these agents to request customers’ card details and input them directly into websites or guide users towards payment methods lacking adequate protections.
To address consumer safety, banks plan to engage with policymakers on various proposals, including mandates for disclosure when an AI agent is involved in transactions, enhanced transparency regarding the decision-making processes of AI agents, and measures to safeguard customer data.
Moreover, the report emphasizes that both consumers and merchants should have the freedom to select which AI-enabled e-commerce services they prefer, promoting the need for interoperability among different systems.
Agentic AI systems are distinct from chatbots, as they can perform tasks autonomously and interact with other systems with user-granted authority, rather than merely responding to prompts.






