Banks Warn AI Shopping Agents Can Complicate Fraud Claims

Matthew Leo · September 23, 2026 · Business & Policy

A shopper uses a laptop facing her beside a parcel, notebook and face-down payment card.

Banks are warning that AI shopping agents are moving faster than the payment rules meant to protect customers.

The concern is not that every shopping bot is a scam. It is that a tool can now search, compare, choose and sometimes pay with much less human involvement. When something goes wrong, it may be unclear whether the mistake came from the shopper, the agent, the merchant or the payment service.

Why banks are speaking up now

A group that includes NatWest, Bank of America, ING, ASB Bank, Capital One and Commonwealth Bank of Australia issued a report on agentic commerce, according to Reuters.

The banks identified several practical risks: an agent buying the wrong item, exposing payment or personal data, being redirected by a scam, or choosing a payment method with weaker consumer protection. They also want shoppers and merchants to be able to choose which agents they trust instead of being locked into one platform.

The warning arrives as technology companies and payment networks are building tools that can complete transactions. The useful distinction is simple: a chatbot that suggests three pairs of shoes is giving advice. An agent that signs in, selects a size and pays is acting.

A purchase can be authorized and still be wrong

Traditional fraud controls are built around questions such as whether the cardholder approved a transaction and whether the merchant delivered what was purchased.

An AI agent adds another layer. You might authorize it to buy “the cheapest refundable flight after 6 p.m.” and receive a ticket that technically meets those words but uses a distant airport, has a short connection or includes a refund condition you did not expect.

That is not necessarily an unauthorized transaction. It may be an instruction problem or a product-selection error. A bank dispute process may not treat it the same way as a stolen card purchase.

Agents can also see more than a normal checkout page if users give them access to email, shopping history, loyalty accounts or stored payment details. That data can reveal travel plans, home address, family information and spending habits.

Do not give an agent an open-ended shopping job

If you use an AI tool to research or complete a purchase, narrow the task before it reaches checkout.

Use payment controls the agent cannot change

A separate spending control is safer than relying only on instructions typed into a chat.

Where your bank or card supports them, use purchase alerts, a low-limit virtual card, a one-time card number or a card you can lock quickly. Avoid giving an agent direct access to a primary bank account or debit credentials for an experimental purchase.

Do not let an agent move a transaction outside the merchant's normal checkout. Requests to pay by cryptocurrency, gift card, e-transfer to an individual or an unfamiliar payment link should stop the process.

If a tool installs as a browser extension, check its permissions first. Mapletechie's guide to auditing browser extensions explains why a shopping helper that can read and change every page deserves more scrutiny than a normal website.

Canadian protections do not remove the grey area

Canadian consumers still have the protections attached to their card agreement, provincial consumer law and the merchant's return policy. The Office of the Privacy Commissioner of Canada also says private-sector organizations covered by federal law must handle personal information appropriately.

None of that creates a simple national rule for every mistake made by an autonomous shopping agent. Liability can depend on what the user approved, how the tool represented the purchase and which company actually processed it.

That is why the agent should not be the only place where consent exists. The final merchant checkout should show the item, seller, full amount and terms in a form the customer can review.

What to do if the purchase goes wrong

First, stop further activity by disconnecting the agent from the merchant and payment account. Lock the card if you see transactions you did not authorize.

Then contact the merchant and payment provider promptly. Describe the transaction accurately. If you approved the agent but it bought the wrong product, say that. If you did not approve the purchase at all, say that instead. Save screenshots and receipts before deleting the tool or its history.

For now, AI shopping agents are best used as researchers with a supervised checkout. Letting one compare products can save time. Giving it broad account access and permission to spend without a final review creates a problem that banks, merchants and regulators have not fully sorted out.

Sources

Tags: AI agents, online shopping, fraud, payments, consumer protection

Read on Mapletechie