Banks Want Guardrails Before AI Shopping Agents Move Money
Disclosure, data protection, consumer choice and recourse are becoming design requirements for agentic commerce
A group including NatWest, Bank of America, ING, Capital One, Commonwealth Bank of Australia and ASB has warned that AI shopping agents can create fraud, privacy and recourse risks. The banks’ proposed principles include disclosing when an agent is acting, explaining material decisions, protecting data and preserving consumer choice and interoperability. These are industry proposals, not a binding global standard.
From search assistance to delegated action
The issue is moving quickly because agents are becoming a visible route to commerce. John Lewis said agent-originated searches increased from 0.3% to 2.5% over a year. That remains a small share, but the rate of change suggests businesses should design controls before agents become a material transaction channel.
Identity and authority must travel with the agent
Traditional online commerce assumes that a person sees an offer and confirms a payment. An agent may search, compare, select and initiate actions across several services. Each participant therefore needs to know who owns the agent, what it is authorised to do and whether the customer approved the relevant constraints. A generic login is not enough for high-consequence actions.
A robust mandate should specify product scope, spending limits, timing, data permissions and when explicit confirmation is required. The merchant and payment provider should receive enough evidence to validate the mandate without collecting unnecessary personal information. Logs should connect the agent’s recommendation, the user’s instruction and the resulting transaction.
Explanation and recourse are equally important. Consumers need to understand why a product was selected, whether commercial relationships influenced ranking and how to stop or reverse an action. Liability cannot be left as a gap between the model provider, the agent operator, the merchant and the bank. Contractual allocation will vary, but the customer needs one intelligible route to challenge an outcome.
A control model for employee benefits agents
The same questions apply when an AI agent helps an employee choose or administer benefits. Recommendations can affect health coverage, savings and personal data. The agent should identify itself, distinguish education from regulated advice and show the assumptions behind a comparison. Irreversible actions—such as enrolment, beneficiary changes or transfers—should require strong authentication and explicit confirmation.
We would recommend six controls for any transactional benefits agent:
- verified identity,
- a narrow mandate,
- minimum necessary data,
- an explanation of material recommendations,
- confirmation for consequential actions and
- a documented route for human review.
Interoperability should allow the user to export records and change provider without losing the history needed to understand a decision.
These controls may add friction, but friction is not always a defect. A well-placed confirmation can prevent a costly error while routine research remains fast. The goal is graduated autonomy: allow low-risk tasks to proceed smoothly, require evidence and approval as consequences rise, and retain a clear audit trail. Firms that build trust into the transaction layer will be better positioned than those that treat governance as a notice added after launch.
Test the failure paths before launch
Agent design should include situations in which the customer changes their mind, the merchant rejects the action, prices change or the agent misinterprets a constraint. Teams should verify that the system stops safely, informs the user and preserves evidence for investigation. Fraud monitoring will also need to distinguish legitimate delegated behaviour from account takeover or manipulated instructions.
Governance should include merchants and payment providers because no single participant sees the full journey. Shared technical signals can confirm that an agent is authorised without exposing the complete personal context. Common standards may take time to emerge, so early deployments should use narrow scopes, conservative limits and clear contractual responsibility while evidence accumulates.
The next review should test the recommendation against fresh operating evidence, identify any unintended consequences and record who owns the resulting action. That discipline keeps the proposal proportionate and allows governance to evolve as market practice, technology and regulation change.


No Comment