Six major global banks, including Bank of America and Capital One, have published a paper warning that the rise of AI agents capable of shopping on behalf of consumers introduces a set of risks that the financial industry is not yet equipped to handle. The paper, titled "Building Trust in Agentic Commerce," identifies five areas of concern: transparency, safety, privacy and data, choice, and interoperability. The banks acknowledge the commercial potential of agentic commerce but argue that the technology and its regulatory framework are moving at different speeds.
What the banks are actually worried about
The core concern is that as AI agents gain more autonomy in commercial transactions, the surface area for something to go wrong expands with it. Consumers may not understand whether an agent is acting in their best interest, the paper notes, and they are worried about agents purchasing the wrong product, overspending, or falling victim to scams and fraud. The banks also flag a structural problem: an agent could prioritize certain products or payment methods not because they serve the customer best, but because those options carry higher commissions or lower token costs for the systems running the agent.
The report also warns of elevated rates of scams, fraud, and disputes in an agentic commerce environment. A data breach in this context would expose particularly sensitive information belonging to both consumers and merchants who have granted agents access to their accounts and payment credentials.
A real-world illustration from Meta and Amazon
The paper's concerns found a vivid illustration shortly after publication. Meta announced that it had discovered and fixed a zero-day vulnerability in its AI assistant Muse, which promotes agentic shopping among its capabilities. The flaw could allow an attacker to hijack the AI assistant and exploit any permissions the user had previously granted it.
Shortly before that, Amazon asked Muse to stop accessing its e-commerce platform. The reason was that Meta's agent failed to properly identify itself while shopping on Amazon's site, raising concerns about how the platform handles customer credentials and account data. These two incidents, occurring within a day of each other, demonstrated that the security and identification problems the banks flagged in their paper are not theoretical.
Industry skepticism beyond the banks
The banks are not alone in their reservations. Ron Johnson, the former Apple executive who built the original brick-and-mortar Apple Stores, told TechCrunch in a recent interview that while AI will improve the online shopping experience, it will not change the fundamental way people shop.
"AI will never be able to have you physically experience a product," Johnson said. "They'll just become more informed shoppers when they come to the store." His argument is that agentic commerce addresses the transactional layer of shopping but cannot replace the sensory evaluation that happens when a person touches, tries, or physically interacts with a product.
Meanwhile, consumer adoption of agentic shopping remains difficult to measure. Some consumers use AI chatbots to find products or gather information about what to buy, but many remain reluctant to hand over full purchasing authority to an agent with access to their financial accounts.
Where the banks stand on the future
It is important to note that the six banks are not rejecting agentic commerce outright. The paper states that the consortium is excited by the promise of agentic commerce and eager to work with customers, industry, and stakeholders to enable its future. The banks even claim it could eventually become a mainstream way for consumers and merchants to transact.
But they argue that trust must be built first, through industry standards, policies, and consumer protections that are currently lagging behind the technology. The consortium is now working on a subsequent paper to detail how the five key principles from the report can be practically implemented to make agentic AI-led e-commerce as safe as possible.
What this means in practice
The intersection of banking security concerns and the technical realities of AI agents points to a clear gap. The infrastructure for agentic commerce exists, and the commercial incentives to make it work are strong, but the guardrails are still being designed. The banks' paper frames this not as a reason to halt development but as a reason to slow down and build the necessary protections before agents are handling real money at scale.