AI companies want to automate the boring parts of shopping.
Tell an agent what you need.
Let it compare products.
Let it choose.
Let it pay.
Convenient.
Until something goes wrong.
Several major banks are now warning that the financial system is not ready for AI agents to make purchases with the same freedom humans have online.
And the problem is much bigger than whether a chatbot buys the wrong shoes.
Agentic commerce is arriving
OpenAI, Google, Anthropic, Meta and others are building systems that can act instead of simply answer. Shopping is an obvious use case. An agent could search hundreds of products, compare delivery times, apply preferences, fill forms and complete checkout.
Retailers are already seeing the shift.
Reuters reports that British retailer John Lewis said searches originating from AI systems increased from 0.3 percent to 2.5 percent over one year.
That is still small.
The direction is not.
The web is beginning to receive customers who are represented by software.
Banks see a new fraud surface
Reuters reports that banks including NatWest, Bank of America, ING, Capital One, Commonwealth Bank of Australia and ASB Bank have raised concerns around AI-powered shopping.
Their worries include fraud, scams, misuse of financial data, insecure payment choices and unclear consumer protections.
The central question is painfully simple:
Who is responsible when the AI gets it wrong?
If an agent purchases a fraudulent product, was the user responsible?
The AI provider?
The merchant?
The bank?
The card network?
The answer is not always obvious.
Your payment method becomes an AI permission
Today, giving an app access to your card already requires trust. Giving an autonomous agent access is different. The agent may operate across multiple websites.
It may use information from previous conversations. It may select a merchant you have never visited. It may optimize for criteria you did not explicitly specify.
A permission like “help me buy a laptop” can therefore contain dozens of hidden decisions.
Price.
Seller.
Warranty.
Shipping.
Country.
Currency.
Subscription options.
Payment method.
Return policy.
A human makes those decisions visually while browsing.
An AI agent may compress them into one action.
That is powerful.
It also makes transparency harder.
Confirmation screens are not enough
The obvious solution is to ask users before payment.
That helps.
But it does not solve everything. A user may approve a transaction without understanding why the agent chose that merchant. The AI may have been manipulated by advertising.
A compromised webpage may feed malicious instructions to the agent. A scammer may design a site specifically to look trustworthy to automated systems. The agent may even select a payment path that offers weaker consumer protection.
A useful checkout therefore needs more than a final “Approve” button.
It needs an audit trail.
We need receipts for AI decisions
Imagine a purchase summary that shows:
Requested: noise-cancelling headphones under €300 Selected: Product X Merchant: Retailer Y Price: €249 Alternatives checked: 18 Payment method: Visa ending 1234 Subscription created: No Return window: 30 days Why selected: price + delivery + user preference Final authorization: User approved at 14:32
That may sound excessive.
For autonomous transactions, it could become normal. The point is not to expose the model's hidden reasoning. The point is to expose the decision path that affects the user.
AI identity will matter too
Banks are also pushing for clearer disclosure when AI is involved in a transaction. That opens another unresolved question. Should a website know whether the buyer is a human or an agent?
For security, probably.
For privacy, things become more complicated.
An AI identity layer could eventually allow services to distinguish between:
the person,
the agent acting for the person,
the permissions granted to that agent,
and the action the agent is authorized to perform.
That is not how today's web works.
But agentic commerce may force it to evolve.
The Zerionia view
The most important interface in AI commerce may not be the shopping assistant. It may be the permission screen. AI agents are becoming capable enough to make decisions across the web.
Now financial infrastructure has to answer a harder question: How much authority should software receive before the user has to come back into the loop? The winners will not simply build the smartest shopping agent.
They will build one people trust with money.


