Banks warn AI shopping agents raise scam, fraud risks
Six major banks—NatWest, Bank of America, ING, Capital One, ASB Bank, and Commonwealth Bank of Australia—issued a coordinated warning on September 22, 2026 that AI shopping agents could substantially increase fraud, scam, and data-privacy risks Reuters. The warning, surfaced in Paris, represents the first concrete institutional pushback against the deployment of autonomous shopping assistants in consumer commerce.
The Emerging Agent Crime Vector
The banks identified specific attack surfaces where AI shopping agents could be exploited or misused. Agents could request sensitive card details, enter payment credentials directly into merchant websites, or steer users toward payment methods with weaker fraud protections Yahoo Finance. Beyond direct credential theft, the banks flagged a broader class of risks: agents could execute unauthorized or incorrect purchases, overspend customer budgets, or be hijacked to steer transactions toward scam merchants entirely.
"They are concerned that AI agents may buy the wrong thing or spend too much – or even worse, lose their money to scams and fraud," according to the banks' position Reuters. Critically, the warning also flagged a consumer-protection gap: "They are not sure whether they will be protected or who they will need to go to if things go wrong."
Regulatory Proposals
The coalition did not stop at warnings. The banks announced plans to bring formal proposals to regulators addressing three concrete requirements: clearer disclosure when an AI agent is involved in a transaction, transparency on how agents make decisions, and stronger customer-data protections Reuters. These proposals signal an intent to establish agentic commerce as a regulated financial activity, similar to how card-present and card-not-present transactions are currently governed.
The warning comes as AI shopping agents are beginning to ship into production environments, particularly ahead of seasonal retail events. No specific agent product has been named as the target of these concerns, but the timing and breadth of the coalition suggest the banks view agentic commerce as a systemic emerging risk rather than a single-vendor problem.
The absence of reported fraud incidents, data breaches, or court action tied to AI shopping agents indicates this is a preemptive regulatory intervention—banks moving to establish guardrails before criminal misuse becomes widespread.