In a paper published Tuesday, six major global banks, including Bank of America and Capital One, warned that agentic shopping has “risks spanning transparency, safety, privacy & data, choice, and interoperability” that increase “as greater autonomy is given to AI agents.”
AI developers, as well as various retailers and major payment processors, have been working to unveil agentic commerce chatbots, aka AI agents that promise to completely automate the process of online shopping. But adoption has been trickier to quantify. Some consumers use AI chatbots to find stuff or get information on what to buy when shopping online, but many still feel reluctant to let the agents roam free on the internet with access to their entire fortune.
“Consumers are unclear if AI agents will act in their interests,” the report says. “They are concerned that AI agents may buy the wrong thing or spend too much – or even worse, lose their money to scams and fraud.”
Many tech experts also don’t seem to hold total faith in the future of agentic commerce.
Ron Johnson, the former Apple executive behind the original brick-and-mortar Apple Stores, told TechCrunch in a recent interview that he believes AI “will improve the online shopping experience,” but it won’t actually change the “way we shop.”
“AI will never be able to have you physically experience a product,” Johnson said. “They’ll just become more informed shoppers when they come to the store.”
The six banks that co-wrote the report, titled “Building Trust in Agentic Commerce,” seem to agree that many problems and questions still plague this use case of AI agents.
AI agents could prioritize certain products or payment methods simply because of incentives such as higher commissions and lower token costs, rather than choosing what’s best for the customer.
Agentic commerce also has “potential for higher rates of scams, fraud and disputes,” the report says, and any data breach would jeopardize particularly sensitive data belonging to consumers and merchants who rely on these agents.
Case in point: Meta just announced that it found and fixed a zero-day vulnerability in its new AI assistant, Muse, which counts agentic shopping among its promoted capabilities, which could allow an attacker to pretty much hijack the AI assistant and take advantage of any permissions the user had given it. The announcement came only a day after Amazon asked Muse to stop using its e-commerce site, saying that Meta’s agent failed to identify itself while shopping on the platform and that this raised concerns about how Amazon handles customer credentials and account data.
But the banks are not wholesale dismissing the idea of agentic commerce, and even claim that it could potentially become “a mainstream way in which consumers and merchants transact.”
“We, too, are excited by the promise of agentic commerce and are eager to work with customers, industry and stakeholders to enable its future,” the paper reads.
But first, agentic commerce needs to build trust through industry standards, policies and consumer protections, all of which are currently lagging technological developments, the banks say. The consortium is now working on a subsequent paper to detail how the five key principles outlined in this report—transparency, safety, privacy and data, choice, and interoperability—can actually be implemented to ensure that any deployment of agentic AI-led e-commerce is as safe as possible.