AI now handles everything from search to checkout
Global banks warn of fraud and data risks
Liability unclear when AI makes wrong purchases
John Lewis sees AI-driven traffic jump from 0.3% to 2.5% in a year
As AI moves beyond searching for products and comparing prices to making purchases on consumers' behalf, financial institutions are growing increasingly alarmed. Their concern: when AI buys the wrong item or falls victim to a fraudulent transaction, it is far from clear who is responsible — and the risk of data breaches grows as consumers' financial information becomes linked to AI systems.
Bank of America, Capital One, ING and other global financial firms warned Saturday (local time), according to Reuters, that "AI shopping agents" — systems that carry out purchases on behalf of consumers — could amplify new financial risks including fraud and personal data exposure.
An AI shopping agent does more than recommend products after a consumer enters their preferences. It compares prices, selects a retailer and completes the payment. If a consumer asks, for example, "Find me black sneakers under $100 and place the order," the AI can locate a matching product and execute the purchase.
Major technology companies including OpenAI, Anthropic, Google and Meta are also accelerating development of "agentic commerce" technology, in which AI handles the entire consumer purchasing process.
The number of consumers using AI to find products is rising rapidly. British retailer John Lewis said the share of traffic arriving at its website through AI services climbed from 0.3 percent a year ago to 2.5 percent recently — more than an eightfold increase in a single year, even if the overall share remains modest.
As AI shopping spreads, the financial sector's biggest concern centers on payment fraud and consumer protection risks that could arise during transactions.
For AI to purchase goods on a consumer's behalf, it must be connected to a payment method such as a credit card or bank account. The broader the AI's access to financial information, the greater the potential damage from hacking or data leaks.
There are also concerns that AI could steer consumers toward payment methods with relatively weak protections — since the level of recourse available to consumers who do not receive goods or fall victim to fraud can vary significantly depending on how a transaction is processed.
AI agents themselves could be hacked or manipulated. If an attacker were to interfere with an AI's decision-making process, the system could complete purchases from specific retailers or execute unwanted transactions without the consumer ever reviewing them.
It also remains unclear who bears responsibility when AI makes a mistaken purchase.
Questions of liability could arise in cases such as a consumer asking AI to book the cheapest available flight, only for the system to select a non-refundable ticket — or an AI mistaking a fraudulent online store for a legitimate retailer and completing a payment. In such scenarios, it is unclear whether the consumer, the financial institution, the retailer or the AI company should bear the loss.
Existing e-commerce and financial consumer protection regimes are built on the assumption that a person selects the product and approves the payment. Financial institutions say those frameworks will be difficult to apply as it becomes more common for AI to receive broad instructions from a consumer and then independently decide on the specific product, retailer and payment method.
Concerns have also been raised that AI shopping could encourage overspending. Once AI learns a consumer's purchase history, preferences and price range and begins executing purchases rather than merely recommending them, consumers may have fewer opportunities to exercise judgment at the final payment stage.
In response, global financial firms are calling for safeguards to be put in place — ones that can identify and track AI-driven transactions — before AI shopping becomes mainstream.
They argue that banks and retailers should be able to verify when an AI agent was involved in a transaction, and that it should be possible to trace how the AI selected a product and payment method.
Setting spending limits and restricting the categories of goods an AI can purchase on a consumer's behalf in advance is also being discussed, as is the creation of a separate authentication system that would allow financial institutions to confirm whether a transaction was genuinely initiated by the consumer.
AI companies and financial firms are already working on related payment technologies. Options under discussion include hard caps on AI-executed transactions that cannot exceed pre-set limits, and mechanisms to verify consumer approval before a purchase is completed.
As AI expands from product recommendations into actual purchases, the e-commerce market is expected to change at an accelerating pace — with AI taking over much of the comparison shopping that consumers once did themselves across multiple online stores.
However, as AI moves into the stage of accessing consumers' financial information and spending their money directly, preventing fraud, protecting personal data and clarifying liability when things go wrong are emerging as the central challenges that must be resolved for AI shopping to reach its full potential.
sjy@heraldcorp.com
