By Jessica Kendall, Contributor at The Financial Brand
Agentic commerce is moving beyond controlled experiments and into live pilots, early deployments and broader market testing. As artificial intelligence agents begin recommending products, selecting payment options and completing purchases for consumers, banks must rethink how trust is established during a transaction.
A new industry paper, Building Trust in Agentic Commerce, co-authored by ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group and NatWest Group, outlines five principles for developing a trusted agentic commerce ecosystem: transparency, safety, privacy and data, customer choice, and interoperability.
The shift is significant because an AI agent may eventually perform many tasks traditionally handled directly by a customer. It could compare offers, choose a product, use stored payment credentials and complete a purchase based on instructions given earlier.
For banks, this creates urgent questions about delegated authority, agent identification, fraud detection, transaction disputes and data governance. These issues cannot be addressed separately from consumer protection. The systems supporting AI-powered transactions must be designed with trust and accountability at their core.
Key Banking Implications of Agentic Commerce
- Make AI agent identity clear: Customers should understand when an AI agent is acting for them, which organization operates it and how it evaluates available products or services.
- Control delegated authority: Consumers need simple ways to view, change and revoke the permissions granted to an AI agent.
- Create useful transaction records: Banks require sufficient information about customer intent, agent decisions and transaction outcomes to investigate fraud and resolve disputes.
- Prepare for a fragmented market: Banks, payment providers, merchants, wallets and AI platforms will need shared standards for core functions without limiting innovation.
Customers Must Know When an AI Agent Is Acting
One of the most important questions in an AI-enabled transaction is also one of the easiest to miss: who made the decision to buy?
Traditional commerce generally involves a customer selecting a product, a merchant completing the sale and a payment provider processing the transaction. Agentic commerce adds another participant capable of searching, comparing, recommending, selecting and purchasing on the customer’s behalf.
As AI agents become more independent, their identity, incentives and authority become part of the transaction itself. Customers and merchants should be able to identify when an agent is involved and understand whether it is acting for the consumer, the merchant or another commercial party.
Transparency should also extend to the way an agent ranks products and payment methods. Consumers may need to know whether a recommendation is sponsored, whether an AI provider receives a commission and how personal data influences the result.
An agent could favor a product because it generates more revenue for its provider, carries a lower support cost or is easier to process. That recommendation may not always represent the best option for the consumer.
Trust depends on visibility. Explaining the agent’s role and incentives should become part of the customer experience, especially when an automated system makes decisions with financial consequences.
Delegated Authority Needs Clear Rules
When an AI agent acts for a customer, the distinction between customer authorization and an agent’s independent decision becomes increasingly important.
Agentic commerce may operate across several levels of autonomy. A consumer may ask an agent to search for products but make the final decision personally. Another customer may approve a specific purchase for the agent to complete later. Some users may give an agent permission to make purchases independently within defined limits.
Each scenario creates different expectations for authentication, authorization and liability. Customers should be able to see what permissions they have granted, set spending or merchant limits and withdraw access when necessary.
Secure and auditable processes will also be needed for entering payment credentials and confirming purchase intent. Banks and other parties that may carry liability must have the ability to request stronger authentication when the transaction presents elevated risk.
There is an important difference between proving who initiated a transaction and proving what the customer intended. A valid credential may show that a payment came through an approved channel, but it may not demonstrate that the customer intended an AI agent to buy a particular product, at a specific price, from a specific merchant.
As agent autonomy grows, the record of the customer’s original instructions will become just as important as the payment credential. That record may help establish whether the agent acted within its authority.
Fraud Prevention Must Include AI Agent Risks
AI-driven commerce introduces new opportunities for fraud and social engineering. Criminals could impersonate legitimate agents, compromise an agent account or create a fake merchant interaction designed to obtain payment credentials.
There is also a risk that a legitimate AI agent could act beyond the authority granted by a customer. A dispute may involve several parties, including the agent provider, merchant, payment network, card issuer, wallet provider and technology platform. Determining responsibility could become more difficult when each participant controls only part of the transaction.
Banks may also face limited visibility. An issuer or acquirer may not know which AI agent was involved, what instructions the customer provided, who the merchant of record was or why the agent selected a particular payment method.
Without this context, even advanced fraud detection tools may assess the transaction using incomplete information. Effective risk controls will need to combine traditional authentication with data about delegated authority and customer intent.
A central question for the financial services industry is whether a transaction record will contain enough evidence to explain what happened when something goes wrong.
Transaction Data Could Become Evidence
AI-led purchases may generate a more detailed record than conventional online transactions. That record could include customer prompts, agent recommendations, decision logs, spending instructions, authentication events, warnings and final purchase details.
These records could help banks investigate scams, recover funds and resolve customer disputes. They may also help determine whether an AI agent followed its instructions or exceeded the authority granted to it.
However, collecting more data creates substantial privacy responsibilities. Financial institutions and technology providers will need to consider how information is collected, stored, shared and used for profiling or other secondary purposes.
A responsible framework should give service providers access to the information required to perform their functions safely and effectively. Additional uses should be subject to appropriate customer and merchant consent.
In the future, resolving a disputed agentic transaction may require reconstructing an entire chain of events: what the customer requested, what authority was granted, which products the agent considered, why it made a recommendation, what authentication occurred and what outcome followed.
Data minimization and auditability should work together. Banks need reliable evidence for fraud prevention and dispute resolution, but that does not mean every conversation or interaction should be retained indefinitely.
Interoperability Will Shape Customer Choice
The structure of the agentic commerce ecosystem will determine how much control customers and merchants have. Users may interact with a wide range of AI agents, payment methods, wallets, marketplaces, platforms and protocols.
If these systems remain highly fragmented, integration costs could rise and customers may face inconsistent protection standards. Switching between providers could also become more difficult if transaction histories, permissions or payment credentials cannot move easily between services.
Standardization can improve safety and consistency, but excessive standardization could restrict competition and slow the development of new services. A balanced approach would establish interoperability for essential functions while allowing providers to differentiate through additional features and customer experiences.
Customers and merchants should have meaningful choice in the agentic services they use. At the same time, banks and other providers may need to limit support for services that create unacceptable safety, legal, regulatory or commercial risks.
No single company will control the entire agentic commerce journey. AI providers, banks, payment networks, merchants, wallets and technology platforms will each manage different parts of the experience. A trusted ecosystem will depend on these participants exchanging enough information to manage risk while preserving competition.
What Banks Should Do Now
The technology behind agentic commerce will continue to evolve, but the foundations of a trusted transaction are more enduring. Banks should begin assessing how delegated authority will be represented, how AI agents will be identified and what transaction evidence will be available to support fraud investigations and disputes.
Financial institutions should also consider how customers will set permissions, review agent activity, approve high-risk purchases and revoke access. Clear communication will be essential because consumers need to understand not only what an AI agent can do, but also what it cannot do.
The next stage of agentic commerce will test whether financial institutions can combine automation with transparency, convenience with control, and personalization with privacy. Banks that address these issues early will be better positioned to build confidence as AI agents become more active participants in everyday financial transactions.
Source: Thefinancialbrand.com
日本語
한국어
Tiếng Việt
简体中文