All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Using AI agents to shop online, find the best products and deals, and then authorize them to execute transactions on your behalf could expose you to several security and privacy risks, according to a new report from Bank of America and five other banks.[1]
The report highlights the need to build trust with AI agents before giving them the authority to handle sensitive personal information or make purchases on your behalf. Because the technology is still developing, industry standards and consumer protections have yet to catch up.
The AI agent you trust could fall for a fake shopping website or phishing page and enter your personally identifiable information, such as credit card details, email address, or home address. This could leave you vulnerable to targeted phishing attacks, identity theft, or financial fraud.
Here’s what the report says about the risks of agentic shopping and the steps you can take to make your AI-assisted shopping safer.
The risks of using agentic AI for online shopping
How to stay safe when using AI shopping agents
The bottom line
What banks recommend to make AI shopping safer
Six banks — ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING, and NatWest — have published a joint report called “Building Trust in Agentic Commerce.” It outlines five principles for building a safer ecosystem.
1. Transparency
When an AI agent isn't clearly defined or identifiable, it can be difficult to tell who customers are dealing with, who is accountable, or whose interests the agent represents. This could lead to conflicts of interest. For instance, an AI agent might favor products or payment methods that are more beneficial to its provider rather than choosing what’s best for the consumer.
The report recommends that everyone involved in a transaction should know when an AI agent is involved and on whose behalf it acts. More importantly, consumers should be able to see how agents rank options and make decisions, including any sponsored results.
Just days ago, Amazon blocked Meta's new personal AI agent Muse from shopping on its platform. Amazon said Muse failed to identify itself while browsing Amazon and raised privacy and security concerns around its handling of customer credentials.
2. Safety
The use of agentic commerce could increase fraud, disputes, and scams. It's still unclear who would be liable if an agent exceeds its authority. Agents might also request customers' card details and enter them directly into websites, or prioritize payment methods that offer weaker protections.
Malicious third parties could also attempt new types of attacks by compromising or impersonating AI agents and merchants, or using social engineering to steal users' financial data.
The report recommends giving consumers more control over the authority they grant to AI agents, including the ability to view and edit those permissions.
3. Privacy and data
Using agentic commerce creates a new stream of rich data, including prompts, decision logs, purchase details, and records of what the user instructed the AI agent to do. This creates risks around excessive data collection, profiling, data breaches, and retaining information for too long.
For example, this data could be used to build a detailed profile of a consumer and potentially support targeted advertising. If that information ends up in a data breach, it could reveal a person's choices and preferences and give attackers material for targeted phishing attacks.
The report recommends that providers maintain auditable records of this customer-rich data and that each party only access the information it needs to perform its role. Any additional use or sharing of data should require the consumer's consent.
4. Choice
Both customers and merchants should be able to choose which agentic services they use without unreasonable restrictions. Large platforms, such as online marketplaces, digital wallets, or payment networks, should not become gatekeepers that favor their own infrastructure or affiliated services at the expense of alternatives.
5. Interoperability
The agentic commerce ecosystem includes various participants, many of which are still developing. If AI agents, payment methods, and protocols become fragmented, integration costs could rise and switching could become harder. Inconsistent protections could also undermine customer trust.
However, forcing everyone to adopt common standards too early could slow innovation. The report therefore recommends focusing first on interoperability for core functions while leaving room for companies to innovate on additional features.
The risks of using agentic AI for online shopping
Given the sheer amount of personal data you hand over when shopping online, including your credit card details, address, phone number, login credentials, and email, using an AI agent to handle those tasks creates a much larger security and privacy risk.
Hidden instructions can make agents leak your data
A major structural weakness in AI agents that read webpages or emails is that they can't always reliably distinguish between content and instructions. An attacker can hide malicious instructions in a page, and the agent could follow them using your logged-in access.
In July 2025, Brave's security team disclosed research showing how a hidden instruction in a Reddit comment could compromise a Perplexity Comet browser session. The agent was asked to summarize a Reddit thread, but the hidden instructions told it to access the user's email address, obtain a one-time password from Gmail, and send both pieces of information back to the attacker.
Brave warned that because these AI agents operate with full user privileges, an attack like this could potentially gain access to banking accounts and private email.
The 2025 Microsoft 365 Copilot “EchoLeak” vulnerability provided another example of this problem. A malicious email could contain hidden instructions that caused Copilot to retrieve sensitive information from the user's Microsoft 365 environment and send it to an attacker-controlled server.
Agents can fall for scams and hand over your details
This is one of the most direct consequences of using agentic AI for shopping online.
In August 2025, Guardio Labs tested an agentic AI browser by directing it to a fake Walmart page and asking it to buy an Apple Watch. The agent reached checkout, autofilled the saved card and address details, and completed the purchase without asking for confirmation. It ignored several signs that the website was fake.
In a separate but similar phishing test, the agent fell for a fake Wells Fargo email, clicked the link, and entered the user’s banking credentials on the fake login page.
Agents can also go rogue
There have already been examples of AI agents taking actions that users did not authorize. In February 2025, Washington Post columnist Geoffrey Fowler asked OpenAI's Operator to find cheap eggs but not buy them. However, Operator went ahead and authorized a $31.43 purchase using his credit card.
And while it wasn't related to shopping, Replit's AI coding agent deleted a live production database during a 2025 experiment despite being told not to make changes. The database contained records for over 2,400 executives and companies.
How to stay safe when using AI shopping agents
It's good practice not to overly rely on AI agents for shopping. Be particularly careful about how much personal and financial information you allow an agent to access.
For starters, don't authorize an AI agent to access your credit card or other financial details. You could still use these AI agents to search for products and find the best deals, but make sure you’re the one who completes the final payment and enters details such as your email address and delivery address.
Also, review the website the AI agent recommends before buying anything. Check the URL and page design, and if anything looks suspicious, consider abandoning the purchase altogether. You can also use a third-party antivirus program with real-time web protection to flag suspicious pages and links before you interact with them.
If you've already given an AI agent more access than you're comfortable with, revoke its access to your personal information and saved payment methods. You could also consider using an identity theft protection service, which can alert you if your information appears in known data breaches or on the dark web.
The bottom line
Bank of America's report is a reminder that AI shopping agents are still a relatively new technology with significant risks that industry standards and consumer protections have yet to fully address.
An AI agent with access to your personal information and payment details could potentially make purchases without your approval, fall for phishing scams, or expose sensitive data while navigating the web on your behalf.
As a result, you should carefully control what personal information your AI agent can access. Consider using these tools to find the best deals and products, but make a habit of executing the transaction yourself and entering your sensitive personal and payment details manually.