The Price of Convenience? Major Banks Warn AI Shopping Bots Are Moving Faster Than Your Fraud Protections

AI agents could make shopping easier, but giving them access to your personal and payment data could expose you to scams, fraud, and data theft.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Using AI agents to shop online, find the best products and deals, and then authorize them to execute transactions on your behalf could expose you to several security and privacy risks, according to a new report from Bank of America and five other banks.[1]

The report highlights the need to build trust with AI agents before giving them the authority to handle sensitive personal information or make purchases on your behalf. Because the technology is still developing, industry standards and consumer protections have yet to catch up.

The AI agent you trust could fall for a fake shopping website or phishing page and enter your personally identifiable information, such as credit card details, email address, or home address. This could leave you vulnerable to targeted phishing attacks, identity theft, or financial fraud.

Here’s what the report says about the risks of agentic shopping and the steps you can take to make your AI-assisted shopping safer.

In this article
What banks recommend to make AI shopping safer
The risks of using agentic AI for online shopping
How to stay safe when using AI shopping agents
The bottom line

What banks recommend to make AI shopping safer

Six banks — ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING, and NatWest — have published a joint report called “Building Trust in Agentic Commerce.” It outlines five principles for building a safer ecosystem.

1. Transparency

When an AI agent isn't clearly defined or identifiable, it can be difficult to tell who customers are dealing with, who is accountable, or whose interests the agent represents. This could lead to conflicts of interest. For instance, an AI agent might favor products or payment methods that are more beneficial to its provider rather than choosing what’s best for the consumer.

The report recommends that everyone involved in a transaction should know when an AI agent is involved and on whose behalf it acts. More importantly, consumers should be able to see how agents rank options and make decisions, including any sponsored results.

Just days ago, Amazon blocked Meta's new personal AI agent Muse from shopping on its platform. Amazon said Muse failed to identify itself while browsing Amazon and raised privacy and security concerns around its handling of customer credentials.

2. Safety

The use of agentic commerce could increase fraud, disputes, and scams. It's still unclear who would be liable if an agent exceeds its authority. Agents might also request customers' card details and enter them directly into websites, or prioritize payment methods that offer weaker protections.

Malicious third parties could also attempt new types of attacks by compromising or impersonating AI agents and merchants, or using social engineering to steal users' financial data.

The report recommends giving consumers more control over the authority they grant to AI agents, including the ability to view and edit those permissions.

3. Privacy and data

Using agentic commerce creates a new stream of rich data, including prompts, decision logs, purchase details, and records of what the user instructed the AI agent to do. This creates risks around excessive data collection, profiling, data breaches, and retaining information for too long.

For example, this data could be used to build a detailed profile of a consumer and potentially support targeted advertising. If that information ends up in a data breach, it could reveal a person's choices and preferences and give attackers material for targeted phishing attacks.

The report recommends that providers maintain auditable records of this customer-rich data and that each party only access the information it needs to perform its role. Any additional use or sharing of data should require the consumer's consent.

4. Choice

Both customers and merchants should be able to choose which agentic services they use without unreasonable restrictions. Large platforms, such as online marketplaces, digital wallets, or payment networks, should not become gatekeepers that favor their own infrastructure or affiliated services at the expense of alternatives.

5. Interoperability

The agentic commerce ecosystem includes various participants, many of which are still developing. If AI agents, payment methods, and protocols become fragmented, integration costs could rise and switching could become harder. Inconsistent protections could also undermine customer trust.

However, forcing everyone to adopt common standards too early could slow innovation. The report therefore recommends focusing first on interoperability for core functions while leaving room for companies to innovate on additional features.

The risks of using agentic AI for online shopping

Given the sheer amount of personal data you hand over when shopping online, including your credit card details, address, phone number, login credentials, and email, using an AI agent to handle those tasks creates a much larger security and privacy risk.

Hidden instructions can make agents leak your data

A major structural weakness in AI agents that read webpages or emails is that they can't always reliably distinguish between content and instructions. An attacker can hide malicious instructions in a page, and the agent could follow them using your logged-in access.

In July 2025, Brave's security team disclosed research showing how a hidden instruction in a Reddit comment could compromise a Perplexity Comet browser session. The agent was asked to summarize a Reddit thread, but the hidden instructions told it to access the user's email address, obtain a one-time password from Gmail, and send both pieces of information back to the attacker.

Brave warned that because these AI agents operate with full user privileges, an attack like this could potentially gain access to banking accounts and private email.

The 2025 Microsoft 365 Copilot “EchoLeak” vulnerability provided another example of this problem. A malicious email could contain hidden instructions that caused Copilot to retrieve sensitive information from the user's Microsoft 365 environment and send it to an attacker-controlled server.

Agents can fall for scams and hand over your details

This is one of the most direct consequences of using agentic AI for shopping online.

In August 2025, Guardio Labs tested an agentic AI browser by directing it to a fake Walmart page and asking it to buy an Apple Watch. The agent reached checkout, autofilled the saved card and address details, and completed the purchase without asking for confirmation. It ignored several signs that the website was fake.

In a separate but similar phishing test, the agent fell for a fake Wells Fargo email, clicked the link, and entered the user’s banking credentials on the fake login page.

Agents can also go rogue

There have already been examples of AI agents taking actions that users did not authorize. In February 2025, Washington Post columnist Geoffrey Fowler asked OpenAI's Operator to find cheap eggs but not buy them. However, Operator went ahead and authorized a $31.43 purchase using his credit card.

And while it wasn't related to shopping, Replit's AI coding agent deleted a live production database during a 2025 experiment despite being told not to make changes. The database contained records for over 2,400 executives and companies.

How to stay safe when using AI shopping agents

It's good practice not to overly rely on AI agents for shopping. Be particularly careful about how much personal and financial information you allow an agent to access.

For starters, don't authorize an AI agent to access your credit card or other financial details. You could still use these AI agents to search for products and find the best deals, but make sure you’re the one who completes the final payment and enters details such as your email address and delivery address.

Also, review the website the AI agent recommends before buying anything. Check the URL and page design, and if anything looks suspicious, consider abandoning the purchase altogether. You can also use a third-party antivirus program with real-time web protection to flag suspicious pages and links before you interact with them.

If you've already given an AI agent more access than you're comfortable with, revoke its access to your personal information and saved payment methods. You could also consider using an identity theft protection service, which can alert you if your information appears in known data breaches or on the dark web.

The bottom line

Bank of America's report is a reminder that AI shopping agents are still a relatively new technology with significant risks that industry standards and consumer protections have yet to fully address.

An AI agent with access to your personal information and payment details could potentially make purchases without your approval, fall for phishing scams, or expose sensitive data while navigating the web on your behalf.

As a result, you should carefully control what personal information your AI agent can access. Consider using these tools to find the best deals and products, but make a habit of executing the transaction yourself and entering your sensitive personal and payment details manually.

4.8
Editorial Rating
Claim Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription
Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Building Trust in Agentic Commerce