ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING and NatWest published Building Trust in Agentic Commerce on September 22. The joint paper looks beyond AI-assisted product discovery and toward systems that can participate directly in transactions on a consumer's behalf.

The banks define agentic commerce broadly: an AI agent can help make or facilitate a payment between a consumer and a merchant. At the low-autonomy end, software might find suitable products while a person still handles checkout. At the other end, one instruction can give an agent enough authority to select an item and purchase it without the customer reviewing the final choice.

A recommendation error becomes a money problem

The risk changes once an agent receives spending authority. A bad recommendation is inconvenient. A bad autonomous transaction can involve the wrong merchant, the wrong item, too much money or a payment route with weaker consumer protections.

The paper flags practices such as agents collecting card details and typing them directly into websites. It also considers fraud scenarios in which criminals compromise or impersonate agents and merchants. Existing payment systems are very good at answering whether a transaction was authorized in the conventional sense. That may not be enough to establish whether the software stayed inside the mandate the customer actually gave it.

Imagine telling an agent to buy a particular laptop for no more than $1,000. A successful card authorization says money moved. It does not, by itself, explain whether the machine was allowed to choose that retailer, substitute another configuration, cross the spending limit or change payment methods along the way.

The banks want an audit trail from instruction to checkout

Their proposed answer is traceability. Relevant participants should be able to preserve evidence covering the customer's instruction, the authority delegated to the agent, authentication, intent, transaction decisions and the final outcome.

That record matters most when something fails. A consumer may need to dispute an unauthorized action, a merchant may face a chargeback for a decision it did not control, and a payment provider may need to determine where the error or fraud entered the chain.

The paper therefore argues that dispute mechanisms should include the parties that actually influenced the transaction and that participants exposed to potential liability should be able to require authentication where appropriate.

Trust is split into five pieces

The framework is organized around transparency, safety, privacy and data, choice, and interoperability. Transparency includes knowing when an AI agent is involved, whose interests it represents and how it prioritizes products or payment options.

That becomes awkward as soon as commercial incentives enter the model. An agent could rank the best deal for the customer, a sponsored option that pays its provider more, or a payment method that is cheaper for the service operating the agent. If those incentives are invisible, convenience starts looking uncomfortably similar to delegated advertising.

More auditing also creates a privacy trade-off. Records of prompts, permissions, purchase decisions and spending constraints may be extremely useful for fraud investigations. They may also become an unusually detailed profile of a consumer if too many companies can access them or keep them indefinitely.

The banks consequently call for access to be limited to the data each participant needs, with additional uses and sharing subject to appropriate consent.

The shopping agents are arriving before the rulebook

This is not a discussion about a distant prototype. OpenAI, Anthropic, Google, Meta and payment companies are already building systems around AI-assisted and agentic shopping. Reuters reported that British retailer John Lewis saw searches originating from AI agents rise from 0.3% to 2.5% over a year.

Search traffic is not the same thing as letting software spend money autonomously. The distance between those two actions is precisely where identity, authorization and liability suddenly become much harder.

The six-bank document does not solve that problem yet. Its principles are voluntary and nonbinding, it specifies no single technical protocol, and it comes with no implementation deadline. The group says a subsequent paper will address how the principles could be translated into protocols, industry standards and policies, while inviting other companies across the payments ecosystem to participate.

For now, the useful idea is simpler than the infrastructure required to implement it: if software is going to hold purchasing authority, the checkout system needs to know which agent showed up, who it was acting for, what it had permission to do and where to look when the result no longer matches the instruction.