Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,347▼ 2.52%ETH$2,686▼ 2.75%SOL$115.20▼ 2.73%TOTAL CRYPTO$2.88T▼ 4.95%S&P 5007,706.03▲ 0.41%NASDAQ26,936.04▲ 2.89%DOW51,511.59▼ 3.31%GOLD4,328.40▼ 7.86%WTI91.47▲ 7.60%BRENT97.39▲ 5.66%EUR/USD1.1387▼ 2.53%USD/JPY157.87▼ 0.65%DXY101.09▲ 2.11%
Technology

Banks Warn AI Shopping Bots Raise Scam and Privacy Risks

NatWest and other banks say AI agents that shop on your behalf create new openings for scams, fraud and data leaks that current protections do not cover.

Pexels – Kindel Media

Banks including NatWest are warning that AI shopping agents create fresh openings for scams, fraud and data-privacy breaches. The caution arrives just as the technology moves from demos to real wallets, with several major platforms rolling out agents that can browse, compare and buy without a human clicking anything.

The warning, reported by Insurance Journal from reporting by Reuters, came in remarks from fraud specialists at banks tracking the space. Their concern is simple: when an agent acts for you online, it carries your payment credentials, your account logins and your personal data into places no human would type them. Each of those handoffs is a new point where something can go wrong.

Agentic shopping is no longer hypothetical. OpenAI, Google and Perplexity have all shipped or announced agents that complete purchases, and payment networks have built flows that let a model check out on a user behalf. The pitch is convenience: tell the agent what you need, get a shortlist, approve it once, and never open a browser tab again. The banks do not dispute the convenience. They question what happens when the same pipeline meets a professional fraud operation.

Three Ways the Model Breaks

The first risk is the oldest one in the book dressed in new code: phishing reimagined for machines. A malicious website can be built to look trustworthy to an agent, which has no instincts, only instructions. Researchers have already shown that hidden text on a product page, invisible to humans but readable by a crawler, can steer an agent toward a hostile checkout. The consumer sees a normal order confirmation. The card details went somewhere else.

The second is account compromise at scale. If an agent holds stored credentials for retail sites, email and payment apps, one breach empties all of them at once. Fraud teams already handle this pattern with human users, and their tooling assumes a person is on the other end of the session. An agent that logs in from new places at odd hours looks, to a fraud model, exactly like an attacker. Legitimate automated behavior and criminal automated behavior are, from the outside, often the same behavior.

The third is data leakage that no one intended. Agents summarize, cache and sometimes share context to work better. Details about a household shopping patterns, income signals and health-adjacent purchases can end up in logs held by several companies. Privacy rules like GDPR give people rights over data they knowingly handed over. Whether they cover inferences an agent made on its own is unsettled, and regulators on both sides of the Atlantic have started asking the question.

What the Banks Want

NatWest and its peers are not asking for a ban. They want liability clarity and authentication standards before the volume grows. Today, when a human makes an unauthorized card payment, well-defined chargeback rules decide who pays. When an agent makes an unauthorized payment because it was tricked, nobody is sure whether that falls to the bank, the platform, the merchant or the customer. That ambiguity, the banks argue, will be exploited, and exploited fast.

They also want agents to prove who they are. Several proposals now circulating would give shopping agents a verifiable identity, so a merchant can tell a legitimate buyer-bot from a scraper or a fraud script. Payment networks including Mastercard have announced agentic checkout standards with tokenized credentials, an attempt to keep raw card numbers away from models entirely. The design principle is the same one that worked for contactless payments: give the system a way to say yes that never exposes the thing being protected.

Consumer groups have added a further demand: a clear pause button. A shopper who realizes an agent is about to buy the wrong thing, or has been steered by a manipulated page, needs a way to stop the transaction chain mid-flight, the way a human can simply close a tab. Early agent products offer confirmations, but confirmation fatigue sets in quickly, and a user who approves everything is not really approving anything.

The Timing Problem

The warning lands while adoption is accelerating. Holiday-season pilots are planned across several retail platforms, and every major browser vendor is wiring agents into the tools people already use. Fraud losses in online retail already run into billions annually. Adding a layer that removes human judgment from the purchase moment, banks argue, removes the single best fraud control the industry has ever had: the customer own doubt.

Merchants sit in an awkward spot too. Refuse agent traffic and they lose the growing share of buyers who arrive through one. Accept it and they carry the fraud exposure that follows it. A handful of large retailers have started labeling their sites as agent-friendly or agent-hostile, an improvised solution to a problem that really needs standards.

None of this means agentic shopping will fail. ATMs, card-not-present payments and one-click checkout all faced fraud panics of their own, and all became mainstream once the liability rules settled. The banks are effectively asking for that settlement to happen before the volume arrives, not after the first big incident. History suggests the industry tends to do it the other way around.

For shoppers, the interim advice is what the banks tell their own staff: keep agents on a separate payment method with tight limits, review what data the agent can see, and treat the first year of the technology the way you would treat a new acquaintance with your wallet. Helpful, probably. Verified, not yet.

SourcesInsurance Journal (Reuters reporting); NatWest fraud team remarks; Mastercard agentic checkout announcements
Share: X