Banks want disclosure rules for AI shopping agents. Disclosure isn't verification.
Hot take: the scariest part of agentic commerce isn't that an AI agent might buy the wrong thing. It's that nobody can tell you afterward why it bought it.
This week a coalition of banks — NatWest, Bank of America, ING, Capital One, ASB, Commonwealth Bank of Australia — put out a joint warning to regulators about AI shopping agents. Their report lists the obvious risks: agents that collect a customer's card details and submit them on third-party sites, agents that quietly favor payment methods with weaker consumer protections, bad actors impersonating agents or merchants, new flavors of social engineering aimed at the agent instead of the human. Their proposed fix is disclosure and transparency rules: tell the customer an agent is involved, explain how it decided, add safeguards around the data.
I've spent the last several years building autonomous systems that make decisions without a human confirming every step — an offline multilingual AI avatar handling customer interactions for Mercedes-Benz in Germany, real-time drone threat detection for the Indian Army and police running at 94% precision. Different domain, same underlying problem the banks just rediscovered: the moment you let a system act on someone's behalf, capability stops being the interesting metric. Verifiability is.
Everyone building agentic commerce right now is optimizing for the demo — the agent finds the item, compares prices, checks out, done. That's the same 95%-of-LinkedIn-demos problem I keep pointing at, just wearing a shopping cart. A demo only has to work once, in front of an audience that isn't trying to break it. A production agent handling someone's card details has to survive a motivated attacker, a malformed merchant page, and its own hallucinated confidence, every single time, with no one watching.
The banks are asking for disclosure and transparency. Fair, but it's the weaker half of the fix. Disclosure tells a customer an agent was involved after the fact. It doesn't tell you whether the agent's decision was correct, or catch it before the money moves. That requires the same thing I build into every high-stakes system I ship: a verification layer that sits outside the model and checks its output against constraints before anything irreversible happens — before a purchase clears, before a payment method is selected, before a card number leaves the device. Not a second opinion from another LLM. A deterministic check.
There's also a control question underneath the privacy one, and it's the one I'd push back on hardest. An agent that "collects card details and submits them on third-party sites" is, by design, routing sensitive data through infrastructure the customer doesn't control and often can't see. Every time I've built a system that touches money, health data, or defence-relevant information, the safer architecture kept the sensitive material on-device and sent only the decision — not the raw payment data — out to wherever the transaction needed to happen. That's a harder engineering problem than piping card numbers through a cloud agent. It's also the difference between a company that can tell a regulator exactly what happened and one that's guessing from logs it doesn't fully trust.
None of this is a reason to slow-walk agentic commerce. It's a reason to stop treating "the agent completed the purchase" as the finish line. Completion isn't correctness, and a transaction that clears isn't the same as a transaction that should have cleared. I've watched that gap bite automotive deployments and defence systems before it ever showed up in a bank's risk report; retail is just the domain where it's visible enough now to make the news.
The banks did the right thing sounding the alarm before the fraud numbers force the issue. But disclosure rules without a verification layer just means customers will know, in detail, exactly how they got scammed. The takeaway: if your AI agent can spend real money, the question that matters isn't "did it disclose itself" — it's "what stopped it from being wrong."