The proposal addresses the issue of whether an agent bought what its customer actually intended. It’s a problem that a routine payment authorization may not resolve.
In a paper published Tuesday (Sept. 22) called “Building Trust in Agentic Commerce,” ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING and NatWest said providers should preserve evidence of consumer instructions, authentication, intent, transaction decisions and outcomes. Records should also capture warnings or interventions, giving participants a basis to investigate scams, recover money and resolve disputes.
The banks defined agentic commerce in the paper as the use of AI agents to help make or facilitate payments between consumers and merchants. An agent might simply search for a product before a person completes checkout. With greater autonomy, it could select and purchase an item after an initial instruction, without the customer reviewing the final choice. The risks can grow as agents gain more authority.
The risks are already raising questions across the payment chain. Issuers and acquirers may lack real-time access to an agent’s identity, the merchant of record, the customer’s intent and purchase details, the paper said. Meanwhile, customers may not know whom to contact if an agent buys the wrong item, overspends or falls for a scam. Merchants fear disputes and chargebacks arising from decisions they did not control.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
The paper’s proposed safety principle would give customers a way to view and manage the authority delegated to agents. It called for secure, auditable methods of entering payment credentials and authorizing purchases and payments. Any party facing potential liability should be able to require authentication. There should also be dispute processes to involve the relevant participants, with liability reflecting where an error or risk entered the transaction.
The paper cited unsafe practices, including agents asking for card details and entering them directly into websites or favoring payment methods with weaker protections. Criminals could impersonate or compromise agents and merchants. Information sharing, customer warnings, fraud interventions and recovery efforts across the payment chain are needed.
Consumers, merchants and payment providers should know when an agent is involved and on whose behalf it acts, the paper said. Agents should explain how they prioritize products and payment methods, including sponsored options. An agent might otherwise favor a choice that generates a higher commission or lowers its provider’s costs, even when another choice offers better value to the customer.
That explanation would itself create sensitive information. Shopping prompts, decision logs, records of delegated authority and purchase details could aid fraud investigations, but they could also expose consumers and merchants to profiling, breaches or excessive data retention, according to the paper. There should be limited access to data needed to perform each participant’s function and consent for additional uses or sharing.
The remaining principles in the paper addressed choice and interoperability. Customers and merchants should be able to select agents, wallets and payment services without unreasonable restrictions. At the same time, providers should be able to choose which services they support on safety, commercial and legal grounds. Common connections for core protections could reduce fragmentation while leaving room for competing features.
The paper is voluntary and nonbinding. It did not call for any particular implementation method or include a timetable. A subsequent paper will explore how to translate the principles into protocols, industry standards and policies. For now, the central argument is that trustworthy agentic commerce will require participants to reconstruct the path from a customer’s instruction to the resulting transaction, and to use that record when something goes wrong.
For all PYMNTS AI coverage, subscribe to the daily AI newsletter.