Skip to main content

When AI Agents Act for Customers, Banks Must Rethink Trust

By Jessica Kendall, Contributor at The Financial Brand

Published on October 2nd, 2026 in Artificial Intelligence

Simple Subscribe

Subscribe Now!

Stay on top of all the latest news and trends in the banking industry.

Consent Granted*

Agentic commerce is moving from closed trials into live pilots and early scaling, even as the standards and consumer protections governing it continue to develop.

A new paper — Building Trust in Agentic Commerce — co-authored by ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group, and NatWest Group outlines five principles for creating a trusted ecosystem: transparency, safety, privacy and data, choice, and interoperability.

The framework addresses a fundamental change in how transactions happen when AI agents can recommend products, make decisions, handle payment credentials, and complete purchases on a customer’s behalf.

Key insight: For banks, that raises practical questions about how to authenticate delegated authority, identify AI agents, detect fraud, resolve disputes, and govern the increasingly rich data generated around each transaction. The report’s central message is that these capabilities need to develop alongside clear customer protections and shared standards, rather than being treated as separate concerns.

Need to Know:

  • Treat agent identity as a customer experience issue. Customers need to understand when an AI agent is acting for them, whose interests it represents, and how it decides among products, payment methods, and other options.
  • Build controls around delegated authority. Banks will need ways for customers to see, manage, and authenticate the authority they give an AI agent, particularly as transactions become increasingly autonomous.
  • Make transaction data useful and auditable. Agentic commerce will create richer records of customer intent, instructions, decisions, and outcomes. Banks need appropriate access to that information for fraud prevention, disputes, and recovery while respecting customer consent.
  • Prepare for an ecosystem, not a single platform. Fragmented agents, payment methods, and protocols could increase integration costs and undermine consistent customer protections. Interoperability around core functions will matter as the market develops.

Make the Agent’s Role Visible

The most basic question in an agentic transaction may also be one of the easiest to overlook: who is actually making the decision?

In traditional commerce, the parties are relatively straightforward. A customer chooses a product, a merchant sells it, and a payment provider facilitates the transaction.

Agentic commerce introduces another participant that can search, recommend, compare, select, and potentially purchase on the customer’s behalf. As the agent takes on more responsibility, questions about its identity, authority, and incentives become harder to separate from the transaction itself.

Transparency is needed at several points in the buying process. Customers and merchants should know when an AI agent is involved and on whose behalf it is acting. They should also have visibility into how the agent prioritizes options and makes decisions, including whether an option is sponsored and how data is being collected and used.

That last point introduces an important commercial consideration. An agent may have incentives that are different from those of the customer. An AI provider could, for example, favor a product or payment method that generates a higher commission or costs the provider less to support. The result could be a recommendation that serves the economics of the agent provider without necessarily producing the best outcome for the customer.

Key insight: Transparency should become part of the customer experience and a way to establish accountability when an AI system is making choices on someone’s behalf.

Define Authority Before Transactions Happen

Once an agent can act for a customer, the line between “the customer authorized this” and “the agent decided this” gets considerably more important.

Agentic commerce can involve very different levels of autonomy. A customer might ask an agent to find options but make the final purchase themselves. They might approve a specific purchase for the agent to execute later. Or they might allow the agent to complete a transaction independently after an initial instruction.

Those scenarios create different expectations around authentication, authorization, and liability. Consumers need to be able to view and manage the authority they grant to AI agents. We also need secure and auditable methods to enter payment credentials and authorize purchase intent, with parties that may bear liability able to require authentication.

This creates a useful distinction between authentication of the customer and authentication of the customer’s intent.

A valid credential may establish that a transaction came through an authorized channel. It does not necessarily establish that the customer intended an AI agent to make that particular purchase, at that particular price, from that particular merchant. As agents become more autonomous, the record of what the customer instructed the agent to do becomes increasingly important.

-- Article continued below --

In addition, standards and consumer protections need to account for new forms of fraud and social engineering. Malicious actors could compromise or impersonate AI agents or merchants, while legitimate agents could exceed the authority a customer intended to grant. Disputes could become harder to resolve if responsibility is distributed across the agent provider, merchant, payment provider, issuer, and other participants.

There is also an information problem. Issuers and acquirers may not have real-time visibility into the AI agent involved, the merchant of record, the customer’s intent, or the details of the purchase. Without that context, even sophisticated fraud and risk controls may be working with an incomplete picture of the transaction.

That puts delegated authority and transaction intent alongside existing authentication and fraud controls. It also raises a practical question for every participant in the ecosystem: when something goes wrong, does the transaction record contain enough information to establish what happened?

Treat Transaction Data as Evidence

Agentic commerce could produce a much richer record of a purchase than conventional e-commerce does, including conversational prompts, decision logs, intent mandates, and purchase details. The paper also calls for auditable records that can establish consumer instructions, authentication, intent, transaction decisions and outcomes, warnings, and interventions.

That information could be valuable well beyond the transaction itself. It may help service providers investigate scams and fraud, support recovery efforts, and resolve disputes. But the same richness creates additional privacy concerns, particularly around collection, retention, sharing, profiling, and secondary uses.

The paper’s approach is deliberately narrow: service providers should have access to the information they need to perform their functions safely and effectively, while additional uses or sharing should be governed by consumer and merchant consent.

An agentic transaction may eventually require the ability to reconstruct a chain of events: what the customer asked for, what authority was delegated, what the agent recommended, what decision it made, what authentication occurred, and what ultimately happened. That record could become essential when a customer disputes a transaction or when a fraud investigation needs to distinguish an authorized agent action from an unauthorized one.

Key insight: The challenge is making those records useful without turning every interaction into an excuse to collect and retain more customer information. The paper explicitly links data governance to customer safety and consent, making data minimization and auditability complementary rather than competing objectives.

Keep the Ecosystem Connected

The way this ecosystem is structured will shape how much control customers and merchants actually have. Customers and merchants may interact with a growing mix of AI agents, payment methods, wallets, marketplaces, platforms, and protocols. Fragmentation could increase integration costs, make switching more difficult, and produce inconsistent levels of customer protection.

Standardization has its own tradeoff. Common approaches can improve consistency and customer protection, but trying to standardize every part of the experience could slow innovation and limit differentiated services. The paper therefore draws a line between core functions that need safe, sustainable interoperability and value-added features where providers should have room to innovate.

Choice introduces a different tension. Consumers and merchants should be able to choose the agentic services they use without unreasonable restrictions, but service providers still need discretion over which services they support based on safety, commercial sustainability, and legal or regulatory considerations.

The emerging ecosystem will not be controlled by a single participant. AI agents, payment networks, banks, merchants, wallets, and technology platforms will each control different parts of the transaction. A trusted system depends on those participants being able to exchange the information necessary to manage risk while preserving room for competition and differentiation.

What it means: The practical work is to start translating those principles into the systems and customer experiences that will support transactions when the customer is no longer the only actor in the room.

That means understanding how delegated authority will be represented, what transaction evidence will be available, how fraud and disputes will work across multiple participants, and where interoperability will be necessary.

The technology will continue to evolve. The underlying requirements for a trusted transaction are considerably more durable.

-- Article continued below --

About the Author

Profile PhotoJessica has more than 20 years of experience crafting communications, research, and stories for enterprise technology and financial services organizations, including Spinwheel, MX, and USAA.