Big Story: It’s 10pm. Do you know what your AI agent is buying?

On Sept. 22, six banks (ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING, and NatWest) published Building Trust in Agentic Commerce, a principles paper that starts from a question with no settled answer: when an AI agent buys the wrong thing, who pays? Reuters reported the group’s warning that agents could raise the risk of scams, fraud, and privacy breaches, and noted that British retailer John Lewis has seen searches originating from AI agents climb from 0.3% to 2.5% in a year, meaning autonomous shoppers are arriving before the rules are.

The banks lay out a spectrum. At one end, an agent searches and a human checks out. At the other, it picks and buys off a single instruction and the customer never sees the final choice. And the further along you go, the murkier the disputes get. Issuers and acquirers may lack real-time access to the agent’s identity, the merchant of record, the customer’s intent, and the purchase details. Customers don’t know whom to call when an agent overspends or falls for a scam, and merchants fear chargebacks over decisions they never controlled.

The proposed fix is voluntary. Providers should keep evidence of the customer’s instruction, the authentication, the agent’s decision, and the outcome, including any warnings or interventions. Customers should be able to see and manage the authority they’ve delegated. Liability should follow wherever the error or risk entered the transaction. The paper also names some positively Black Mirror-esque scenarios: agents keying card numbers into unfamiliar websites, agents favoring payment methods with weaker protections, and criminals impersonating or compromising agents and merchants.

FIDO Alliance CEO Andrew Shikiar, interviewed by Payments Dive, is working the same gap from the standards side. His answer is “know your agent”: tie every agent action back to a verified human, and track an agent’s breadcrumbs (where it has been, what it has bought, what services it has touched). Shikiar doesn’t expect agentic commerce at scale for years because chargebacks and liability for a rogue agent are unresolved, and when he cited McKinsey’s $3 trillion-by-2030 projection, he said the industry isn’t there yet.


More

Biometric Update: Agents are going rogue, and it’s up to the identity sector to govern them

The AI apocalypse is trending. Warnings are flying that continuing to develop AI technology at the current…

Read More →

WiredGov: How we made it easier for millions of users to sign into government services

This month, the Government Digital Service (GDS) made it faster, easier and more secure to…

Read More →

Biometric Update: UK rolls out passkeys for GOV.UK One Login

The UK government is expanding passkey sign-in for GOV.UK One Login after an initial trial.…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.