Agentic commerce is rapidly moving from a speculative AI use case toward a payments-governance problem where, if software agents can choose products and initiate purchases, banks need clearer ways to establish security, customer intent, privacy, and interoperability. That new reality was recently exemplified by a joint publication by six global banks including ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group and NatWest Group. The publication establishes a set of principles needed to guide trusted agentic commerce, where AI agents go beyond simply recommending products to selecting, ordering and potentially initiating payment on a customer’s behalf.
The publication aims to address a common concern across the banking sector: agentic capabilities are advancing faster than existing industry standards and consumer-protection mechanisms. For example, Reuters reported that UK retailer John Lewis saw searches originating from AI agents increase from 0.3% to 2.5% in just one year, a strong indication that AI-mediated shopping is already becoming measurable. Across the board, major technology companies, including fintechs, are increasingly promoting AI assistants as full-fledged shopping tools, which naturally has major implications for banks, payment providers, and many other highly regulated sectors.
The joint announcement covers five main areas where additional control and governance mechanisms for agentic AI are increasingly becoming nonnegotiable: transparency, safety, data privacy, choice, and interoperability. For instance, both customers and merchants should know when an AI agent is invoked, who it represents and, where relevant, why it selected a particular product or payment method. Meanwhile, choice and interoperability establishe standardized connections for core protections with a view to reducing fragmentation.
One of the publication’s most important focus areas is authorization, audit trails and liability. This addresses a common practical concern whereby, if an agent buys the wrong item, spends too much, or is even tricked by a scam, then every participant needs evidence showing what the user instructed the agent to do, how they were authenticated and what the agent actually did. After all, agents alone can’t be held accountable if something goes wrong. Liability ultimately sits with merchants, issuers, acquirers, wallet providers and AI-agent vendors themselves, meaning that every party needs clearer rules for determining where and how an error or risk entered the transaction.
There’s also another side to the story, and it’s one of the biggest apparent contradictions in agentic AI—the tension between auditability and privacy. While intent logs and shopping prompts can help identify errors in agentic workflows or resolve disputes and fraud, they can also expose sensitive behavioral and purchasing information.
For fintech companies and payments leaders, the principles presented by the six aforementioned banks translate into clear operational requirements. Those include delegated-authority controls, agent identity, consent records, fraud monitoring, transaction logs, data minimization and dispute-resolution workflows. For many companies, the biggest challenge will be to make such controls interoperable rather than designing one-off protections for every AI platform they use. Ultimately, the harder problem is not teaching an agent how to make payments, but proving that a payment reflected the customer’s actual intent—while preserving recourse if it doesn’t.
.png?width=1816&height=566&name=brandmark-design%20(83).png)