The Banks Have Identified the Real Problem With AI Shopping Agents: Who Controls the Money?

Six major global banks have issued a warning about the emerging market for agentic commerce. Their concern is straightforward: Consumers are being asked to give artificial intelligence increasing authority over purchasing decisions, payment methods and sensitive financial information before the industry has established consistent protections around that authority.

The report, covered by Gizmodo, identifies five areas requiring attention: Transparency, safety, privacy and data, choice, and interoperability. The banks, including Bank of America and Capital One, warn that the risks increase as shopping agents become more autonomous. They also acknowledge the potential for agentic commerce to become a mainstream way for consumers and merchants to transact.

This is an important development because the financial industry is identifying a problem that extends well beyond online shopping. As AI agents become capable of acting on behalf of humans, the distinction between making a recommendation and having authority to execute it becomes increasingly consequential.

For agentic commerce, that distinction determines who ultimately controls the customer’s money.

The Consumer’s Interests Must Remain the Priority

An AI shopping assistant can provide substantial value. It can compare products across retailers, identify relevant features, evaluate pricing and help consumers navigate an increasingly complicated purchasing process. With the right access, it can also prepare orders, coordinate delivery and manage recurring purchases.

The difficulty emerges when the agent begins making decisions independently.

The banks raise concerns that shopping agents could favor particular products or payment methods because of commercial incentives, including commissions or lower operating costs. An agent might recommend something that satisfies the customer’s stated requirements while prioritizing a merchant or transaction that benefits the platform operating the agent.

That creates a conflict between the customer’s objective and the incentives influencing the system.

The problem becomes more serious when the agent can complete a transaction without requiring the customer to review its decision. A recommendation influenced by an undisclosed commercial incentive is one concern. An autonomous purchase based on that recommendation creates a financial consequence.

The consumer needs a way to establish requirements that remain enforceable regardless of the agent’s reasoning, the commercial incentives surrounding the transaction or the underlying model being used.

Authorization Must Be Specific

Consider a customer who asks an AI assistant to find a replacement laptop for less than $1,500. The agent searches several retailers, compares specifications and identifies a suitable product.

At this stage, the AI is performing a useful research task. The customer has provided an objective and the system is working toward it.

But the agent may encounter several decisions that require different levels of authority. Can it purchase from an unfamiliar merchant? Can it select a refurbished product? Can it use a different payment method to obtain a discount? Can it accept a recurring subscription bundled with the purchase?

A general instruction to find and purchase a laptop does not necessarily establish permission for every decision the agent might make.

This is where deterministic runtime governance becomes valuable. Spending limits, merchant restrictions, payment permissions and approval requirements can be established independently of the agent’s interpretation of the task.

If the agent discovers a different purchasing strategy, it can still evaluate that strategy. Whether the resulting transaction is permitted remains subject to the customer’s authorization.

That approach allows the AI to remain useful without requiring the customer to surrender unrestricted financial authority.

The Risk Extends Beyond the Original Shopping Request

The banks also warn about fraud, scams and the potential consequences of exposing sensitive customer information. These concerns become particularly important when shopping agents interact with unfamiliar websites, external services and other autonomous systems.

A shopping agent might encounter a malicious product listing, a fraudulent merchant or instructions embedded in information retrieved from the internet. If the agent treats that information as authoritative, an attacker may be able to influence its purchasing behavior.

The consequences depend on the permissions available to the agent.

An assistant limited to researching products may produce a misleading recommendation. An assistant with unrestricted payment credentials could potentially expose the customer to a financial loss.

The security architecture must therefore account for what happens when the model is manipulated or makes an incorrect decision. Credential protection, transaction verification and payment security remain essential, while runtime governance can independently restrict the actions the agent is permitted to execute.

An agent’s ability to identify a transaction should never automatically establish its authority to complete that transaction.

What We’ve Demonstrated With VERN OS

At VERN, we’ve been developing the independent control architecture needed for increasingly autonomous AI.

VERN OS provides deterministic runtime governance outside the underlying probabilistic model. Human-defined controls govern tool use, authorization requirements, behavioral boundaries and consequential actions while allowing the AI to reason and adapt.

Our agentic-control experiments demonstrate why this separation matters.

In one test, an ungoverned agent pursued a computational task through a strategy that could have required as many as 187 tool calls. With VERN OS enforcing a deterministic tool-call budget, the same model adapted its strategy and completed the task in two turns.

In another experiment, an angry customer demanded an immediate $240 refund. The ungoverned agent issued it. With VERN OS governing the interaction, the AI could investigate the account and prepare the refund, but execution required explicit authorization.

That second experiment is particularly relevant to agentic commerce. The AI retained the ability to investigate the situation and prepare a consequential financial action, while the control layer preserved the authorization boundary.

The same architectural principle can be applied to shopping agents, where research, product selection, order preparation and payment execution require different levels of authority.

Trust Must Be Enforced During the Transaction

The banking industry’s concerns also expose a limitation of relying exclusively on model-level safety instructions.

An AI provider can instruct its shopping agent to act in the customer’s interests, avoid suspicious merchants and request authorization before completing certain transactions. Those instructions are valuable, but they are interpreted by the same probabilistic system making the purchasing decisions.

The model may encounter ambiguous instructions, conflicting information or adversarial content. It may also be updated or replaced as the provider introduces new capabilities.

An independent governance layer allows the customer’s authorization requirements to remain consistent across those changes.

For merchants, payment providers and financial institutions, this separation can also improve accountability. The system can maintain records of what the agent attempted, which restrictions applied and whether a transaction received the necessary authorization.

That operational evidence becomes valuable when investigating disputes, identifying unauthorized behavior or demonstrating that the agent operated within its assigned authority.

Trust in agentic commerce will depend on the ability to establish and enforce these requirements throughout the transaction.

The Future of Commerce Requires Human Control

The banks are not rejecting agentic commerce. Their report recognizes its potential while calling for standards and protections that address the risks associated with increasing autonomy.

That is an important distinction. Shopping agents could make commerce substantially more convenient, particularly for consumers navigating complicated products, comparing large numbers of options or managing routine purchases.

But convenience should not require consumers to surrender control over their money, personal information or purchasing preferences.

The architecture needs to preserve the customer’s authority as the agent moves from research to recommendation, from recommendation to order preparation and from order preparation to payment.

VERN OS provides a way to establish those boundaries independently of the underlying intelligence, allowing organizations to deploy capable shopping agents while maintaining deterministic control over their behavior and authorized actions.

The financial industry is asking how consumers can trust AI agents with their money. A meaningful answer requires enforceable limits on what those agents are permitted to do.

As AI becomes an increasingly active participant in commerce, human control needs to remain part of every transaction.

VERN is human control over artificial intelligence.

Source: https://gizmodo.com/big-banks-say-theyre-uneasy-about-people-shopping-via-ai-agents-2000815443

VERN agentic-control demonstrations: https://vernai.com/agentic-control/