
On September 22, 2026, a coalition of six major banks warned regulators that AI shopping agents are outpacing consumer fraud protections. According to Reuters, the group includes NatWest, Bank of America, ING, Capital One, New Zealand’s ASB Bank, and Commonwealth Bank of Australia. They jointly published a report on the risks of agentic commerce. Their central finding was blunt. Consumers are unclear whether the AI will act in their interests. The technology is moving faster than existing consumer protections can keep pace.
The banks named two specific concerns. First, some AI agents enter a shopper’s card information directly into a checkout page. That cuts the person out of the step where they would normally catch an error or a red flag. Second, these agents could route purchases through payment methods that carry weaker fraud protections, without the shopper ever knowing. The coalition asked regulators to act before a problem forces the issue. They requested clear labeling whenever an AI handles part of a purchase.
This warning is not a reason to slow down on agentic commerce. It is a map of exactly where the trust gaps are, delivered by the institutions whose entire business is managing financial trust. The retailers who read this as a warning to wait will fall behind. The ones who read it as a specification for what trustworthy agentic commerce requires will build the channel that consumers actually adopt. Trust is the bottleneck. It is also the opportunity.
The Trust Gap the Banks Measured
The bank warning did not arrive in a vacuum. It landed on top of consumer data that says the same thing from the shopper’s side. PYMNTS Intelligence research found that half of American consumers have completed a retail purchase with some form of AI help. However, only about one in four say they would be comfortable handing both the shopping and the payment entirely to an AI agent. The gap between those two numbers is the trust gap, and it is wide.
This aligns with what I described in the Year One agentic commerce analysis. Shoppers are comfortable letting AI help them research and narrow options. They are far less comfortable letting AI complete the transaction autonomously. The bank report gives that hesitation a concrete foundation. Consumers are not being irrational when they hold back. They are responding to real gaps in fraud protection that the institutions responsible for payment security have now documented.
Moreover, the fraud threat is not hypothetical. Deepfake detection firm Pindrop estimates that three in ten retail fraud attempts are now AI-generated. The same technology that powers helpful shopping agents also powers more sophisticated fraud. A consumer who has read even one headline about AI-generated fraud brings that awareness to every interaction with a shopping agent. The trust has to be earned against that backdrop.
Why This Is an Opportunity, Not a Warning to Wait
The Channel Is Growing Regardless
The agentic channel is not waiting for the trust problem to resolve. British retailer John Lewis reported that searches originating from AI agents rose to 2.5 percent of its total from 0.3 percent a year earlier. That is an eight-fold increase in a single year. The channel is growing whether or not the trust infrastructure is ready. That growth is exactly why the trust question is urgent rather than theoretical.
Consequently, the retailer who waits for someone else to solve the trust problem is choosing to enter the channel later. By then, the consumers who adopted early will have formed habits with the retailers who were there first. As I described in the AI recommendations and human reviews analysis, the retailers who build the trust signals the agent needs are already capturing a disproportionate share of AI citations. Trust is not a reason to wait. It determines who wins the channel that is growing regardless.
The Banks Just Wrote the Specification
Read the bank warning as a product specification and it becomes a roadmap. The banks want clear labeling when an AI handles part of a purchase. That is a design requirement a retailer can build. They want transparency in how the agent makes decisions. That is a requirement a retailer can meet by choosing agent architectures that explain their recommendations. They are concerned about agents routing payments through less secure methods. A retailer can address that by controlling the checkout rather than handing it to a third-party agent.
This connects directly to what I described in the Anthropic commerce agent blueprint analysis. The blueprint that skipped the wallet, keeping payment on the retailer’s own checkout rather than routing it through the agent, is precisely the architecture the banks are asking for. The retailer who deploys an agent that builds the cart and hands it to their own secure checkout has already solved the payment-security concern. The trust-preserving architecture and the commercially effective architecture are the same architecture.
What Trustworthy Agentic Commerce Actually Requires
Keep the Human in the Payment Decision
The banks’ first concern was agents entering card information without a human checkpoint. The answer is not to remove AI from the shopping experience. It is to keep a human confirmation at the payment step. As I described in the AI shopping trust gap analysis, consumers want AI for discovery and a human touchpoint at the moment of highest consequence. Payment is that moment. The retailer who lets the agent build the cart but returns control to the shopper for the final confirmation is building exactly the trust architecture consumers want.
Own the Checkout and the Payment Security
The banks’ second concern was agents routing payments through less secure methods. The retailer who controls their own checkout controls the payment security. When the AI agent hands the completed cart to the retailer’s own checkout, the retailer’s existing fraud protection and data handling apply. When the agent completes the payment itself through a third-party path, the retailer loses control of exactly the security layer the banks are worried about. Owning the checkout is not just a commercial advantage. It is a trust and security advantage.
Make the Agent Explain Itself
The banks want transparency in how agents make decisions. A shopping agent that recommends a product and explains why builds more trust than one that produces a recommendation with no visible reasoning. As I described in the AI recommendations and human reviews analysis, shoppers want recommendations grounded in authentic human reviews rather than in the model’s opaque judgment. Transparency is not just a regulatory nicety. It is a conversion advantage. The shopper who understands why the agent recommended a product is more likely to trust it enough to buy.
What This Means for LatAm Retailers
The trust and fraud concerns the banks raised are more acute in LatAm markets for two reasons. First, fraud rates in several LatAm e-commerce markets are already higher than in the United States and Europe. The incremental fraud risk from AI agents lands on a base of consumer caution that is already elevated. Second, consumer protection frameworks for AI-driven commerce are less developed in most LatAm markets. The regulatory clarity the banks are requesting is further away.
However, this raises the payoff for the LatAm retailer who builds trust deliberately. Consumers there are more cautious about fraud and regulatory protection is thinner. The retailer who visibly controls payment security, keeps the human in the payment decision, and makes the agent’s reasoning transparent stands out more sharply. As I described in the Year One agentic commerce analysis, the trust advantage compounds. In a lower-trust market, it compounds faster.
The Question Every Retailer Should Answer Now
Does Your Agentic Strategy Solve the Trust Problem or Ignore It?
The bank warning gives every retailer a clear test. Look at your agentic commerce deployment and ask whether it addresses the specific concerns the banks raised. Does it keep a human in the payment decision, or enter card information autonomously? Is the payment routed through your own secure checkout, or a third-party path you do not control? Can the agent explain its reasoning, or does it produce recommendations the shopper cannot evaluate?
The Trust Layer Is the Competitive Layer
The retailers who treat the bank warning as a compliance problem will do the minimum required and move on. The retailers who treat it as a competitive opportunity will build agentic experiences that consumers trust. That trust will show up in adoption, conversion, and loyalty. When only one in four consumers is comfortable handing shopping and payment to an agent, the retailer who earns the trust of the other three captures a market that competitors are leaving on the table.
The Specification Is Already Written
Six of the world’s major banks just told regulators that agentic commerce is moving faster than the trust infrastructure underneath it. They are right. But the retailer who reads that as a reason to wait has misread it entirely. The trust infrastructure is not something to wait for. It is something to build, and the specification was just handed to every retailer by the institutions that understand financial trust better than anyone. Keep the human in the payment. Own the checkout security. Make the agent explain itself. The retailers who do this will own the agentic channel. The ones who wait will enter it after their customers have already learned to trust someone else.
If you are building an agentic commerce strategy or evaluating whether your AI shopping experience meets the trust and security standard consumers and regulators are now demanding, connect with me here or reach me on LinkedIn. I am happy to walk through the framework we use across the U.S. and Latin America.
Adriana Rivas is a retail technology executive and AI strategist. She is the recipient of the Gold Stevie® Award, Thought Leader of the Year 2026, recognized by Thinkers360 as the #7 Global Thought Leader in Retail, and named to the RTIH Top 100 Retail Technology Influencers 2026. She is the author of How to Implement Self-Service Without Failing, now available in a Revised and Expanded Edition.