THE SIGNAL IN ONE SENTENCE

Six banks from five countries have published a shared set of principles for shopping systems that can search, choose and pay on a person's behalf. ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group and NatWest Group call the paper Building Trust in Agentic Commerce. Their five principles are transparency, safety, privacy and data, choice, and interoperability. The banks want every participant to know when an AI agent is involved, whose interests it represents and how it ranked the options. They want customers to see and manage the authority they have delegated, payment credentials to enter through secure and auditable methods, records that preserve instruction and intent, dispute systems that include every relevant party, and enough connectivity to keep one platform from owning the whole checkout. This is the correct shape of the problem. An agentic purchase is not only a smarter recommendation. It is a chain of identity, permission, merchant selection, payment routing, delivery, return, refund and responsibility. A bot can choose the wrong product, exceed a budget, expose a card, send money through a weaker protection route, mistake a scam for a merchant or optimize for the commission paid to its provider. The uncomfortable bit is that the new paper does not yet solve those problems. It says its principles are voluntary and nonbinding, prescribes no conduct or implementation timetable and leaves the protocols, standards and policies to a later paper. The banks also have interests of their own. They issue cards, acquire merchants, investigate fraud, process disputes and compete for control of the payment relationship. Their warning can be useful and commercially convenient at the same time. The plain signal is that the checkout now needs to recognize the software holding the card. A safe transaction should carry a durable receipt showing what the shopper asked for, what the agent was allowed to do, which merchant and payment method it chose, what influenced that choice, who authenticated it and where a human can stop, reverse or dispute the result.

01

WHAT ACTUALLY CHANGED

ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group and NatWest Group jointly published Building Trust in Agentic Commerce on September 22. The participating banks operate across New Zealand, the United States, Australia, the Netherlands and the United Kingdom.

The paper defines agentic commerce as the use of AI agents to help make or facilitate payments between a consumer and a merchant for a product or service. It covers cards, account-to-account transfers and tokenized money, while excluding broader agentic payments such as peer-to-peer transfers and accounts payable.

The authors describe a spectrum from ordinary online shopping through human-reviewed agent purchases to autonomous shopping. At the far end, an agent can identify a need and purchase on its own after a broad initial instruction.

The first principle is transparency. All parties should know when an AI agent is helping make or facilitate a transaction and on whose behalf it is acting. Consumers and merchants should be able to see how the agent prioritizes options, including sponsored options, and how their data is collected and used.

The second principle is safety. Customers should be able to view and manage the authority they grant. Providers should use secure, auditable methods for entering payment credentials and authorizing purchase intent. A party that may carry liability should be able to require authentication.

The safety section also calls for timely intelligence sharing, warnings, interventions, recovery activity and effective dispute resolution. It says liability outcomes should reflect where risks and errors entered the transaction chain.

The third principle covers privacy and data. The paper identifies prompts, decision logs, intent mandates and purchase details as new records. Providers should retain auditable evidence of instructions, authentication, intent, decisions and outcomes while collecting only the data needed for safe operation and obtaining consent for additional uses.

The fourth principle is choice. Consumers and merchants should be able to choose agentic services without unreasonable restrictions. The paper warns against preferential payment methods, affiliated wallets, gatekeeping fees and platform rules that make alternatives harder to use.

The fifth principle is interoperability. The banks support common connectivity for core trust functions while leaving room for differentiated features. They also acknowledge that forcing agreement too early can slow useful innovation.

The paper is explicit about its limits. The principles are voluntary and nonbinding, prescribe no commercial position, implementation method or timetable, and require none of the authors or other companies to act. A later paper is supposed to detail protocols, standards and policies.

Reuters independently reported the release and highlighted concerns about direct card entry, weaker payment protections, scams, fraud, privacy breaches and uncertainty over who helps when something goes wrong.

NatWest's release says the next step is a subsequent implementation paper and invites banks, merchants, technology providers, payment companies, industry bodies, regulators and consumers to participate. No publication date for that paper was stated.

02

WHY THIS MATTERS

An ordinary checkout gives a person several visible moments to catch trouble. They see the merchant, item, price, shipping terms and payment method before clicking. An agent can compress those moments into one instruction, which makes the invisible permission design more important than the final button.

Delegated authority needs boundaries that a bank and merchant can verify. Buy me a useful laptop is not a safe payment mandate. A workable delegation names the product class, budget, merchant rules, payment method, delivery address, timing, substitution limits, recurring status and the events that require fresh human approval.

Authentication must cover more than the shopper. The transaction may need to prove the person, the authorized agent, the current software version, the permission, the merchant and the link between the approved cart and the money that actually moved.

A masked token is safer than letting an agent copy a raw card number into any page it finds, but tokenization does not establish intent. The receipt still needs to show which merchant, amount, item and time the credential was authorized for and whether the permission was used once or kept alive.

Payment protections vary by rail, jurisdiction, card type, merchant and circumstance. An agent that quietly prefers a cheaper or more profitable route can change the customer's practical options after fraud, non-delivery or a bad purchase. The choice of rail belongs in the explanation, not under the floorboards.

The merchant of record must remain visible. A marketplace, agent platform, wallet and fulfillment company can all touch one purchase. The customer still needs to know which legal seller charged them, who owes delivery, where the return goes and whose name should appear in a dispute.

Recommendation conflicts become payment conflicts at checkout. The paper notes that an agent may favor products or payment methods that produce higher commissions or lower computing costs for its provider. A sponsored result label is useful, but a shopper also needs a plain account of what materially changed the ranking.

Disputes become harder when each participant holds a different slice of the evidence. The agent knows the instruction, the merchant knows the cart, the wallet knows the credential, the network knows the authorization and the bank knows the account. A durable transaction identifier and common evidence format are needed before everyone begins forwarding the customer to the next company.

Privacy is not solved by asking for blanket consent. Shopping conversations can expose health concerns, relationships, travel, religion, income, location, children, habits and vulnerability. The system needs data minimization, purpose limits, retention schedules and a way to delete or export the records that are not legally required.

Interoperability can protect choice by letting customers move an agent or permission across compatible merchants and payments. It can also spread a compromised credential or bad instruction across more systems. Common connections need common revocation, authentication, versioning, incident and liability rules.

Banks are credible participants because they already authenticate customers, operate payment controls and investigate disputes. They are not neutral referees. The same institutions can benefit when policymakers require transactions to use bank-controlled identity, tokens, records or payment rails.

The absence of an implementation timetable is the largest limitation. Principles can align a conversation. They cannot stop an unauthorized purchase, return money, identify a compromised agent or decide liability until code, contracts, rules, tests and responsible institutions make them operational.

For shoppers, the most useful design is a transaction receipt created before the payment moves. It should be understandable enough to approve and structured enough for banks, merchants, courts and investigators to reconstruct after a failure.

For merchants, the system must distinguish legitimate agent traffic from scraping, fraud and impersonation without forcing every seller to integrate separately with every large platform. A shared baseline can reduce cost, but it should not let incumbent networks turn safety into a tollbooth.

FIG. 202MAKE THE RECEIPT BEFORE THE MONEY MOVES
1IDENTIFY THE CUSTOMER AND AGENT→
2READ THE DELEGATED LIMITS→
3COMPARE PRODUCTS AND DISCLOSE INCENTIVES→
4LOCK THE CART AND MERCHANT OF RECORD→
5SELECT A PROTECTED PAYMENT RAIL→
6AUTHENTICATE WHEN RISK OR LIABILITY REQUIRES IT→
7ISSUE A SHARED TRANSACTION RECEIPT→
8DELIVER, RETURN OR REFUND AGAINST THE SAME RECORD→
9REVOKE THE AGENT AND RESOLVE THE DISPUTE
The safe checkout is a chain of proofs. Every participant should be able to see the same identity, permission, cart, merchant, payment, outcome and correction without receiving private data it does not need.

03

WHERE IT COULD HELP

  • Issue a verifiable identity for the agent, provider, software version and customer account involved in every agent-assisted purchase
  • Bind each delegation to named product categories, maximum spend, approved merchants, payment rails, delivery rules, time limits and required human checkpoints
  • Let customers view, narrow, pause and revoke delegated authority from one place, including queued purchases and stored payment credentials
  • Replace raw card entry with scoped payment tokens that expire and cannot be reused outside the approved merchant, amount, item or time window
  • Create a signed purchase mandate connecting the customer instruction, ranked options, selected cart, merchant of record, payment method and final authorization
  • Disclose sponsored placement, commissions, affiliate relationships, platform preferences and any payment incentive that materially affected ranking
  • Require fresh human approval when the product, total, merchant, delivery term, subscription status or payment protection differs from the mandate
  • Give banks and merchants reliable agent identity, customer intent and cart data without exposing the full private conversation when it is unnecessary
  • Use one transaction identifier across the agent, merchant, wallet, network, issuer, acquirer, delivery, refund and dispute records
  • Design a dispute path that identifies the first responsible contact, preserves every party's evidence and assigns liability where the error or unsafe practice entered
  • Make the merchant of record, return policy, refund destination and expected protection visible before payment and on the final receipt
  • Test agents against fake storefronts, altered prices, malicious product text, compromised merchants, social engineering, duplicated orders and refund manipulation
  • Publish interoperability profiles for identity, delegation, authorization, receipts, revocation and incidents while allowing competition in optional features
  • Measure wrong-item purchases, unauthorized spend, fraud, disputes, recovery time, refund success, false declines, merchant cost and customer abandonment before expanding autonomy

KEEP A HAND ON THE WHEEL

These are voluntary, nonbinding principles written by six banks, not law, a payment-network rule, a technical protocol or proof that an agentic checkout is safe. The paper prescribes no implementation method, commercial position or timetable, and says no participant is required to act. The promised follow-up paper on protocols, standards and policies has not been published. The paper does not assign final liability among shoppers, agent providers, merchants, wallets, issuers, acquirers and payment networks. It does not define a standard identity credential, delegation format, authentication rule, data-retention period, audit-record schema, dispute deadline, revocation mechanism, safety test or enforcement body. The authors discuss customer and merchant concerns but do not publish the underlying research sample, questionnaire or measurement method in the paper. Banks bring valuable payments expertise and their own commercial interests. Interoperability can improve competition while widening the blast radius of compromised agents and credentials. Transparency about agent involvement does not prove that the recommendation, payment route or purchase is fair. Watch for the implementation paper, named standards bodies, technical profiles, independent security testing, jurisdiction-specific consumer protections, measurable pilots, public incident data, clear liability allocation and evidence that customers can stop and reverse a purchase without being passed through a corporate relay race.

04

TERMS WORTH KEEPING

SOURCES AND VERIFICATION STATUS

This article was written from the materials below. Product claims and dates were checked against those sources on September 22, 2026.

PUBLICATION RECEIPT: Revision 1. Published September 22, 2026.

THE PUBLICATION ENGINE

WANT A SIGNAL OF YOUR OWN?

We build source-grounded publications, private briefings, and editorial systems for organizations with something useful to say.

WORK WITH US