Six major international banks put an uncomfortable question at the center of artificial intelligence commerce this week: agents can already research products, choose sellers and complete payments, but the rules for proving what the consumer authorized — and determining who is responsible when something goes wrong — are still being built.

Bank of America, Capital One, ING, NatWest, Commonwealth Bank of Australia and ASB Bank published on September 22 joint principles for so-called agentic commerce. The document advocates transparency, security, data protection, choice and interoperability, and also points to identity, authorization, fraud prevention and liability management as problems that need to be solved.

The warning comes as commercial use of these systems begins to leave testing. Meta launched Muse, an agent capable of browsing the web and completing purchases after user approval. A few days later, however, Amazon asked to be removed from the experience: it said it had not been notified in advance nor authorized the agent to access its store.

The episode exposes a division that could become more important than the models' own capability: an agent needs consumer authorization to spend, but it may also need merchant authorization to enter, browse and transact on its infrastructure.

Authorizing the agent is not the same as authorizing each purchase

In traditional commerce, checkout creates a relatively clear sequence: the consumer chooses a product, sees the final amount and authenticates the payment.

With an autonomous agent, these steps can be separated by hours or days.

The user can instruct: buy a certain product when the price falls below US$ 200. The agent can later choose the seller, calculate shipping, select a payment method and complete the transaction without the buyer being present at that moment.

This turns payment authorization into a problem of proving, later on, which limits and conditions the consumer actually defined.

The Agent Payments Protocol, or AP2, developed by Google with industry partners, tries to solve this gap using cryptographically verifiable records of the buyer's intent. The protocol allows defining conditions in advance such as maximum price, allowed merchant and spending limits and, then, linking the transaction actually carried out to those instructions.

Mastercard is working in a similar direction with Verifiable Intent, which creates a tamper-resistant record of what the consumer authorized. Visa, in turn, developed the Trusted Agent Protocol to allow merchants to confirm the agent's identity, the user represented and the specific authorization for a given interaction or payment.

In a future dispute, it may be necessary to demonstrate not only that a payment occurred, but what exactly the consumer asked the agent to do.

The problem starts before payment

The conflict between Amazon and Meta shows that buyer authorization solves only half of the equation.

According to Amazon, Muse accessed its operation without prior authorization. The company's position is that third-party applications that make purchases on behalf of consumers need to identify themselves and respect providers' decision to participate or not in this type of experience.

This problem already appears in the design of the new protocols.

Visa's specification explicitly starts from a difficulty for merchants: distinguishing a legitimate agent from a crawler, resale bot or malicious system. The protocol creates digital signatures to identify the agent and inform that there is a verifiable commercial intent behind the request.

Shopify followed another approach: it turned agents into a formal commerce channel. Merchants can make their catalogs available on different AI surfaces, while orders made through these channels remain recorded in Shopify Admin and linked to the channel of origin.

The difference is structural: formal integrations establish in advance who can access products, which data can circulate and how the order will be processed. A generic agent can try to perform the same task without that relationship existing.

Who pays when the agent makes a wrong purchase?

There is still no universal answer.

A transaction can involve the consumer, the agent provider, the merchant, a digital wallet, the payment processor, the card network and the issuing bank. In addition, dispute rights and rules on unauthorized payments vary according to payment method and jurisdiction.

The protocols that are emerging do not eliminate this complexity. They try to create enough evidence to determine where the failure occurred.

If the consumer authorized spending of up to US$ 300 and the agent spent US$ 500, for example, a verifiable record of the limit makes it possible to identify a violation of the instruction. If the agent bought correctly within the defined conditions, but the merchant did not deliver the product, the problem is different.

The six banks' own statement points in this direction by placing identity, authorization, fraud, liability and consumer protection within the same discussion. The group has not yet presented definitive operational rules and said it intends to detail later how its principles could be implemented.

The bottleneck, therefore, is not finding a single company that will assume all the risk, but building a chain of evidence capable of separating agent error, fraud, authorized consumer decision and seller failure.

Payment data is being isolated from the agents themselves

Another change can already be observed in the infrastructure.

Muse uses Stripe's Link. At merchants that accept the wallet, the payment can use the method saved by the consumer. At the others, Stripe can generate a single-use virtual card limited to the approved purchase, preventing the agent from having access to the real card number.

Stripe also developed Shared Payment Tokens that can be limited to a specific merchant, amount and period.

The logic is to reduce the financial power available to the agent: instead of handing over a reusable credential, the system provides authorization restricted to the context of that purchase.

This architecture indicates an important characteristic of agent commerce: the greater the AI's autonomy, the more restricted the financial credential placed at its disposal tends to need to be.

Trust may become the real bottleneck of agent commerce

Demand exists. According to the banks, the British John Lewis saw the share of searches originating from AI agents rise from 0.3% to 2.5% in one year. Research released by Visa this month also showed that only 23% of American consumers trust generative AI to execute payments on their behalf.

The distance between these two movements helps explain why banks, card networks, platforms and merchants are simultaneously building authorization layers.

The challenge is no longer simply allowing an AI to find a product and press the buy button. The infrastructure now needs to prove who sent the agent, which limits it received, which merchant agreed to interact with it, which payment was authorized and what actually happened.

The next relevant signals will be less in AI models and more in these mechanisms: adoption of protocols such as AP2 and UCP, expansion of agent identity systems, merchants' rules for accepting or blocking automation and, mainly, how banks, card networks and regulators will handle the first relevant disputes involving autonomous purchases.

Until this liability chain is sufficiently defined, agent commerce may advance technically faster than the trust needed to use it at scale.

More from Radar