← Latest reporting

Agentic commerce needs a transaction mandate before it needs a smoother checkout

Six banks proposed voluntary principles for AI-mediated shopping and payments around transparency, safety, privacy, choice and interoperability. Product teams still need an enforceable mandate, liability map and redress test for each transaction.

Skills Systems and HR TechPolicy, Standards and Governance
A handmade cardboard checkout landscape guides a small parcel towards three protection gates while an unsafe shortcut ends at a removable red stop block.
Conceptual illustration generated with AI under editorial direction; it does not depict a real event.

What happened

On 22 September ASB, Bank of America, Capital One, Commonwealth Bank of Australia, ING and NatWest published joint principles for trusted agentic commerce. They invite wider collaboration and say a later paper will detail implementation.

Why it matters

Principles express outcomes but do not tell a checkout whether an agent may buy, which protection applies, who bears loss or how a person cancels and appeals. Those questions need machine-enforceable transaction evidence before autonomous payment.

Six banks published joint principles for trusted agentic commerce on 22 September. ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING and NatWest organise the paper around transparency, safety, privacy and data, choice and interoperability. They describe it as a foundation for discussion and plan a later paper on implementation.

Reuters reported concerns that agents could request card details, steer people towards weaker payment protections, buy the wrong item, overspend or complicate responsibility for scams. The banks propose disclosure when an agent participates, clearer decision information and safeguards for data. These are proposals from payment institutions, not measured evidence that agentic commerce has produced a particular fraud rate.

Define what the agent is allowed to transact

Before an agent reaches checkout, create a transaction mandate. It should name the principal, agent, merchant category, goods or services, price and cumulative spend limits, payment method, geography, time window and prohibited conditions. Express the mandate in a form that the merchant and payment provider can verify without exposing unrelated conversation.

Separate discovery from commitment. An agent may search and compare broadly while requiring confirmation before an irreversible purchase, a new merchant, a subscription, high-risk goods or a payment method with weaker protection. Show the person the item, total cost, recurring terms, data shared, material recommendation factors and remaining cancellation window.

Carry protection and identity across the chain

Each participant needs to know when it is dealing with an agent and on whose authority, but disclosure should not become unrestricted tracking. Use purpose-bound identifiers and minimal attributes. Record the mandate version, authentication event, agent action, merchant response, payment authorization and delivered outcome so a dispute can be reconstructed.

Map liability before launch. Decide who bears loss when an agent exceeds the mandate, a merchant misrepresents a product, a payment method weakens protection, credentials are stolen or a recommendation is manipulated. The person should have one visible contact for cancellation and dispute rather than being sent between model provider, merchant and bank.

The counterargument is that confirmation and logging can remove the convenience of delegation. A tiered design preserves it. Repeated low-value purchases from approved merchants may proceed within narrow limits; new, expensive, recurring or sensitive transactions pause. Sample low-risk actions for review and reduce authority when corrections or disputes rise.

Test redress, not only purchase success. Run scenarios for an incorrect item, duplicate order, hidden subscription, delayed delivery, compromised account and an agent choosing a less protected rail. Measure time to detect, freeze, cancel, refund and explain. Confirm that revoking the mandate blocks queued and derived transactions.

Interoperability should include protection semantics. A merchant must not interpret the same token as broad consent when a bank reads it as one purchase. Publish common fields and error states, and make unsafe ambiguity fail closed. Competition and consumer choice also require that a platform does not force its own agent or payment method as the only protected route.

The banks' principles are a useful agenda, but voluntary words are not a transaction control. The Skills Intelligence glossary can help teams align terms; the decisive artifact is a verifiable mandate joined to payment protection, liability and redress.

Include accessibility and delegation by carers or business representatives in the test plan. Confirmation patterns that work for a frequent smartphone user may fail for assisted purchasing or shared accounts. The mandate must identify the lawful principal and representative relationship without forcing people to disclose more sensitive information than the transaction requires.

The immediate decision is to stop treating checkout conversion as the primary pilot metric. An agentic-commerce trial should pass mandate enforcement, disclosure, protection-equivalence and end-to-end dispute exercises before it receives broader spend or merchant authority.