AI Agents Taking Over Buying Decisions Changes Customer Ownership

During the last ten years, artificial intelligence deployed by banks has centered on two primary functions: forecasting outcomes and offering counsel. Institutions have rolled out advanced machine learning tools to estimate credit defaults, anticipate market swings, and detect fraud, while generative models have been used to support relationship officers and compose client messages. Despite the variety of scores and suggestions produced, a single operational rule persisted: algorithms could analyze information, but a human retained sole control over the final transaction command.
This clear separation is now eroding. As autonomous software moves from merely predicting market moves to actually authorizing trades, the main conduit for digital commerce is transitioning from user-driven interfaces to machine-to-machine communication protocols. Agent-based systems not only aggregate data; they can launch actions, orchestrate detailed processes, and initiate payments throughout the digital ecosystem. When a self-directed agent is given the power to scan markets, negotiate terms, and complete a purchase on behalf of a human principal, the traditional points of interaction become indistinct.
Participants at Sibos highlighted the strategic implications of this shift. Financial firms will need to remodel approval workflows, guarantee traceability, and address liability concerns when an algorithm generates an unauthorized transfer. Perhaps the most pressing issue is determining who retains the customer relationship when the purchasing decision is executed by an autonomous agent.
At present, the rules governing agent-driven commerce are not being authored by banks or other legacy financial entities. Instead, they are emerging in real time through court decisions, standards-setting organizations, and providers of internet infrastructure. To grasp the operational environment that banks will soon inherit—or help shape—it is essential to examine three core developments currently shaping the regulatory and technical environment of agent-enabled finance.
The Legal Precedent: Establishing the Acting Party
Before institutions can underwrite the risks associated with agent-mediated transactions, courts must clarify a key uncertainty in payment law: does an autonomous program’s initiation of a transfer count as an “authorised” action by the human owner? Under existing regulatory frameworks like Regulation E and PSD2, transaction liability hinges almost entirely on authorisation. If an agent exceeds its parameters, misinterprets a prompt, or succumbs to prompt injection, determining whether the transaction was authorised dictates whether the bank, the merchant, or the consumer absorbs the loss.
The judiciary has started to set a baseline. In the August 2026 decision Amazon.com Services, LLC v. Perplexity AI, Inc. (No. 26-1444, 9th Cir. Aug. 4 2026, 2026 WL 2237587), the Ninth Circuit addressed the question of agency in automated contexts. Overturning a lower-court ruling concerning AI access to external sites, the appellate panel concluded that when a user commands an AI, “the user who ‘accessed’ Amazon’s computers,” not the AI provider, is responsible.
Analyzing the Computer Fraud and Abuse Act, the court explained that the statute’s reference to “whoever” is intended to apply to a person, treating the software as a tool whose actions are attributable to the human directing it. As highlighted in legal analyses by Ropes & Gray, this reinforces that the legal agency resides with the user.
Although the issue remains unsettled, executives can infer the likely trajectory. If jurisprudence treats the algorithm as an extension of the person, banks cannot simply categorize agent mistakes as third-party fraud. Institutions will need to implement systems that cryptographically demonstrate the precise scope and intent of the user before any payment is authorized.
This is the exact challenge being tackled by the Agent Payments Protocol (AP2). Originally announced via a Google Cloud blog post, AP2 is an emerging technical specification designed to standardise how agents interact with payment networks.
The AP2 draft contains a detailed table illustrating how liability might be apportioned across a range of technical and operational failure modes. This inclusion shows that the technical framework for resolving disputes involving autonomous agents is already being formalised, and financial institutions will soon have to embed these protocols within their existing risk-management and compliance architectures.
Closing the Governance Gap
The underlying infrastructure is also being built to equip agents with verifiable identities, digital wallets, and programmable spending limits. Cloudflare’s engineering platform, for instance, focuses on bounded authorisation, enabling agents to conduct online purchases safely within strict parameters defined by their human sponsors. These constraints comprise user-specified spending caps, approved merchant rosters, and maximum transaction amounts that an agent cannot exceed on its own.
The imperative for banks to move proactively into this governance vacuum is evident. By influencing the development of identity, control, and compliance standards now, financial organisations can preserve their role as essential trust anchors in the emerging agent-centric economy. Attendees at Sibos possess a narrow but critical window to help shape these frameworks and avoid being reduced to mere utility providers in a environment where technology platforms control the primary customer interface and set the rules of engagement.