Skip to content

September 22, 2026 · Issue 37 · 5 min read

Six banks want every agent payment disclosed, and say customers cannot tell who covers them when one goes wrong

The daily briefing film for this issue, 4:12.

Six banks, NatWest, Bank of America, ING, Capital One, ASB Bank and Commonwealth Bank of Australia, published a joint report this week arguing that AI shopping agents are moving faster than the protections around them, per Reuters, via CNBC(opens in a new tab). The risks they list are concrete. Agents that ask customers for card details and type them into websites. Agents that steer users toward payment methods with weaker safeguards. Their central ask of policymakers is a disclosure rule: whenever an AI agent is involved in a financial transaction, that fact gets declared.

The sentence a CFO should read twice is about recourse. The report says customers are not sure whether they will be protected, or who they will need to go to if things go wrong, per the same Reuters report(opens in a new tab). That is a statement about consumers, but the institutions making it are the ones that run the dispute process, and they are asking regulators for rules rather than offering an answer. Put plainly, when an agent buys the wrong thing, the loss allocation is not settled. That is an unpriced risk, and it sits on whichever balance sheet is closest when the chargeback arrives.

Yesterday's issue covered Amazon refusing an agent at the merchant's door because it would not identify itself. This is the payment side reaching the same place from the other end. The merchant wants to know what the agent is. The issuer wants to know an agent was involved at all. If a disclosure rule arrives, an undisclosed agent transaction stops being a gray area. Any enterprise running procurement, travel, or expense agents on corporate cards should ask now whether those agents could set that flag truthfully, and whether anyone could prove it afterward.

Disclosure also assumes the human who approved a transaction saw what actually ran. A paper posted to arXiv on September 17, Loopjacking(opens in a new tab), shows why that assumption needs testing. Its author reproduced cases in Agno AgentOS and in a LangGraph Agent Server configuration where a reviewer approves one operation and a different one executes, either because the approval view left part of it out or because workflow state changed after the click. An approval log is evidence only if what the reviewer saw is compared against what executed, at the moment it executed.

Washington's contribution this week is a phone line, not a rule. Treasury Secretary Scott Bessent said the United States proposed an AI incident notification mechanism with China ahead of this week's Trump and Xi summit, per ABC News(opens in a new tab), without saying what counts as an incident. Nothing in it binds an enterprise. The banks' proposal, if a regulator adopts it, would, and it would land on your card program first.

Action items

A disclosure request from the banks that run disputes, a research paper on approvals that do not mean what they record, and a diplomatic channel that binds nobody.

For the CFO. Ask who absorbs the loss when an agent on a corporate card buys the wrong thing, overbuys, or pays a fraudulent merchant. If the answer is the cardholder, meaning an employee, or nobody knows, that is the finding. The banks have just said in writing that their own customers cannot answer it either. Until someone can, cap agent spending authority per transaction and per day, and treat any agent card program without that cap as open-ended exposure.

For the CISO. Card details typed into a website by an agent is the first risk the banks named. Map every agent that can see a card number, and move those flows to tokenized or single-use credentials where the payment provider supports them. Then test your approval gates the way the Loopjacking paper did: approve one action, change the pending state, and see what runs.

For procurement. Any vendor selling agentic purchasing should be able to answer three questions in writing. How does the agent identify itself to the merchant and to the issuer. Where do payment credentials live. Who is liable when the agent acts outside the instruction it was given. A vendor that answers the third question with the terms of service has answered it.

For the governance owner. Add agent disclosure to your agent policy before a regulator makes it mandatory. The rule is simple to state: any transaction an agent initiates or completes is recorded as agent-initiated, with the approving human and the exact approved operation attached. That record is what a dispute will ask for, and it is cheaper to produce now than after the first chargeback.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

Also worth knowing