Why Shopping Agents Are a Security and Payments Headache

When venture capitalist Yuechen Zhao asked Instinct, the popular consumer AI agent, to look up hotels for him on Booking.com this month, he discovered something unsettling.

Zhao, a partner at venture firm Informed Ventures, said the agent promised it could fill out the booking form for him if he entered his credit card information into the Vault, Instinct’s credential manager, which allows users to save and autofill their payment and other credentials such as login passwords. The agent, when prompting users to share the information, says it won’t actually see sensitive details like card numbers directly.

Zhao tested the process with a fake credit card number, and challenged the agent to see if it was technically feasible to read the numbers back. Turns out the agent acknowledged it could indeed see his credit card and passwords and read them back to him in plain text by running a Javascript on the webpage.

“These companies have been doing a lot to try to protect user information and try to create a magical functionalist experience for users,” Zhao said. “But it does raise the question, just in general, for these personal agents—how should people think about security?”

Asked about the episode, a spokesperson for Instinct, a Sequoia Capital–backed startup that raised at a $10 billion valuation this week, said, “Securing user data is a top priority for us, and users are always in control of their data and credentials.”

AI companies have been promising seamless, AI-powered shopping for several years. But that’s mostly been hard to pull off at a large scale, with OpenAI’s high-profile shopping pullback earlier this year showing how hard it is for AI companies to build a shopping business.

Now, there’s been a sudden spate of new agents gaining traction—most recently Meta Platforms’ Muse and Instinct—that can go shopping and handle transactions for users. That has forced merchants, payment providers and AI companies to confront the potential security and financial risks of having an agent make a purchase instead of a human.

Payment firms have been jumping in to support various levels of agentic transactions, from fully autonomous shopping to transactions where a human is still pushing the final “buy” button. Stripe has partnered with both Meta and Instinct to enable agents to make payments. PayPal announced last week it’s also teaming up with Muse to enable checkout with PayPal’s merchants. And Shopify is rolling out a one-click checkout button in Muse to allow users to pay with the cards and shipping address already in their Shop Pay account.

Still, the path to having agents seamlessly pay for purchases is not easy. By default, online shopping websites have been designed to block bots to reduce fraud ever since the emergence of eBay and Amazon in the ’90s. Those same protections can make it hard for shopping agents to navigate sites and make payments.

“For 30 years, we’ve screamed, ‘Bots are bad, bots are bad, bots are bad,’ and all of a sudden, in 2025, we started changing it around, saying, ‘Some bots are good,’” said Dan Coates, product management director at ACI Worldwide, who leads strategy for providing payment platforms for merchants such as Wendy’s. “We spent 30 years building up this infrastructure that blocked all the bots.

“That’s a very significant change,” he said. “We are having to figure out, how do we poke holes in the supposed firewall? How do we let the good ones in and block the other ones?”

Visa and Mastercard, for example, have introduced an agent registry that can verify agents and distinguish them from bots. Such a feature “enables merchants to verify that they are interacting with a legitimate AI agent and [shows] who is behind it,” said Rubail Birwadker, global head of growth at Visa.

Among the risks, preventing an agent from misspending money is the biggest concern. Payment firms have introduced ways to set caps on spending to prevent agents from making an accidental splurge without users signing off first.

Stripe, for example, can issue single-use virtual cards for Muse agents with a spending limit based on the specific approved purchase. The virtual card is linked to the cards and bank accounts already stored in a user’s Stripe Link wallet, but the agents don’t see the underlying payment details. In a blog, Meta said Muse has no visibility into people’s passwords or payment methods, and any credentials a person shares, including passwords a person types into the browser themselves, go into secure storage, so Muse can use them without seeing them.

Then there’s the question of who bears the cost if a shopper disputes a charge. A consumer using an agent to buy something may say their agent made the wrong purchase or didn’t follow their instructions, when initiating a charge reversal request with their card provider. Typically, if a cardholder disputes a charge, issuing banks will make a call on whether to ask the merchant to return the money. The process often involves a lot of back-and-forth over disputes in which merchants may fight over who has to eat the loss.

How disputed charges play out can depend on what kind of evidence merchants have that a shopper really meant to buy something and the goods came as promised. For instance, for in-person shopping, a merchant might show receipts, shipping confirmations or customer communications.

Card networks have started introducing new measures to check what users authorize their agents to do as well. Mastercard, for example, recently introduced a process called “verifiable intent” to record what authority the user had delegated to their agent, and whether the agent followed those instructions when making purchases.

“If something were to go wrong and someone did want to charge back a purchase, the issuer would be able to have access to that intent data in our regular charge-back system,” said Sherri Haymond, Mastercard’s global head of digital commercialization. That paper trail would help determine which party, such as the bank, the merchant or the shopper, would bear the cost of a disputed agent payment.

Even with new innovations in managing payment risks, how much merchants and shoppers will embrace using agents for shopping remains an open question. Merchants are worried AI agents could reduce the role of their own sites in the shopping process and eliminate the human browsing that provides a lot of valuable data on consumer behavior. And some online sellers are wary of introducing another company’s technology into the mix.

When Amazon banned Muse from accessing its site, one of its concerns was about undisclosed third parties accessing customer accounts, processing transactions and handling sensitive data without Amazon’s knowledge or consent, the company said.

And consumers too are worried about agents mispending money, which could be a hard perception to change. In a survey by ACI Worldwide and YouGov, only 7% of fashion shoppers said they trust AI to make purchases for them without approval.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论