Six global banks have published a shared set of principles for AI agents that can help customers choose products and make payments.

ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING and NatWest organised the framework around transparency, safety, privacy and data, choice, and interoperability.

It is aimed at consumer commerce, not enterprise procurement. But it may be one of the clearest early control models for any organisation allowing an AI agent to influence a purchase.

The payment industry is asking procurement's next questions

Reuters reports that the banks are concerned agents could request card details, steer users towards payment methods with weaker protection, buy the wrong product or leave customers unclear about who is responsible when something goes wrong.

Those questions translate directly into enterprise procurement:

  • How does a supplier know that an agent is authorised to represent the buyer?

  • What spending, category and contractual limits apply?

  • Must the agent disclose whose interests it represents?

  • Who is liable when it selects the wrong product or accepts an unsuitable term?

  • Can the organisation reconstruct the decision, authorisation and payment trail?

The banks' next step is a paper describing how the principles could be implemented. That implementation layer is where voluntary language must become identity controls, transaction limits, dispute mechanisms and technical standards.

An agent needs authority, not just access

Giving software access to a catalogue, corporate card or purchasing system is not the same as granting commercial authority.

A procurement agent should carry a machine-readable mandate stating the entity it represents, the person or policy that authorised it, the products and suppliers it can use, the value limit and the circumstances that require escalation.

Suppliers and payment providers also need a reliable way to verify that mandate. Otherwise, an agent can appear technically valid while operating outside the buyer's policy.

Choice and interoperability are commercial issues

The banks argue that customers and merchants should remain free to choose their AI services and that systems should be interoperable.

For procurement, this is an important warning against allowing a single model, marketplace or payment provider to control discovery, recommendation and execution. If the agent's ranking logic, commercial incentives and payment rails all sit inside one ecosystem, the buyer may struggle to test whether it received a genuinely competitive result.

The bottom line

The framework is voluntary and does not yet resolve liability, authentication or technical implementation. It is still valuable because financial institutions are acknowledging that agentic commerce requires more than a capable model and a payment credential.

Before an AI agent can spend, it needs a verifiable identity, a bounded mandate and a clear answer to who carries the loss when it gets the purchase wrong.

Sources