By Faizan Kalemundase
NatWest Group, Bank of America, Capital One, ING Group, ASB Bank and Commonwealth Bank of Australia published a joint set of principles this week for what they call trusted agentic commerce: rules of thumb for a world where an AI agent, not a person, chooses the product and completes the purchase. The document names five areas the banks say need attention: transparency, safety, privacy and data, choice and interoperability. It is a reasonable list. It is also arriving after the infrastructure it is meant to govern has already shipped.
The rails were built first
By the time six banks agreed on shared language for agent-led shopping, the payment networks had already made the decisions that matter most. Visa and Mastercard opened agentic payment rails and a sandbox for testing them, a group of forty companies including Coinbase and the Linux Foundation formalized the x402 protocol for machine-to-machine payment, and Anthropic, Visa and Mastercard split agentic commerce into separate reasoning and payment layers in a partnership this publication covered when the card networks first built shared rules for AI agents. Each of those decisions embedded a default position on questions the new bank principles now say need answering: who is liable when an agent buys the wrong item, how consent is captured before an agent spends, what a merchant is entitled to know about the buyer on the other end. Those defaults are now live in production. A voluntary principles document from six banks does not reopen them.
Advertisement
300 × 250
Mark Brant, NatWest’s chief payments officer, said the banks want to help shape agentic commerce “the right way.” Capital One’s Todd Kennedy put it more plainly: the group is “committed to helping shape it the right way, building a secure, trusted ecosystem.” I believe them. I also think the sequencing gives the statement less power than its authors intend.
The counter-argument, and why it does not hold
The fair objection is that principles-first is usually the right order. Publishing shared definitions and consumer protections in public, before any single company’s product design hardens into the de facto standard, is how the industry avoided a worse outcome with open banking APIs a decade ago. Writing rules against live products, rather than hypothetical ones, also means the banks can base guidance on how agents actually behave rather than how vendors promise they will behave. Both points are true, and if this were the first move in agentic commerce, I would have no argument.
It is not the first move. The card networks, an AI lab and a standards body made the load-bearing infrastructure decisions months ago, and those decisions are already processing real transactions. A bank consortium publishing principles now is not shaping the ecosystem from the outset. It is describing an ecosystem that already has an architecture, and hoping the architecture bends to match the description. Architecture does not bend easily once it is live and carrying volume. The banks’ own next step, a promised implementation paper detailing how the principles translate into practice, will have to work around choices the payment rails have already made rather than inform them.
What would have actually mattered
A liability standard published before the rails went live would have forced the card networks and the AI labs building agents to design around it. A disclosure requirement, telling a customer plainly when an agent is transacting on their behalf, published before agentic checkout shipped, would have been a default rather than a retrofit. What the banks published instead is a statement of values attached to infrastructure someone else already built. Values matter. They do not substitute for the leverage that comes from setting terms before the product exists, and that leverage is the one thing six banks, however large, cannot get back now by agreeing among themselves on what they wish had happened first.
None of this means the principles document is worthless. A shared vocabulary across six large banks on three continents is still useful, if only because it gives regulators a single industry position to react to instead of six competing ones. But usefulness is not the same as timeliness, and the banks’ own framing, that they are “helping shape it the right way,” implies a degree of control over the shape that the timeline does not support. Shaping happens at the design stage. Everything after that is commentary on a design someone else already froze.
What comes next matters more than what was said
The consortium has promised a follow-up paper translating the principles into practical guidance. That document is the one worth watching, because it will show whether the banks can extract concrete commitments from the card networks and AI labs that already built the rails, such as a binding disclosure standard or a clear liability split when an agent’s purchase goes wrong, or whether it will restate the same five themes in more detail without changing what the infrastructure actually does. If it is the former, the sequencing problem I have described here becomes a footnote. If it is the latter, the industry will have spent a news cycle on principles that describe a system nobody with the power to redesign it is obligated to follow.
Source: NatWest Group