In 2026, security researchers at Guardio Labs ran a simple test. They gave an AI shopping agent one job: buy an Apple Watch online. The agent found a listing and bought it right away, using the person's saved card details.
There was one problem. The store was fake. It looked like Walmart, but it wasn't. The agent never noticed. It just did what it was told.
That's the risk worth understanding as more stores add AI agents that shop, compare, and buy on their own. The technology works well. It just doesn't think the way a careful shopper does.
That's the risk worth understanding as more stores add AI agents that shop, compare, and buy on their own. The technology works well. It just doesn't think the way a careful shopper does. We've written before about how you're building faster than ever, and so are the hackers. This is the same pattern showing up on the buying side of the store: the speed arrives first, and the safeguards get added later.
What's already working well
Shopify's Sidekick is a good example of doing this the right way. A store owner can ask it something like "why did my sales drop last week?" and it digs through the store's own data to answer. If it wants to make a change, like setting up a discount, it asks first. It won't act without approval.
That one detail matters a lot. It's the difference between an assistant and something that can spend money without anyone checking.
On the buying side, big platforms are trying to make AI shopping safer too. Google and Shopify built a shared standard called the Universal Commerce Protocol, backed by Walmart, Target, Visa, and Mastercard. OpenAI and Stripe built a similar one with Stripe. The idea is simple: stores that join these systems have already proven they're real, so an AI agent shopping there is safer, because someone already checked.
Where the real risk sits
None of that protection applies once you leave those platforms. Buying from a stranger on Instagram or Facebook Marketplace was always risky, and AI hasn't fixed that. If anything, it's made both sides of the problem harder.
Fraud teams say close to one in three retail fraud attempts now involve AI in some form. Some large retailers see over a thousand AI-driven bot visits a day. Scammers can generate fake product photos, fake reviews, and entire fake storefronts in minutes, and they can look real even to a careful person.
Now put an AI agent into that mix. It isn't weighing whether a seller feels trustworthy. It's just finishing the task it was given. Unless something tells it to slow down and check, it won't.
What's being built to fix this
There's a name for the fix already: Know Your Agent. It works a lot like the ID checks banks run on people. Experian has one version. Visa has its own system, called Trusted Agent Protocol, built to confirm an agent is real and who it's actually shopping for. Google's version uses signed "mandates," basically proof that a real person approved a specific purchase. Some payment companies are also building spending limits directly into the payment itself, so even a hacked or confused agent can't overspend.
These are good steps. But they're built for agents shopping at verified stores. They don't reach the world of buying from a random person online.
What this means if you're building with AI
If you're adding AI to a storefront, the lesson is simple: don't remove the moments where a human should look before money moves. Sidekick's approval step isn't a limitation, it's what makes it trustworthy. An agent that searches and compares is genuinely useful. An agent that can also pay without any check is a different kind of product, and it shouldn't be built the same way by default.
For everyday shoppers, the old advice still holds. Buying from an individual outside a real platform carries the same risk it always did. An AI agent in the middle of that won't catch a scam a careful person would catch, and it can even make people feel safer than they should, simply because it acts so confident.
The real story here isn't that AI shopping agents are dangerous. It's that they're only as careful as the systems built around them, and right now most of those systems assume good faith on the other side of the deal. That's exactly what scammers are counting on.





