On September 22, 2026, ASB Bank, Bank of America, Capital One, Commonwealth Bank of Australia, ING Group, and NatWest Group jointly published a set of shared principles for what they're calling agentic commerce; AI agents that shop and pay on a customer's behalf. The paper, titled Building Trust in Agentic Commerce, is voluntary, non-binding, and deliberately early: a second paper on actual implementation is still to come. But one line in it is worth pulling out on its own, because it's a precise, public restatement of an argument this blog keeps making.
The paper sets out five areas: transparency, safety, privacy and data, choice, and interoperability. Buried inside safety is the line that matters: liability should sit where the risk or error was introduced, not automatically with whichever party the customer happened to be dealing with when something went wrong. Every party involved in a transaction, the paper says, should be part of the dispute process when it's disputed.
That's not a small thing for six of the world's largest banks to put their names to. It's the principle behind ensuring liability lands in the right place rather than defaulting to whoever's easiest to blame, and it's genuinely useful to see it stated this clearly, in public, by this many institutions at once.
Saying liability should sit where the error was introduced assumes something the paper doesn't fully solve for: that anyone involved can actually determine where the error was introduced, quickly enough and clearly enough to act on it. A single agentic transaction can pass through a wallet provider, an agent developer, a merchant, a payment processor, and a bank, in some order, often within seconds. The paper's own answer to this is an audit trail requirement: providers should preserve evidence of consumer instructions, authentication, intent, transaction decisions, outcomes, and any warnings or interventions along the way, specifically so disputes can be investigated and money recovered.
That's the right instinct, but an audit trail kept separately by each of five or six participants, in five or six different formats, updated on five or six different schedules, is not the same thing as a shared, continuously verifiable record of what actually happened across the chain. The principle says where liability should land. It doesn't yet say how a bank, a wallet provider, and a merchant agree on the facts fast enough for that principle to mean anything in an actual dispute.
The timing makes sense once you look at consumer behavior. Research cited alongside the paper's release found that roughly half of Americans have already used AI somewhere in a retail purchase, but fewer than a quarter would actually let an agent complete the payment itself. Usage is running well ahead of trust, and the six banks publishing this paper are, in effect, racing to build the trust before the usage catches up to it and something goes wrong at scale first.
None of this is a criticism of the paper for being early. Voluntary, non-binding principles from a group of competitors, published before regulators have weighed in, are exactly what a first step should look like, and naming the liability question at all puts these six banks ahead of most of the industry. The gap is simply the one the paper itself leaves open: principles describe what good looks like. They don't, on their own, give five or six different institutions a shared, real-time way to see the same facts about the same transaction at the same time.
That's an infrastructure question. And answering it turns ‘liability sits where the error was introduced’ from a good sentence into something a dispute can actually be resolved by.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.