Skillful AI shopping agents can now find a product, fill a cart, and pay for it without the user even opening a browser tab. Amazon, Google, and OpenAI have each shipped a version of this over the past year, though all three do not work the same way. The safety question therefore is not as simple as it seems at the first sight. We’re not promising that this article will give you easy answers to all your concerns about agentic payments, but it surely will make the context of AI shopping safety much clearer.

There are several different agentic commerce models possible
The first model uses tokenization. The agent never receives a stored card number or a bank login. It receives a scoped, single-use credential tied to one merchant, one amount, and one transaction. The model is already actively used in traditional non-agentic transactions and has proven its effectiveness for financial data safety.
The second commercial model relies on stored credentials: a saved password, a saved card, or account access handed to a browser-based agent that then types it into a checkout form itself. To give the agent an open access to a stored card is precarious. This scenario means that the credential persists across sessions, which in turn creates exposure if the agent gets manipulated. Besides, as Mastercard notes, using stored credentials outright would prevent card issuers from recognizing the transaction as agentic.
In a broader sense of how the AI purchase process works, one can distinguish between three different types of AI-driven commerce models:
Agent-completed in-app checkout. The user approves a purchase inside the platform’s own app; the agent then executes the transaction on the merchant’s site using encrypted or tokenized payment data, without the user leaving the app.
Discovery-in-AI, buy-on-merchant-site. The AI surfaces and compares products, then hands the user off to the merchant’s own site or app to finish paying.
Stored-credential browser automation. A general-purpose AI agent controls a browser session directly, sometimes using a saved password or autofilled card rather than any merchant-issued token.
How Amazon’s Buy for Me works
Amazon’s Buy for Me feature lets a shopper buy an item from a third-party brand site without leaving the Amazon app. When a customer taps Buy for Me, they land on an Amazon checkout page where they confirm delivery address, taxes, shipping fees, and payment method, and Amazon’s AI then makes the purchase by securely providing the customer’s encrypted name, address, and payment details to the brand’s site. Amazon has said it cannot see a customer’s previous or separate orders from other brands. The card itself stays inside Amazon’s systems; the brand site receives encrypted transaction data rather than a raw card number.
How Google’s Buy for Me goes along with Gemini
Google’s version of Buy for Me agentic experience basically runs the same way as Amazon one. A shopper taps “track price” on a product listing, sets size, color, and target budget, and gets a notification when the price drops; tapping “buy for me” adds the item to the cart on the merchant’s site and securely completes checkout on the shopper’s behalf using Google Pay. The capability was announced at NRF 2026 as part of Google’s Universal Commerce Protocol, built with Shopify, Etsy, Walmart, and Target and endorsed by more than 20 companies including American Express and Visa.
Like Amazon’s version, the user stays inside Google’s interface (there’s a buy button directly on Google search, AI mode and Gemini) while the agent completes the transaction using stored, tokenized payment credentials. The difference is that Google’s tool doesn’t stop at facilitating discovery for new items but actually helps a “reluctant shopper” overwhelmed by decision fatigue to select among different options already narrowed-down based on shopper’s priorities. Instead of presenting dozens or hundreds of search results, the AI can identify a handful of products that best match the shopper’s requirements.
“Now, you can type in exactly what you’re looking for, including really specific details and quirks. And AI can do the hard work, narrowing it down to what you’re most interested in buying.”
“When we do get this right, shoppers will be able to find exactly what they’re looking for, get inspired by new ideas and transact more easily than ever before.”
Sundar Pichai, CEO of Google and Alphabet
The question here remains which criteria AI would use for recommendations, and whether it would make any biased or inobjective choices rather than is it safe to link my bank account to Gemini, since that’s not something you’re even required to do. Besides, if you are using any paid Google services, your payment credentials are already in the system.
Where ChatGPT stands in agentic commerce landscape
OpenAI has been changing its agentic commerce perspectives as its technology develops. First, the ChatGPT creator company launched native in-chat checkout, called Instant Checkout, in September 2025, built on the Agentic Commerce Protocol (ACP) and Stripe’s Shared Payment Token. It did not last.
This March, OpenAI pivoted away from Instant Checkout after the feature failed to take off, saying the initial version didn’t offer the flexibility it wanted, and it now lets merchants use their own checkout experiences while ChatGPT focuses on product discovery. Only around 30 Shopify merchants had actually gone live on the feature as of February 2026, and Walmart’s own data showed checkout inside ChatGPT converting roughly three times worse than a direct visit to walmart.com.
ChatGPT today sits in the second agentic commerce model. It discovers and recommends, then routes the purchase back to the retailer’s own site or app. The ACP token infrastructure still exists for merchants who build on it directly; the native in-chat checkout UI that used it is, however, gone.
The card networks are building the same guardrail
Underneath all three interaction types, Visa and Mastercard have shipped network-level tokenization for agent-initiated payments.
Mastercard’s Agentic Tokens bind a tokenized card credential to a specific agent, a specific merchant, and a specific consent policy, so the agent completes checkout without ever holding the raw card number, and issuer fraud liability and consumer chargeback rights carry over from standard tokenized transactions.
Visa’s parallel framework issues merchant-specific tokens scoped to a particular agent and transaction, such as a token valid only for one airline and one trip window. Whether the interface is Amazon, Gemini, or a merchant site reached through ChatGPT, the underlying payment layer is increasingly built around scoped tokens rather than shared card numbers.
Actual risk may just sit in stored-credential agents
While people are reluctant to trust popular AI agents with agentic shopping, PaySpace Magazine Global wants to note that the higher-risk category is different software. General-purpose “agentic browsers” that complete tasks by controlling a browser session directly, sometimes using saved passwords or autofilled card data rather than a merchant-issued token.
Security researchers have documented cases where an agentic browser given a basic shopping task clicked a phishing ad, entered credit card details on a fake site, and completed a fraudulent transaction without a human ever noticing the scam. Password managers have responded directly to this gap. Password built a human-in-the-loop safeguard specifically because AI agents could otherwise retrieve and autofill stored login credentials without additional authentication.
“It was an unsettling reminder of how powerful browsers already are. They know where we go, what we search for, and what we buy. They hold cookies, credentials, tokens, and autofill data that quietly authenticate us across the web. Every digital habit, every login, every trace of behavioral metadata flows through that single application. When an AI layer begins operating inside it, the result isn’t just a smarter interface, it’s an exposed attack surface.”
Mallory Sword Glenn, Director, Okta for AI Agents Product Marketing
Okta team has also highlighted that for most of the web’s history, browsers have been wrongly viewed as passive tools that simply display content. In reality, they have always been much more than that. The rise of agentic browsers such as OpenAI’s Atlas, Perplexity’s Comet, and Microsoft Edge Copilot Mode raises the stakes even further.
As browsers evolve from passive gateways into AI-powered assistants capable of acting on users’ behalf, they gain broader access to personal data and greater autonomy, expanding both their pretty useful capabilities and, unfortunately, the potential privacy and security risks. Malicious pages may include a hidden instruction or manipulative prompt. But whether the AI agent can detect that remains a rhetorical question nobody wants to test with their own wallet at stake.
A working framework for deciding which agentic commerce scenario is safer to use
Before linking any financial account to an AI tool, check which model applies:
- Agent-completed, tokenized (lower risk): Amazon Buy for Me and Gemini’s Buy for Me. The agent transacts with encrypted or tokenized credentials; the raw card number and bank login stay out of the merchant’s hands.
- Discovery-then-redirect (lower risk, different exposure): ChatGPT today. The agent never touches payment at all — the purchase happens on the merchant’s own site, under whatever protections that site already offers.
- Stored-credential automation (higher risk): General AI browser agents that log into sites, save passwords, or autofill card fields carry the same exposure as any autofill tool, amplified by the agent’s ability to act on phishing pages or fake checkouts without pausing for review.
The practical test for whether to share your bank account or card details with an AI agent is simple. Ask if the purchase routes through a named checkout partner, e.g. Stripe, a card network, a bank, that issues a scoped token, or does the agent itself hold and type in the credentials? The first model is closer to routine Apple Pay transaction. The second is akin to handing a stranger your saved passwords and asking them to shop for you.
Frequently Asked Questions (FAQ)
1. Is it safe to let AI buy products for you?
AI shopping can be safe if it relies on tokenized payment credentials rather than stored passwords or raw card numbers. Services such as Amazon Buy for Me and Google’s Buy for Me use encrypted payment information, while browser agents that access saved credentials generally present greater security risks.
2. How does Google’s Buy for Me work?
Google’s Buy for Me uses Gemini to help shoppers discover, compare, and purchase products directly from participating merchants. After you approve the purchase, Google Pay securely completes the checkout using tokenized payment credentials without exposing your card number to the retailer.
3. Does ChatGPT make purchases on your behalf?
No. ChatGPT currently focuses on product discovery and recommendations. When you’re ready to buy, it redirects you to the retailer’s own website or app, where you complete the payment using the merchant’s existing checkout process.
4. Are AI shopping agents safer than browser automation tools?
Generally, yes. Dedicated AI shopping agents from companies like Google and Amazon operate within controlled payment systems that use tokenization. In contrast, browser automation agents may rely on saved passwords or autofilled payment details, making them more vulnerable to phishing attacks or malicious websites.
5. Should you connect your bank account or card to an AI shopping assistant?
Before linking any payment method, check how the AI completes transactions. If it uses a trusted payment partner and tokenized credentials, the risk is similar to using a digital wallet such as Apple Pay or Google Pay. If the AI stores or enters your passwords or card details directly, it’s safer to avoid granting those permissions.


