On September 22, 2026, a consortium of six global banks—ASB, Bank of America, Capital One, Commonwealth Bank of Australia, ING, and NatWest—released a document titled Building Trust in Agentic Commerce. The timing is not accidental. It is a direct response to the Trust Paradox, where 89% of merchants are prepping for agentic commerce, yet only 3% of transactions actually involve AI agents. With consumer trust hovering at a meager 24%, these institutions are attempting to price governance into the infrastructure before regulators decide to do it for them.
The Governance Playbook
The paper outlines five pillars: Transparency, Safety, Privacy and data, Choice, and Interoperability. The definitions are functional, bordering on the clinical. Transparency mandates that all parties know when an agent is acting. Safety focuses on consumer control and collaborative fraud prevention. Privacy demands data-governance standards. Choice aims to prevent monopoly dominance by selecting counterparties on merit. Interoperability seeks cross-ecosystem compatibility from day one.
These principles are voluntary and lack an implementation timetable. It is a classic institutional hedge: establish the frame of the conversation without committing to the cost of enforcement. However, the inclusion of a liability principle is sharper than expected. The paper suggests that liability should reflect where risks or errors are introduced. As Mark Monaco, Head of Global Payments Solutions at Bank of America, noted: “As agentic commerce continues to evolve, establishing trust and confidence across the ecosystem will be critical to its long-term success. Building confidence among consumers, merchants and financial institutions will require thoughtful approaches to identity, authorization, fraud prevention, liability management and customer protection.”
The Identity Vacuum
The consortium is stepping into a fragmented landscape. We have seen five distinct identity products released in five weeks, none of which share a standard. According to the Agent Identity Stack, non-human identities now outnumber human employees by 144-to-1, yet 78% of organizations lack any documented policy for managing these entities. The banks are essentially trying to write the constitution for a market that currently lacks a common language for machine-to-machine interaction.
The gap between the ambition of these six banks and the reality of the market is wide. While the consortium invites broader ecosystem engagement and plans a follow-up paper on implementation, the current state remains a holding pattern. The industry is waiting for the NIST AI Agent Interoperability Profile, expected in Q4 2026, to provide the technical scaffolding that these principles currently lack.
The Real Test
For now, the banks are positioning themselves as the architects of the trust layer. The question is whether this consortium can move beyond voluntary guidelines to create a functional, interoperable standard. The focus for observers should be on whether other institutions join this framework and how the promised implementation paper addresses the liability principle in practice. Until then, the gap between the promise of agentic commerce and the reality of consumer adoption remains a significant hurdle. The banks have set the table, but the agents have yet to arrive.
