AI-powered shopping: are retailers ready for the legal risks?
Tuesday 29th September 2026
There has been a flurry of activity in recent months as both brands and big tech such as Amazon (through its Alexa and Buy For Me agents) and Meta (through its AI agent, Muse) have introduced Artificial Intelligence (AI) agents to assist consumers with their online shopping.
John Lewis reported this month that searches from AI agents rose to 2.5% from 0.3% a year ago, and speaks to a shift in consumer behaviour to harness the power, and efficiency, of AI in their everyday lives.
However, the growing use of AI agents is not without legal challenge, and e-commerce platforms should be alive to legal risks posed by their use.
How do AI shopping agents work?
AI shopping agents are autonomous AI systems which are able to research products based on consumer requirements, add products to a user’s basket, and sometimes make a payment and therefore complete a purchase on behalf of a user. These agents typically interact with retailer websites by browsing and scraping product pages in much the same way a human user would, though some operate through APIs where available, raising questions about authorised access and the boundaries of a retailer’s terms of use.
The consumer benefit is tangible when considering potential use cases – for example using loyalty card data to automate grocery shopping, and to find clothing items they are interested amongst thousands of results.
Legal considerations for retailers
For retailers, as the use of AI assistants becomes more prevalent, it is worth considering whether additional protections are needed in their terms of service and/or website terms. Key areas include:
- Consumer contract formation – where an AI agent completes a purchase on behalf of a consumer, is there a valid contract? Retailers may need to ensure their checkout process requires sufficient human confirmation, and consider who bears liability for erroneous purchases.
- Privacy, Data Protection and Security – AI agents scraping product pages may collect and process data in ways retailers have not anticipated. Privacy notices and cookie policies may need to address automated access, alongside the implications of AI agents handling consumer payment and personal data. Retailers should consider whether there are any security risks posed by the use of AI shopping agents and take steps to address these from a platform security perspective, too.
- Consumer returns and remedies – under the Consumer Rights Act 2015 and the Consumer Contracts Regulations 2013, consumers have cancellation and return rights. If an AI agent purchases the wrong item or a product that does not match the consumer’s actual requirements, questions arise about how existing refund and returns processes apply.
- Intellectual property – AI agents that scrape product descriptions, images, and pricing data may raise IP infringement concerns, particularly around database rights and copyright in product listings.
- Fraud and payment authentication – Retailers may need to consider whether existing payment verification processes, such as Strong Customer Authentication under the Payment Services Regulations 2017, are adequate when a transaction is initiated by an AI agent rather than the consumer directly.
The landscape shifted further this week as Amazon removed Meta’s Muse AI agent from its platform, stating that access by an “unauthorised AI agent” violates Amazon’s Conditions of Use.
Major banks in the US have also issued a joint statement this week, stating that AI shopping bots and ‘agentic commerce’ are ‘advancing faster than consumer protection laws’.
Retailers who review their terms, tighten their platform safeguards, and stay ahead of the evolving regulatory landscape now will be best placed to manage the risks, and hopefully reap the commercial benefits, of this rapidly emerging technology.
Get in touch with our retail and privacy and data protection teams to discuss your requirements.