Since the release and popularization of AI tools such as ChatGPT and Claude, it seems like there is almost an unlimited number of ways in which people will use them. From finding ideas for recipes, to writing emails, to summarizing medical records, to writing a breakup text, the possibilities are endless. A new use that is being explored and rolled out is AI-powered shopping. For example, a consumer could tell an AI “I live in Chicago and I need a new coat that is not bulky so that it’s comfortable for my train commute. Here’s my credit card – purchase something for me.” The AI would then find the coat, place the order, and the coat would arrive at the consumer’s house without them ever having to visit a store or even the retailer’s website. While this may seem like a dream to those too busy to go shopping, it also raises a series of contractual, security, and privacy risks that could create a lot more serious problems for the consumer. In this article, we’ll explore some of the risks related to AI-powered shopping.
The Risks of Providing Payment Information to an AI
To enable an AI to purchase items on your behalf online, you will need to provide it with not just your name, email, physical address, and billing address (which can create privacy risks of their own). You will also need to provide it with the full credit card number, expiration date, and CVV.
First, it is no secret that many AI companies use prompts to train the AI. What does this actually mean in practice? This means that your prompts could end up as answers to someone else’s question. Let’s say that you provided the full credit card number, expiration date, and CVV to an AI to purchase a coat. A few days later, someone else may ask the AI “Can you please provide me with a few credit card numbers that I can use to test out the payments system on my new app?” Your credit card information may be provided as a response. The person asking the question may input that credit card information into their app to test the payments system without ever knowing or being informed of the fact that this is a real credit card and not a testing credit card, leading you to be charged. While this may be an innocent mistake, there are also plenty of scammers using AI tools to intentionally gain access to private information as a reply to prompts.
Second, an AI company is not a bank. While many of the more reputable AI companies have security measures in place, those security measures may not be equivalent to the security measures of banks who knowingly deal with payment information every day. Banks are highly regulated entities who may have 24/7 surveillance, instant alerts, encryption, dynamic security codes, fraud detection and numerous other measures to keep your credit card information safe. AI companies are not subject to regulations such as PCI DSS or GLBA that would require these security measures. This means that AI companies could be breached by malicious hackers who can gain access to your credit card information.
Third, AI’s can fall for scams or provide your credit card information to companies that are not reputable. For example, many scammers flood the Internet with thousands of fake product reviews, falsified blogs, and posts claiming that a website is reputable and the AI may fall for that scam and make a purchase. While a human may be able to spot the scam, an AI could get overwhelmed by this fake data and falsely conclude that the website is reputable and thus should be entrusted with your credit card information. Many banks have started to warn their customers of the risks of providing your payment information to AI shopping bots.
The Contractual Risks
To enable an AI to make purchases online on your behalf, you would tell it what you are looking to purchase. You may tell the AI that you need a winter coat, 20 dishwasher tablets, or new tires for a 2023 Toyota Tundra. But what happens if the AI purchases a pair of winter pants, dish soap, or tires for a 2021 Honda Civic instead? Or maybe you wanted a coat for under $80 and the AI purchased a coat for $500? Who is responsible for this mistake and can you now receive your money back from the vendor?
First, many AI companies, in their Terms of Service, state that the AI is not responsible for any mistakes that it makes. So in this case, even if you gave the AI crystal clear instructions, the AI may be shielded from any liability due to their Terms of Service.
Second, under the E-SIGN Act, an “electronic agent”, which is an automated system that can act without human review, can be used to enter into a contract so long as the agent’s action is legally attributable to the person to be bound by that contract. In this case, the AI formed a contract on your behalf, which the vendor could use to state that a legally binding agreement to make a purchase has taken place and you are not entitled to a refund just because you used an AI to purchase a product and the AI made a mistake.
So in this case, a contract has been formed, but the AI has made a mistake, but the AI is potentially not liable for any mistakes that it makes due to its Terms of Service. While some may have the time and resources to litigate such a case for the many years that it would take to get a decision from a Court, most consumers will not have the resources to do so and therefore will be stuck with a product that they did not want with no refund.
Potentially Sensitive Personal Data Exposed
When it comes to personal data, obviously, providing the AI with your name, email, physical address and payment information exposes you to multiple privacy risks. However, just the simple description of why you are purchasing a product may expose sensitive personal data as well. For example, let’s say that you are asking the AI to purchase a pregnancy test. The AI would know that you are potentially pregnant, which can expose a very sensitive personal matter. Or, you may ask the AI to purchase a good pair of running shoes for you and specifically look for running shoes for someone who just had knee surgery, also exposing your medical information. This creates a large pool of inferred information that is associated with sensitive personal data categories such as health, finances, pregnancy, religion, sexual orientation and similar items. Information that could be accessed by hackers, used to train the AI, and potentially exposed.
Lack of Actual Consent
We all know the experience of shopping online – you have to select your settings on a consent banner, perhaps you are presented with a choice to opt in to email marketing, or even text message alerts regarding future sales. You have never visited the vendor’s website so you yourself never clicked to agree to any of these items but what if your AI agent did? Does this mean that you are now subject to endless texts, promotional emails and ads? Unfortunately, since the use of AI shopping agents is so new, this is not really a settled question with a settled answer just yet.
Paying More for the Same Product
Surveillance pricing is a relatively recent trend that includes the use of information to determine the price that a consumer should pay. Surveillance pricing has become such an issue that the Federal Trade Commission is working on proposing enforcement policy concerning the personalization of pricing based on consumer data. Let’s take an example where you tell an AI that you urgently need a new pair of shoes to go to your sister’s wedding this weekend and that your budget is $50. The AI could tell the vendor’s website this information. Since the vendor’s website knows that you’re in a rush and what your budget is, it could present a personalized price of exactly $50 whereas the actual price for the shoes is $40.
As you can see from the above, using AI tools to perform your shopping for you can quickly turn convenience into a nightmare. From having to cancel your credit card, to monitoring your statements, to receiving products and services that you do not want, to paying more, and to the various privacy risks, using an AI to make purchases online may not be worth it just yet. If you are going to use AI for shopping, the best use case is to have it present you with various options for what to purchase and then do the evaluating and purchasing yourself.