Is it safe to let AI shop for you right now? For anything tied to your saved card, the honest answer is no, not without an approval step you control. Security researchers have shown that an AI shopping agent cannot reliably tell a real store from a convincing fake, and it will act on your saved payment details faster than you would ever click. The ai shopping agent scam problem is not that agents are dumb. It is that they are fast, trusting, and willing to complete a checkout on a counterfeit site without pausing to ask you first.
This is not a hypothetical. In research they called Scamlexity, first published in August 2025, the security team at Guardio Labs pointed a live agentic AI browser at a set of scam pages and watched it hand over money and credentials. The point for a normal person is simple: an agent that browses and buys on your behalf is a new attack surface, and the safety guardrails around it are still thin.
What the researchers actually showed
Guardio Labs tested Perplexity's Comet, an AI browser that does not just summarize pages but clicks, navigates, and completes tasks on your behalf. In their August 2025 Scamlexity research, they ran three scam scenarios against it. The agent failed all three, and in ways that would cost a real person real money.
- The fake store. Researchers built a counterfeit Walmart page and asked the agent to buy an Apple Watch. It scanned the fake site, went to checkout, auto-filled the card and address, and completed the purchase without asking the user for confirmation.
- The phishing email. When told to check email, the agent treated a spoofed Wells Fargo message as a genuine bank instruction, clicked the link, loaded a fake login page, and moved to enter banking credentials on it.
- The booby-trapped CAPTCHA. On a fake CAPTCHA page with hidden instructions buried in the code, the agent read the hidden text as legitimate commands and triggered a malicious file download, an attack the researchers named PromptFix.
Two things matter about how this was done. First, these were controlled tests run in 2025, not a live crime wave, so treat it as a demonstration of what can go wrong, not proof of mass losses. Second, the failures were not exotic. A counterfeit storefront, a spoofed bank email, and a fake CAPTCHA are the oldest tricks online. A cautious human catches at least one of them. The agent caught none.
Guardio's core warning: in an AI-versus-AI world, a scammer does not need to trick millions of different people. They only need to fool one AI model, then run that same exploit at scale.
Why an agent falls for scams a person would catch
An AI shopping agent falls for fakes because it is built to finish the task, not to doubt the page. You slow down at small tells: a domain that reads walmart-deals-shop dot com, a checkout that looks a little off, a bank email with odd grammar, a price that is too good. Those hesitations are not in the agent's job description. Its goal is to complete your instruction, and a well-made fake gives it every signal it needs to keep going.
There is also a deeper flaw called prompt injection. An agent reads the words on a page as instructions it might follow. A scammer can hide text on a site that says, in effect, click this button or enter these details, and the agent can obey because it cannot always separate the real user's instruction from malicious text planted in the page. That is exactly how the fake CAPTCHA download worked. A human never reads hidden page code as an order. An agent can.
Add speed to trust and you get the core risk. The agent acts in seconds, using details you saved once and forgot about. By the time anything looks wrong, the card has already been charged or the credentials already typed.
The real risks for a normal person
The danger is not that AI shopping goes away. It is that a convenient setup, a saved card plus no approval step, removes the exact checkpoints that usually save you. Three risks stand out.
- Money sent to scammers on autopilot. If your card is saved to the agent and there is no confirmation gate, a fake store gets a completed, auto-filled purchase. You find out when the charge appears, not before.
- Credentials on phishing pages. An agent that follows a spoofed bank link can load a fake login and move to enter your username and password. Handing over banking credentials is worse than one bad charge, because it can open the door to more.
- No human checkpoint at all. The single most important safety feature in online shopping is the moment you look at the final screen and decide to pay. Remove that moment and every other protection has to be perfect. None of them are.
If a shopping agent ever offers to save your card so it can buy without asking, treat that offer as the risk, not the feature. The convenience it sells is the exact checkpoint that stops fraud.
How big is this trend, really
Big enough that the fraud industry is naming it. Consumers reported losing more than 12.5 billion dollars to fraud in 2024, a jump of about 25 percent over the year before, according to the US Federal Trade Commission. That figure predates shopping agents, so read it as the scale of the con-artist economy that agents are now stepping into, not as a measure of agent losses.
Looking ahead, Experian's 2026 Future of Fraud Forecast, published in January 2026, names agentic AI as a top fraud threat for the year and warns that fraudsters will exploit it for new kinds of digital fraud, with machines transacting with machines and no clear owner of the risk. In other words, the people who study fraud for a living see agent-driven scams as the next front, not a fringe worry.
Keep the honest framing in mind. The Scamlexity results are a lab demonstration, and the FTC number is total consumer fraud, not agent fraud. What connects them is direction of travel: a proven weakness in how agents handle money and data, meeting an economy already built to exploit weaknesses.
How to reduce the risk without giving up AI shopping
You do not have to swear off shopping agents to stay safe. You have to keep the checkpoints an agent removes. Four habits carry most of the protection.
- Keep a human in the loop. Use agents to research, compare, and fill a cart, then approve the actual payment yourself. If a tool cannot be set to ask before it pays, that is a reason to say no.
- Use a virtual card with a spend cap. Many banks and card apps let you create a single-use or limited virtual card. If an agent gets fooled, the loss is capped at the limit you set, and you can kill the number without replacing your real card.
- Do not save your real card to an agent. A card the agent cannot reach is a purchase it cannot complete on a fake store. Enter payment yourself, or use a capped virtual card each time.
- Verify the merchant before you trust the deal. Check the exact domain, look for real contact details, and be suspicious of prices that beat everyone else. An agent will not feel that suspicion for you.
The table below compares three ways to let an agent near your money and data, from the risky default to a controlled setup.
| What you are weighing | AI agent, card saved, no approval | AI agent, approval plus virtual card | Private data store you control (MemX approach) |
|---|---|---|---|
| Who decides to spend | The agent, alone and instantly | You approve each payment | No autospend; you decide what any tool may see |
| What a fake store can capture | Full card and address, auto-filled | A capped virtual card at most | Nothing without your explicit permission |
| Human checkpoint | None | Required before payment | You grant access per request |
| If the agent gets tricked | The charge goes through | Loss limited to the cap | Your data stays isolated, not auto-shared |
| Honest trade-off | Most convenient, least safe | Slightly slower, far safer | Control over what leaves your hands |
Where control of your own data fits in
The Scamlexity lesson is not only about payment. It is about what an agent can reach and act on without asking. An agent that can silently pull your card, address, and logins is one convincing fake page away from handing all of it over. The safer pattern is the opposite: your personal information sits somewhere you control, and a tool can only touch it when you say so.
That control-first idea is how MemX is built. MemX is a private memory app for your documents, photos, voice notes, and messages, so you can snap something now and find it later just by asking. It is private by architecture: per-user isolation, customer-managed encryption keys, encryption at rest, on-device processing where possible, and no training on your data. It is not a shopping agent and it does not hold your card. The relevant part is the principle it runs on, which is the same principle these scam tests point to. Your data should stay yours by default and only be reachable with your permission, not auto-shared by a tool moving faster than you can check.
The through-line of the research is control and verification. Whether it is money or personal information, the safe setup is the one where nothing important leaves your hands until you have looked and agreed.
The honest verdict
Letting an AI shop for you is genuinely useful for the boring parts: finding options, comparing prices, filling a cart. It is not yet safe for the final step of paying with a saved card and no approval, because the agent cannot reliably tell a real store from a fake and will act before you can catch the difference. The fix is not to fear the technology. It is to keep the checkpoints that agents are designed to remove: approve your own payments, cap what a mistake can cost with a virtual card, keep your real card out of the agent, and check the merchant yourself. Use the speed, keep the judgment.
01Is it safe to let an AI agent shop for me?
For research and comparison, yes. For paying with a saved card and no approval step, not yet. Researchers showed an AI browser completing a purchase on a fake store and entering bank credentials on a phishing page, both without asking the user first. Keep a human approval step on any payment.
02What is the Scamlexity research?
It is testing by security firm Guardio Labs on Perplexity's Comet AI browser. In three controlled scenarios the agent bought from a counterfeit store, moved to enter credentials on a fake bank page, and triggered a malicious download from a booby-trapped CAPTCHA, showing agents can be tricked by ordinary scams.
03Why do AI shopping agents fall for fake stores?
They are built to complete the task, not to doubt the page, so they miss the small tells a cautious person notices. They can also treat hidden text on a page as instructions, a flaw called prompt injection, which lets a scammer steer the agent using content planted on the site itself.
04How can I use a shopping agent more safely?
Keep a human in the loop and approve payments yourself. Use a virtual card with a spend cap so any loss is limited. Do not save your real card to the agent. And verify the merchant's exact domain and details before trusting a deal, especially one with a price that looks too good.
05Does using a virtual card actually help?
Yes. A single-use or capped virtual card limits what a fooled agent can spend and lets you cancel that number without replacing your main card. It does not stop a scam by itself, but it turns a potential open-ended loss into a small, contained one.
