The next time you ask an AI to find something for you, there is a good chance that the conversation may not end with a list of recommendations. It may end with: “I’ve bought it for you.”
That sounds like a small change, but it could fundamentally alter the way we interact with AI.
A recent development in India makes this more than just a theoretical possibility. The National Payments Corporation of India (NPCI) is reportedly developing a registry to verify and monitor AI agents that conduct transactions on its Unified Payments Interface (UPI). The initiative is part of a proposed framework for “agentic payments”, where AI agents could make payments on behalf of users without requiring approval for every individual transaction.
The initial focus is expected to be on relatively small, routine purchases such as groceries, with the possibility of supporting more complex transactions in the future. The proposed framework is also expected to incorporate mechanisms such as spending limits, identity checks and rules governing transactions.
This is an interesting development because UPI has already made digital payments almost frictionless in India. Adding AI agents to that ecosystem could take convenience another step further. But it also raises a question that I find more interesting than the technology itself:
If an AI agent spends my money and gets it wrong, who is responsible?
We are moving from asking AI to acting through AI
Most of us are already comfortable using AI for recommendations. We can ask it to compare smartphones, suggest a holiday itinerary, find a restaurant, research a product or help us decide which laptop to buy. The AI does the research and presents its reasoning. Ultimately, however, we make the decision and click the “Buy” or “Book” button ourselves.
Agentic AI changes that relationship.
Instead of saying, “Find me the best washing machine,” we could say, “Find me the best washing machine under ₹50,000 and buy it.”
Instead of asking, “Which hotel should I stay at?” we could say, “Find a suitable hotel for these dates, and book it if it meets my criteria.”
The difference may seem like one additional step. From a responsibility and trust perspective, it is much bigger. Once an AI agent is authorized to act on our behalf, we are no longer simply consuming information generated by AI. We are delegating decisions to it and this delegation could have consequences.
Imagine giving AI control of your grocery shopping
Grocery shopping is probably one of the easiest places to imagine this becoming useful. I could tell an AI agent that my household’s regular grocery list should be ordered every Sunday. It could look at what I usually buy, check prices across different grocery platforms, consider delivery charges and choose the best combination within a specified budget. During the festive season, the task could become even more interesting.
Suppose I give the agent a list of ten people I want to buy gifts for, along with a total budget of ₹15,000. It could search across retailers, look at reviews, compare prices, consider delivery dates and suggest appropriate gifts for each person. If I give it enough authority, it could even place all the orders.
That sounds extremely convenient. But what exactly does “best” mean?
If one gift costs ₹899 and another costs ₹1,199, is the cheaper one automatically better? What if I trust the more expensive brand? What if the cheaper product has a poor return policy? What if the ₹899 product has great reviews but looks cheap when it actually arrives?
A human who knows me might understand these preferences without my having to explain them every time. An AI agent needs to be told.
This is where agentic AI gets interesting. The challenge isn’t necessarily that the AI will be unintelligent. It may be perfectly capable of comparing prices and reviews. The challenge is that our instructions rarely capture everything we mean.
What happens when the AI manages your wishlist?
Consider another everyday example.
I have a wishlist containing several products I would like to buy eventually. Instead of manually checking prices, I could ask an AI agent to monitor them across retailers.
“Buy this product when the price falls by at least 20%, provided it is from a reliable seller and the final price, including delivery, is below ₹5,000.”
The agent could potentially do this much better than I could. It doesn’t forget to check. It can monitor multiple retailers and react immediately when the conditions are met.
But there are plenty of ways this could go wrong.
Perhaps the price fell because the retailer is clearing the older model. Perhaps a new version is about to launch. Perhaps the cheapest seller has a poor return policy. Perhaps the product is discounted because it is refurbished, while I assumed it was new.
Or perhaps the AI interprets my instruction literally and buys the product at 2 AM (whilen I am sleeping) because all my conditions have been met.
The agent hasn’t necessarily made an obvious mistake. It has simply acted on information and rules that did not fully represent what I wanted.
Travel is where I have already experienced an early version of this
I don’t have to imagine how useful AI can be for travel planning. I have already used ChatGPT for it.
When I was planning my vacation, I used its help put together an itinerary. I asked ChatGPT to recommend how I could structure the trip and what places would be worth visiting. I also had a very specific requirement. I wanted to watch the live fireworks show on a Saturday evening, and was looking for rooftop restaurants from where I could have dinner while also getting a good view of the fireworks.
ChatGPT was able to bring several pieces of information together and recommend restaurants based not simply on their popularity, but on the particular experience I was looking for. The itinerary and restaurant recommendations were useful because they helped me make decisions that would otherwise have required quite a bit of research.
But there was an important boundary. I made the final decision.
I could look at the itinerary, change it, reject a recommendation, choose a restaurant and then make the booking myself.
Now imagine taking the next step. Instead of asking ChatGPT to recommend rooftop restaurants, I could tell an AI agent:
“Find me a rooftop restaurant with a good view of the fireworks on Saturday evening. Check availability for for our group (of n people) between 7 and 8 PM. Book it if the price is below ₹x,xxx per person.”
The agent would have to do considerably more than search. It would need to identify suitable restaurants, establish that the fireworks were actually taking place, assess whether the restaurant offered a reasonable view, check availability, evaluate the price and then make the reservation.
And potentially charge my card.
What happens if the restaurant has a great view but the fireworks are cancelled because of weather? What if the AI interprets “good view” differently from me? What if there is a minimum spend that wasn’t obvious when the booking was made? What if the reservation is non-refundable?
These aren’t hypothetical problems with AI intelligence. They are problems with delegating a decision that involves money, preferences and uncertainty. My experience was essentially AI-assisted travel planning.
The next progession is AI-directed travel planning, where the system doesn’t just tell me what I should do but actually does it.
Even movie tickets aren’t quite as simple as they sound
Take something as mundane as booking movie tickets. I could tell an AI agent, “Book two good seats for the new movie this weekend. Any evening show is fine.”
It might find a 6:15 PM show and book two seats. But perhaps I meant Saturday and the agent interpreted “this weekend” as Sunday, which ideally could have been prevented if the agent also had access to my calendar. Additionally, perhaps by “good seats” I meant somewhere near the centre, while the agent decided that the most expensive seats were the best ones. Or perhaps it booked the cheapest cinema because I said any show was fine, even though that cinema is inconvenient for me.
Again, the AI may have followed my instruction perfectly. It is my instruction that wasn’t precise enough.
Humans deal with this kind of ambiguity constantly. When a friend asks us to book “a nice restaurant,” we have some understanding of what that person probably means based on previous conversations and experience. An AI agent will increasingly have access to that context too. But the more important the transaction, the more uncomfortable we may become with letting it make assumptions.
So who is liable when something goes wrong?
This is where I think we need to be careful about how we frame the question.
There isn’t a simple, universal legal answer today that says “the AI company is responsible” or “the consumer is responsible.” Liability will depend on the nature of the transaction, the authorisation given to the agent, the applicable laws and contracts, and ultimately how regulators and courts interpret these new situations.
That uncertainty is itself significant.
Suppose I give an AI agent permission to make purchases up to ₹10,000. The agent buys something for ₹9,500 that I didn’t actually want. If the agent was acting within the authority I gave it, I may have a difficult argument that the transaction was unauthorised simply because I subsequently disliked the decision.
But suppose the agent exceeded the spending limit I had specified. Or it made a purchase after its authorisation had been revoked. Or there was a technical failure in the authentication process.
The question becomes very different. There is also a distinction between a transaction I authorised but regret and a transaction that I never authorized at all.
The first could be comparable to giving another person permission to make a purchase on my behalf and then disagreeing with their choice. The second is simply an action that I never asked to be done.
And then there is a third category: the agent did something different from what I authorised because of a technical failure, malicious manipulation or misleading information. Imagine an AI agent is instructed to buy a product below ₹5,000. A website displays one price to the agent, but the final transaction charges ₹7,000. Or malicious instructions embedded in a webpage cause the agent to change its behaviour. Or a software bug causes it to purchase the same item multiple times.
Who bears the loss in those situations? That is precisely the kind of question that needs clearer rules as agentic commerce develops.
Interestingly, the recent reporting on NPCI’s proposed framework specifically points to the need for mechanisms around authentication and liability as AI agents begin conducting transactions.
So I don’t think we should look at the NPCI initiative as having already solved the liability problem.
Rather, the fact that liability is being considered as part of the framework tells us that the problem is becoming real enough to require an answer.
Maybe we shouldn’t give AI unlimited authority
I don’t think the answer is to avoid AI agents altogether. In fact, I can see myself using them for many of these activities. On the work side, I have AI connected to my calendar, CRM, SharePoint, Outlook email and have agents that can do campaigns, updates pipelines, reports and other stuff.
But in my personal life, especially when it comes to making transactions, I would probably start with limited authority.
For example, I might allow an agent to monitor a product and notify me when it reaches a certain price. Once I become comfortable with its recommendations, I might allow it to purchase products below a particular value.
For groceries, I could give it a monthly budget and permission to buy items that are already part of my regular shopping pattern. For movie tickets, I could give it a simple rule: two seats, central section, evening show, maximum ₹1,500. For travel, I might allow it to shortlist options but still require my approval before making a non-refundable booking.
You could think of this as a spectrum of autonomy.
At one end, AI simply recommends. Then it can prepare a purchase or booking for our approval. Next, it can make conditional purchases based on rules we establish and eventually, it could manage entire categories of spending on our behalf.
The technology may allow us to move quite far along this spectrum. Whether we want to is a different question.
The better the AI gets to know us, the more useful it becomes
There is another interesting consequence of all this. The better AI agents become, the less useful simple instructions such as “find the cheapest option” will be.
A genuinely useful personal agent would need to know that I prefer reliability over the absolute lowest price. It would need to know that I don’t like non-refundable bookings, that I prefer certain airlines or hotel chains, that I am willing to pay a little more for faster delivery and that I don’t want to buy a new gadget simply because there is a discount.
It might also need to know my boundaries such as:
- Don’t make purchases above ₹5,000 without asking me.
- Don’t book flights with more than one stop.
- Don’t buy a replacement for something I already own unless there is a significant improvement.
- Don’t use a seller with poor after-sales service even if the price is lower.
These preferences could eventually become part of an AI agent’s understanding of me. That could make the agent much more useful than a conventional search engine or shopping app. But it also means that we will be giving AI systems a surprisingly detailed understanding of our behaviour, preferences and spending patterns. That is another issue we will eventually have to think about.
The biggest risk may be poorly defined instructions
When we talk about AI making mistakes, we usually think about hallucinations or incorrect information. With agentic AI, I think there will be another category of mistakes that deserves more attention.
The AI does exactly what we told it to do, but not what we intended.
If I ask an AI to find the cheapest hotel, it can do that perfectly. But perhaps what I really meant was: “Find the cheapest hotel that I would actually enjoy staying in.” The second instruction is much harder to define.
This is why I suspect that one of the important skills of the AI era will be learning how to delegate effectively. We have spent a lot of time talking about prompt engineering. With AI agents, we may need something closer to delegation engineering.
We will need to define budgets, preferences, approval thresholds, exceptions and circumstances in which the AI should stop and ask us before proceeding. That is very similar to managing a human assistant.
You don’t simply tell an assistant, “Handle my travel.” You gradually teach them how you like to travel. The difference is that an AI can potentially execute the instruction instantly and at scale.
Would I let an AI spend my money?
Eventually, probably yes. But I wouldn’t begin by giving an AI unrestricted access to my bank account.
I’d start with low-risk activities where the consequences of a mistake are manageable.
- Buy my regular groceries within a specified budget.
- Find and buy a product when it reaches a particular price.
- Book two movie tickets according to clearly defined preferences.
Perhaps eventually handle routine travel bookings within specified limits. The more successful those interactions are, the more comfortable I might become with increasing the agent’s authority.
There is also a psychological hurdle here. We are already accustomed to delegating money-related decisions to people. We give a travel agent a budget. We ask a family member to pick up groceries. We ask an assistant to book a flight. But trusting a software agent with the same authority feels different.
When a human misunderstands us, we can usually have a conversation and correct the misunderstanding. With an AI agent, we have to think about the boundaries before the mistake happens.
The real test for agentic AI
For years, we have evaluated AI by asking how intelligent it is. For AI agents, I think another question will become equally important:
How safely can I delegate to it?
An agent that finds me a ₹500 cheaper flight isn’t particularly useful if it occasionally books the wrong flight. An agent that finds the cheapest television isn’t necessarily useful if it doesn’t understand that I care about after-sales service. And an agent that can complete a purchase in three seconds isn’t necessarily better if I have to spend twenty minutes checking what it did.
The most useful AI agent may ultimately be the one that understands not just what to do, but when to act and when to ask. That is perhaps the most important shift we need to prepare for.
We have spent the last few years getting comfortable with AI saying, “Here are some options.” We are now moving towards AI saying, “I’ve taken care of it.”.
That sounds convenient but before we hand over the credit card, we should probably decide exactly what “take care of it” means.
