Financial firms are rolling out AI “agentic” tools that can execute card purchases and trades, raising fresh concerns about fraud and data security. Robinhood has enabled AI agents to buy with its credit card and trade on users’ behalf, while Visa said its tie-up with OpenAI will support secure agent-driven payments. Analysts warn the bigger risk isn’t the technology itself but how easily consumers can be manipulated into oversharing credentials or bypassing safeguards. Security experts point to tactics like indirect prompt injection—malicious instructions hidden in webpages or data sources accessed by AI—as a growing vector for theft and account takeover. Consumers are advised to limit the data they share with AI tools, scrutinize permissions, and maintain traditional protections such as strong authentication and transaction alerts.
Related articles:
– OWASP Top 10 for LLM Applications: Risks and Mitigations
– NIST AI Risk Management Framework
– OWASP AI Security and Privacy Guide
– IdentityTheft.gov: Report and Recover from Identity Theft




























