Retail AI security now runs in both directions: the chatbot you deployed can be talked into giving away margin, and more than half the traffic hitting your storefront is automated. Courts, the FTC, and California regulators have all noticed.
No other industry has this shape. A bank's AI risk mostly points inward. Retail put its AI in front of the public, gave it pricing and refund authority, and then invited the public's own AI in to shop. Both halves can hurt you now, and neither is hypothetical anymore.
A tribunal made the chatbot's word binding
In February 2024 the British Columbia Civil Resolution Tribunal decided Moffatt v. Air Canada, the case every retail counsel now cites. Jake Moffatt, booking travel after a death in the family, asked the airline's website chatbot about bereavement fares. The bot invented a policy: book now, claim the discount retroactively within 90 days. The real policy, on a page the bot itself linked to, said the opposite.
Air Canada's defense was remarkable. It argued the chatbot was, in effect, a separate entity responsible for its own statements. The tribunal rejected that outright and held the company responsible for everything on its website, chatbot included. Moffatt was awarded CAD $812.02.
The money is nothing. The principle is not. Once a bot's promise binds the company, every jailbreak that extracts a discount code or a refund commitment stops being a screenshot for social media and becomes a claim against revenue. Nothing equivalent has surfaced from a US court yet, and you should not assume it has. Most legal teams are planning as if it will.
The incident file
The pattern since late 2023 is depressingly stable: a general-purpose model, thin branding, real authority, no guardrails. Last verified: September 7, 2026.
| Date | Company | What happened | Outcome |
|---|---|---|---|
| Aug 2022 | Sephora | California AG's first CCPA action: third-party trackers feeding personalization amounted to a "sale" of personal information without disclosure or opt-out; Global Privacy Control signals ignored | $1.2M settlement; failed to cure in the 30-day window |
| Dec 2023 | Chevrolet of Watsonville | Customer prompt-injected the dealership's ChatGPT-based site bot into agreeing to sell a 2024 Tahoe for $1, "no takesies backsies" | Not honored; chatbot pulled |
| Dec 2023 | Rite Aid | FTC found facial-recognition surveillance deployed without reasonable safeguards; customers, disproportionately women and people of color, falsely flagged as shoplifters | Five-year FRT ban; 45 days to delete all system imagery |
| Jan 2024 | DPD | Customer coaxed the "Ruby" chatbot into swearing and writing a poem calling DPD the worst delivery firm in the world | AI element disabled immediately after a system update was blamed |
| Feb 2024 | Air Canada | Tribunal held the airline liable for a bereavement policy its chatbot invented | CAD $812.02 awarded; the liability precedent |
| Nov 2025 | Gap (reported) | Sierra-built care agent steered into sex toys and Nazi Germany; Sierra reportedly described a coordinated jailbreak attempt on a dozen-plus client agents, with Gap's guardrails misconfigured | Widely covered; primary sourcing thin |
| Feb 2026 | UK small business (reported) | Support bot flattered over an hour into inventing discount codes escalating to 80% off; customer placed an £8,000+ order and demanded honoring | Order cancelled and refunded |
Two rows carry a caution flag. The Gap incident and the 80% discount case are sourced to aggregators and a niche security blog respectively; treat both as reported, not established. We keep the cited, dated record in our AI agent incident and litigation tracker.
What is established is the friction. CNBC reported in April 2026 that nearly one in five consumers who used AI for customer service saw no benefit at all, a failure rate roughly four times higher than for AI use generally. Refunds were the flashpoint.
Amazon v. Perplexity will decide who your customers are allowed to be
The other direction is stranger. In November 2025, Amazon sued Perplexity, alleging its Comet browser agent concealed itself to access logged-in customer accounts and make purchases without Amazon's authorization. In March 2026 a federal judge agreed and enjoined Comet's shopping agent, reasoning that a user's permission is not the site owner's authorization. In August 2026 the Ninth Circuit overturned that injunction, finding Amazon's Computer Fraud and Abuse Act theory could not support it. The underlying case continues in the Northern District of California, and Amazon can still seek rehearing. Three stages so far, and no settled answer to whether an AI agent may visit your website.
While the courts argue, the rails are being laid anyway. OpenAI and Stripe launched Instant Checkout and the Agentic Commerce Protocol in September 2025, US Etsy sellers first, over a million Shopify merchants announced as next, the protocol open-sourced under Apache 2.0.
And the money is real. Adobe Analytics measured AI-referred traffic to US retail sites up 693% year over year during the 2025 holidays, converting 31% better than other sources, with revenue per visit 37% above non-AI traffic by March 2026. Salesforce estimated AI agents influenced more than 20% of global online retail sales that season. Walmart says roughly half its app users have interacted with Sparky, its shopping assistant, whose users carry an average order value about 35% higher than everyone else's.
Now the hostile half. Imperva's 2026 Bad Bot Report put automated traffic above 53% of all web traffic in 2025, bad bots alone at 40% of the internet, and counted a 12.5x jump in AI-driven attacks it detected, from 2 million blocked incidents a day to 25 million. Retail was the single most targeted industry for AI-enabled bot activity, with business-logic abuse aimed at pricing, inventory, loyalty programs, and APIs.
So the same storefront must turn away 25 million hostile automations a day and welcome the agent carrying a customer's card. Blanket bot-blocking is now a revenue decision, not a security default, and the courts have not told you where the line sits. What separates the two populations is authorization and behavior, which means giving agents identity and scoped permissions, then watching what they actually do once inside, the case we make at length in AI agent runtime security.
PCI DSS has no AI clause. Your QSA will still ask.
Scoping rules do not care whether a system is intelligent. Let's say the quiet part first: PCI DSS 4.0 contains no AI-specific requirements, and any vendor pitching "PCI AI compliance" as a mandate is selling you an obligation that does not exist. What the standard has is scope. If a chatbot can see order and payment context, or an agent executes checkout, that component can touch or influence the cardholder data environment, and the familiar requirements follow it there. A copilot summarizing transactions with card data in them raises the same question.
The PCI Security Standards Council sees where this goes. Its AI principles for payment environments note that AI use is expanding to "agentic AI systems which have a level of agency to perform actions on their own behalf," and its guidance on AI in assessments warns the technology "can also introduce false positives, incorrect assumptions, and biases" without human oversight. Principles, not requirements. The design burden stays yours.
Agentic checkout shows what good design looks like: under the Stripe protocol, shared payment tokens keep the agent from ever holding raw card credentials, which is exactly the move that keeps agents out of cardholder-data scope. The same logic applies inside the building. Card-adjacent data leaks into prompts constantly, from support macros to finance exports pasted into a copilot. Inline redaction is the control that fits: AccuroAI's gateway runs 40+ data classifiers and 60+ secret detectors across 14M+ prompts a day at under 38ms p99, stripping card-adjacent fields before a prompt leaves your perimeter, so the AI tool never enters the scope argument at all.
The AI you didn't buy is already processing customer data
Per eMarketer, 85% of retailers have implemented generative AI in customer service and 83% in marketing and promotions. Those are the deployments somebody approved. The harder problem is the AI nobody procured: features switched on inside loyalty platforms and marketing clouds you already licensed. The vendor flips a flag, your data processing changes, and your procurement records don't. Your data-processing agreements were negotiated before the feature existed.
California has been here before; Sephora's $1.2M settlement was about exactly this class of quiet third-party data flow. Now layer on the CPPA's automated decisionmaking technology rules, in force since January 1, 2026, with compliance for "significant decisions" due by January 1, 2027: pre-use notices, at least two opt-out methods, formal risk assessments. Personalization engines that set pricing and offers sit uncomfortably close to that definition, and the stakes are not small, Target's COO has told analysts its personalization engine generates billions in incremental sales, inside a $2B investment plan. The Rite Aid order shows the other regulator on this beat: the FTC needed no AI-specific statute to ban a retailer's facial recognition for five years.
Governing any of this starts with seeing it, at the browser and endpoint where the usage actually happens. Our guide to endpoint AI security covers the mechanics; workforce AI governance is the product answer, with a 1,400+ tool catalog that treats embedded vendor AI features as a first-class case rather than a footnote.
Where to start
- Inventory authority, not just tools. For every customer-facing agent, write down what it can promise: prices, refunds, codes, policy statements. Air Canada says you own all of it.
- Move limits server-side. A system prompt saying "never offer discounts" is a suggestion. A checkout service that rejects unauthorized codes is a control. Watsonville and the 80% case were both prompt-side failures.
- Write your agentic-commerce posture down. Decide whether verified shopping agents are customers or intruders, and what verification means, before holiday traffic decides for you. The Ninth Circuit just guaranteed the courts won't settle it soon.
- Run the PCI scope exercise on every AI touchpoint before your QSA runs it for you.
- Start the ADMT clock now. January 2027 is close for risk assessments on personalization and pricing engines.
The vertical-specific reference architecture, mapped to these controls, lives on our retail industry page.
Questions that come up in every retail review
Are we legally bound by what our chatbot tells customers?
In Canada, yes: Moffatt v. Air Canada held the company liable for a policy its bot invented. No US court has issued an equivalent ruling yet. The safe planning assumption is that a customer-facing bot's statements are your statements, both because that is how the first tribunal to consider it ruled and because the FTC has already run an enforcement sweep, Operation AI Comply, against companies whose AI claims misled consumers.
Does PCI DSS 4.0 require anything specific for AI?
No. There is no AI-named requirement in the standard. The exposure is scope: an AI component that can touch or influence the cardholder data environment pulls existing requirements onto itself. Tokenized designs like ACP's shared payment tokens exist to keep agents outside that boundary, and redaction keeps internal AI use outside it too.
Should we just block AI shopping agents?
Blocking everything automated means turning away traffic Adobe measured converting 31% better than average, while the legal right to block is itself in flux in Amazon v. Perplexity. The defensible middle is differentiation: verified agent identity with scoped, monitored access, plus abuse controls on the business-logic surfaces where Imperva says the attacks concentrate.
What does shadow AI look like in retail specifically?
Less standalone chatbot use, more AI quietly embedded in tools you already own. A loyalty platform or marketing suite adds an AI feature, customer data starts flowing through a model pipeline, and nothing new ever appears in the expense report for procurement to catch. Discovery has to happen where the usage does, not where the contracts do.