Retail Cybersecurity in the Agentic Age: Securing Autonomous Shopping Agents in E-Commerce
Bhargav Trivedi · European Modern Studies Journal · 2025
The retail industry is ushering in a new wave of intelligent automation as agentic artificial intelligence (AI) or systems that can make autonomous decisions and act in multi-step processes begin to influence digital commerce. From personal shopping assistants to automated fulfillment agents, the use of agentic AI is creating experiences for customers to be more seamless and responsive to need. Nevertheless, they come with unique cybersecurity concerns in how they act. Agentic AI systems are much different than traditional rule-based bots, as they are able to make autonomous decisions, interact with sensitive customer information, and operate in vaguer environments, each of which causes the surface area for potential attack to grow. This article explores the unexplored risks and issues of governance emerging from agentic AI activity in retail spaces. It draws on practical and contemporary academic sources, and introduces a layered security framework which applies behavioral checks, validated transactions on a blockchain, and a governance model called Model–Control–Policy (MCP) in advance of agentic AI deployment. The article builds a prototype retail agent and explores several adversarial action types - identity spoofing, data leaks, and prompt attacks - assess these attacks on this prototype agent, and explore both responding to each attack, and reduced exposure with the combined preventative defenses. The article suggests combining approaches reduces exposure to known and new risks significantly. By framing cybersafety as a co-design consideration and not an afterthought, this research offers a trenchant model for retailers to examine the governance challenges of deploying intelligent agents safely and responsibly.