Consumer protection law has grown in prominence with the introduction of the UK’s Digital Markets, Competition and Consumers Act 2024 (DMCCA), as well as a raft of regulatory action from the Competition and Markets Authority (CMA), the UK’s consumer regulator. Coupled with increased adoption of AI tools and emerging use of agentic AI systems, many businesses are now asking how agentic AI can be deployed in a way which satisfies the UK’s consumer protection rules.
In March 2026, the CMA released a research paper on Agentic AI and consumers, as well as a guide for businesses deploying agentic AI. Notably, these CMA papers do not provide a set definition of agentic AI - but we’ve covered the current state of play in a previous article in this series.
Benefits and risks of agentic AI
Currently AI agents are used in a fairly limited capacity, for example having a chatbot deal with customer queries and issuing refunds. However, the ultimate goal of agentic technology is increasing – and perhaps even in some instances total – autonomy, with agentic tools capable of building, learning and adapting to each consumer’s preferences at an individual scale.
AI agents have the potential to reshape the entire commercial landscape, changing how businesses and consumers engage with each other. In particular, a consumer could save a significant amount of time by delegating tasks to a sophisticated AI agent. Take for example a car insurance renewal - rather than manually searching countless websites for the best price and coverage, a consumer could instruct an AI agent to continuously monitor all insurers’ websites and, where it identifies a better price, automatically swap the consumer to the new policy.
However, increased use of and reliance on AI Agents comes with a real risk to consumers as well. A straightforward example is an AI agent that errs or acts outside of its instructions – ranging from overspending to making unauthorised financial decisions or investments on behalf of the user. The Mills Review published by the Financial Conduct Authority specifically called out autonomy in AI tools as a real risk for retail financial services, flagging the difficulty consumers may have in unwinding decisions an agent has taken without human checkpoints.
There are also greater data protection, privacy and security risks where consumers share more information with agents and delegate more responsibility to them. This loss of control could lead to over-reliance by consumers, with reduced oversight meaning errors and variance go unnoticed until it is too late.
Alongside these risks is increased scope for agents to collude, engage in a cartel, or take part in other anti-competitive practices. This is a whole topic in itself that we will address later in this series.
Businesses will need to consider how AI agents could be used to ensure that they do not compromise compliance with consumer law.
What should businesses be doing now?
Consumer protection laws are technology agnostic and apply equally to AI as to other technologies used by businesses. If you are thinking about using or currently making use of consumer-facing AI (including agentic AI) you should:
Get up to speed with consumer protection law: ensure business, product and customer-facing teams understand consumers’ rights. Build consumer protection into the design process e.g. by ensuring an AI agent correctly implements statutory refund rights. Most importantly, ensure consumers are being treated fairly.
Understand how AI agents are being used: map the use case properly. Will the AI agent(s) be interacting directly with consumers, with other AI agents, within or outside your infrastructure? Build in mitigations to address potential risks identified during the mapping process.
Undertake testing: test agentic AI systems against real-world scenarios, identify potential gaps and take steps to fix them.
Continue reviewing: revisit how agentic AI is being used by your business. Has the use case evolved? Factor in processes to identify and correct errors and ensure humans remain in the loop to review decisions made by AI agents where necessary.
Manage any third party suppliers: ultimately, compliance with consumer protection laws remains the responsibility of the business deploying agentic AI. Where you are deploying AI developed by a third party, you are responsible for how it interacts with consumers in your environment. Communicate with your suppliers about required updates to ensure your agentic AI continues to perform correctly and in compliance with consumer protection laws.
Is an AI agent actually an “agent”?
A key question at the moment is whether AI agents are “agents” in a legal sense, noting that such tools do not have a separate legal personality. There is a question of whether an “agency agreement” of sorts exists between the AI agent (or the developing company) and the consumer.
While an interesting legal discussion, the CMA does not engage with this in its guidance, nor does it suggest any concerns around the validity of a contract formed by an AI agent (i.e. where the agent makes a purchase on a consumer’s behalf).
As set out above, its concerns focus on the practical impact of the AI agent doing something wrong rather than whether the AI agent can do it in the first place. This is obviously just one regulator’s view, so it remains to be seen whether the concept of legal agency raises issues elsewhere.
What’s next?
Transparency and fairness have always been cornerstones of consumer protection laws in the UK and further afield. Because of this, there is increasing regulatory focus on manipulative design practices, as well as ensuring that information is presented to consumers in a way that is clear.
In the UK, changes to subscription contracts under the DMCCA are expected to come into force in Spring 2027. With the enhanced rules around the corner, businesses should focus on ensuring that AI agents can handle consumer queries, provide clear pre-contractual information and, depending on how they are deployed, follow up with subscription contract confirmations and renewal reminder notices.
In the EU, there is a legislative proposal for a new Digital Fairness Act, aimed at tackling dark patterns and addictive design choices. We expect to have more information about the proposals and what they mean for the design of AI agents interacting with consumers, towards the end of this year.
It is not necessarily a given that the market as a whole will adopt AI agents. Some companies are already resisting AI agents operating on their websites. Take for example Amazon, whose preliminary injunction against Perplexity's Comet tool was paused by the Ninth Court in March 2026, meaning Comet can continue to operate on Amazon as the trial continues. This decision is part of Amazon’s argument that the tool breached its terms of use by finding items and making purchases on consumers' behalf. Depending on how the appeal is resolved, agentic commerce may hit a stumbling block if AI agents cannot be used on key e-commerce platforms like Amazon.

/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2025-09-29-13-48-10-128-68da8e1af6347a2c4b96de4e.png)
/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2024-08-01-13-11-10-549-66ab896ee543bf94f9636c73.png)
/Passle/5f3d6e345354880e28b1fb63/SearchServiceImages/2026-07-20-09-37-57-766-6a5dec75ad21f102480902ca.jpg)
/Passle/5f3d6e345354880e28b1fb63/SearchServiceImages/2026-07-20-10-26-55-193-6a5df7efad21f10248092a3d.jpg)