AI is no longer emerging. It is embedded in threat actor toolkits, in regulatory agendas, and now in frontline retail systems.
This month, we look at how AI is reshaping cyber security in practice. From autonomous attacks and adaptive malware, to regulatory pressure on high-risk AI systems, to the real-world risks of integrating agentic AI with payments and customer data. The common thread is simple: AI is no longer a future risk. It is a present responsibility.
Retailers are beginning to deploy agentic AI platforms that integrate directly with payment processors to deliver seamless, automated sales journeys.
The Ashley Furniture, Perplexity AI and PayPal model is a live example of what many in the industry are calling the future of retail. Customers interact with an AI agent that answers questions, recommends products and processes payments.
But beneath the convenience lies a growing set of cyber security and data protection risks that must be addressed before deployment, not after.
Cyber Security Risks
Agentic AI systems are autonomous, goal-driven agents that can take real-time action across multiple systems. This changes the nature of risk.
The most critical issues include:
• Prompt injection attacks where the AI is manipulated into revealing restricted information, issuing unauthorised discounts or bypassing controls
• Session hijacking or token theft, particularly if the AI operates with persistent or overly broad permissions
• Poorly governed APIs between the AI platform, payment processor and internal systems, introducing vulnerable integration points
• Automated transactions or actions made without real-time human oversight, which may escalate without detection
• Expanded attack surface due to dependencies on third-party platforms and services that are often outside the organisation's direct control
Data Protection and Regulatory Exposure
These platforms are also active processors of personal data. Once integrated with payments, the AI becomes part of the data lifecycle for customer identities, preferences, behaviours and financial transactions.
Key risks include:
• Lack of transparency around what data is collected, how it is processed and by whom
• Automated decisions affecting pricing, eligibility or refunds, potentially triggering UK GDPR Article 22 obligations
• Unclear data flows between systems, raising risks around data minimisation and purpose limitation
• Potentially unclear whether the personal data is stored in the UK, EU or EEA
• Inability to fulfil data subject rights if records are not logged or traceable
• Over-collection or long-term retention of personal data without a lawful basis
Business and Reputational Impact
Security and privacy failures in AI-driven retail environments will not be seen as technical errors. They will be seen as leadership failures.
Retailers face:
• Loss of customer trust if AI agents make inappropriate recommendations, expose data or process incorrect transactions
• Legal liability for unauthorised processing, profiling or decision-making
• Reputational harm if the AI behaves in biased, unsafe or inconsistent ways
• Contractual exposure if third-party providers are not secure, resilient or accountable
• Board-level scrutiny as AI becomes more embedded in regulated processes and commercial outcomes
Practical Actions for Retail Leaders
Security and compliance must be built in from day one. The following actions are essential:
• A business case detailing the opportunity, clear goals, evaluated options, detailed costs and benefits, risk analysis with mitigations, strategic alignment and delivery plan
• A proper use case documenting how the customer interacts with the AI agent and the desired outcomes
• Conduct threat modelling and a Data Protection Impact Assessment for all agentic AI use cases
• Define clear boundaries for what the AI can do, and ensure all high-risk actions include human oversight
• Apply least privilege principles to all API access between AI systems, payment providers and back-end platforms
• Implement detailed logging and audit trails for all AI-initiated actions, particularly financial transactions
• Ensure vendor contracts address liability, transparency and security responsibilities
• Monitor emerging regulatory guidance from the UK, EU and international bodies
Final Thought
Agentic AI in retail is not a concept. It is already live, connected to real customer data, real systems and real money.
If your AI can act, then your organisation is responsible for the consequences.
Security and data protection must be integrated into the technology, governance and culture from the start. Not layered on after the headlines.
Innovation without control is not leadership. It is exposure.
AI is no longer a future concern. It is a present-day threat and a critical defensive asset.
Attackers are using AI to scale, adapt and personalise cyber attacks at a speed most businesses cannot match. Malware is evolving. Phishing is now highly targeted. Identity-based intrusions are being carried out by synthetic identities crafted to bypass verification, onboarding and multi-factor authentication.
This is not about more attacks. It is about more intelligent ones.
The Offensive AI Shift
The biggest shift is autonomy. AI agents are now capable of executing attack chains without human input. From reconnaissance to exploitation, escalation to exfiltration, attackers are using AI to automate everything.
Malware is mutating mid-execution. Phishing campaigns are adapting tone and language in real time. AI bots are probing websites, customer portals and public APIs looking for business logic flaws and social engineering opportunities.
What used to take weeks can now be attempted in minutes.
The State of Defensive AI
Defenders are responding, but there are limitations.
Security teams are using AI for behavioural analysis, anomaly detection and automated incident response. This is helping identify subtle attacks and reduce noise in the security operations centre.
But trust remains an issue. Many AI tools operate as black boxes. Teams cannot always explain how decisions are made. Integration challenges persist. And AI-enhanced security controls often overlap, leading to visibility gaps and alert fatigue in new forms.
However, data quality in the SOC can be greatly improved reducing the quantity of false positives and false negatives.
What Business Leaders Need to Understand
AI is no longer just a technology issue. It is reshaping how attacks work and how security operations must respond.
Boards and executive teams must recognise that AI is changing the nature of cyber risk.
• Incident response plans must now include AI-specific threat scenarios
• Procurement processes must ask vendors to explain their AI models, not just their outputs
• Security strategies must assume autonomous threats, not just human ones
• Cyber insurance coverage may change based on AI-related risk exposure
Where to Focus Now
• Build AI literacy across security, legal and executive teams
• Conduct AI-specific threat modelling and red teaming
• Avoid standalone AI tools that do not integrate with your detection and response workflows
• Treat AI attack simulation and tabletop exercises as part of business continuity planning
AI is accelerating the arms race in cybersecurity. Whether it becomes a business enabler or a liability depends on how prepared you are.

Regulators are no longer observing AI from a distance. They are acting.
In February 2026, the European Union is expected to publish new guidance on high-risk AI systems. This will include clearer obligations on documentation, human oversight and explainability.
The UK is following its own path post- BREXIT, but the direction is the same. More control. More accountability. More pressure to govern AI systems before harm occurs.
What Counts as High-Risk AI
Many businesses assume high-risk AI only applies to government or critical infrastructure. That is no longer the case.
Under the EU AI Act, high-risk systems include those used in:
• Recruitment and employment decision-making
• Financial scoring, fraud detection and lending
• Healthcare diagnostics and treatment support
• Customer profiling that affects access to services or pricing
• Systems that interact with consumers in ways that influence contracts, payments or eligibility
If your AI system makes decisions, processes personal data or influences a customer outcome, it is likely in scope.
Compliance Expectations Are Rising
Organisations deploying high-risk AI systems will be expected to:
• Perform and document risk assessments before deployment
• Maintain logs of automated decision-making outcomes
• Ensure human oversight for impactful or sensitive actions
• Provide meaningful explanations of how decisions are made
• Monitor system performance, fairness and bias continuously
• Restrict access to training data and sensitive model outputs
These obligations apply whether you build the system or buy it as a service.
The Regulatory Environment Is Shifting
This is not just about the EU.
The UK’s AI Regulation Roadmap is moving towards mandatory transparency and accountability. Rather than a single regulation the UK’s evolving framework is a pro-innovation, risk based sector specific approach emphasising transparency, governance, accountability and explainability.
The United States has no federal law equivalent to the EU AI Act and is following an innovation first approach similar to the UK. Individual states and industry sectors are introducing specific rules.
International standards have also evolved rapidly with ISO 42001 Artificial Intelligence Management Systems providing a framework for organisations to develop, provide and use AI systems responsibly. Whilst the US National Institute of Standards & Technology (NIST) Artificial Intelligence Risk Management Framework organizations designing, developing, deploying, or using AI systems to help manage the many risks of AI and promote trustworthy and responsible development and use of AI systems.
Global coordination efforts are increasing, especially around cross-border data use and third-party AI vendors.
Procurement teams, legal counsel and data protection officers must now treat AI platforms as regulated services, not just tools.
What Business Leaders Need to Prioritise
• Map AI usage across business functions and processes to identify high-risk systems
• Assign ownership for AI governance within risk and compliance functions
• Review contracts with AI vendors for liability, explainability and audit access
• Ensure that AI-related risks are included in board reporting and enterprise risk frameworks
AI is now firmly within the scope of regulatory scrutiny. If your organisation uses it to make decisions that affect people, you must be able to justify how it works, who oversees it and what controls are in place.
This is not optional. It is the new baseline.
