Agentic Commerce Fraud

What is agentic commerce fraud?

Agentic commerce fraud is unauthorized, deceptive, or manipulative activity in commerce environments where AI agents are allowed to act on behalf of a user or business. It can target the user, the agent, the merchant, the payment credential, or the delegation model that allows the agent to transact.  

Why does agentic commerce create new fraud risks?

Agentic commerce changes the fraud model because the user is not always present when a transaction is executed. In delegated commerce environments, an AI agent may search for products, compare options, assemble a checkout, and in some cases initiate or complete payment under rules defined in advance by the user.

As payment networks, merchants, and technology providers build infrastructure for this model, fraud risk shifts from a purely human-driven checkout journey to one that must also account for delegated authority, machine-executed actions, and cryptographic proof of user intent.

The concept is still emerging, but the underlying risk is already becoming clear. As AI agents begin acting on behalf of customers, every party in a transaction needs to be able to verify who authorised the action, what the agent was permitted to do, and whether the final transaction remained within those parameters. Without those assurances, fraud could occur through impersonation, mandate abuse, credential misuse, merchant deception, or manipulation of the agent itself — risks that are already prompting discussion around how fraudsters could target AI mandates as agentic commerce develops.

How does agentic commerce occur?

Agentic commerce fraud occurs when trust in the delegation chain between the user, the agent, the merchant, and the payment ecosystem is compromised. Since agentic commerce introduces a wider trust surface than conventional digital commerce, several new vulnerabilities have emerged, heightening the risk of fraud.

Key vulnerabilities include:

  • Delegated authority risk: the user is not always present when the transaction is executed.

  • Identity ambiguity: merchants and payment providers must distinguish a trusted agent from a malicious bot or impersonator.

  • Instruction drift: the final transaction may differ from the user’s original intent if constraints are weak or poorly enforced.

  • Complex ecosystem coordination: security depends on consistent verification across agents, merchants, credential providers, processors, and networks.

  • Privacy and data exposure: agent ecosystems may handle identity, device, payment, and behavioral data that require strict minimization and protection.

  • Expanded attack surface: attackers can target the user, the agent, the merchant, the integration layer, or the payment credential itself.

The implications of agentic commerce fraud

The significance of agentic commerce fraud extends beyond unauthorized purchases. If trust fails in this model, the result may include fraud losses, disputes, higher friction, false declines, merchant reluctance, regulatory scrutiny, and reduced consumer confidence in autonomous commerce. The challenge is therefore strategic as well as operational: the ecosystem must preserve the efficiency benefits of agent-led transactions without weakening accountability or user control.

  • For financial institutions and payment providers, this means combining secure authentication, tokenized credentials, verifiable authorization, transaction controls, and real-time fraud intelligence.

  • For merchants, it means recognizing trusted agents while resisting impersonation and marketplace deception.

  • For users, it means maintaining clear control over what an agent may do, when it may act, and how exceptions are handled.

As AI agents move from assistance to execution, fraud prevention must move from simple checkout authentication to a broader trust architecture that verifies identity, preserves intent, constrains agent behavior, and produces clear evidence for every transaction.

The future of agent-led commerce will depend not only on convenience, but on whether the ecosystem can make autonomous transactions secure, accountable, and demonstrably aligned with the user’s original instruction.

How to prevent agentic commerce fraud

Preventing agentic commerce fraud depends on strong proof of identity, explicit delegation, and transaction-level controls.

  • Passkeys and user authentication: Passkeys are emerging as an important mechanism for authenticating the user when payment authority is first granted or when a higher-risk instruction requires step-up confirmation. In this model, the goal is not only to verify the user’s identity, but also to bind the user’s approval to a secure device and a specific action. This reflects the broader evolution of authentication and the need for financial institutions to rethink how they balance security, customer experience and emerging authentication technologies.

  • Tokenization: Tokenization reduces risk by replacing underlying payment credentials with restricted tokens that can be limited to a given agent, merchant, amount, or use case. This limits the value of stolen credentials and helps prevent misuse outside the approved transaction context.

  • Delegated authorization and mandates: A core control in agentic commerce is the use of structured, cryptographically verifiable mandates or instructions that express what the user has approved. These may define constraints such as merchant, amount, product type, payment method, timing, or recurrence. When implemented correctly, they provide verifiable evidence that the agent acted within the user’s authorization.

  • Trusted agent verification: Merchants and payment providers increasingly require a way to determine whether an agent is recognized, approved, and acting for a legitimate user. This may include signed requests, time-bound credentials, nonce-based replay protections, and public-key verification models.

  • Commerce signals and risk scoring: Transaction context remains essential. Agent identity, device information, merchant integrity, transaction amount, instruction history, and behavioral anomalies can all support risk-based authentication and fraud decisioning. In agentic commerce, effective risk scoring must evaluate both the transaction itself and whether the agent’s behavior is consistent with the user’s authenticated instruction.

Emerging standards and frameworks

Several industry efforts are beginning to define how trust should operate in agent-led payments.

  • Agent Payments Protocol (AP2): AP2 is an emerging open protocol designed to secure agent-performed payment transactions. It introduces structured mandates to represent what is being purchased and how it is being paid for, and it is intended to support both human-present and autonomous transaction models. Its importance lies in creating a common method for expressing delegated authority and preserving evidence for verification and dispute handling.

  • Verifiable intent: Verifiable Intent is a standards-based trust model designed to create tamper-resistant proof of what a user authorized when an agent acts on their behalf. Its role is to make user intent explicit, portable, and verifiable across merchants, payment providers, and networks.

  • Trusted agent verification models: Emerging merchant-facing frameworks are also focused on verifying whether an automated commerce interaction originates from an approved agent rather than a malicious bot. These models are intended to help merchants recognize trusted agent activity without weakening existing fraud controls.

The future of agentic commerce fraud prevention

As agentic commerce develops, fraud prevention will need to evolve alongside the technology. Traditional payment security controls remain important, but they will need to work alongside mechanisms that establish who authorized an action, what an agent was permitted to do, and whether the transaction remained within those boundaries.

The strongest security models will therefore combine user authentication, delegated authorization, tokenized payment credentials, agent verification, transaction controls, and real-time risk assessment. Together, these controls can help preserve user intent and accountability even when transactions are initiated and completed without direct human involvement.

For banks, payment providers, merchants, and technology platforms, the challenge will be to establish trust across the entire agentic commerce ecosystem. As AI agents take on greater responsibility for purchasing and payment decisions, verifiable identity, authorization and intent will become increasingly important foundations for secure digital commerce.

The video below details how agentic commerce fraud works, where the risks emerge, and what organizations can do to strengthen trust and reduce exposure.

Video - Agentic Commerce Fraud

 

Related articles

If you’d like to explore the building blocks behind secure agent-led commerce in more detail, these resources offer useful additional context:

Together, these articles help frame how authentication, delegation, tokenization, and fraud controls can support safer digital commerce as agentic transaction models evolve.


Keep exploring

A
All insights

Find the right path forward

Explore the solutions most relevant to your organization

Solutions by outcome

Explore the outcomes that matter most, from fraud reduction to lower friction.

Solutions by use case

Find the right path for the challenges you need to solve across channels and journeys.

Solutions by industry

See how Entersekt supports banks, credit unions, and other financial institutions.

We don't just protect - we revolutionize

See how Entersekt helps financial institutions move forward