Global banks tighten controls on agentic commerce fraud

Banks are tightening onboarding, monitoring and industry data-sharing to counter scams tied to autonomous software agents that transact without direct human control.

Global banks are increasing controls to counter scams tied to agentic commerce, a system in which autonomous software agents can buy goods, book services and initiate payments on behalf of users. Financial institutions report stepped-up measures as the use of these agents grows.

Agentic commerce uses software agents or bots, often driven by generative AI, to act for customers. Banks describe benefits such as faster transactions and automation of routine tasks. They also report that fraudsters can misuse agents to open accounts, run large-scale social engineering, automate credential stuffing and route payments through complex chains to hide fund destinations.

Banks are focusing on three main areas: prevention, detection and coordination. On prevention, lenders are tightening onboarding for accounts that interact with automated agents. Measures include expanded identity checks, clearer capture of customer consent for agent-authorized transactions, contractual provisions for third-party software providers and stricter access controls for application programming interfaces used by agents.

For detection, institutions are deploying behavioral analytics and machine-learning models tuned to spot agent-driven activity, such as rapid repetitive requests from one identity or coordinated actions across accounts. Banks report investment in device and session fingerprinting, anomaly scoring that considers the origin of API calls, and response playbooks that allow temporary suspension of automated flows for human review.

Coordination efforts involve information-sharing arrangements among banks, payment networks and merchant platforms. Several global lenders participate in data-sharing consortia to exchange indicators of compromise and merchant-level risk signals. Banks are also working with card schemes and payment processors to flag suspicious merchant acquirers and refine rules for agent-initiated payment flows.

Regulatory and legal questions are shaping bank strategies. Current consumer-protection and anti-money-laundering frameworks were developed for human-driven transactions. Banks are seeking guidance from regulators on liability when autonomous agents act without explicit human direction and on standards for authentication, consent capture and recordkeeping for agent activity.

Operational changes at the transaction level include stronger authentication for high-risk agent tasks, transaction signing that requires human digital approval for certain payments, and rate limits on automated requests. Some banks are testing forensic tools to trace complex payment chains and identify mule accounts and shell entities used to launder funds tied to agentic scams.

Industry participants point to practical challenges. Agentic commerce can scale fraud at machine speed, shortening the window for human intervention. Cross-border payments complicate investigations when money moves through jurisdictions with different rules on data sharing and enforcement. The rise of merchant fronts that appear legitimate and AI-generated identities makes it harder to distinguish legitimate automation from fraudulent activity.

Background context: digital fraud has moved from manual phishing and single account takeover to more automated threats as bot tools and AI have matured. Banks say they are applying lessons from past waves of automated abuse while developing new policies for autonomous agents.

Banks report that work on controls, contracts and regulatory engagement is ongoing, and that they are prioritizing faster detection, clearer allocation of responsibility for agent actions and broader cooperation across the payments ecosystem.

Articles by this author