Letting AI agents pay for things on your behalf is opening a new category of fraud risk
The rapid growth of agentic commerce features that let AI assistants autonomously complete purchases on a user's behalf - now supported through dedicated protocols and partnerships between major AI labs and payment networks including Visa, Mastercard and several fintech infrastructure providers - has introduced a genuinely new fraud and authorisation risk category that the payments industry has had to build entirely new controls to address, since the traditional fraud-detection models built around human purchasing-behaviour patterns do not straightforwardly apply when the actual purchasing decision and transaction initiation are executed by an AI agent acting on a user's previously granted, but not transaction-specific, authorisation. The technical solutions that have emerged - cryptographically verifiable agent-authorisation tokens, spending-limit and category-restriction controls that users configure in advance, and real-time transaction-review mechanisms that flag unusual agent-initiated purchases for additional confirmation - represent a meaningfully new layer of payments infrastructure that did not exist even a year earlier, built specifically to answer the question of how a merchant or payment processor can distinguish a legitimate user-authorised AI agent transaction from a fraudulent one initiated by a compromised agent or a malicious actor exploiting an agent's granted permissions. Early fraud-incident data, while still limited given how recently agentic commerce features have scaled to meaningful transaction volume, has already surfaced specific attack patterns - prompt-injection attacks that trick a shopping agent into completing an unauthorised purchase, and social-engineering attempts targeting the agent-authorisation setup process itself - that payment-security researchers are treating as an early preview of a fraud category that will likely grow more sophisticated as agentic commerce transaction volume scales. For India's payments ecosystem, built around the UPI infrastructure that already processes an enormous volume of low-friction digital transactions, agentic-commerce authorisation has required specific adaptation of UPI's existing consent and authentication architecture, and the National Payments Corporation of India has been examining how AI-agent-initiated transactions should be classified and secured within the broader UPI framework as agentic shopping features begin reaching the Indian market. What to watch: whether agentic-commerce fraud rates stabilise at a manageable level as security controls mature, whether any high-profile agentic-payment fraud incident triggers broader consumer or regulatory backlash against the category, and how India's UPI framework formally accommodates AI-agent-initiated transaction authorisation.
Original source: PYMNTS