Article
Agentic commerce fraud: why traditional detection breaks down and how to respond
How AI agents are reshaping fraud risk, and what businesses can do to stay ahead

As agent-initiated purchases progress from pilots to reality, businesses are faced with a problem: how can we prevent agentic fraud, and who’s liable when it occurs?
This article draws on findings from Adyen's 2026 Fraud Report to explore why traditional fraud detection breaks down when an agent is involved, the specific risks this introduces, and how businesses can respond.
Curious to learn how we can help you prepare for agentic commerce while keeping fraud under control, get in touch.
Why traditional fraud detection wasn't built for agents
Fraud detection has historically relied on two checks:
Is this a real, verified person?
Are they authorised to transact?
Agentic commerce adds two more important questions: Is the agent legitimate? And are they behaving within the bounds of what the customer actually intended?
A single moment of verification can't answer any of these questions on its own. Verification confirms an agent's credentials but says nothing about any possible future action. To understand this, you need a record of behaviour built over time which you can use to spot anomalies.
Most fraud tools were built to answer the first two questions, not the second two. They check credentials at a single moment rather than tracking behaviour across time. Getting ahead of agentic fraud means building that behavioural record into the tool’s core capabilities. Otherwise, it becomes difficult to identify the risks before they cause damage.
Agentic commerce fraud risks
Agentic commerce fraud risks fall into three main areas:
1. Agent-initiated promotion and inventory abuse
Agents can monitor prices and stock around the clock and buy as soon as conditions match their given criteria. This is great for shoppers. But the speed with which these agents operate means that taking advantage of promotions or limited releases can quickly spiral into abuse.
For example, an agent might combine discounts, loyalty credits and payment incentives in ways you never intended a single customer to use together. Or it might acquire limited-inventory stock within seconds of a product launch, making it exceptionally difficult for human shoppers to compete.
Since neither requires stolen credentials, this type of abuse can go unnoticed for some time, causing losses to add up long before you can take action.
2. Mandate and intent mismatch
Just as an agent can push promotions beyond what a business intended, it can also diverge from what the shopper wanted. For example, a shopper might set a mandate to "buy the cheapest flight to Lisbon under £150, departing Friday." An agent optimising purely for price might book a flight with a layover that adds six hours to the journey, or one departing from an airport several hours from the customer's home. It’s meeting the mandate's stated conditions but missed what the customer actually cared about.
3. Liability ambiguity
As agents make more purchases, you’re going to see more transactions that are technically valid but don't match what the customer actually wanted. In those cases, who is liable for the error?
The business that accepted the payment?
The agent developer whose logic caused the mismatch?
The card issuer that authenticated the transaction?
Until liability is better defined your business may be left absorbing that risk without clear rules for what can and can't be disputed.
Building fraud defence for the agent era
To get ahead of agentic commerce fraud you’ll need three core capabilities: fraud systems that understand agent behaviour, a way to verify which agents can be trusted, and authentication built for delegated purchases.
1. Behavioural intelligence built for agents
Fraud systems need to recognise agent-driven interaction patterns specifically. That means training models on how agents behave, capturing warning signals early, and sharing more data across the businesses, networks, issuers, and AI platforms involved in a transaction.
For example, a human shopper tends to browse unevenly. They might pause on pages, compare items, or leave and return to a cart several times. An agent completing the same task might query dozens of product pages in seconds and go straight to checkout with no browsing in between. So you’ll need a system that has the right context so it can analyse this type of behaviour, checking it against previous activity or pre-defined shoppers mandates. Otherwise, you risk blocking legitimate activity, missing malicious activity, or both.
2. Agent identification through data sharing
Telling legitimate agents from bad actors will depend on payment networks, financial institutions, and businesses sharing data, along with identity frameworks or registries as they emerge. For example, an established agent from a well-known platform with a long transaction history behind it presents a different risk profile to a newly deployed agent, even if both are technically authenticated. Without access to historical data, distinguishing between legitimate and risky agents becomes significantly more challenging.
3. Authentication and delegation built for agents
Your business will need to support support agent-based authorisation, including how consent and delegation get captured and verified at the point the mandate is set, not just at the point of payment.
For example, when a customer authorises an agent to "book a hotel in Rome under £200 a night," that mandate itself needs to be captured and verifiable. In that way, if a dispute arises later over whether the agent stayed within its instructions, you’ll have a record of what was authorised at the outset, not just proof that a valid card was charged.
Adyen’s approach to agentic commerce fraud
Adyen's approach to agentic commerce fraud is based on the principle that identity isn't something you verify once and file away. It's an ongoing signal that needs continuous. That's why we introduced Dynamic Identification to Adyen Uplift, the decision engine behind our fraud and conversion tools.
Because our single platform captures cross-business transaction history globally, businesses gain access to extensive pre-existing behavioural signals. This connected view helps identify returning agents earlier, allowing risk teams to calibrate rules that reduce false declines without loosening controls elsewhere. Behavioural thresholds, risk scores, and identification models can be tailored to a business's specific vertical, inventory type, and dispute tolerance, rather than applied as a fixed, one-size-fits-all default.
Alongside this, Adyen Agentic bridges the emerging protocols across AI platforms, offering a flexible layer that adapts as agent standards evolve, rather than requiring a separate integration for each one.
If you'd like to learn more about how we can help you prepare for agentic commerce while keeping fraud under control, get in touch.
Agentic commerce fraud - FAQs
Most fraud tools were built to check credentials at a single point in time, not to track an agent's behaviour over time. They need extending with behavioural intelligence and agent identification, not replacing outright.