Alejandro Villar Pineda, managing director FICO Iberia

For decades, fraud detection in financial services has been based on a relatively stable premise: a person initiates a transaction and that person’s behavior can be observed, modeled and, if necessary, verified. Human beings are predictable and behavioral signals are often a clear indicator of the risk of fraud by machines. Predictive Artificial Intelligence built on this premise has become the backbone of the sector: it has made it possible to analyze transactions in real time and recognize large-scale patterns, with machine learning models capable of processing thousands of transactions per second to detect anomalies before they become losses.

However, we now find ourselves facing an unprecedented situation: non-human entities now have the capacity to make payments. The vision of the world and the technological base on which we have relied for the last 30 years must face a scenario for which they were never designed: interpreting an environment in which the person behind a transaction is not a person.

It may seem complex on paper, but the reality is very simple: we are talking about refrigerators that automatically make purchases, cars that pay for parking or tolls, or agents who look for the best offers for Christmas gifts.

This is a profound change, not only in the technology that supports the payments ecosystem, but also in the entire consumer purchasing experience. Although these operations initially focus on small-value transactions, the market forecasts are very significant: it is estimated that autonomous commerce based on AI agents will reach a transaction volume of 1.7 trillion dollars in 2030, at which time there could be more agents making payments than people.

For those responsible for fraud prevention, this raises an issue that goes far beyond risk management. Traditionally, the key question has always been: “Who is this customer?” Increasingly, the question will become: “Which agent is acting, under whose authority, and with what intention?”

Answering that question will require fraud prevention to evolve, incorporating autonomous capabilities capable of addressing an equally autonomous ecosystem of payments and technologies. It will not be enough to do faster what banks already do today; a structurally different discipline will be necessary.

A radically different transaction flow

The shift from human-initiated payments to agent-initiated payments completely changes the anatomy of a transaction. In the traditional model, a person identifies a need, authorizes the purchase, the bank processes the operation and confirms the payment directly with them.

In an autonomous environment, on the other hand, the person previously defines their intention, grants authorization based on that intention and establishes limits of action. From that moment on, it is the agent who identifies the need, initiates the payment and only informs the user after the bank has authenticated the agent and processed the transaction.

The sequence becomes simultaneously more complex and faster from the bank’s point of view: there are fewer behavioral signals, biometric variations disappear and the user is practically left out of the real-time process. Therein lies the real problem for anti-fraud teams.

Currently, much of automated attack detection relies on a very simple heuristic: a human cannot initiate hundreds of payments in a matter of seconds, so a burst of high-speed transactions is considered suspicious by default. But the agents completely eliminate that reference. If an authorized agent can legitimately perform transactions at machine speed on behalf of a consumer, speed is no longer a reliable indicator of fraud.

Looking for new suspicious signs

The suite of authentication tools that banks have perfected for years is built almost exclusively on human signals, but many of these tools become useless once an agent interacts with a bank exclusively through an API. Added to this is an additional challenge: although agents act autonomously, they still require the intention, authority and permissions granted by a person. However, “intent” as an indicator of fraud does not yet have a standardized data representation.

Anti-fraud teams are thus faced with an unprecedented question: how to measure a deviation from the authorized intention when that intention must be inferred from the agent’s configuration and the original instructions of its owner, rather than directly observed in its behavior?

How much does AI make us lose?

Fraud officials wondering how seriously they should take this change need not hypothesize about the destructive potential of generative AI in the hands of cybercriminals. Generative AI already has a significant history of participating in frauds of great economic impact, and the evolution of these cases is especially revealing.

A paradigmatic example was the appearance of WormGPT in 2023: an AI tool designed specifically for malicious uses and marketed on dark web forums. WormGPT was found to increase the speed with which adaptive phishing campaigns and other fraudulent operations could be carried out approximately tenfold.

This is probably the clearest example that generative AI not only changes the way a specific attack is carried out, but also transforms the operational capacity of criminal organizations, allowing them to launch much faster, more numerous and effective campaigns.

But now questions are also being raised: When an agent commits fraud, it is still unclear who should take responsibility. Do you own the agent? The developer who created it? Or the bank that authenticated the agent and processed the transaction?

The legal and regulatory frameworks have not yet resolved this issue and, as long as this remains the case, financial institutions will be exposed to a degree of uncertainty for which traditional fraud liability models were never designed.

The European Union AI Law, which came into force in 2024, classifies systems according to their level of risk and imposes transparency obligations for applications considered high risk. It is very likely that this regulation will end up applying to many autonomous payment systems when regulators formally classify them within these categories.

PSD3, for its part, establishes requirements related to Strong Customer Authentication and contemplates a wide range of types of payments and transactions. However, its approach continues to be based on a basic assumption: that the person who initiates the purchase is a person. Still, there is room for PSD3 to evolve and incorporate specific requirements for autonomous commerce, especially given that its full implementation is not expected until 2027 at the earliest.

However, beyond these regulations, there are a series of governance challenges that will especially affect those responsible for fraud prevention, such as transaction monitoring rules or traceability requirements. In addition, regulatory demands are beginning to emerge related to the explainability of decisions made by AI systems regarding fraud. This means that providers of autonomous payment solutions will need to be able to not only justify the decision made, but also explain in a verifiable way how an agent, or the anti-fraud system that evaluated it, reached that conclusion.

Fraud prevention must also become an agent-based system

The most important strategic implication of all of the above is that fraud prevention itself needs to adopt the same architecture and leverage the same capabilities as the threat it seeks to address.

An effective model must retain the core predictive AI that has underpinned fraud detection for decades. Pattern identification, anomaly detection, and real-time risk assessment will remain critical and will not go away.

Building on that, generative AI capabilities can be incorporated specifically aimed at increasing the speed with which anti-fraud teams respond to new attack vectors, analyzing emerging trends and facilitating the deployment of countermeasures much faster than a purely manual analysis would allow.

Agents powered by generative AI can also be used on the defensive side to expand the operational capacity of fraud teams, increasing the number of cases that can actually be investigated and managed.

In short, it is essential to adapt to what is coming. Industry analysis indicates that banks that begin to develop these capabilities today will enjoy a real competitive advantage of three to five years, as mass adoption of autonomous payments is expected to occur between approximately 2027 and 2030. This will be when new fraud patterns appear on a large scale and regulatory frameworks have reached a much greater degree of maturity. And the entities that come forward will have the opportunity to define the standards, the authentication models and, to a large extent, the jurisprudence that will end up regulating this new ecosystem.

Alejandro Villar Pineda, managing director FICO Iberia