Your Fraud Model Was Built for Humans. AI Agents Break It at Machine Speed
SEO title: AI Fraud Detection for Agentic Payments Meta description: AI agents are breaking human-calibrated fraud models. Learn why agent-aware scoring is becoming essential to protect payment success rates. Suggested slug: ai-fraud-detection-agentic-payments-risk-model-recalibration Primary keyword: AI fraud detection payments Secondary keywords: agentic payments, AI payments, AI payment routing, payment success rate, payment orchestration, agent probability score, fraud model recalibration
A fraud model trained on human behaviour cannot reliably interpret a payment initiated by software. Legitimate agents may trigger bot-like signals through high-frequency catalogue calls and machine-speed retries, while compromised agents can imitate authorised traffic with remarkable precision. The result is a new scoring problem: merchants must identify the agent, understand its mandate and assess its behaviour without confusing automation with fraud.
What is the short answer?
Agentic payments require a separate risk-scoring layer alongside existing fraud controls.
Traditional models look for patterns such as typing cadence, device switching, browsing paths, session length, IP reputation and human-scale transaction timing. AI agents remove many of those signals. They may browse without a human session, compare hundreds of products quickly, make repeated API calls and retry payments in milliseconds.
That creates two opposing risks:
Federal Reserve Governor Christopher J. Waller identified fraud as one of three concrete barriers to scaling agent-delegated commerce, alongside authentication and liability. In his 29 September 2026 Sibos speech, Waller stated that existing fraud systems are “calibrated to human behavior” and “may not translate well to agents”. His conclusion is direct: fraud models and rules will need to be recalibrated for agent payment patterns.
Mastercard’s 30 September announcement shows what that recalibration is beginning to look like. Its Agent Pay programme now includes a probability score indicating the likelihood that a transaction was initiated by an AI agent, plus agentic trust and intelligence signals covering identity, intent, behaviour and fraud. The score is currently being tested in the United States.

Legitimate agent traffic can be fast, consistent and highly automated, exactly the characteristics that older fraud rules often penalise.
Why does legitimate agent traffic look like fraud?
Most production fraud systems were designed around an implicit assumption: a person is interacting with a merchant.
That person usually takes a measurable amount of time to navigate a site, enters information through a browser, uses a limited number of devices and follows a recognisable path from discovery to checkout. Even when models use sophisticated machine learning, they are often trained on behavioural data generated by human customers.
An agent breaks those assumptions in several ways.
First, it can call product catalogues and pricing APIs at high frequency. Second, it can compare merchants without spending time on conventional browsing pages. Third, it may use a consistent machine identity rather than the shifting device and network signals associated with a human household. Fourth, it can attempt several payment routes in rapid succession.
These patterns may be perfectly legitimate. An enterprise procurement agent could be checking approved suppliers against a budget. A travel agent could be comparing inventory across multiple providers. A personal shopping agent could be acting inside clearly defined spending and category limits.
The same signals can also indicate attack activity. A compromised agent may use its existing permissions to place orders, change delivery details or test payment credentials at a speed no human operator could sustain.
This is why “bot detection” is no longer a sufficient category. A merchant does not simply need to know whether activity is automated. It needs to know whether the automation is authorised, within scope and behaving as expected.
What is an agent probability score?
An agent probability score is a risk signal estimating the likelihood that a transaction was initiated by an AI agent. It is not the same as a fraud score and it does not mean that an agent transaction is suspicious.
That distinction matters. A high agent probability score should not automatically produce a decline. It should change how the transaction is interpreted.
For example, a high agent score combined with a registered agent identity, valid delegated permissions, an expected merchant category and normal spend limits may support approval. The same agent score combined with a new beneficiary, an unusual delivery location or behaviour outside the declared mandate may justify step-up authentication, manual review or a decline.
Mastercard describes its new signals as part of the intelligence layer of the Agent Pay Trust Framework. The practical direction is clear: networks and payment providers are beginning to give merchants a way to separate “this was likely initiated by an agent” from “this looks like fraud”.
That enables a more useful decision tree:
The distinction between identity and behaviour is important. At Sibos 2026, Johan Gerber of Mastercard said trust must transfer across the full transaction lifecycle and that the starting question is whether there is a real consumer behind the activity: “not even do I have a real agent”. This places account integrity and principal verification ahead of simply labelling traffic as machine-generated.
Does agent-aware scoring replace existing fraud rules?
No. Agent-aware scoring should operate as an additional decision layer, not as a replacement for existing fraud models, velocity controls, authentication rules or transaction monitoring.
The established controls still matter. Card testing, account takeover, stolen credentials, merchant abuse and sanctions risk do not disappear because an agent is involved. In fact, agents may increase attack velocity and make the consequences of a compromised credential more severe.
The change is that existing controls need context. A machine-speed retry may be normal for one registered procurement agent and highly suspicious for an unknown browser automation tool. A stable IP address may be reassuring in one flow and meaningless when a cloud-based agent operates across multiple regions.
Greg Williamson of Nasdaq noted at Sibos that attack velocity is likely to increase, but also argued that agents can be more predictable than humans because their policies and guardrails make deviation easier to detect. That is the strategic opportunity. A well-governed agent can create a clearer baseline than an individual shopper. A merchant can monitor what the agent was expected to do and identify when it moves away from that pattern.
The risk model therefore needs to compare observed behaviour with agent policy, not only with historical human behaviour.
How can merchants protect payment success rate while approving agents?
The answer is not to create a blanket “agent-friendly” bypass. It is to score the agent in context across checkout, risk, routing and post-transaction operations.
That means linking the risk decision to payment orchestration. If a transaction is legitimate but a particular route is generating unnecessary friction, the merchant should be able to select another available payment path or authentication method. If the payment is approved, the same context should remain visible through refunds, reconciliation and business intelligence.
Consumer demand is likely to develop unevenly. PYMNTS Intelligence reports that 56% of consumers would allow AI shopping agents to compare products, but only 35% would allow them to access saved payment methods. The Visa Acceptance 2026 Global Digital Shopping Index also reports that 21% of consumers are likely to abandon a purchase if their preferred payment method or control requirements are not met.
The message is not simply “approve more agents”. It is “make the control model legible and proportionate”. Consumers and businesses need confidence that an agent can act quickly without becoming an invisible source of loss.
Quantum Payments’ role in that architecture is to connect checkout, risk, routing, refunds, reconciliation and business intelligence in one unified commerce environment. Its modular platform supports payment orchestration, omnichannel operations and automation from checkout through reconciliation. That gives merchants the context to treat agent transactions as distinct patterns rather than one undifferentiated channel.

An agent probability score is most useful when combined with identity, intent, behaviour and fraud signals across the payment lifecycle.
Merchant checklist: making risk scoring agent-aware
What does the Federal Reserve say will have to change?
Waller’s position is that agentic commerce will need new trust mechanisms because agents alter payment frequency, timing and transaction characteristics. He distinguishes between agent-assisted commerce, where a person remains in control, and agent-delegated commerce, where an agent acts autonomously within guardrails.
The difference has direct risk implications. Assisted commerce may preserve many existing authentication patterns. Delegated commerce requires systems to establish that an agent has authority to act and that the resulting payment is consistent with that authority.
Waller also notes that agents may need to make micropayments for LLM queries, price feeds and API calls. B2B commerce may be particularly suitable for agents because purchases often follow recurring rules, approved suppliers and budget limits. However, higher-value B2B transactions amplify exposure when an agent makes an error or acts without authorisation.
The industry discussion at Sibos adds another operational warning. Stephany Kirkpatrick of EY said human review fatigue naturally develops when people process large queues of information. At machine speed, manual review cannot be the primary control. It should be reserved for cases where the available signals genuinely indicate uncertainty or elevated risk.
Frequently asked questions
Why does AI agent traffic look like fraud?
AI agent traffic is fast, consistent and highly automated. It may lack human browsing signals, make frequent catalogue calls, retry payments quickly and operate across merchants or channels. Those patterns can resemble bots, credential testing or account takeover even when the agent is authorised.
What is an agent probability score?
An agent probability score estimates the likelihood that a transaction was initiated by an AI agent. It is an agent-origin signal, not a conclusion that the transaction is fraudulent. Merchants should combine it with identity, intent, authority, behaviour and transaction risk.
Does agent-aware scoring replace existing fraud rules?
No. It adds context to existing fraud controls. Traditional rules remain necessary for stolen credentials, account takeover, card testing and other threats. Agent-aware scoring helps those controls distinguish legitimate machine behaviour from malicious automation.
How can merchants approve legitimate agents without damaging payment success rate?
Merchants should register agent identities, record delegated authority, define expected behaviour and monitor deviations from policy. They should also connect scoring to payment orchestration so authentication and routing can be proportionate rather than automatically blocking all automated traffic.
What does the Federal Reserve say must change?
Federal Reserve Governor Christopher J. Waller says fraud models and rules calibrated to human behaviour may not translate well to agents. He argues that systems must be recalibrated for agent payment patterns as agent-assisted and agent-delegated commerce expand.
Strategic read: the score is becoming a new layer of payment infrastructure
The strategic shift is not that fraud teams need to “spot AI”. It is that payment decisions must understand who or what initiated a transaction, what authority it carries and whether its behaviour remains inside an expected operating envelope.
Merchants face two failure modes. Decline legitimate agents and they damage payment success rate on a channel that is likely to grow. Approve agents blindly and they create a loss, evidence and customer-trust problem at machine speed.
The emerging answer is a layered model: agent identity, principal identity, declared intent, delegated authority, behavioural deviation and conventional fraud risk. Mastercard’s agent probability score is an early commercial signal that this architecture is moving from conference discussion into payment operations.
For merchants, the winning capability will not be a single new score. It will be the ability to interpret that score alongside checkout context, payment orchestration, refunds, reconciliation and business intelligence. Quantum Payments is built around that unified commerce view, with a flexible modular platform and an AI insights layer that helps connect operational signals across the business.
Human-calibrated fraud models are not obsolete. They are incomplete. In agentic payments, the central risk question changes from “does this look like a person?” to “does this machine act like the authority it claims to represent?”
Authoritative sources
.png)