Agentic payments: when an approved payment hides fraud

Agentic payments: when an approved payment hides fraud

A payment can pass every spending limit and still result from a manipulated decision. According to Vivox AI, that is the central challenge facing firms preparing for AI agents that buy on behalf of customers.

Writing after QUBE Events’ sixth Financial Innovation Forum: Payments & RegTech, Vivox AI pointed to a simple scenario. A customer asks an agent to book a hotel. The agent could choose a convincing fake website and pay a fraudulent merchant with the customer’s authority. In a more extreme case, it could reach the goal through an action nobody intended, such as cancelling another guest’s booking. Either way, the final transaction tells only part of the story.

The panel, “Agentic Payments: The Companion to Agentic Commerce”, was moderated by Zainab Shode, deputy director of financial crime at Bank of London. She was joined by Manish Kumar, former head of payment acceptance products at Starling Bank; Priyanshi Mathur, vice president of product management at Mastercard; Kamran Hedjri, group CEO at PXP; and Ainsley Ward, vice president of payments solutions at CGI.

Consent was the first sticking point. An instruction like “Book a hotel for me” leaves much unresolved for a payment provider, including spending caps, permitted merchants, expiry and the ability to withdraw authority. Vivox AI notes the panel treated consent as a set of specific permissions that can be checked throughout the payment journey, with rules varying across cards, digital wallets and account-to-account transfers.

Identity also grows more complex. Firms must now confirm not only who the customer is, but which agent is acting and whether it is the one authorised. Linking customer, agent and scope of authority matters both at checkout and in any later dispute. Revoking or changing an agent’s limits only works if the change is recognised across the entire journey.

Fraud, meanwhile, may begin well before payment. Speakers highlighted fake hotel sites, fabricated catalogues and malicious instructions hidden in content agents read, as well as interference when permissions are first set. Once attackers find a weakness, agents could be used to exploit it repeatedly and at speed.

Liability remains unsettled. Panellists differed on where responsibility should sit among customers and the providers of agents, payments and safeguards, and questioned how reimbursement schemes would apply. What they agreed on, Vivox AI reports, is the need for evidence detailed enough to show exactly where a failure occurred.

Shode closed by asking whether monitoring built around human behaviour will spot risks in agent-initiated payments. Fraudsters who once exploited emotions may now target the data, permissions and execution weaknesses of agents. Vivox AI concludes that firms should test now whether existing fraud, money laundering and sanctions controls can tell legitimate automation from compromise.

For more, read the full report here.

Read the daily RegTech news

Copyright © 2026 RegTech Analsyt

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.