Effective fraud prevention in the age of Agentic AI

Troy Nyi Nyi, SVP & GM, APAC, SEON

Agentic commerce is no longer a future concept. AI agents are already browsing, comparing products and beginning to complete purchases on consumers’ behalf, with adoption accelerating faster than most fraud prevention frameworks were built to support.

Nearly half (49%) of consumers globally say they would use AI to search for personalised product recommendations, according to Adobe’s Digital Trends Report. In Asia Pacific, adoption is even greater with Deloitte finding that 74% of consumers in the region already use AI to research products and compare prices.

However, nearly half of consumers say they would not complete a purchase without stronger security assurances.

Trust in commerce has always been built on human verification, a person deciding what to buy and confirming their identity or intent. When the buyer is a machine acting on the consumer’s behalf, that verification has to work differently.

Yet many businesses are still running fraud tools designed for a world where every transaction is driven by human judgement.

The detection gap

Fraud has always been easier to stop the earlier it is spotted, and far harder once a transaction is underway. Agentic commerce collapses that window almost entirely. As AI agents increasingly take on the role of completing purchases, transactions become more automated and near-instant, leaving businesses little to no room to step in before it’s complete.

A system that only reacts at checkout is reacting after the decision has already been made. Detection has to move to the point where there is still time to act on a problem before an agent commits to it.

The new attack surface

For an AI agent to decide what to buy, it depends entirely on the information fed to it, from product listings to seller details to recommendations. That dependency is what turns the data itself into the target.

Fraudsters no longer need to break into a transaction to manipulate its outcome. They only need to tamper with what the agent sees. Feed it a doctored product listing or a planted recommendation, and the agent can be steered toward a fraudulent seller or a fake product on its own, while the purchase it eventually makes looks completely ordinary from the outside.

Businesses have to go well beyond checking the data itself. They also need new ways to confirm the agent itself is reacting on genuine information, since a legitimate-looking agent can still be operating on false signals.

Traditional fraud signals were built around human behaviour, hesitation before a large purchase, an unfamiliar device, a login pattern that doesn’t match. An AI agent doesn’t hesitate, and it doesn’t leave those same behavioural fingerprints behind.

A tampered listing or a planted recommendation works so well against older defences for exactly this reason. The checks are looking for signs of human intent that a machine was never going to produce, so the fraud passes through a gap those tools were never designed to close.

New frameworks for machine-to-machine trust

Traditional trust frameworks were not built for machine-to-machine transactions and simply confirming a customer’s identity is no longer enough. Businesses need clear guardrails around AI agents, namely what an agent is allowed to buy on someone’s behalf, how far that permission stretches, and whether every action it takes can be traced back and explained if something goes wrong.

Solving it takes industry-wide coordination across the businesses and platforms an agent moves through, so that a warning signal picked up in one place is recognised everywhere else, rather than trapped inside a single company’s systems.

When systems don’t talk to each other, gaps open up between them, and that is exactly where a compromised agent or a fraudulent signal can slip through unnoticed.

The long-standing practice of Know Your Customer (KYC), verifying who a person is, now has to work alongside Know Your Agent (KYA), a newer trust framework that applies that same scrutiny to the AI acting on the customer’s behalf. Verification needs to keep pace with transactions that are only getting faster and more autonomous.

The priority for SMEs

For smaller businesses, that shift lands differently. Large retailers have the resources and the in-house expertise to build a robust, crisis-ready fraud detection system from the ground up, whereas SMEs face a different reality.

While they operate in the same connected online systems as their larger counterparts, SMEs rarely have the budget or headcount to build equally durable fraud detection capabilities of their own. Fraudsters are increasingly likely to treat that gap as an easier target as agentic fraud scales.

The good news for SMEs is that securing against agentic fraud does not require enterprise-level spend. It comes down to prioritising a handful of checkpoints, confirming who a seller actually is, making sure product data hasn’t been tampered with, and keeping a closer eye on the systems that feed data in and out of the business. Getting these right closes off most of the exposure agentic fraud depends on.

Accessible AI-powered monitoring tools can also help SMEs analyse patterns of activity over time, instead of relying solely on static rules that fraudsters have already learned to thwart. Smaller businesses can then catch subtle anomalies that would otherwise go unnoticed, without needing to dedicate a large team to watch every transaction manually.

The goal isn’t just seeing more; it’s acting on the right signals before they become a problem.

Looking Ahead

Fraud prevention was not built for a world in which the buyer is a machine.  The businesses recognising this the fastest will be the ones setting the pace. The same speed that makes fraud harder to catch also shifts the real vulnerability into the data guiding an agent’s choices.

Trust now has to extend to cover machines making decisions on a person’s behalf too. Staying ahead means catching problems well before checkout and treating the data that feeds an agent as something that must be secured and explained, not just the transaction it eventually produces.

For SMEs, this is a prime opportunity to prepare for an agentic future as it is still taking shape. Getting the foundations right now, through a few well-chosen checkpoints, lets SMEs compete credibly with far larger players and earn the same trust, without needing the size or budget to back it up.

Previous articleStudy captures perceptions in IT security
Next articleGenerational differences in how Singaporeans spend revealed