December 15, 2025
$67 Billion. That is the total of global sales influenced by AI and AI agents in this year’s Cyber Week alone. This represents 20% of all orders placed. And all of this is just getting started.
Agentic commerce opens the door to unprecedented volume and economic opportunity. It also breaks the assumptions underlying today’s authorization and fraud systems. The concept of trust will become something agents need to build and validate.
What’s New? Agentic Commerce Threats: Why Old Rules Don’t Apply
Agentic commerce doesn’t necessarily invent brand-new fraud categories. But it will remove the friction and inconsistency in transactions that many rely on to catch fraud today.
Why? Because malicious agents mimic human behavior. They can view listings, filter searches, revisit pages, and even abandon carts. They can pass multifactor authentication and avoid anomaly triggers traditional fraud systems rely on. They may even be able to sense when (and how) they are being evaluated for fraud.
In this landscape, merchants will continue to absorb most of the dollar losses of fraud caused by returns, mismatched orders, and disputes. Issuers, however, will absorb most of the fraud exposure, model degradation, and operational burden.
What’s the Same? Agentic Commerce: The Top 3 Fraud Risks for Issuers
While the fraud categories don’t necessarily change with agentic commerce, the scale and ambiguity of the problem does. Agent mistakes and gray-area transactions increase disputes and force issuers to make harder decisions faster and with less information.
1. Unauthorized Agent Transactions – aka Card Not Present (“CNP”)
This is the #1 financial exposure for issuers. If an AI agent initiates a purchase the customer did not authorize, the issuer will be responsible for the fraud loss under existing CNP rules. This includes:
- agent acting outside user intent
- compromised agent
- rogue agent instruction
- user-agent misunderstanding that looks like fraud
2. Compromised or Spoofed Agent Tokens – aka Counterfeit Fraud
Issuers will approve a transaction because it looks perfect. Fraudsters can fake these “perfect” transactions by:
- cloning the token
- intercepting token metadata
- spoofing the agent’s identity
- injecting themselves into the agent instructions
3. High-Speed Account Takeover via Agents – aka ATO Fraud
ATO in agentic commerce is faster, harder to detect, and more damaging. Agents can:
- issue high volume transactions instantly
- execute transactions simultaneously across different merchants
- hide behind “trusted agent metadata”
Agentic Commerce Fraud Detection: What’s Ahead
Amidst these threats, issuers are being forced to adapt in real-time, making critical decisions on how to enable agents, what controls they will require, and where current fraud tools fall short. Read more on how institutions are adapting.
Stratyfy lets issuers and processors test, control, and learn with agent-driven transactions safely without ripping out their existing fraud stack. Email Stratyfy at sales@stratyfy.com to discuss how to implement your agentic AI fraud defenses.