August 13, 2026 · 7min read
What Agentic AI Actually Changes in Fraud Prevention
Our industry is awash with insights on agentic AI. Most of them boil down to the same point: agents can do more than chatbots, so deploy agents everywhere.
However, we at Feedzai think that’s the wrong lesson. Agent capability is converging fast. Foundation models are commoditizing, and the gap between a good agent and a great one is shrinking.
What isn’t commoditized is the ability to prove, on demand, what an agent did, why, on whose authority, and who the accountable human is. The first major regulatory action against agentic AI in fraud operations won’t target a wrong decision. It will target an institution that couldn’t answer that question.
That’s the bet this article makes. In this post, we’ll dive deeper into where agentic AI genuinely helps, where the real risk sits, and what “getting it right” looks like in practice.
Key Takeaways
- According to Juniper Research, global fraud losses are projected to climb by 153% by 2030, reaching an estimated $58.3 billion.1 Financial institutions must adopt defensive strategies that can keep pace with modern payment rails.
- Autonomous systems should function as a force multiplier for human expertise, handling routine evidence gathering so that analysts can concentrate on high-value, complex investigative work.
- As agentic AI begins approving transactions on users’ behalf, trustworthy models will require a framework grounded in two key criteria. A technical layer to determine a good agent from a bad one and a business layer that clearly defines agent roles and permissions.
- Looking ahead, financial institutions’ competitive advantage will be defined by agents’ governance and auditability, ensuring they are trustworthy.
Crime was able to move faster than many institutions. Not anymore.
A synthetic identity can be generated, tested during onboarding, and iterated on thousands of times a day at close to zero cost. Most institutions still update rules monthly and retrain models quarterly. Meanwhile, real-time payment rails clear in seconds while manual investigations can take days.
Machine learning already gave fraud prevention continuous monitoring and real-time scoring. Agentic AI adds something different: the ability to execute multi-step work across evidence gathering, alert triage, report drafting, and detection rule testing.
The Blueprint for a World of Safer Money
A blueprint for stopping financial crime, from the leaders who are doing it. Perspectives from law enforcement, financial services, and policy leaders on fighting fraud, scams, and financial crime.
Done right, that reduces the speed gap while keeping every decision that matters in the hands of an accountable human. Done wrong, it’s a layer of automation regulators will pull apart, and customers won’t forgive.
The difference-maker for success here is proper governance, not just the tech.
Agentic AI in Fraud is Not Classified ‘High-risk’ Under the EU AI Act
This gets misquoted often enough that it’s worth stating plainly: Annex III of the EU AI Act carves out fraud detection from its high-risk creditworthiness category.2 The European Commission’s draft guidance from May 2026 confirms the exception holds where fraud detection is the system’s primary purpose.3 4 Agentic systems are assessed as a whole, not agent by agent.
That doesn’t mean it’s unregulated. GDPR Article 22 still requires meaningful explanation for automated decisions that materially affect someone. DORA treats AI embedded in fraud detection as critical infrastructure. Model drift is an operational incident, and you need the ability to halt a system that begins to behave erratically. In the US, supervisors already treat an agent as a model under SR 11-7: validated, stress-tested, and monitored. The CFPB has been explicit that “the AI did it” is not a defense.
Put together: the rules don’t ask you to slow down. They ask you to show your work.
The real risk isn’t a bad decision. It’s agent sprawl.
As agents get cheap to build, the temptation is to deploy them everywhere. This can lead to dozens of uncoordinated automations, each defensible on its own, but collectively ungovernable. That’s the failure mode heading for this market, and it’s the opposite of what we’ve built.
We’ve deliberately gone the other way: a focused set of agents, each aimed at a specific bottleneck in the fraud prevention lifecycle, running on a single governed layer. This means one gateway, one audit trail, and one set of controls.
Institutions building their own agents don’t need to abandon that work to obtain this; a Bring Your Own Agent (BYOA) framework, connected via a Model Context Protocol gateway, lets proprietary agents inherit the platform’s permissions and audit trail rather than recreating them from scratch. The build-versus-buy debate misses the point. The real question is whether every agent in your environment, wherever it came from, falls under a single auditable layer.
Human-in-the-loop Isn’t Just a Safety Net
When payments are flagged as risky, by definition, these are alerts that a machine couldn’t resolve definitively: the coerced victim, the vulnerable customer, the typology nobody’s seen before. As a result, the real competitive edge lies in the judgment of the person handling it, combined with the assistance of a machine’s complete, already assembled evidence.
This is also where accountability lives structurally, not just ethically. US regulators require the final call to freeze an account or file a report to be documented and attributed to a named human. UK accountability rules expect a named senior person to own the systems a firm runs. An agent that declines a legitimate customer for reasons no one can explain is a Consumer Duty problem on day one.
Know Your Agent: the Next Identity Problem
KYC was built to verify a human being. Cifas’ 2026 Fraudscape report shows that identity fraud remains the most common threat, with 242,003 cases recorded in 2025, and identity fraud plus account takeover together accounting for about 72% of all filings, underscoring how much harm now flows through compromised or synthetic personas.5
As agents start initiating transactions on people’s behalf, that framework doesn’t disappear, but it’s no longer sufficient on its own.
Two things need to be true at once, and neither one alone gets you there.
- The technical layer is distinguishing a good agent from a bad one. This is the automation equivalent of knowing whether a device or an IP address is behaving normally or like an attack. That’s a detection problem, and it’s one that good fraud prevention platforms are already built to solve.
- The business layer is different, and it’s where most of the industry conversation stops short: establishing trusted agents, with permissions defined once and clearly within an authorized session, rather than re-verifying identity on every single action. E.g., what an agent is allowed to do, on whose authority, and within what limits.
The challenge ahead is holding both without undermining the reason someone chose to use an agent in the first place. If every agent action triggers friction, the agent stops being useful, and people route around it.
If no agent action triggers friction, you’ve built an unmonitored channel into the financial system. That’s not a new problem. It’s the same principle behind smart friction: the right amount of resistance, in the right place, calibrated to risk rather than applied uniformly. KYA is smart friction applied to machine identity instead of human identity.
Financial institutions will need live registries of authorized agents. With a verified identity, a permissioning certificate, and a clear chain of accountability defined before something goes wrong, not reconstructed after the fact when responsibility has to be assigned between the agent’s owner, its developer, and the institution that let it operate.
How Agentic AI is Going to Change
As institutions move beyond simple anomaly detection toward goal-oriented, autonomous workflows, the competitive advantage will be defined not by the agents themselves, but by the governance and auditability that bind them. The institutions that will stand apart will successfully operationalize agentic AI as a structured, defensible part of their infrastructure, rather than those that add another layer of unmanaged automation.
- Agent-assisted investigation will become the norm at leading institutions. The gap between an analyst who starts at the point of judgment and one who starts at the point of data gathering isn’t incremental. Every day this gap compounds.
- The first major regulatory action against agentic AI in fraud will target governance, not performance. Not “the agent was wrong,” but “the institution couldn’t show who authorized it.” Institutions that treat auditability as a design requirement, not an afterthought, will be able to watch that action from a comfortable distance.
- The advantage compounds through the network, not the model. Fraud losses for financial institutions are expected to rise 153% from around $23 billion in 2025 to $58.3 billion by 2030, according to Juniper Research.1 Agents grounded in cross-institutional signals will be better positioned to identify the driving forces behind that curve earlier than those using a single institution’s data. This gap will widen as the network grows.
None of this arrives as a single disruption. It accumulates through product decisions, infrastructure choices, and the regulatory responses now taking shape. Soon, it’s likely that the environment will look nothing like the one institutions operate in today.
The ones still treating agentic AI as a distant question will find themselves navigating that environment with governance built for a world that no longer exists. The ones building the audit trail now, not after a regulator asks for it, are the ones who will get to define what trust looks like.
Footnotes
1 https://www.juniperresearch.com/press/fraud-to-cost-financial-institutions-58bn/
5 https://www.cifas.org.uk/newsroom/fraudscape2026
All expertise and insights are from human Feedzaians, but we may leverage AI to enhance phrasing or efficiency. Welcome to the future.
