Here's the blind spot most fraud models don't have on their radar yet: the AI agent that doesn't look suspicious at all.
Fraud detection was built to catch deviation, the login from a new device, the typing cadence that doesn't match, the hesitation before entering a routing number. AI agents don't hesitate. They don't mistype. They don't deviate. An agent executing a transaction on a legitimate customer's behalf can look cleaner than the human it's acting for which means the models trained to flag anomalies are, in some cases, scoring agentic traffic as lower risk than the real customer. That's not a bot problem. That's a blind spot with a $1.7 trillion transaction volume headed straight into it.
This session skips past the fraud-101 framing of "AI agents are the new bot problem" and into the questions banks are being forced to operationalize right now: How do you extend KYC and KYB logic to a third category of actor — the agent — without rebuilding your entire identity stack? What does an authorization event need to capture to hold up in a dispute when the "customer" who initiated a transaction was, technically, software? And as coordinated account takeover increasingly blends stolen credentials, synthetic identity, and now agentic tooling, where are legacy, compliance-driven controls already losing ground to attackers who've industrialized all three?
Drawing on Prove's work building the identity infrastructure behind Know Your Agent (KYA) — and leadership perspective shaped by decades on the bank side of this exact problem — this conversation will get specific about:
- Why "is it human?" is the wrong first question, and what the right one looks like in practice
- What a defensible chain of custody — identity, intent, authorization, execution — actually requires when an agent is in the loop
- Where coordinated ATO patterns are already exploiting the gap between compliance-era identity controls and agent-era transaction volume
- What forward-leaning fraud and risk leaders are building now, ahead of regulatory clarity, to avoid re-fighting this battle a year from now
This is a conversation for risk and fraud leaders who are past "should we worry about AI agents" and into "how do we architect for them."


