- The fraud mix flipped: first-party fraud (44%) and fake-account/identity abuse (42%) now outrank stolen cards and account takeover (36%).
- AI lowered the cost of attacks — tactics are scripted, tested, and shared. Fraud shifted from high-value and rare to low-value and high-frequency.
- Agentic commerce (AI agents buying on a consumer's behalf) industrializes the edge cases: agent-initiated transactions dispute at roughly 2.4× the human card-not-present rate, and consumers keep chargeback rights.
- The defense is a layered, real-time system — identity, behavior, transaction scoring, disputes — monitored continuously, since it's the same machinery your sponsor bank (the bank behind your program) examines.
Most fraud strategies are built to stop yesterday's fraud: a stolen card number, an account takeover, a stranger forcing their way in. That model now defends the wrong perimeter. In 2026, the most expensive fraud increasingly comes from people the system already trusts — recognized customers, authenticated accounts, verified devices — and from machines acting on their behalf.
This is the framework we use with growth-stage teams, built from years inside the institutions and networks that run the rails.
The fraud mix flipped
Start with the data, because the headline numbers reorder your priorities. In Adyen's 2026 fraud report, first-party fraud is now the most commonly reported type of fraud (44%), closely followed by fake accounts and identity abuse (42%) and policy or promotion abuse (40%). The more traditional threats — stolen cards and account takeovers — were reported by 36% of businesses (Adyen, 2026).
Two structural shifts sit underneath that ranking:
- Fraud got cheaper to run. Automation and AI have lowered the barrier to entry for bad actors, letting tactics be scripted, tested, and shared across closed networks. Fake and bot accounts are now the second most-encountered fraud type globally (Adyen, 2026).
- The economics inverted. On Adyen's platform, fraudulent-chargeback losses fell 20% in 2025, but the average value of a fraudulent dispute dropped 23% over the same period — fraud moved from a few high-value hits toward high-frequency, low-value abuse inside trusted environments (Adyen, 2026).
Synthetic identity (a fabricated identity blending real and invented data) is the connective tissue. As risk leaders noted at the 2026 Identity & Payments Summit, these identities let bad actors build trust with a business over time, then disappear once they've extracted enough value — and AI is accelerating the trend (Secure Technology Alliance, 2026).
The operator's read
If your fraud spend is concentrated on stopping stolen cards at checkout, you're guarding a door that fewer attackers use now. The money is leaking through onboarding (synthetic and fake accounts), through trusted-customer behavior (first-party fraud and abuse), and increasingly through machines. Rebalance the budget toward where the loss actually is.
Agentic commerce breaks the chargeback model
When a consumer delegates purchasing to an AI agent, the agent shops, selects, authorizes, and completes the transaction — and the cardholder may never touch the checkout page. The consumer keeps their chargeback rights: the CFPB's January 2026 advisory on autonomous-agent purchases under Regulation Z was explicit that dispute rights survive the delegation (FraudBeat, 2026).
That creates a transaction type the chargeback system has no framework for: the consumer authorized the agent in general, but can plausibly claim they didn't authorize the specific purchase. Agent-initiated transactions dispute at roughly 2.4× the rate of comparable human card-not-present transactions (FraudBeat, 2026). Agentic tokens can prove an agent is legitimate; they can't prove it acted within the scope the consumer intended.
This is live infrastructure, not a hypothetical: Visa, Mastercard, and OpenAI already run agentic-commerce rails, with authentication, liability, and risk-model design still catching up (PaymentBrief, 2026). With AI agents projected to influence 5% to 20% of payment volume within five years, 30% of merchants now name AI-platform trust scoring as their most critical new signal (Adyen, 2026).
Four layers, one real-time system
A fraud strategy is not a tool you buy — it's a system you operate. Four layers, each feeding the next, scored in real time rather than in batch.
1. Identity
Identity verification is often just a snapshot in time, and that's no longer enough when deepfakes and LLMs can generate high-quality fake documents in minutes (Secure Technology Alliance, 2026). Treat onboarding identity as a continuous trust score: combine document and biometric checks with device, network, and consortium signals, and re-evaluate as behavior accumulates.
2. Behavior and device
Because the threat now comes from authenticated accounts, you need signals that distinguish a real customer from a recognized-but-abusive one: behavioral biometrics, device and session intelligence, velocity analysis, and dynamic trust-scoring — the shift the whole industry is making, away from static defenses (Adyen, 2026). This is also your first line on agent traffic.
3. Transaction-level risk scoring
At authorization, fuse those upstream signals into one decision — approve, challenge, or decline — in milliseconds. The discipline that matters here is explainability: every decline and challenge needs a documented rationale, both to tune the model and to answer a sponsor bank or examiner later.
4. Disputes and recovery
This is where first-party fraud and agent-initiated disputes are won or lost. Build a disciplined chargeback-representment process, and decide your posture on agent-initiated disputes now: assume merchant liability for agent transactions lacking verified delegation credentials, and price that risk accordingly (PaymentBrief, 2026). Feed every dispute outcome back into your scoring layers.
Tie it to a loss budget
Set an explicit fraud-loss budget by product and channel, then run the four layers against it. Over-tuning toward zero fraud quietly kills good customers and revenue; under-tuning bleeds the P&L. The right answer is a number you choose on purpose — and can defend to your sponsor bank.
Where AI and agents belong
Agentic AI is moving from pilot to infrastructure in fraud and financial crime. FIS and Anthropic launched a Financial Crimes AI Agent that compresses AML investigations from hours to minutes by assembling evidence across core systems, with BMO and Amalgamated first to deploy and general availability targeted for the second half of 2026 (FIS, 2026). The lesson for a growth-stage team is the governance pattern, not the vendor: client data stays inside controlled infrastructure, and every agent decision is traceable and auditable.
Use AI and agents where they earn their place — triage, evidence assembly, pattern detection, false-positive reduction — with a human in control of consequential decisions and guardrails built in, not bolted on later. “Verified AI” beats “AI-first” every time a regulator or sponsor bank asks you to show your work.
Why this is a diligence issue, not just a loss issue
The same fraud machinery is what your sponsor bank examines. In 2026, FinCEN and the banking agencies proposed shifting AML/CFT programs away from checkbox compliance toward demonstrated results tied to your actual products and customers (Ncontracts, 2026). Responsibility doesn't transfer, either: in BaaS (banking-as-a-service), third-party relationships extend the bank's BSA/AML obligations, so gaps land on the bank's exam, then on you (FinWise, 2026). A documented, continuously monitored fraud strategy is table stakes for keeping your banking relationship.
Building or rebuilding your fraud strategy?
Whether you're standing up a fraud program for the first time, rebalancing toward first-party and synthetic-identity risk, or handling agent-initiated traffic without breaking approval rates, that's exactly what our senior operators — from Fiserv, FICO, Oracle, Citi, and Wells Fargo — work on with growth-stage teams.
Book a working callFAQ
What is the most common type of payment fraud for fintechs in 2026?
First-party fraud is now the most commonly reported fraud type, cited by 44% of enterprises in Adyen's 2026 fraud report, closely followed by fake accounts and identity abuse at 42%. The risk has shifted from strangers forcing their way in toward recognized customers and authenticated accounts. A strategy built only to stop stolen-card and account-takeover attacks now defends the wrong perimeter.
Why does agentic commerce create new fraud risk?
When a consumer delegates purchasing to an AI agent, they keep their chargeback rights, but the dispute system has no framework for a purchase authorized in general but not specifically. Agent-initiated card transactions dispute at roughly 2.4 times the rate of comparable card-not-present purchases. Agentic tokens can prove an agent is legitimate, but not that it acted within the scope the consumer intended.
How should a growth-stage fintech structure a fraud strategy?
Treat fraud as a layered, real-time system, not a single tool: identity proofing at onboarding, continuous behavioral and device signals, transaction-level risk scoring, and a disciplined dispute process, all tied to a loss budget by product. Document and monitor it continuously — it's the same system your sponsor bank examines.