Fraud Teams Shift From Blanket Rules to Tailored Trust

At MRC Vegas 2026, over 2,000 payments leaders gathered to examine how fraud patterns, authentication and agentic commerce are evolving. The takeaway from the sessions: fraud is now heavily automated and harder for traditional systems to catch.

In response, sophisticated fraud operations are moving away from blanket policies. They are cutting friction for known-good users, building fraud detection into agent transactions, and layering identity checks to counter deepfakes.

Targeted Friction Based on User Intent

Applying authentication to every transaction may seem like a way to catch all bad actors, but the cost is often overlooked. Roberta Del Monte Radford, payment risk operations lead at Airbnb, noted that a false positive results in a declined transaction and the loss of a legitimate customer's potential lifetime value. Her session, focused on connecting refund fraud and reseller fraud, proposed instead building a behavioral profile per user over time to gauge intent—what she terms "high-trust velocity."

When intent can be measured accurately, authentication becomes selective. "If we have high-trust velocity, why would we put that entity through friction?" said Del Monte Radford. "We don't need to; we know they're good, so they don't need any friction whatsoever. We'll reserve the friction package to the 1% of the traffic that actually is proven to be risky."

Stripe Radar's adaptive 3DS is built on this principle. It uses AI to assess risk and only triggers an authentication challenge when activity looks unusual. Per Stripe, businesses on the platform have realized more than a 30% reduction in fraud on eligible transactions.

Agentic Commerce Outgrows Rules Engines

Ashley Furniture runs a comprehensive rules-based fraud operation, supporting both products shipping within days and custom orders requiring over 30 days of manufacturing, each with distinct authorization cycles. That system works when humans handle the process, but the company found it insufficient when launching agentic commerce.

"Rule-based fraud detection was not going to be sufficient," said Kyle Dorcas, head of product management at Ashley Global Retail. "We firmly believe that in order to combat fraud, [detection] really has to be in the payment fabric."

When agents purchase across channels, post-transaction evaluation is too late. Fraud detection must reside in the payment infrastructure itself to react in real time to patterns static rules cannot anticipate.

Stripe's Shared Payment Tokens let AI agents initiate payments using a buyer's stored payment method without exposing credentials. Combined with Stripe Radar, they transmit underlying risk signals in real time, including likelihood of fraudulent dispute, card testing, stolen card use, and issuer declines, helping to separate high-intent agents from low-trust automated bots.

Deepfakes Demand Layered Identity Checks

The infrastructure previously required to craft a convincing fake identity—criminal networks, specialized know-how, significant effort—has largely vanished. Bad actors now access templates for driver's licenses, bank statements, utility bills, and government IDs with ease. Meanwhile, generative AI accelerates impersonation.

Gordon Sheppard, head of fraud operations at H&R Block, demonstrated this in his session on identity verification for ecommerce fraud. From one still photo, a 30-second audio clip, and about 20 minutes of effort, he produced a convincing video of himself speaking fluent Mandarin, Italian, and Russian. Those same tools are open to anyone.

Sheppard argued that identity verification now hinges on finding the anomalies fraudulent actors cannot perfectly replicate every time, such as an incorrect signature or a mirror-image headshot. He cited a fraudulent license that was flawless except for one detail: the expiration date did not match the authoritative data source for that license. His conclusion: no single check suffices because a convincing forgery will fail somewhere.

Stripe Identity enables businesses to programmatically verify customers globally, using AI to catch fake IDs and spoofed photos, compare the ID photo against a selfie of the holder, and check SSNs and addresses against global databases.