Machine Against Machine: Fraud’s Autonomous Turn
Fraud has spent years learning to deceive humans. Its next act is to deceive machines — and to fight them. As people begin handing their shopping and payments to AI agents, criminals are deploying fraud agents that blend in with the legitimate ones, and the defining security question is shifting from "is this person real?" to "is this bot authorised?"
What Happened
In its 2026 Future of Fraud Forecast, the credit and analytics company Experian named its number-one threat for the year "machine-to-machine mayhem" — cybercriminals blending "good bots" doing a consumer's shopping with "bad bots" tasked with fraud. Experian predicts 2026 will be a tipping point for AI-enabled fraud, forcing new conversations about liability and regulation around agentic AI in e-commerce; in a related survey, 72% of business leaders said AI-enabled fraud and deepfakes would be among their top operational challenges this year.
The trigger is the arrival of "agentic commerce" — AI assistants from companies like OpenAI and Perplexity that can browse, choose, and pay on a user's behalf. That convenience creates a new problem for merchants who already struggle to tell legitimate automated traffic from malicious bots. Some are responding bluntly: Amazon generally blocks third-party bots from shopping on its platform and moved legally to block Perplexity's shopping agents in late 2025, citing security and privacy. Meanwhile, identity firms report the emergence of autonomous "AI fraud agents" — systems that weave together generated content, scripting, and imitated human behaviour to clear verification gates, learning from each failed attempt and adjusting in real time.
Why It Matters
For its entire history, fraud has been a con played on a person. Agentic commerce introduces a world where the buyer, the seller's defences, and the attacker can all be autonomous software transacting at machine speed. That breaks the assumptions security is built on. You can no longer defend by asking "does this feel human?" — because the legitimate customer may not be human either. The question becomes whether a given agent is authorised to act for the person it claims to represent, and today's systems are poorly equipped to answer it. This is the same loss-of-the-human-bottleneck warrier has tracked in influence operations, now arriving in commerce.
Source Notes
The "machine-to-machine mayhem" designation, the "tipping point" prediction, the liability/regulation framing, and the 72%-of-business-leaders figure are from Experian's 2026 Future of Fraud Forecast as reported by Fortune (13 January 2026), including remarks attributed to an Experian executive. Amazon's general blocking of third-party bots and its late-2025 legal move against Perplexity's shopping agents (on security and privacy grounds) are reported in that coverage. The description of autonomous "AI fraud agents" that clear verification gates and adapt in real time is from Sumsub's 2026 fraud-trends analysis. The figure that consumers lost over $12.5 billion to fraud in 2024 (up roughly 25% year over year) is attributed to the FTC via the same reporting; the ~11% deepfake share of global fraud is Sumsub's. Forward-looking claims are forecasts, and Experian and the identity firms cited sell fraud-prevention services.
MEMBERS ONLY — THE FULL BRIEFING FILE CONTINUES BELOW
🔒 This analysis is for warrier.ai Intelligence members only. → Become a Member
Already a member? Log in here
