By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: IncodePublished August 13, 2026

TL;DR: Agentic AI is making fraud run at software scale, with Incode citing 66 cross-checked AI-fraud cases, reported losses approaching 900 million dollars, and a 20.4 billion dollar US loss total in 2025. The core issue is that fraud is no longer constrained by human labor, so identity verification becomes the last reliable checkpoint.


At a glance

What this is: This is Incode’s analysis of how agentic AI is removing the human labor ceiling from fraud operations, with a report-backed case database and loss projections showing fraud is becoming cheaper, faster, and more scalable.

Why it matters: It matters to identity practitioners because agentic fraud changes verification, trust, and risk decisions across KYC, onboarding, support, and account recovery, where human review alone can no longer keep pace.

By the numbers:

👉 Read Incode's analysis of how agentic AI is scaling fraud losses


Context

Agentic fraud is fraud that can plan, adapt, and continue without a human operator driving every step. The article argues that this changes the economics of abuse, because attackers can scale conversations, impersonation, and follow-up at a pace that exceeds manual fraud operations, while identity verification remains the boundary that still has to distinguish a real person from a synthetic interaction.

For IAM, fraud, and identity verification teams, the key governance problem is not whether AI can help attackers write better scripts. It is whether current controls can still detect a synthetic actor, a deepfake participant, or a machine-run scam loop before trust is transferred. That makes this a genuine identity-verification and account-security problem, not just a fraud-awareness problem.


Key questions

Q: How should identity teams handle agentic fraud in customer support and recovery flows?

A: Identity teams should treat support and recovery as high-risk verification points, not routine service interactions. Require separate-channel proof, higher assurance for account changes, and behavioural or device signals that can confirm the request matches the legitimate user. If the same channel can be spoofed, it should not be the channel that authorises the action.

Q: Why does agentic AI complicate fraud compliance work?

A: Because compliance no longer reviews only model outputs. It must also account for machine-initiated actions, escalation logic, and the evidence trail behind each decision. That changes accountability, because errors can now come from workflow design as much as from analytics quality.

Q: What do security teams get wrong about deepfake-enabled fraud?

A: They often treat deepfakes as a novelty problem instead of a verification economics problem. The real challenge is that synthetic content increases the volume of credible attempts, which drains manual review capacity and makes exception handling less reliable. Controls need to account for scale, not just realism.

Q: Who is accountable when account takeover and synthetic identity fraud occur?

A: Accountability usually sits across fraud, IAM, security, and product teams because the failure spans onboarding, session trust, and action-level controls. In practice, the owner should be the team that can change the decision point where abuse becomes possible. Shared risk does not mean shared inaction.


Technical breakdown

How agentic fraud changes attack economics

Traditional fraud is limited by human effort. Agentic AI removes that ceiling by letting one operator coordinate many parallel conversations, iterate on victim responses, and keep working continuously. That makes fraud closer to a distributed software process than a person-driven scam. The technical shift matters because the attacker no longer needs a large labour force, only enough access to models, scripts, and infrastructure to sustain scale. The article’s point is not that AI invents fraud categories, but that it multiplies the throughput of existing ones by reducing time, cost, and fatigue constraints.

Practical implication: identity programmes need controls that assume scams can be executed at machine speed, not reviewed at human speed.

Why deepfakes and synthetic interaction defeat legacy trust checks

Voice cloning, real-time video generation, and chatbot-driven dialogue all attack the same trust model: humans use familiar cues to infer legitimacy. Once those cues can be manufactured cheaply and iterated live, the interaction itself becomes an unreliable signal. A fraudster can simulate authority, urgency, and familiarity long enough to trigger payment, disclosure, or access. The article’s example of a deepfake video call shows that the issue is not only content authenticity, but the collapse of the social verification process used in business operations.

Practical implication: verification needs independent challenge steps that do not depend on the same channel the attacker is already controlling.

Why identity verification becomes the control point for agentic fraud

When attackers can automate outreach, adaptation, and persistence, the remaining control question is whether the organisation can prove a real person is present and authorised. That pushes identity verification from onboarding-only use into ongoing transaction and support workflows. In practice, this means identity evidence, device context, risk scoring, and step-up checks have to work together. Fraud control is no longer separate from identity governance, because every synthetic interaction is also an access and trust decision.

Practical implication: teams should treat identity verification as a runtime control tied to fraud risk, account recovery, and high-value actions.


Threat narrative

Attacker objective: The attacker aims to convert synthetic trust into money, credentials, or account access at scale without increasing human staffing.

  1. Entry occurs through AI-generated outreach, deepfake impersonation, or chatbot-led contact that looks credible enough to start a trusted interaction.
  2. Escalation happens when the attacker uses iterative machine-driven dialogue to adapt after resistance, gather more context, and steer the victim toward disclosure or payment.
  3. Impact follows when the victim transfers money, credentials, or account control to what appears to be a legitimate person or process.

NHI Mgmt Group analysis

Agentic fraud is now an identity governance problem, not only a fraud problem. The article shows that AI agents can conduct outreach, adapt, and escalate without a human at every step. That shifts the control boundary from static fraud rules to identity verification, authorization, and trust validation across the whole customer journey. Fraud teams, IAM teams, and verification teams now share the same failure surface.

The new failure mode is verification trust collapse. Once a synthetic voice, face, or conversation can sustain a convincing interaction, legacy step-up checks that rely on the same communication channel lose value. The organisation is no longer validating a person, only a channel that the attacker may already control. Practitioners should recognise this as a trust-boundary issue that spans identity proofing, support, and payment workflows.

Agentic fraud amplifies the need for runtime identity assurance. If a scam can be run end to end by software, then trust decisions must also become runtime decisions. That means linking identity evidence to device, behaviour, and transaction context rather than treating verification as a one-time onboarding event. The practical conclusion is straightforward: assurance must persist beyond first contact.

Fraud operations are becoming industrial, which changes the governance baseline. The article’s loss projections matter because they show how quickly attack economics can outrun manual review. Identity programmes should expect higher volumes of synthetic contact, more account recovery abuse, and more support-channel impersonation. The right response is to harden the verification layer before attackers normalise this playbook at scale.

Identity verification is becoming the last defensible checkpoint in agentic workflows. When AI can generate the conversation, the face, and the voice, the organisation needs a control that can prove who is really present and whether the request is legitimate. That makes verification policy, evidence quality, and escalation paths central to fraud resilience, not peripheral compliance tasks.

What this signals

Agentic fraud expands the identity surface faster than most verification programmes can absorb. The operational signal is not just higher fraud volume, but a wider set of trust decisions that now need runtime checks. Teams should expect support queues, recovery workflows, and high-value approvals to become the preferred attack paths, which makes identity verification architecture a core control plane rather than a back-office function.

Verification trust gap: when a synthetic voice, face, or chat can carry a whole scam to completion, the boundary between fraud prevention and IAM disappears. Practitioners should anchor their response in separate-channel verification, device context, and stronger escalation rules, using guidance from the NIST AI Risk Management Framework where AI-assisted decisioning is already in use.


For practitioners

  • Strengthen step-up verification for high-risk actions Require stronger identity proof before account recovery, payment change, beneficiary change, or support escalation. Use a separate channel and evidence source so the attacker cannot reuse the same conversation path to complete the fraud.
  • Add synthetic-interaction detection to trust workflows Instrument support, onboarding, and transaction flows for signs of deepfake audio, scripted language reuse, velocity anomalies, and repeated failed challenge attempts. Feed those signals into decisioning rather than relying on manual review alone.
  • Rebuild risk scoring around runtime context Combine device reputation, behavioural patterns, session history, and identity evidence when deciding whether to approve sensitive actions. Treat a successful login as insufficient proof when the request itself is high impact.
  • Separate fraud controls from the same channel attackers abuse Move sensitive approvals away from email, voice, or chat threads that can be impersonated. Use out-of-band confirmation and authoritative back-office checks for requests that move money or alter credentials.
  • Test support teams against agentic fraud playbooks Run exercises for voice cloning, real-time deepfake calls, and AI-driven social engineering so front-line teams know when to pause, verify, and escalate. Update scripts so staff do not treat fluent synthetic dialogue as proof of legitimacy.

Key takeaways

  • Agentic AI is turning fraud into a software-scale operation that no longer depends on human labour constraints.
  • Identity verification now sits on the critical path for fraud prevention, especially in support, recovery, and payment-change workflows.
  • Controls that rely on the same channel as the attack will fail first, so practitioners need independent verification and runtime risk signals.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF and NIST CSF 2.0 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNAI-driven fraud workflows need governance over assurance and accountability.
NIST CSF 2.0PR.AC-1Identity proofing and access decisions underpin fraud-resistant workflows.
GDPRArt.32Identity verification and fraud controls may process personal data and security signals.

Assign clear owners for AI-assisted verification and review escalation paths for synthetic interactions.


Key terms

  • Agentic Fraud: Fraud executed by systems that can plan, adapt, and complete tasks with limited or no human intervention during the session. The control problem is not only account creation, but whether the system can continue to behave within approved bounds after access is granted.
  • Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.
  • Runtime Identity Verification: Runtime identity verification is the process of proving a workload's identity at the moment access is requested rather than trusting a pre-stored secret. It ties access decisions to the current workload instance, which is more suitable for ephemeral services and short-lived sessions.

What's in the full report

Incode's full article covers the operational detail this post intentionally leaves for the source:

  • The report’s 66-case incident database and how the vendor classified each fraud pattern by agentic capability.
  • The 1-to-5 scoring model used to judge which fraud categories an AI agent can already run end to end.
  • The projection model behind the 155.3 billion dollar and 380.1 billion dollar loss scenarios.
  • The specific examples and methodology behind the documented fraud cases and loss estimates.

👉 The full Incode article covers the case database, fraud category scoring, and loss projection model.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle controls. It helps practitioners build the governance foundation needed to secure identity-driven workflows across modern security programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org