TL;DR: Agentic AI is lowering the cost of fraud while accelerating attacker throughput, according to Arkose Labs, with Deloitte’s Center for Financial Services projecting US AI-facilitated fraud losses will reach $40 billion by 2027, up from $12.3 billion in 2023. The real shift is that fraud controls must now make attacking economically irrational before scale overwhelms detection.
At a glance
What this is: This article says agentic AI has changed fraud from a detection problem into an economic contest, because attackers can now scale and adapt faster and more cheaply than human-run operations.
Why it matters: IAM, fraud, and platform security teams need to rethink control design when legitimate AI agents and malicious automation look similar at the session layer, making classification and deterrence more important than blanket blocking.
By the numbers:
- AI-facilitated fraud losses in the US will reach $40 billion by 2027, up from $12.3 billion in 2023, according to Deloitte’s Center for Financial Services cited by Arkose Labs.
- Arkose Labs says FraudGPT is available for $1,700 per year.
- Arkose Labs says Gartner predicts that by 2028, 25% of enterprise breaches will trace back to AI agent abuse.
Context
Agentic AI has changed fraud economics by reducing the cost and effort required to mount attacks, while also increasing the speed at which attackers can iterate. Traditional detection-heavy fraud programmes assumed attackers would remain constrained by human time, manual tooling, and limited scale, but that assumption no longer holds when autonomous systems can run many sessions in parallel.
The identity angle is not just about bots versus humans. Platforms now have to distinguish between legitimate AI agents acting on behalf of users and malicious agentic traffic used for credential stuffing, account creation abuse, payment fraud, and API abuse. That makes classification, intent assessment, and enforcement economics central to fraud prevention.
The article frames this as an architectural shift, not a tuning problem. If attacking stays cheaper than defending, fraud will keep scaling, regardless of how strong the perimeter appears.
Key questions
Q: What breaks when fraud controls treat all automation the same?
A: When fraud controls treat all automation the same, they either block legitimate AI assistants and accessibility tools or allow malicious agentic traffic through. The result is a policy model that cannot distinguish intent, so defenders lose precision and attackers exploit the gap with machine-speed retries.
Q: Why do agentic AI attacks change the cost of fraud?
A: Agentic AI lowers the attacker’s cost of experimentation, scaling, and adaptation, which makes many fraud schemes economically viable at lower skill levels. When abuse becomes cheap enough to repeat indefinitely, detection alone cannot change behaviour unless the control also raises attacker effort and failure cost.
Q: How do you know if fraud deterrence is actually working?
A: Deterrence is working when attackers abandon the target, not just when individual attempts fail. Look for rising attacker effort, lower success rates across repeated sessions, reduced reuse of the same infrastructure, and evidence that the platform is no longer a low-friction target.
Q: What should security teams do when legitimate AI agents share signals with malicious bots?
A: Security teams should classify traffic by intent and behaviour, then apply graduated friction instead of a blanket block. That approach preserves authorised automation while forcing hostile sessions to pay a higher operational cost, which is the point of economic deterrence.
Technical breakdown
Why agentic AI breaks the old bot-or-not model
The legacy fraud model assumed a binary control plane: either traffic was human or it was automated, and automation could be blocked or challenged at the edge. Agentic AI collapses that distinction because legitimate agents, accessibility tools, and malicious automation can all behave like software acting on behalf of a person or organisation. The practical problem is intent, not just syntax. Security controls that rely on fingerprints or static signatures cannot reliably separate authorised agent behaviour from abuse when both use browser-like interaction patterns. That is why the article emphasises classification, behavioural context, and enforcement economics rather than blanket denial.
Practical implication: build traffic policy around intent and behavioural evidence, not simple automation detection.
How fraud economics shift when attackers use autonomous tooling
Fraud has always followed return on investment. What changes with agentic AI is the cost curve on the attacker side. Tools, infrastructure, and labour become cheaper to assemble, and the attacker can iterate faster after each failed attempt. That means the same defensive gap can now be exploited at far greater volume and at lower unit cost. In economic terms, detection still matters, but it is no longer enough if the attacker can cheaply re-enter the flow. The article’s core argument is that defenders must raise the cost of each attempt until the target is no longer worth attacking.
Practical implication: measure controls by how much attacker time, compute, and operational effort they consume.
Why classification and challenge design now matter more than block rules
A modern fraud platform has to treat traffic as a mix of self-disclosing good agents, non-disclosing good agents, and malicious agents. That is an identity and intent problem as much as a security problem, because the same technical session may represent accessibility automation, enterprise workflow automation, or hostile automation. Static rules decay quickly when the attacker adapts, so effective systems need layered signal collection, behavioural learning, and challenge mechanics that change the attacker’s economics. The aim is not perfect blocking. It is to make abuse continuously more expensive than success.
Practical implication: design friction that scales with risk and preserves legitimate agent access.
NHI Mgmt Group analysis
Agentic AI turns fraud prevention into an economics problem, not a detection problem. The article is right to frame the shift this way because attacker cost, reuse speed, and adaptation now define fraud volume more than raw sophistication. Detection still has value, but it no longer sets the boundary condition for success. Practitioners should treat control design as a pricing problem for abuse, not just a visibility problem.
Legacy bot controls fail because they assume the platform can safely classify automation as hostile. That assumption was workable when most automation was crude and non-adaptive. It fails when legitimate AI agents, accessibility tools, and malicious agents all present similar interaction patterns at the session layer. The practical consequence is that intent-aware classification becomes a governance requirement, not a nice-to-have tuning layer.
Three-tier agent classification is the right framing for mixed traffic environments. Self-disclosing good agents, non-disclosing good agents, and malicious agents require different policy treatment because the same technical footprint can have very different legitimacy. This is especially important where customer experience, accessibility, and enterprise automation intersect. Security teams should build policy on categorisation plus behavioural evidence, not a single bot/no-bot decision.
Agentic traffic governance: the new control boundary is not whether automation exists, but whether the system can prove the actor is authorised, benign, and operating within acceptable intent. That shifts fraud prevention toward identity-aware enforcement, where cost imposition and classification become the durable defence.
From our research library:
- U.S. fraud losses are projected to reach $40 billion by 2027.
- Read next: Agentic AI Security Guide
What this signals
Agentic AI fraud economics: security teams now have to govern abuse as a cost problem, not only an authentication problem. If attacker tooling becomes cheap and adaptive, controls that merely detect anomalies will always trail the next automated variant.
Fraud controls will increasingly be judged by whether they force hostile automation to spend more time, compute, and retries than the value of a successful attack. That changes the design brief for fraud programmes, especially where legitimate AI agents must still be allowed to operate.
For practitioners
- Define a three-tier traffic classification model Separate self-disclosing good agents, non-disclosing good agents, and malicious agents so policy can distinguish legitimate automation from abuse at runtime.
- Measure attacker economics, not only detection rates Track the time, compute, retry cost, and operational friction that your controls impose on fraud attempts, then tune for higher attacker spend per successful session.
- Replace binary bot rules with behavioural intent signals Use session-level behaviour, interaction patterns, and context across the flow to decide whether automation is authorised, ambiguous, or hostile.
- Introduce adaptive challenge enforcement Escalate friction only when risk rises, so legitimate users and accessibility agents are not blanket-blocked while abusive automation becomes uneconomic.
- Inventory AI agent traffic across customer journeys Map where agentic traffic appears in registration, login, payment, and API flows so you can control the exact stages attackers target most heavily.
Key takeaways
- Agentic AI has shifted fraud prevention from a simple detection challenge to an economic contest over attacker cost and defender friction.
- The article ties that shift to a major projected increase in AI-facilitated fraud losses and to the rapid commoditisation of attacker tooling.
- Fraud programmes now need classification, adaptive challenge design, and cost-imposition controls that make abuse less attractive than moving on.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on authorised vs malicious agent behaviour and intent misuse. |
| ASI02 — Tool Misuse | Fraud tooling uses browser automation and proxies to misuse legitimate interfaces at scale. | |
| ASI09 — Human-Agent Trust Exploitation | The piece highlights legitimate-looking automation that exploits user and platform trust. | |
| Recommendation — Apply ASI03 controls to distinguish authorised agent activity from malicious impersonation and abuse. Use ASI02 guardrails to constrain how agents can exercise browser and workflow tools. Map deceptive automation patterns to ASI09 and challenge any agent that cannot prove intent. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is about governance decisions for AI-driven automation and risk ownership. |
| Recommendation — Establish GOVERN responsibilities for AI-assisted fraud controls and decision authority. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The piece focuses on authorising or denying agentic traffic at the platform boundary. |
| Recommendation — Apply PR.AA-05 to ensure automated actors only reach the sessions and flows they are authorised to use. | ||
| MITRE ATT&CK | TA0006; TA0007 — Credential Access; Discovery | The article references credential stuffing and session probing as core fraud behaviours. |
| Recommendation — Map automated fraud activity to TA0006 and TA0007 to improve detection and response prioritisation. | ||
Key terms
- Agentic Traffic: Traffic generated by software that can act on behalf of a user or process with some degree of independent decision-making. In fraud prevention, it includes both legitimate assistants and malicious automation, so the control question becomes intent and behaviour, not automation alone.
- Economic Deterrence: A control strategy that makes abuse too costly to sustain. Rather than relying only on detection and blocking, it increases attacker time, effort, and compute until the expected return from targeting a system becomes unattractive.
- Three-tier Agent Classification: A governance model that separates self-disclosing good agents, non-disclosing good agents, and malicious agents. It helps teams apply policy more precisely so legitimate automation is preserved while adversarial automation is constrained.
- Fraud ROI: Fraud ROI is the attacker’s return on investment from running a fraud campaign, measured against the cost of tooling, infrastructure, labour, and retries. Security teams reduce fraud ROI by increasing friction, failure cost, and the time required to reach a successful outcome.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org