TL;DR: Authentication, fraud prevention, and application security are converging around stronger trust, verification, and layered controls as OneSpan’s January 2026 newsletter ties together its Build38 acquisition, 2025 fraud trends, PSD3 and PSR updates, and emerging risks from agentic commerce.
At a glance
What this is: OneSpan’s January 2026 newsletter argues that authentication, fraud prevention, mobile app protection, and agentic commerce are converging into a single trust problem for digital identity programmes.
Why it matters: IAM, fraud, and NHI teams need to design for continuous trust negotiation across users, devices, and agents instead of relying on static authentication alone.
Context
The core governance gap is no longer just whether a user authenticated. It is whether trust still holds as actions move across devices, payment rails, application protections, and delegated AI activity. In that environment, authentication becomes one control in a broader identity assurance model.
For IAM and fraud teams, the article is useful because it connects customer authentication, fraud detection, mobile app security, and agentic commerce in one operating picture. That matters because the controls that work for a human user session do not automatically extend to delegated, machine-mediated transactions.
Key questions
Q: How should organisations govern sub-agents in agentic commerce?
A: Organisations should treat sub-agents as separately governed actors with explicit scope, bounded delegation depth, and revocation tied to the parent workflow. If sub-agents inherit broad permissions automatically, the platform creates a recursive privilege surface that is hard to audit and harder to contain after misuse.
Q: How should fraud teams combine behavioural signals and device fingerprinting?
A: Fraud teams should combine both in the same decision engine so session behaviour is interpreted in the context of a durable device identifier. Behavioural analysis helps detect interaction patterns, while device fingerprinting links activity across visits and accounts. Together, they reduce false positives, improve first-touch decisions, and make coordinated abuse easier to spot before it scales.
Q: What breaks when a mobile identity is not kept inside the government app?
A: When the mobile identity is not kept inside the government app, trust boundaries expand and key handling becomes harder to control. Shared credentials or loose app integration can expose signing material, weaken policy enforcement, and make it easier for third-party apps to misuse the identity. Keeping authentication inside one controlled app limits that exposure.
Q: Should passkeys replace fraud controls in customer authentication programmes?
A: No. Passkeys reduce phishing risk, but they do not replace fraud detection, device intelligence, or transaction validation. The strongest programme uses phishing-resistant authentication as one input to a broader decision model that also checks behaviour, device state, and the legitimacy of the transaction itself.
Technical breakdown
Why authentication alone no longer contains agentic commerce risk
Authentication proves a party reached a trusted starting point, but it does not by itself validate the full transaction path. In agentic commerce, an AI agent may act on a consumer’s behalf, but the security question shifts to whether the agent’s intent, authority, and transaction scope remain consistent as it shops, negotiates, and transacts. That turns a one-time identity check into a continuous trust problem. The important distinction is between proving who or what entered the session and proving that each action still matches the delegated purpose. Practical implication: build controls that re-check intent and authority at transaction time, not only at login.
Practical implication: build controls that re-check intent and authority at transaction time, not only at login.
How fraud stacks now blend authentication, device signals, and behavioral analytics
Modern fraud does not stop at stolen credentials. The article points to account takeover, impersonation scams, voice phishing, biometric abuse, and manipulated customer behaviour, which means the defender has to correlate identity signals with device risk and transaction context. That is why a layered trust model matters: authentication confirms access, device intelligence flags compromise, and behavioural analytics tests whether the interaction looks legitimate. None of those signals is sufficient on its own. The security value comes from combining them before a transaction is finalised. Practical implication: treat authentication as an input to fraud detection, not as the endpoint of assurance.
Practical implication: treat authentication as an input to fraud detection, not as the endpoint of assurance.
What mobile app protection adds to identity assurance
Mobile app protection matters because the application itself is part of the trust boundary. If an attacker can tamper with the app, instrument the device, or abuse the runtime, then even strong authentication can be undermined after the user has signed in. That is especially relevant for banking and payments, where the article links mobile security, impersonation fraud, and account takeover. The technical point is that the app must help preserve the integrity of the session and the transaction, not merely hand off credentials to a backend. Practical implication: combine authentication controls with application integrity and runtime tamper resistance.
Practical implication: combine authentication controls with application integrity and runtime tamper resistance.
Threat narrative
Attacker objective: The attacker’s objective is to convert trusted identity and transaction access into authorised fraud, account takeover, or unauthorised payments.
- Entry begins when attackers use phishing, impersonation, deepfake-assisted social engineering, or compromised mobile environments to reach a trusted user or transaction path.
- Credential access or abuse follows when the attacker captures passwords, passkeys, session access, or delegated payment authority and uses them within the authenticated channel.
- Escalation occurs when the attacker moves from access to authorised fraud by initiating transfers, account takeover actions, or agent-driven transactions that appear legitimate to point controls.
- Impact is realised through fraud loss, manipulated account records, and fraudulent transactions that bypass controls focused only on initial authentication.
Breaches seen in the wild
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Authentication is becoming a trust negotiation, not a gate. The article correctly shows that human login controls are no longer enough when transactions move through devices, fraud engines, and agent-mediated workflows. The governance shift is from proving initial access to continuously validating intent, authority, and context across the full journey. Practitioners should treat authentication as one layer in a broader dynamic trust model.
Agentic commerce creates an accountability gap that classical IAM does not resolve. A consumer may authorise an agent, but the platform still has to decide what that agent is allowed to do, when it may do it, and how far delegated authority extends. That is not the same problem as password authentication or even step-up MFA. The implication is that identity programmes will need policy expression for delegation, transaction scope, and revocation boundaries.
Dynamic trust stacks are now the organising principle for fraud and identity convergence. OneSpan’s framing makes clear that authentication, verification, fraud detection, device risk, and application integrity are no longer separate workstreams. They are interdependent controls that must share signals if they are going to stop authorised fraud and impersonation at the transaction layer. Practitioners should expect governance, fraud, and IAM teams to converge around shared decisioning.
Mobile app security now belongs inside identity governance, not beside it. If the app or device layer can be manipulated, then authentication outcomes become weak evidence rather than durable assurance. That is why mobile protection, behavioural analytics, and transaction validation are converging with identity controls. The practical conclusion is that identity assurance has to extend into runtime integrity, not stop at credential verification.
From our research library:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
What this signals
Delegated identity will force IAM and fraud teams into the same control plane. Agentic commerce, customer authentication, and transaction monitoring now overlap in ways that make siloed ownership brittle. Programmes that still separate identity proof, fraud detection, and app integrity will struggle to explain who owns trust when an agent acts on behalf of a customer.
Continuous trust is the new design requirement. The article’s real signal is not that authentication is failing, but that it is being asked to do a job it was never designed to do alone. Practitioners should expect governance to move toward continuous verification, shared signal correlation, and tighter policy around delegated authority.
For practitioners
- Define delegated transaction scope Map exactly what an AI agent or digital assistant may buy, approve, transfer, or negotiate on behalf of a user, and require explicit policy for limits, revocation, and high-risk steps.
- Correlate authentication with device and behavior signals Feed device risk, behavioural anomalies, and transaction context into the fraud decision rather than treating successful login as sufficient evidence of legitimacy.
- Harden mobile runtime integrity Assume the app environment can be inspected or manipulated and add runtime protection, integrity checks, and anti-tamper controls around sensitive banking and payment flows.
- Review authentication design for AI-assisted commerce Test whether passkeys, MFA, and step-up controls still hold when a transaction is initiated or completed by an agent rather than by the human account owner.
Key takeaways
- Authentication remains necessary, but it is no longer sufficient when AI agents, mobile apps, and fraud workflows all participate in the same transaction path.
- The strongest defence pattern combines identity proof, device risk, behavioural analytics, and application integrity so fraud is detected after login as well as before it.
- IAM teams should now govern delegated authority and transaction scope as first-class controls, especially where agentic commerce is expected to grow.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agentic commerce depends on delegated identity and privilege that can be misused mid-transaction. |
| ASI02 — Tool Misuse | AI agents shopping or transacting can invoke the wrong tools or flows if scope is not constrained. | |
| Recommendation — Restrict agent privileges to the minimum transaction scope and revalidate authority before sensitive actions. Bind agent workflows to approved tools and block unsupported transaction paths by policy. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The newsletter centers on authentication changes as fraud and delegated commerce converge. |
| NHI-10 — Human Use of NHI | Agentic commerce blurs human and machine use of the same identity and access flows. | |
| Recommendation — Harden NHI and customer authentication paths against phishing, replay, and delegated access abuse. Separate human-authenticated actions from machine-executed actions and record which identity acted. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article’s core issue is ongoing authorisation across transactions, not login alone. |
| Recommendation — Reassess entitlements and authorisations for delegated transactions and step-up on high-risk actions. | ||
Key terms
- Agentic Commerce: Agentic commerce is a buying and transaction model where software agents act on behalf of a person. The identity challenge is not just proving who owns the account, but constraining what the agent may do, for how long, and under what revocation and audit rules.
- Dynamic Trust: Dynamic trust is a model where access is re-established based on current context rather than assumed from a previously issued credential. For machine identities, this means access decisions should reflect workload, environment, and policy at the point of use, not just at enrollment.
- Transaction Journey: The end-to-end path a payment or account action follows from initiation to completion. In identity security, the transaction journey matters because compromise can occur after login, so controls must assess intent, device state, and behavioural consistency throughout the flow.
- Application Integrity: Application integrity is the assurance that delivered software has not been altered in ways that change expected behaviour. For client-side applications, it includes resistance to tampering, script modification, instrumentation, and abuse of exposed logic.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org