TL;DR: Traditional bots follow fixed scripts, while AI agents adapt to context and outcomes, making malicious automation harder to spot and more expensive to block, according to Signifyd. The practical issue is no longer just scale, but whether fraud controls can separate legitimate automation from adaptive abuse without driving false declines.
At a glance
What this is: This article explains why ecommerce fraud controls that work against fixed-script bots are less reliable against AI agents that can vary timing, signals and transaction details.
Why it matters: It matters because IAM, fraud, and trust teams now need to evaluate account control, authorization, and behavioral signals together across the full customer journey.
By the numbers:
- Fraudsters now use AI tooling to run attacks that are 4.5 times more profitable, pushing North American fraud pressure up 33% in early 2026 versus 2025.
- Signifyd data found that AI-driven card-testing incidents jumped 175% between Jan. and April 2026 compared with the same stretch in 2025.
- A 2026 LexisNexis study found that every dollar retailers lose directly to fraud actually costs U.S. retailers about $5.13 once chargebacks, operations costs and product losses are factored in.
👉 Read Signifyd's analysis of bots versus AI agents in ecommerce fraud
Context
Ecommerce fraud is shifting from repetitive bot activity to adaptive automation that can adjust to context, which makes simple block or allow rules less effective. The primary issue is not just traffic volume, but whether controls can distinguish fixed-script bots from AI agents that mimic legitimate shopping behavior while pursuing fraud.
That distinction has an identity dimension because account control, authorization, and customer behavior now determine whether an automated session is legitimate or abusive. For IAM and fraud teams, the operational question is how to evaluate trust across the journey, not only at login or checkout.
Key questions
Q: How should merchants distinguish AI agents from fraud bots in ecommerce traffic?
A: Merchants should combine behavioural analytics with device trust, transaction history and policy scope rather than relying on browsing depth alone. Legitimate AI agents often move quickly and with fewer human signals, so the control goal is to identify customer-authorised automation without opening the door to hostile bots. That requires risk scoring before checkout, not after the order is already complete.
Q: Why do AI agents make fraud controls less reliable?
A: AI agents can change timing, transaction amounts, device attributes, and other signals after each outcome, which defeats controls that depend on repetition. That means a valid-looking session can still be abusive if it is learning from declines or challenges. The control goal becomes detecting adaptation and intent, not just volume.
Q: What breaks when fraud controls rely on a single signal?
A: Single-signal decisions are easy to bypass because one indicator can be benign in isolation. A new device or fast session may be legitimate, but the combination of unusual order value, changed payment details, and inconsistent account history often reveals abuse. Correlation is what turns weak signals into a useful decision.
Q: Who is accountable when fraud controls block legitimate customers in real time?
A: Accountability should sit with the team that owns the end-to-end decision path, not only the fraud model. If checkout, identity, and risk signals are not orchestrated into one control, then the business is responsible for the conversion loss as well as the fraud loss. Governance needs shared ownership across fraud, product, and security leaders.
Technical breakdown
Why AI agents break traditional bot detection
Traditional bot controls work because many bot attacks are repetitive: the same request patterns, the same timing, and the same transaction shape. AI agents change that. They can interpret outcomes, alter timing, vary device or transaction signals, and continue probing after a decline or challenge. That makes them look less like a single scripted attack and more like a sequence of related human-like decisions. In fraud operations, this matters because a policy tuned to repetitive behaviour can miss adaptive abuse or incorrectly block efficient but legitimate automation.
Practical implication: tune detection for behavioural drift and outcome-based adaptation, not only for repetition.
Connected signals are more reliable than single-point checks
A single signal rarely proves legitimacy or fraud. A new device, fast session, shipping change, or high-value order can each be benign on its own. The better approach is signal correlation across identity, device, payment, account history, and transaction behaviour. This is especially important when automation is authorised, because the system must separate permitted machine-driven activity from account takeover, promo abuse, or card testing. In governance terms, the risk is treating one good signal as proof of trust, when fraud often emerges from the combination of several weak signals.
Practical implication: evaluate identity, device, payment, and behaviour together before making approve or decline decisions.
Why account control and authorization still matter in automation
The article’s identity angle is that valid credentials do not equal valid intent. An attacker using stolen account access can still change shipping details, alter payment methods, or submit unusual orders that do not match the account’s normal history. That means fraud controls need to test whether the current session still reflects the original account holder’s authorization. In practice, this moves fraud and IAM closer together: the question is not just whether credentials are correct, but whether the person or agent using them still has the right to act in that way.
Practical implication: add step-up checks when session behaviour diverges from historical account patterns.
Threat narrative
Attacker objective: The attacker aims to maximise fraudulent revenue while avoiding detection by making each attempt appear different enough to bypass static controls.
- Entry begins with scripted or AI-assisted probes against login, checkout, or promotion flows, often using stolen credentials, device signals, or disposable identities.
- Escalation happens when the attacker varies timing, order values, device attributes, or claims based on which attempts succeed or fail, reducing the usefulness of static bot rules.
- Impact is fraudulent purchase completion, card testing, promo abuse, refund abuse, or account takeover that increases losses and false declines at the same time.
NHI Mgmt Group analysis
Adaptive automation changes the fraud control problem from signature detection to trust evaluation. Traditional bot management is built to catch repetition, but AI-assisted fraud can change pace, device signals, and transaction shape after each outcome. That means the control question shifts from 'is this a bot' to 'is this session still acting within authorised intent.' Practitioners should treat behavioural variance as a governance issue, not just a tuning problem.
Account control is now a fraud and identity concern, not only a login concern. The article shows why valid credentials and valid payment details are no longer enough to establish trust. Once an attacker or agent can act inside a live account, downstream actions matter more than the initial authentication event. IAM and fraud teams should align around authorization boundaries, not just access approval.
False declines are part of the risk surface, not a side effect. Controls that are too blunt will block legitimate shopping automation and create revenue friction, while controls that are too loose will miss adaptive abuse. The practical conclusion is that fraud governance now depends on contextual decisioning that preserves both customer experience and account integrity.
Identity and fraud programmes need a shared model for machine-mediated customer activity. When authorised AI agents shop, support, or post-purchase tools act on behalf of customers, the boundary between legitimate automation and abuse becomes a policy problem. That makes identity verification, authorization, and behavioural analytics part of the same control plane. Teams should define which automated actions are permitted, which require challenge, and which are never allowed.
Signal correlation is the named concept here: isolated checks cannot keep pace with adaptive abuse. The article’s core lesson is that one signal, whether device, velocity, or account age, is too easy for an attacker or AI agent to manipulate. The stronger governance pattern is cross-signal decisioning that looks for consistency across identity, payment, and order behaviour. Practitioners should build controls around signal combinations, not single indicators.
What this signals
Adaptive fraud detection will increasingly look like authorisation governance. As AI agents become more common in customer-facing workflows, merchants need controls that understand which actions are permitted, not just which requests are automated. The programme implication is that fraud, IAM, and customer experience teams will have to coordinate thresholds, escalation paths, and challenge logic around the same identity signals.
Machine-mediated customer activity needs explicit policy boundaries. If an automated session can shop, refund, or update account data on behalf of a customer, the organisation must define what 'allowed' means across each step of the journey. That governance model should be documented alongside account recovery, chargeback handling, and dispute workflows, not left to ad hoc operational decisions.
The broader signal is that identity verification and fraud prevention are converging around behavioural consistency, access context, and account control. Teams that already use Top 10 NHI Issues will recognise the same pattern in non-human access: if the actor can change behaviour faster than rules can be tuned, you need stronger context, not more brittle signatures.
For practitioners
- Implement cross-signal fraud decisioning Correlate identity, device, payment, account history, and order behaviour before approving high-risk actions. Use the full customer journey, not just login or checkout, so AI-assisted abuse cannot exploit a single weak signal.
- Separate authorised automation from abusive automation Define which customer-facing AI agents or workflows are allowed to place orders, change details, or request refunds, and require stronger checks when activity departs from normal account history.
- Tune controls for adaptive patterns Look for low-and-slow probing, small changes after declines, and mixed transaction values that indicate the attacker is learning from each attempt rather than repeating the same script.
- Track false declines alongside fraud loss Measure approval rate, false decline rate, chargeback rate, and manual review rate together so you can see when fraud prevention is suppressing legitimate automation.
Key takeaways
- AI-assisted fraud makes adaptive behaviour more dangerous than simple volume because it can learn from each blocked attempt.
- The real control gap is not login verification alone, but whether account actions remain authorised throughout the customer journey.
- Merchants need correlated identity, device, payment, and behavioural signals to reduce fraud without driving avoidable false declines.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | NHI-03 is relevant where automated actors rely on abused credentials and account control. |
| NIST CSF 2.0 | PR.AC-4 | The article centres on access authorization and session trust decisions. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is central to detecting misuse of customer accounts and automated sessions. |
| CIS Controls v8 | CIS-5 , Account Management | Account management controls are needed to govern account takeover and unusual session behaviour. |
| NIST AI RMF | GOVERN | AI RMF GOVERN applies where AI-assisted automation needs policy boundaries and accountability. |
Monitor account changes and step up verification when account state shifts unexpectedly.
Key terms
- Adaptive automation: Automation that changes its behaviour based on live inputs rather than fixed rules alone. It is useful in variable environments, but it still requires clear guardrails, validation, and ownership so that flexibility does not turn into uncontrolled decision-making.
- False decline: A false decline is a legitimate transaction that is rejected because the fraud controls interpret it as risky. It matters because the operational cost is not limited to one lost sale. It can also damage customer trust, reduce retention, and distort fraud programme metrics.
- Connected Signals: Multiple indicators used together to judge whether an action is trustworthy, such as identity, device, payment, account history, and behaviour. Connected signals are stronger than isolated checks because fraud often looks normal on one dimension while revealing itself in the combination.
- Account Control: The degree to which a session or actor demonstrably controls an account and is authorised to act on its behalf. In modern fraud and identity governance, account control is more important than credentials alone because valid access can still be used for unauthorised intent.
What's in the full article
Signifyd's full post covers the operational detail this post intentionally leaves for the source:
- The specific fraud patterns Signifyd maps to bots versus AI agents, including checkout abuse, card testing, and account takeover.
- Examples of how the vendor evaluates connected signals across identity, device, payment, and behaviour.
- Operational guidance on when to step up verification, review account-control changes, and preserve legitimate automation.
- The reported revenue impact of false declines and the supporting calculations used in the article.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management in practical terms. It helps security practitioners connect identity controls to broader risk decisions across modern digital systems.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org