TL;DR: Authentication, fraud prevention, and application security are converging around stronger trust, verification, and layered controls as OneSpan’s January 2026 newsletter ties together its Build38 acquisition, 2025 fraud trends, PSD3 and PSR updates, and emerging risks from agentic commerce.
Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “The Authentication Newsletter for January 2026”.
Key questions
Q: How should organisations govern sub-agents in agentic commerce?
A: Organisations should treat sub-agents as separately governed actors with explicit scope, bounded delegation depth, and revocation tied to the parent workflow.
Q: How should fraud teams combine behavioural signals and device fingerprinting?
A: Fraud teams should combine both in the same decision engine so session behaviour is interpreted in the context of a durable device identifier.
Q: What breaks when a mobile identity is not kept inside the government app?
A: When the mobile identity is not kept inside the government app, trust boundaries expand and key handling becomes harder to control.
Practitioner guidance
- Define delegated transaction scope Map exactly what an AI agent or digital assistant may buy, approve, transfer, or negotiate on behalf of a user, and require explicit policy for limits, revocation, and high-risk steps.
- Correlate authentication with device and behavior signals Feed device risk, behavioural anomalies, and transaction context into the fraud decision rather than treating successful login as sufficient evidence of legitimacy.
- Harden mobile runtime integrity Assume the app environment can be inspected or manipulated and add runtime protection, integrity checks, and anti-tamper controls around sensitive banking and payment flows.
Bottom line: Authentication remains necessary, but it is no longer sufficient when AI agents, mobile apps, and fraud workflows all participate in the same transaction path.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authentication is becoming a trust negotiation, not a gate. The article correctly shows that human login controls are no longer enough when transactions move through devices, fraud engines, and agent-mediated workflows. The governance shift is from proving initial access to continuously validating intent, authority, and context across the full journey. Practitioners should treat authentication as one layer in a broader dynamic trust model.
A few things that frame the scale:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
A question worth separating out:
Q: Should passkeys replace fraud controls in customer authentication programmes?
A: No. Passkeys reduce phishing risk, but they do not replace fraud detection, device intelligence, or transaction validation. The strongest programme uses phishing-resistant authentication as one input to a broader decision model that also checks behaviour, device state, and the legitimacy of the transaction itself.
👉 Read our full editorial: Authentication, fraud and agentic commerce are converging in 2026