Join our Newsletter — 33% off our NHI Course

Agentic commerce and authentication risk: what IAM teams need now

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Authentication, fraud prevention, and application security are converging around stronger trust, verification, and layered controls as OneSpan’s January 2026 newsletter ties together its Build38 acquisition, 2025 fraud trends, PSD3 and PSR updates, and emerging risks from agentic commerce.

Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “The Authentication Newsletter for January 2026”.

Key questions

Q: How should organisations govern sub-agents in agentic commerce?

A: Organisations should treat sub-agents as separately governed actors with explicit scope, bounded delegation depth, and revocation tied to the parent workflow.

Q: How should fraud teams combine behavioural signals and device fingerprinting?

A: Fraud teams should combine both in the same decision engine so session behaviour is interpreted in the context of a durable device identifier.

Q: What breaks when a mobile identity is not kept inside the government app?

A: When the mobile identity is not kept inside the government app, trust boundaries expand and key handling becomes harder to control.

Practitioner guidance

  • Define delegated transaction scope Map exactly what an AI agent or digital assistant may buy, approve, transfer, or negotiate on behalf of a user, and require explicit policy for limits, revocation, and high-risk steps.
  • Correlate authentication with device and behavior signals Feed device risk, behavioural anomalies, and transaction context into the fraud decision rather than treating successful login as sufficient evidence of legitimacy.
  • Harden mobile runtime integrity Assume the app environment can be inspected or manipulated and add runtime protection, integrity checks, and anti-tamper controls around sensitive banking and payment flows.

Bottom line: Authentication remains necessary, but it is no longer sufficient when AI agents, mobile apps, and fraud workflows all participate in the same transaction path.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Authentication is becoming a trust negotiation, not a gate. The article correctly shows that human login controls are no longer enough when transactions move through devices, fraud engines, and agent-mediated workflows. The governance shift is from proving initial access to continuously validating intent, authority, and context across the full journey. Practitioners should treat authentication as one layer in a broader dynamic trust model.

A few things that frame the scale:

A question worth separating out:

Q: Should passkeys replace fraud controls in customer authentication programmes?

A: No. Passkeys reduce phishing risk, but they do not replace fraud detection, device intelligence, or transaction validation. The strongest programme uses phishing-resistant authentication as one input to a broader decision model that also checks behaviour, device state, and the legitimacy of the transaction itself.

👉 Read our full editorial: Authentication, fraud and agentic commerce are converging in 2026


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.