Join our Newsletter — 33% off our NHI Course

PSD3 and AI agent payments: are current controls enough?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: PSD3 is moving European payment rules toward bank liability for bank impersonation scams and stronger fraud prevention expectations, while also signalling that AI agents are not yet covered by current legislation, according to OneSpan's interview with ThreatFabric's Eward Driehuis. The gap is no longer theoretical: payment governance is now colliding with delegated automation, and identity controls must catch up.

Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “PSD3 updates: Deep dive on fraud prevention, bank liability, and the regulatory impact”.

Key questions

Q: What breaks when AI agents can initiate payments without verified consent?

A: When consent is not verified, the trust chain becomes weak at the exact point where payment decisions are made.

Q: Why do bank impersonation scams matter more under PSD3 than under older payment rules?

A: Because PSD3, as described in the article, moves liability toward the bank when impersonation of the bank or its staff leads to fraud.

Q: What are the main mistakes teams make when governing delegated payment activity?

A: The biggest mistake is treating customer authentication as if it automatically authorises any software acting for that customer.

Practitioner guidance

  • Map impersonation scenarios to the full fraud chain Trace where a bank impersonation scam starts, how it reaches payment initiation, and which control owner is accountable at each stage.
  • Define a delegated payment authority model Specify what an AI agent may do, which payment types it may access, and what approval or constraint logic applies before execution.
  • Review fraud signals that depend on human behaviour Identify any detection logic built on user cadence, typing, device familiarity, or session behaviour, then determine how it fails when a software agent performs the action instead of a person.

Bottom line: PSD3 is pushing bank impersonation scams into a clearer liability framework, but the operational burden shifts earlier in the control chain.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

PSD3 is shifting fraud liability, but the deeper issue is identity accountability across the payment chain. The article shows that banks may become liable for bank impersonation scams even when the initial deception starts outside the banking application. That means the governance question is no longer confined to transaction monitoring, but extends to where identity influence begins and ends across channels. Practitioners should treat liability as a signal that identity assurance now spans messaging, payment initiation, and fraud response.

A few things that frame the scale:

A question worth separating out:

Q: What should payment teams do when fraud originates outside the banking app?

A: They should treat the payment app as one control point in a wider deception chain, not the whole problem. That means tracing social media, messaging, telecom, and handoff channels back to the payment event, then assigning responsibility based on where the impersonation and authority abuse actually occurred.

👉 Read our full editorial: PSD3, fraud liability, and the limits of AI agent governance


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.