Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should merchants balance password-free checkout with fraud…
Identity Beyond IAM

How should merchants balance password-free checkout with fraud prevention as agentic commerce grows?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 8, 2026 Domain: Identity Beyond IAM

Merchants should treat password-free checkout as an authentication design problem, not just a UX upgrade. The goal is to reduce friction for known users while adding stronger checks for unknown or risky sessions. Device intelligence helps by recognizing returning devices, flagging suspicious behaviour, and escalating friction only when the risk profile changes. That balance protects conversion without opening the door to more payment fraud.

Password-free checkout is an identity decision, not only a conversion decision

Password-free checkout changes the trust model at the point of payment. Instead of asking the shopper to prove identity with a static secret, merchants rely more heavily on session context, device signals, behavioural consistency, and step-up checks when the transaction looks abnormal. That can improve conversion and reduce account fatigue, but it also shifts fraud pressure toward account takeover, synthetic identity abuse, and scripted purchase attempts that exploit weak recovery or permissive session reuse. For that reason, the question is less about whether passwords disappear and more about how assurance is rebuilt without creating friction for genuine customers. For a broader AI governance lens on this shift, see OWASP Top 10 for Agentic Applications 2026.

In practice, many merchants discover the control gap only after a frictionless flow becomes the easiest path for automated abuse, rather than through intentional design of adaptive trust.

How merchants balance low-friction checkout with fraud controls in practice

The practical balance is to separate convenience from assurance. Known-good shoppers should move through a low-friction path when the signals around them are stable, while unknown, new, or inconsistent sessions should trigger progressive verification. That means checkout design should combine device reputation, account history, velocity checks, basket characteristics, payment risk, and behavioural signals rather than leaning on one factor alone. If the merchant is growing into agentic commerce, the same logic extends to delegated actions: an AI agent may act on behalf of a user, but the merchant still needs to distinguish a legitimate delegated purchase from an automated abuse attempt.

The strongest implementations do three things well. First, they preserve continuity for returning shoppers by recognising trusted devices and sessions without storing more trust than is justified. Second, they make escalation conditional, so step-up authentication appears only when risk indicators change materially. Third, they ensure the fraud model is not blinded by “passwordless” branding. A password-free flow can still require challenge, re-authentication, or transaction confirmation when the risk profile suggests takeover, bot activity, or abnormal purchase intent.

  • Use session and device context to keep routine purchases smooth.
  • Trigger additional checks when location, behaviour, velocity, or basket risk deviates.
  • Apply stronger confirmation for account changes, first-time devices, and high-value orders.
  • Treat AI-mediated checkout as a separate trust condition, not the same as a returning human user.

Where this guidance breaks down is when merchants lack reliable telemetry, because adaptive friction becomes guesswork and both fraud and abandonment rise.

Where passwordless breaks down: delegation, device churn, and bot pressure

Tighter checkout controls often increase operational complexity, requiring merchants to balance lower abandonment against the cost of weaker fraud visibility. The edge cases matter most when customer devices change frequently, travel patterns are volatile, or legitimate shoppers use shared devices and privacy tools that weaken device confidence. In those conditions, a simple “trusted device equals trusted user” rule becomes brittle. The same problem appears when merchants start accepting agentic purchases: an agent may generate more consistent machine behaviour than a human shopper, but that consistency alone does not prove the action is authorised.

Industry consensus is still forming on how much autonomy merchants should grant agent-driven checkout, especially when delegated purchasing, stored credentials, and payment approval all intersect. The conservative approach is to bind trust to a specific user, device, and transaction scope rather than to a generic account state. That helps reduce the blast radius if a session is hijacked or if a legitimate agent is repurposed for abuse. For identity assurance context, merchants can also review the eIDAS 2.0 EU Digital Identity Framework where formal digital identity assurance is relevant to the checkout model.

Merchants get into trouble when they assume frictionless checkout and fraud prevention are competing goals rather than two parts of the same trust policy.

Risk and Threat Considerations

Password-free checkout can increase exposure to account takeover, automated purchase abuse, and delegated-agent misuse if the merchant treats session convenience as proof of identity. In agentic commerce, the threat is not only a stolen account, but also a trusted automation path that can perform purchases at scale before the merchant notices abnormal behaviour.

Failure mechanism: Attackers exploit weak session binding, over-trusted devices, or permissive recovery flows to reuse access without needing a password. Bot-driven checkout can also exploit low-friction flows by mimicking legitimate behaviour until a payment or fulfilment step is reached, while agentic workflows may extend that trust into repeated authorised-looking transactions.

Impact: Merchants can see higher chargeback rates, account compromise, fulfilment abuse, and degraded confidence in fraud controls. If delegated checkout cannot be distinguished from legitimate user intent, the merchant loses the ability to apply proportional step-up checks where they matter most.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST AI RMF, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10A1 — Agentic Access ControlAgent-mediated checkout changes delegated action and trust boundaries.
Recommendation — Bind agent actions to scoped permissions and require explicit confirmation for high-risk purchases.
NIST AI RMFGOV-2 — Map AI RisksAdaptive checkout using AI needs explicit risk identification and governance.
Recommendation — Map AI-mediated checkout risks and define escalation rules for abnormal agent behaviour.
MITRE ATLASAML.T0001 — Input ManipulationFraud actors can manipulate behavioural and session signals in AI-enabled commerce.
Recommendation — Hunt for manipulated signals and model evasions that let fraud mimic legitimate intent.
CIS Controls v86.1 — Access Control ManagementPassword-free checkout still requires strict control over access and session trust.
Recommendation — Restrict checkout access paths and revoke trust quickly when sessions become suspicious.
NIST CSF 2.0PR.AC-7 — Users, devices, and permissions are managed commensurate with riskRisk-based checkout depends on managing users and devices by trust level.
Recommendation — Adjust authentication friction to the risk posed by each user, device, and session.

Practitioner Guidance

What to prioritise: Treat trust as session-specific, not account-wide. The control objective is to preserve convenience for stable, known-good sessions while making risky paths expensive enough to deter abuse without punishing ordinary shoppers.

Decision rule: If device confidence, behavioural consistency, and transaction context all align, keep the flow light; if any of those signals drift, escalate to stronger confirmation before authorising payment or fulfilment.

What practitioners underestimate: Agentic commerce changes the meaning of “normal” purchase behaviour. Teams often tune fraud rules only for human shoppers and then discover that delegated automation can look unusually consistent, which can either evade weak controls or trigger false positives if the model is not adapted.

Practitioner takeaway: The best balance is not “passwordless versus secure”; it is a risk-based checkout model that preserves conversion for trusted intent while forcing clearer proof when the user, device, or agent ceases to look trustworthy.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org