Security teams should focus on behavioural signals across the full customer journey, from account creation through login, checkout, and post-purchase activity. Static rules alone miss adaptive fraud and create false positives. The stronger approach is continuous monitoring, real-time risk scoring, and dynamic friction that increases verification only when risk rises. That keeps legitimate users moving while disrupting AI-assisted attacks earlier.
What to look for when fraud adapts to the customer journey
AI-driven fraud rarely fails at a single step. It tends to look human enough at sign-up, login, checkout, and post-purchase activity to slip past one-off checks, then changes tactics as soon as the environment gets harder. The practical answer is to score the whole journey as one sequence, not a set of isolated events.
That means teams should weight signals that are hard to fake at scale, such as velocity changes, device and session consistency, interaction timing, navigation patterns, delivery changes, and account recovery behaviour. These signals are most useful when correlated over time, because the attack often becomes obvious only after several small anomalies line up.
Continuous monitoring becomes more valuable than static rules when the fraud model can adapt faster than a fixed policy. A rule can still catch obvious abuse, but the decisioning layer should be able to reinterpret the same behaviour in context, especially when legitimate users naturally create unusual patterns during high-value purchases or account recovery.
- Track transitions between journey stages, not just single-step failures.
- Look for repeated low-and-slow anomalies rather than only obvious threshold breaches.
- Use step-up checks only when the behavioural pattern becomes materially risky.
For a broader security-control view of the same operating model, the NIST Cybersecurity Framework 2.0 is a useful reference because it ties detection and response to ongoing risk management rather than one-time checks.
NHIMG’s Ultimate Guide to NHIs and 2026 Identity Security Trends & Predictions are also useful where fraud paths rely on weak credential hygiene, over-privileged access, or poor visibility into reusable access material.
How to add friction only when the risk justifies it
The key design choice is not whether to use friction, but where to place it. Legitimate customers should flow through the default path, while suspicious sessions are asked to prove more only when the current evidence suggests the risk has crossed a meaningful threshold. That keeps friction proportional and reduces the common failure mode where every customer gets treated like a suspect.
Dynamic friction works best when it is progressive. Start with passive controls such as scoring, watchlists, and silent enrichment, then move to step-up verification, rate limiting, or temporary holds only if the risk remains elevated. This avoids overreacting to ordinary customer behaviour such as travel, new devices, or larger-than-usual orders.
Teams should also be careful not to overfit to one fraud pattern. AI-assisted attackers can change text, timing, and navigation while keeping the underlying abuse the same, so the decisioning logic needs to recognise relationships among signals rather than depend on one brittle indicator. The more the control can adapt, the less often it needs to interrupt a legitimate user.
In practice, this means verification should feel conditional rather than universal. The customer should only see added friction when the model is confident that the marginal security value is worth the conversion cost, support burden, and user frustration.
- Prefer silent enrichment first, visible friction second.
- Escalate only on combined risk, not on one noisy signal.
- Keep step-up challenges short, explainable, and recoverable.
AI-specific detection and response patterns are also reflected in the NIST Cyber AI Profile (IR 8596), which aligns cybersecurity functions to AI risk management for detection and response.
Practitioner guidance for balancing detection and customer experience
What to measure: Track false-positive rate, step-up challenge abandonment, fraud catch rate, and the share of high-risk sessions that were disrupted before value transfer. If friction is rising but fraud loss is not falling, the policy is probably too blunt or too late in the journey.
Decision rule: If a signal only works as a blunt deny-list, treat it as a coarse filter rather than a customer-facing control. If the signal improves confidence when combined with other behavioural evidence, it belongs in the real-time risk score and can justify graduated friction.
What practitioners underestimate: The hardest part is not detecting suspicious automation, it is preserving trust when legitimate customers are asked to prove themselves. Good controls are visible enough to stop abuse, but narrow enough that most customers never notice them.
Practitioner takeaway: The best anti-fraud design is usually a risk-adaptive one, because customer experience deteriorates faster from unnecessary friction than from well-targeted step-up verification.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM — Security Continuous Monitoring | Continuous behavioural monitoring is central to detecting adaptive fraud. |
| PR.AA — Identity Management, Authentication and Access Control | Step-up checks and account recovery controls depend on authentication strength and access assurance. | |
| RS.AN — Analysis | Fraud signals must be analysed in context to separate legitimate edge cases from abuse. | |
| Recommendation — Monitor customer-journal behaviour continuously and correlate anomalies into live risk decisions. Apply stronger authentication only when risk signals justify extra verification. Analyse multi-signal fraud patterns before escalating customer friction. | ||
| CIS Controls v8 | 6 — Access Control Management | Risk-based friction is an access decision that should preserve least-privilege customer flows. |
| 8 — Audit Log Management | Journey-stage monitoring depends on reliable logs and traceable user actions. | |
| Recommendation — Restrict elevated verification to sessions that warrant it. Collect and retain event logs that support behaviour-based fraud detection. | ||
| MITRE ATT&CK | T1110 — Brute Force | Adaptive fraud often includes automated credential and login abuse that requires behavioural detection. |
| Recommendation — Hunt for automated login abuse and rate-limit suspicious authentication attempts. | ||
Related resources from NHI Mgmt Group
- How should security teams detect AI-generated identity documents without adding friction for legitimate users?
- How should security teams reduce online payment fraud without creating excessive friction for legitimate customers?
- How should security teams detect AI agent traffic without blocking legitimate customers?
- How should security teams reduce return fraud without hurting legitimate customers?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org