Banking · July 31, 2026
Mastercard Rebuilds Fraud Logic for Agentic AI Payments
Mastercard is restructuring its fraud-detection framework to allow autonomous AI agents to transact legitimately across its 175-billion-transaction-per-year network.
What happened
Mastercard is overhauling the fraud-detection logic at the heart of its global payments network to accommodate a fundamental shift in who — or what — is initiating purchases. Speaking at VB Transform 2026 in Menlo Park on 14 July, Greg Ulrich, Mastercard's chief AI and data officer, told attendees that the company's risk framework, built over decades to treat automated bots as a signal of fraud, must now be restructured to allow those same bots to transact legitimately.
The trigger is the rapid rise of agentic AI: autonomous software that acts on behalf of consumers to browse, select and pay for goods and services without a human clicking "confirm." Ulrich acknowledged the scale of the challenge plainly: Mastercard's network processes roughly 175 billion transactions per year, each assessed for fraud risk in under a tenth of a second. Rules written to flag non-human behaviour as suspicious are now, by definition, at risk of blocking legitimate AI-driven commerce.
Ulrich, who joined Mastercard eleven years ago when the analytics firm he worked for was acquired, framed trust as the foundational currency of the entire payments ecosystem — the invisible contract that lets a merchant accept payment from a stranger and a consumer expect delivery in return. Extending that contract to machine-initiated transactions is, he argued, the defining infrastructure challenge of the current AI moment.
Why it matters
For customer-experience and service-design practitioners, this is a signal that the customer journey is about to gain a new, non-human actor at its most sensitive touchpoint: payment. When an AI agent completes a purchase on a user's behalf, the traditional behavioural cues that fraud systems — and indeed, merchants — rely upon to confirm intent simply disappear. There is no hesitation, no browsing pattern, no device fingerprint that looks like a person. The entire trust architecture of digital commerce was designed around human decision-making, and agentic AI breaks those assumptions at speed and scale.
From a behavioural-economics perspective, the deeper issue is the delegation of choice. Consumers who authorise an AI agent to shop for them are exercising a form of bounded rationality — offloading cognitive effort — but they retain accountability for the outcome. Merchants and payment networks must therefore build new consent and verification layers that preserve consumer protection without creating so much friction that the convenience proposition of agentic AI collapses entirely. Getting that balance wrong in either direction carries significant cost: false positives frustrate customers, while false negatives enable fraud at machine speed.
By the numbers
- 175 billion transactions processed by Mastercard's network in the past year, each assessed for fraud risk.
- Less than one tenth of a second — the window in which Mastercard's system must make each fraud determination.
- 11 years — Greg Ulrich's tenure at Mastercard, dating to the acquisition of his former analytics employer.
The Renascence take
Most commentary on agentic AI focuses on convenience and efficiency gains for the end user. What Mastercard's disclosure reveals is that the real design problem sits one layer deeper — in the identity and intent verification infrastructure that commerce runs on. The industry is not ready for this, and the gap between "AI can buy things" and "payment networks trust AI buying things" is where customer experience will be won or lost.
The instinct will be to bolt new verification steps onto existing fraud frameworks — essentially asking bots to prove they are "good" bots. That is the wrong starting point. A customer-obsessed operator should instead redesign consent architecture from the customer's perspective outward: what does a person actually authorise when they activate an AI agent, and how is that authorisation made legible to every downstream system in real time? Trust in agentic commerce will not come from better bot-detection; it will come from clearer, portable, human-anchored delegation signals. Operators who invest in that layer now will own the experience when agentic purchasing goes mainstream.
Sources
This briefing was written by the Renascence newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
More in Banking
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.