Mastercard is rewriting its risk framework because AI shopping agents are now making legitimate purchases that trigger fraud alerts [1].

This shift represents a fundamental change in digital commerce. For years, automated scripts were viewed primarily as tools for theft, but the rise of consumer-led AI agents is turning those same patterns into valid transactions.

Greg Ulrich said the challenge during a presentation in Menlo Park on July 14 [1]. He said that the company spent decades building a defense system specifically designed to block automated activity. This legacy approach creates a conflict as AI agents begin to act on behalf of human users to complete purchases [1].

"We've built a bunch of risk rules over time that were intended to stop a bot from ..." Ulrich said [1].

The scale of the challenge is significant given the volume of activity the network handles. Mastercard processes 175 billion transactions [1]. When a system is trained to see bots as thieves, the sudden influx of authorized AI buyers can lead to high rates of false positives, where legitimate purchases are blocked.

To address this, the company is updating the rules that govern how it identifies the source of a transaction. The goal is to distinguish between malicious bots and AI agents that have been authorized by a cardholder to manage their spending [1]. This requires a transition from a binary "bot or human" detection model to a more nuanced understanding of agent intent and authorization [1].

AI shopping agents are now making legitimate purchases that trigger fraud alerts.

The transition toward 'agentic commerce' is forcing a paradigm shift in cybersecurity. By moving away from simple bot detection and toward authorization-based verification, Mastercard is acknowledging that AI will soon be the primary interface for many financial transactions. This evolution is necessary to prevent the friction of false fraud declines from stifling the adoption of AI-driven consumer spending.