With AI-powered shopping moving from concept to reality, the conversation is no longer whether AI will shop on our behalf, but how businesses can build trust when AI starts making purchasing decisions.
Deloitte’s recent report on agentic commerce in Asia Pacific found that 74% of consumers in the region already use AI to research products and compare prices — yet nearly half say they would not complete a purchase without stronger security assurances.
As Deloitte noted, trust will have to be built into every transaction. It raises an important question: if AI becomes the buyer, how does fraud evolve?
Instead of manipulating people, fraudsters will now increasingly target the systems that AI relies on. This could mean injecting fake product listings into AI-readable catalogues, poisoning recommendation signals, or creating synthetic seller identities that pass automated verification checks.
None of which follows the patterns fraud systems were built to detect.
We discussed with Troy Nyi Nyi, SVP & GM, APAC, SEON, what this means for retailers trying to get ahead of the risks before they industrialize, and how businesses can detect fraud when the attack surface shifts upstream to the data, signals, and systems that AI depends on.

Troy Nyi Nyi, SVP & GM, APAC, SEON
How has agentic commerce reshaped the fundamentals of trust, authentication, and fraud prevention?
Troy: Agentic commerce fundamentally changes how businesses think about trust, as the customer is no longer the only decision-maker in the transaction.
Traditionally, fraud prevention focused on verifying a person’s identity and looking for suspicious behavior, such as unusual login attempts, unfamiliar devices or abnormal spending patterns. Those controls, however, were designed around human interactions.
As AI agents begin researching products, comparing options and even completing purchases on behalf of consumers, trust extends beyond customer verification. Businesses need confidence that whatever is guiding the agent – the product listings, seller information, pricing and recommendations – has not been tampered with.
This shifts fraud prevention further upstream. The transaction itself used to be where fraud teams focused. That’s too late now. By the time an AI agent reaches checkout, it may already be acting on data someone else tampered with. That means fraud teams need to see identity, merchant behavior and transaction signals together, in real time, not after the fact.
As fraud becomes more difficult to detect at the point of transaction, how can businesses monitor seller identity data, product feeds, APIs, and recommendation engines to identify threats earlier in the process?
Troy: Businesses can no longer rely on the transaction itself to tell them whether something is wrong. In an AI-driven shopping journey, many of the risk signals appear much earlier. By the time an agent reaches checkout, it may already be acting on data that was manipulated well before.
Organisations need to pay closer attention to the data flowing through their systems, because that data influences the decisions AI agents make.
SEON’s 2026 Fraud & AML Leaders Report found that even before agentic buying scaled, 77% of APAC organizations already struggled to get a unified view of risk across their existing systems. Layer AI on top of that fragmentation and you tend to make individual tasks faster without actually improving control. Agentic commerce makes that gap more expensive, because an agent’s decision is only as good as the data and systems feeding it.
Rather than assessing events in isolation, businesses need to see how signals relate to one another, so anomalies surface earlier in the journey. A sudden spike in new seller accounts, unexpected pricing changes or API activity patterns may all indicate that something has been compromised well before any purchase happens.
With AI systems more involved in purchasing decisions, recommendations, and payments, how can businesses detect when data, product feeds, or recommendation engines have been manipulated?
Troy: Detection has to move toward integrity checks on the data itself. That means tracking provenance, where a product listing, price or review signal originated and whether it changed unexpectedly. It means applying anomaly detection to feed updates the same way fraud teams already monitor transaction anomalies. And it means watching for clusters of signals that individually look normal, but together suggest coordination: new seller accounts appearing alongside pricing changes and shifts in recommendation rankings.
The safe pattern recognition that makes AI useful for attackers works in the other direction. By analyzing behavior over time rather than relying on static rules, organizations can identify subtle anomalies that would be difficult to detect manually.
The key is making sure that when a system flags a manipulated feed or a suspicious seller, the teams can see the full context behind the flag and not just an alert without an explanation.
As trust frameworks in commerce were built around human verification, what new frameworks are needed to prevent fraud in machine-to-machine transactions?
Troy: Before agentic AI scaled, commerce often relied on a relatively simple trust model. Businesses would verify the person, authenticate the payment and monitor the transaction
Know Your Customer (KYC) was built for a world where a human was making the purchase. Now trust will need to extend beyond identity verification to include clear governance over how AI is authorized to act, what decisions it can make and how those decisions can be traced and validated.
This is why the industry is moving toward Know Your Agent (KYA), verifying not just that an agent exists, but who it’s acting for, what it’s authorized to do and whether its behavior stays within those limits. This system, however, requires a few structural shifts:
- Clear delegation records, a verifiable link between a human’s intent and the agent’s specific action.
- Behavioral baselines for agents themselves, since an agent suddenly requesting unusual permissions or transacting outside its normal pattern is a stronger fraud signal than any single transaction amount.
- Shared accountability between merchants, payment networks and agent platforms, so that when a transaction was technically authorized but the authorization itself was manipulated, it is clear who owns the dispute.
Sharing intelligence, standardizing trust signals and building more interoperable security frameworks will be essential as AI agents become more common in commerce.
The goal is to keep asking whether an interaction is still trustworthy as it unfolds, rather than deciding that once and assuming it holds.
None of this replaces the existing KYC, it sits alongside it. Trust in machine-to-machine transactions has to evolve as quickly as AI does, without slowing down legitimate customers.