Glossary
Agentic fraud is fraud that is carried out, automated, or scaled by autonomous AI agents: either malicious agents built to commit fraud, or legitimate agents that have been hijacked or manipulated into harmful actions. It’s an emerging threat category created by the rise of agentic AI, and it demands defenses focused on intent and authorization rather than simply detecting automation.
As AI agents gain the ability to act (logging in, navigating, transacting) they become both a tool fraudsters can weaponize and a target fraudsters can hijack. Agentic fraud captures both.
The central challenge is that an agent’s activity can look like legitimate, authorized behavior, because sometimes it is. Traditional bot detection assumes automation is suspicious and can be blocked, but in the agentic world, some automation is explicitly authorized by the user. So the question shifts from "is this a bot?" to "is this agent authorized to do exactly this, and is its intent legitimate?" Answering that requires understanding the agent’s authorization (what it’s actually permitted to do), detecting anomalous or malicious intent, and distinguishing a user’s sanctioned agent from a hijacked or hostile one, a new detection problem.
Defense centers on identity, authorization, and intent. Agents should be authenticated and bound to the user they represent, and granted just-in-time, tightly-scoped authorization so a compromised agent can do little (an agent allowed only to "book travel under $500" can’t drain an account). Detecting malicious intent (through behavioral signals and anomaly detection tuned to agent activity) catches hijacked or hostile agents. And human oversight or step-up for high-risk actions provides a backstop. Transmit Security’s AI Agent fraud detection reflects this approach: anticipating malicious intent and stopping hijacked or harmful agents, paired with just-in-time authorization that limits what any agent can do.
Agentic fraud is a frontier threat where defenses are still forming, which is exactly why it’s a strategic priority. Organizations that extend identity, authorization, and fraud detection to AI agents now will be positioned to safely enable the agentic experiences customers will demand, while those that don’t will face fraud vectors their human-or-bot defenses can’t address. It’s the clearest example of how the convergence of identity, fraud prevention, and fine-grained authorization is being driven by a new class of autonomous actors.
What is agentic fraud?
Fraud carried out or scaled by autonomous AI agents, either malicious agents built for fraud or legitimate agents hijacked into harmful actions.
How is agentic fraud different from bot fraud?
Some agent automation is user-authorized, so detection shifts from "is this a bot?" to "is this agent authorized and acting with legitimate intent?"
How do you defend against agentic fraud?
Authenticate and bind agents to users, grant just-in-time scoped authorization, detect malicious intent, and keep human oversight for high-risk actions.
Why is agentic fraud a growing concern?
As AI agents gain the ability to transact, they become both a weapon for fraudsters and a target to hijack, creating vectors human-or-bot defenses miss.
Related: AI Agents / Agentic AI · Non-Human Identity (NHI) · Fine-Grained Authorization (FGA) · Bot Detection · Generative AI Fraud · AI in Fraud Prevention