Glossary
AI agents (the technology behind "agentic AI") are autonomous or semi-autonomous AI systems that can take actions on a user’s behalf: browsing, making decisions, completing tasks, and increasingly transacting and moving money, rather than just answering questions. Their rise is reshaping identity and fraud, because they blur the line between a legitimate human user and automation, and create an entirely new category of identity that needs to be authenticated and authorized.
Where earlier AI produced text or images, agentic AI acts. A consumer AI agent might shop, book, manage accounts, or pay, operating in systems that were designed on the assumption that a human (or a clearly-malicious bot) is on the other end. That assumption is breaking.
An AI agent doesn’t just respond; it plans and executes multi-step tasks toward a goal, often with access to tools, accounts, and the ability to act in the real world (making purchases, sending messages, moving funds). A consumer might authorize an agent to "book my travel" or "manage my subscriptions," and the agent then logs in, navigates, and transacts. This autonomy and access are what make agents powerful, and what make them a serious identity and security consideration.
AI agents break the traditional identity model in several ways. First, the "is this a human or a bot?" question becomes "is this a sanctioned agent acting for a real user, or a malicious/hijacked one?", bot detection can no longer simply block automation, because some automation is now authorized. Second, agents need their own identity and authorization: who is this agent, whom does it act for, and what exactly is it allowed to do? Third, the risk of over-permissioned or compromised agents is acute, an agent with broad, standing access to a user’s accounts is a dangerous target. This is why agent identity, delegated authority, and tightly-scoped, ephemeral permissions are emerging as critical concepts.
AI agents introduce new fraud vectors. A hijacked or manipulated agent could be turned against the user it serves, draining accounts or making unauthorized transactions while appearing legitimate. Malicious agents could be deployed at scale to commit fraud faster and more adaptively than human fraudsters or simple bots. And agents acting in systems not designed for them can be tricked (for example, via prompt injection) into harmful actions. The core difficulty is that an agent’s activity can look like legitimate authorized behavior, so distinguishing a trustworthy agent from a hostile one requires new detection approaches focused on intent and authorization, not just "human vs. bot."
Securing the agentic era requires extending identity and fraud capabilities to agents: authenticating agents and binding them to the user they represent, issuing just-in-time, narrowly-scoped authorization (an agent should be able to do exactly its task and nothing more, for as long as needed), detecting malicious or hijacked agents through behavioral and intent signals, and maintaining human oversight for high-risk actions. Transmit Security has positioned Mosaic as built for this era, introducing capabilities like AI Agent fraud detection (anticipating malicious intent and stopping hijacked or harmful agents) and just-in-time authorization (ephemeral, scoped access for agents), built with Google Cloud AI. This is where identity, fraud, and authorization converge for a world of autonomous actors.
Agentic AI is moving quickly from novelty to mainstream, with major platforms enabling agents to act on users’ behalf. Businesses that treat every automated interaction as either "human" or "block-it bot" will be caught out: unable to serve customers’ legitimate agents, or unable to stop malicious ones. Preparing means building identity and fraud systems that can recognize, authorize, and monitor agents. This is arguably the most important emerging shift in identity security, and it’s why it’s a strategic focus rather than a distant concern.
What are AI agents?
Autonomous or semi-autonomous AI systems (agentic AI) that take actions on a user’s behalf (browsing, deciding, transacting) not just answering questions.
Why do AI agents create an identity challenge?
They blur "human vs. bot," need their own identity and scoped authorization, and pose risk if over-permissioned or hijacked.
What is the fraud risk from AI agents?
Hijacked or malicious agents can act against the user or commit fraud at scale while appearing legitimate, requiring intent- and authorization-based detection.
How should identity adapt to AI agents?
Authenticate agents, bind them to the user, issue just-in-time scoped authorization, detect malicious agents, and keep human oversight for high-risk actions.
Why is agentic AI a priority now?
It’s moving mainstream fast, and systems that only distinguish "human vs. bot" can’t serve legitimate agents or stop malicious ones.
What is just-in-time authorization for agents?
Granting an agent ephemeral, tightly-scoped access to exactly its current task and nothing more, so a compromised agent can do little damage.
How do you tell a legitimate agent from a malicious one?
Through the agent’s authorization (what it’s permitted to do) and intent/behavioral signals, not just detecting that it’s automation.
Related: Agentic Fraud · Non-Human Identity (NHI) · Machine Identity · Bot Detection · Fine-Grained Authorization (FGA) · AI in Fraud Prevention