Ready to get started?
Easily integrate next-generation payments and financial data into any app. Build powerful products your customers love.
Payment fraud in the UK is not slowing down. Criminals stole £1.28 billion through payment fraud in 2025, a 4% increase on the year, across more than four million cases. The industry prevented a further £1.68 billion, roughly 70p of every £1 of attempted fraud, but the scale of what gets through is still significant, and the methods being used are getting harder to catch with traditional rules (UK Finance Annual Fraud Report 2026).
For merchants and payment providers, the question is no longer whether to use AI in fraud detection. It is understanding what AI actually does, where it fits alongside Strong Customer Authentication, and what the new risks around AI agent payments look like. This guide covers all three.
Why payment fraud is a moving target
The reason static rules struggle is that fraud is adaptive. Criminals now run high-volume, low-value attacks and use their own automation to probe defences. A fixed rule that blocks transactions over a certain amount or from certain locations gets noticed and worked around quickly. That is why fraud detection has shifted toward machine learning models that can update continuously and catch patterns no rule has been written for yet.
How AI detects and prevents payment fraud
There are several distinct ways AI is applied in payment security. Most modern fraud systems combine several of them.
Real-time risk scoring
Machine-learning models assign a fraud risk score to each transaction using signals like amount, location, merchant type, device, and transaction history, typically in 10 to 50 milliseconds. That score drives a tiered response: let the transaction through, step up to extra authentication, or block. Unlike a human team reviewing hundreds of cases a day, a model reviews millions at once without getting slower or tired.
Anomaly and behavioural analysis
Rather than fixed rules, AI learns each customer’s normal pattern and flags deviations. This may include a sudden high-value order, an unusual shipping address, or a burst of rapid attempts from the same device. This is what catches new fraud patterns that no one has written a rule for yet, because the system spots that something does not fit rather than matching against a known pattern.
Behavioural biometrics
Behavioural biometrics go beyond passwords and credentials. They look at how someone interacts with a device: typing rhythm, mouse movement, touchscreen pressure and speed, device fingerprint, and geolocation. Together these signals can spot account takeover and bot activity in real time, even when the correct password is used.
Network and graph analysis
Graph models map the relationships between accounts, devices, IP addresses, and payees. An individual transaction might look harmless. Mapped across a network, it forms part of a clear pattern. This is particularly useful for catching organised fraud rings operating across multiple accounts.
Fewer false declines
Fraud is only half the cost. False declines, where a genuine customer is wrongly blocked, are estimated to cost merchants a lot more than fraud itself, and a large share of declined orders are good customers. Well-tuned AI reduces this by scoring more accurately, so you stop fraud without turning away real buyers.
AI and Strong Customer Authentication work together
AI decides how much friction a payment needs. Strong Customer Authentication (SCA) provides that friction when it is warranted.
Under UK rules, many payments require SCA – verification using two independent factors, such as a fingerprint or Face ID plus a trusted device. For card payments, 3D Secure adds a verification step at checkout. The best setups use AI to apply authentication intelligently, stepping it up only when risk is elevated, so most genuine customers pass through without friction while higher-risk transactions face a challenge.
The two work as a system: AI identifies the risk level, SCA handles the verification where needed.
Are AI agent-led payments safe?
Yes, when the payment is authorised by the customer with Strong Customer Authentication and the agent’s authority is provable and limited. This is a question that comes up more often as agentic commerce develops.
The safety of an agent-led payment does not come from trusting the AI. It comes from the same controls that protect any modern payment: the customer approves it, or approves a clear mandate for it, in their own Bank app, the rail is authenticated, and the amount and scope are capped. An agent can only make payments within the limits approved by the customer, making it more like a standing instruction than handing over a card.
The questions worth asking are about how consent is captured, how much an agent can spend, and who is accountable if something goes wrong.
The risks that are genuinely new
Most payment risks with AI agents are familiar risks in a new context. A few are specific to agents and worth naming clearly.
- A tricked or manipulated agent: An agent that reads web pages or messages could be fed misleading instructions (a prompt-injection style attack) and act on them. The defence is to keep spending authority narrow and authentication in the human’s hands.
- Overspend or the wrong purchase: An agent might buy the wrong thing, buy too often, or spend more than intended. Caps, per-transaction limits and confirmation steps contain this.
- Unclear consent: If it is not clear what the customer actually authorised, a payment is hard to defend. Provable, specific consent matters more here than in a normal checkout.
- Unsettled liability: If an autonomous agent makes a bad payment, who bears the loss is not yet defined in UK rules. That is a live regulatory question, covered below, not a solved one.
How agent-led payments are secured
The controls that make agent payments defensible already exist and can be stacked.
- Strong Customer Authentication: The customer approves the payment, or the mandate behind it, with SCA in their own Bank app. The bank confirms a human is behind the instruction.
- Provable, scoped consent: Emerging agent-payment standards use signed mandates so a merchant can prove what the customer authorised and within what limits. These are developing standards rather than a finished norm, so treat mandate support as an emerging capability, not a universal one. See the protocols behind agentic commerce.
- Authenticated instant rails: Account-to-account rails like Pay by Bank are approved by the payer and settle as a push payment, which suits agent payments and avoids stored card credentials. Variable Recurring Payments let a customer set a consented, capped mandate once.
- No card-style chargebacks on bank payments: A bank-authorised push payment is not exposed to card chargebacks, though that also means consumer redress works differently, which is part of what regulators are examining.
- Tokenisation and no shared card data: Where cards are used, tokenisation and 3D Secure reduce what an attacker can capture. Pay by Bank shares no card details at all.
For the wider picture of how agents pay, see what agentic commerce is and Atoa’s agentic payments.
The UK regulatory picture
UK regulators are actively shaping this, and two developments matter most as of 2026.
The Competition and Markets Authority published guidance, “Complying with consumer law when using AI agents”, on 9 March 2026. It expects businesses to stay in control of their agents, with appropriate human oversight, transparency and swift redress, particularly where an agent takes decisions with financial or contractual consequences. The CMA flags risks around manipulation, errors and loss of consumer agency, and notes that breaches of consumer law can carry fines of up to 10% of worldwide turnover.
HM Treasury published its “Modernising Payment Services Regulation” consultation on 14 July 2026, open for responses until 6 October 2026. It states that the current Payment Services Regulations were written before AI and may not fully facilitate agentic payments, and it asks specifically whether the rules on authentication, consent and liability need updating. It also proposes a long-term statutory framework for open banking, including a right of access for Variable Recurring Payments.
The direction of travel is clear: human oversight, provable consent and defined liability. The detail is still being written.
Who is liable if an agent payment goes wrong?
As of 2026, UK rules do not clearly define who bears the loss when an autonomous agent makes a payment the customer did not intend. That is exactly why HM Treasury is consulting on authentication, consent, and liability. Until it is settled, the practical approach is to keep a provable record of consent, cap what an agent can spend, and keep a human able to step in and review. Anyone claiming the liability question is fully resolved today is overstating it.
Where Atoa fits
Atoa’s approach to payment security is to shrink the attack surface, not just detect attacks on it.
- Pay by Bank shares no card details. The customer approves the payment inside their own Bank app with SCA, so there is no card number to steal, store or phish.
- No chargebacks on Pay by Bank. Because it is a bank-authorised push payment, there is no card-style chargeback or friendly-fraud dispute to absorb.
- Cards are processed securely. Where you take cards, they run on PCI DSS-compliant processing with 3D Secure.
- Regulated and certified. Atoa is FCA authorised (FRN 1007647), ISO 27001 and SOC 2 certified, with security backed by UK banks.
The point is simple: the most effective fraud reduction is a payment that has less to attack in the first place, backed by authentication the customer performs in their own bank.
What merchants should do
A few practical points worth keeping in mind:
- Offer methods that reduce fraud by design, such as Pay by Bank alongside cards.
- Use a provider with real-time risk scoring and SCA, so you block fraud without over-declining genuine customer.
- Watch false declines, not just fraud, since blocking good customers is the bigger hidden cost.
- For agent payments, set limits and log consent. Cap per-transaction and total spend, keep a provable record of what the customer authorised, and keep a human able to review or intervene.
- Keep certifications and regulation in view: PCI DSS for cards, FCA authorisation, ISO 27001 and SOC 2, and the CMA’s human-oversight expectations for AI agents.
FAQs
Are AI payments safe?
Yes, when the customer authorises the payment with Strong Customer Authentication and the agent’s authority is provable and limited. The safety comes from the consent and the controls, not from trusting the AI, so caps, logging and authentication matter.
How does AI detect payment fraud?
AI scores each transaction in real time using signals like amount, location, device and behaviour, learns each customer’s normal pattern, and flags anomalies before money moves. It also maps networks of accounts to catch organised fraud.
How does AI improve payment security?
By spotting fraud faster and more accurately than fixed rules, applying extra authentication only when risk is high, and reducing false declines so genuine customers are not turned away.
Is agentic commerce safe?
It is as safe as the consent and controls around it. Provable, scoped mandates, authenticated rails and spend limits make agent payments defensible; weak consent and unlimited authority make them risky.
Who is liable if an AI agent makes a bad payment?
This is not yet settled in the UK as of 2026. HM Treasury is consulting on whether authentication, consent and liability rules need updating for agentic payments, with responses due by 6 October 2026. Until then, keep provable consent, spend caps and human oversight.
How is consent proven for agent payments?
Through Strong Customer Authentication and signed, scoped mandates that record what the customer authorised and within what limits. Emerging agent-payment standards are being built around this, though they are not yet a universal norm.
Are Pay by Bank payments secure?
Yes. Pay by Bank is approved in the customer’s own Bank app with Strong Customer Authentication, shares no card details, and has no chargebacks. Atoa is FCA authorised and ISO 27001 and SOC 2 certified.
What is Strong Customer Authentication (SCA)?
A UK and EU requirement that many payments be verified with two independent factors, for example a fingerprint or Face ID plus a device, to confirm the customer is who they say they are.
Sources
- UK payment fraud losses and prevention (£1.28bn lost, £1.68bn prevented in 2025): UK Finance Annual Fraud Report 2026.
- AI real-time fraud scoring and capabilities: Redis, AI in payment processing.
- Behavioural biometrics in fraud prevention: LexisNexis Risk Solutions.
- CMA guidance “Complying with consumer law when using AI agents” (9 March 2026): Competition and Markets Authority.
- HM Treasury “Modernising Payment Services Regulation” consultation (14 July 2026, closes 6 October 2026): HM Treasury on GOV.UK.
- Strong Customer Authentication (UK): FCA, Strong Customer Authentication.
- Atoa security and FCA authorisation (FRN 1007647): Atoa Pay by Bank; FCA Register.