Mastercard agentic commerce push rewrites fraud rules for AI buyers
Mastercard says AI purchasing agents require new identity, intent and risk controls across its payments network.
By Colin Brandt · Enterprise Reporter
· 4 min read
Mastercard agentic commerce is forcing the payments network to revise fraud systems built for years to treat automated buyers as suspicious. Greg Ulrich, Mastercard’s chief AI and data officer, told the VB Transform 2026 audience in Menlo Park on July 14 that the company now has to permit some bots to transact while still blocking malicious automation.
The shift matters because Mastercard’s fraud decisioning runs at network scale. Ulrich said the company evaluated 175 billion transactions last year, with less than 100 milliseconds to produce a risk score for each card tap or online payment and send that assessment to the issuing bank.
How is Mastercard changing fraud controls for AI agents?
Mastercard’s existing rules were designed to stop bot-driven transactions, Ulrich said. Agentic buying changes that premise because a consumer or business may delegate authority to software that can select items, place orders and pay within constraints. Mastercard’s challenge is to distinguish an approved agent acting on a user’s instructions from a bad actor trying to exploit the same payment rails.
Ulrich described five layers Mastercard is using for that work: identity, verifiable intent, controls, execution and intelligence. The identity layer includes what he called “know your agent,” which means validating the software agent and binding it to the consumer or business behind it. Verifiable intent is meant to create a cryptographic record of what the user authorized, such as item, size, price or return constraints, so disputes can be judged against the original instruction.
Controls would set the agent’s limits, including allowed merchants, spending caps and other conditions. Execution runs through Mastercard Agent Pay, which Ulrich said includes tokenization, authentication and acceptance capabilities, and has launched with Microsoft, OpenAI, Google and other partners. The intelligence layer covers risk rules, permissioned insight tokens for personalization and threat monitoring through Recorded Future.
Mastercard says AI is already changing fraud detection
Ulrich said Mastercard assigns each transaction a score from zero to 999 based on the probability that it is fraudulent. He said generative AI has let the company use more context in that scoring and identify 300% to 400% more fraudulent transactions in high-risk bands, without increasing consumer friction or false positives. Mastercard’s Safety Net system has stopped more than 70 billion fraudulent transactions, according to Ulrich.
The company is also building a transformer model on its own transaction data to support safety, security and personalization products. Ulrich said about 40% of Mastercard’s business is now in services, including marketing, fraud and security, and business intelligence. Roughly a third of those services are based on AI, he said, and are growing faster than the rest of the business. Mastercard did not disclose revenue figures for those AI-based services.
Why Mastercard sees B2B agents as the larger market
Consumer shopping is the visible starting point for agentic commerce, but Ulrich pointed to business procurement as the larger opportunity. He gave the example of a manufacturer using an agent to monitor inventory, keep an assembly line supplied, order from approved vendors and stay within a budget.
That use case requires multiple autonomous systems to trust each other, including procurement, supplier and banking agents. Ulrich said common standards for agent identity and transaction intent will be needed before those systems can operate across companies at scale.
Mastercard has also tested advanced security models, including Anthropic’s Mythos model through Project Glasswing and OpenAI’s GPT-5.5-Cyber, Ulrich said. He described them as useful for finding vulnerabilities that were previously hard to detect, while adding that the work still fits into the company’s existing security process. Mastercard’s chief security officer oversees a team that prioritizes critical assets, runs models against them, ranks findings by severity and uses similar tools for patching.
Ulrich said Mastercard’s own agent deployments have already forced architecture changes. The company built agents last year for 4,000 consultants, including research, text-to-SQL, Excel and PowerPoint tools. After 14 months, he said Mastercard would design them differently, with compliance, observability and security guardrails built into the operating layer from the start.
Enterprise adoption still has gaps. VentureBeat’s June 2026 Pulse research found that 32% of 107 qualified enterprise respondents give every agent a scoped, managed identity, while 12% include an agent-identity product in their evaluation set. Ulrich said agent identity is becoming part of Mastercard’s broader identity work alongside traditional KYB and KYC systems.
This story draws on original reporting from VentureBeat.