🧬 Interested in pharma, biotech and medical device news? Visit PharmaDeviceNews.com →

Incognia targets AI agent fraud as banks prepare for machine-initiated payments

Incognia is extending its fraud platform to distinguish AI agents from human users and judge the risk of individual agent-led actions as banks prepare for autonomous payments, account changes and increasingly machine-driven customer interactions.

Incognia is pushing its fraud-prevention technology into agentic banking with a new AI Agent Detection capability designed to help financial institutions determine not only whether an artificial intelligence agent initiated an interaction, but whether the specific action it is attempting should be trusted. The San Jose-based private company is combining signed-request verification, agent-origin classification, bot and automation detection with its existing device, network, account and location intelligence, creating a risk layer around AI-initiated payments and account activity. Incognia is simultaneously adding Web Behavioral Biometrics and an MCP Server that can bring its fraud intelligence into compatible AI-assisted investigation tools. The central issue is becoming increasingly important for banks because authenticating a legitimate AI agent does not prove that a customer authorized every payment, credential change or account action the agent attempts to perform.

The launch comes as agentic commerce begins moving from demonstrations into live payment environments. Visa has already enabled AI agents to complete purchases at participating European merchants, while Mastercard has expanded Agent Pay with identity, intent, behavioral and fraud intelligence intended to give banks and merchants more context around AI-led transactions. That development creates a new security problem alongside the commercial opportunity: financial institutions must increasingly distinguish legitimate automation from malicious bots while also judging whether a valid agent remains inside the authority its human user intended to grant.

Why does authenticating an AI agent still leave banks with a major fraud problem?

Traditional digital fraud controls have generally assumed that a person is sitting behind an interaction. A bank might verify a password, device, biometric factor, one-time code or behavioral pattern and then decide whether the customer attempting a login or transaction appears legitimate. Agentic AI breaks part of that assumption because software can now act between the customer and the financial institution.

An AI agent could eventually shop, initiate a payment, modify account information, renew a subscription or perform other tasks after receiving instructions from a customer. The bank may therefore see an automated request arriving from a recognized agent rather than a conventional customer browser or mobile application.

Cryptographic authentication can help establish which agent sent the request. Emerging Web Bot Auth technology, for example, allows automated agents to sign HTTP requests so a receiving service can verify their origin rather than relying on easily spoofed user-agent strings or changing IP addresses. Cloudflare already supports the approach for verified bots and agents, while Google has been testing the emerging protocol with some AI agents.

That still answers only the identity question. A properly authenticated agent could be acting on manipulated instructions, operating through a compromised account or attempting an action outside the customer’s intended permission. Incognia is building its product around that distinction between knowing who the agent is and deciding whether the action should be allowed.

How does Incognia AI Agent Detection decide whether an agentic action looks risky?

Incognia says its approach evaluates the agent and the requested action separately. AI Agent Detection combines signed-request verification with agent-origin classification and conventional bot and automation detection, then adds the broader risk information the company already gathers around devices, accounts, networks and location.

For lower-risk activity, a financial institution could potentially allow a legitimate agent to continue without interrupting the customer. Higher-risk actions could trigger additional verification tied to the human behind the agent.

That distinction is fundamental to making agentic finance usable. Requiring direct human confirmation every time an AI assistant takes an action would eliminate much of the convenience that autonomous agents are supposed to provide. Allowing every action merely because the agent has been authenticated would create the opposite problem, granting automation too much implicit trust.

Incognia instead envisions risk-based intervention. An ordinary low-value action might proceed under existing permissions, while a large payment, account recovery change, credential update or similarly sensitive request could require fresh customer verification through a trusted device.

The company says it can then examine signals including the device’s relationship with the account, device integrity, network risk and location history. Those signals provide additional context around whether the customer associated with the agent appears consistent with the established account relationship, although the financial institution retains responsibility for defining its own authorization policies.

Why could prompt injection and stolen credentials make legitimate AI agents dangerous?

One of the more difficult aspects of agentic security is that malicious activity does not always require impersonating the agent itself. Attackers may instead attempt to manipulate the instructions an otherwise legitimate agent receives.

Prompt injection is one example. An agent interacting with external information could encounter malicious instructions designed to redirect its behaviour, disclose information or perform an unintended task. Credential theft, compromised customer accounts and replayed requests create additional paths through which technically legitimate automation could become part of a fraudulent transaction.

This changes the conventional concept of bot detection. Banks can no longer divide automated traffic neatly into trusted bots and malicious bots. A trusted agent can still become the vehicle for an untrusted action.

Incognia’s strategy is therefore to push fraud assessment closer to the individual action. That makes the product less a conventional bot blocker and more an attempt to create continuous trust assessment around delegated authority.

The competitive challenge is that payment networks and other security providers are working on the same broad problem from different layers of the transaction. Mastercard’s Agent Pay framework, for example, combines agent identity, user intent, controls and fraud intelligence, while Visa is embedding credentials, authentication and transaction protections into its own agentic-commerce infrastructure. Incognia will need to demonstrate that its additional device and physical-world context materially improves the decisions banks already receive from network and platform controls.

How does Web Behavioral Biometrics extend Incognia beyond mobile device intelligence?

Incognia is also expanding its web fraud capabilities with Web Behavioral Biometrics, adding interaction patterns such as mouse movement, keyboard activity, clicks and clipboard behavior to existing browser, device, location and automation signals.

Those patterns can reveal characteristics associated with automated or manipulated sessions. Artificially generated mouse or keyboard events, unusual cursor movement and unexpected copying or pasting can contribute to a higher-risk assessment.

The company is careful not to treat individual behavioral signals as proof of fraud. Legitimate customers can copy information between fields, move a mouse unusually or behave differently depending on accessibility tools and device conditions. Behavioral biometrics becomes more useful when several signals are interpreted together.

That multi-signal strategy reflects a broader change in fraud prevention. Financial institutions have historically added more authentication when confidence falls, but excessive challenges can block legitimate customers and increase abandonment. Better risk intelligence is commercially valuable when it allows high-confidence interactions to proceed while concentrating friction on the smaller portion of sessions that remain ambiguous.

Incognia says an uncertain web session can also be linked to a trusted mobile device through Cross Device Authentication. That allows the institution to bring additional device, proximity, integrity and location evidence into a web transaction rather than judging it entirely from browser information.

Why is Incognia launching an MCP Server alongside its AI agent fraud controls?

The third part of the launch addresses fraud analysts rather than customer-facing transactions. Incognia’s MCP Server is intended to connect the company’s risk intelligence with compatible AI applications so analysts can investigate suspicious activity through natural-language questions.

A fraud investigation may involve multiple accounts, devices, previous risk assessments, watchlists, fraud feedback and historical events. Analysts traditionally need to search through several views and manually reconstruct the relationship between those pieces of information.

Incognia’s Model Context Protocol implementation is designed to let an AI tool retrieve that supporting evidence and organize it around a question. An analyst could ask why one account moved from a high-risk assessment to a low-risk assessment and have the agent retrieve relevant devices, watchlist information, prior feedback and policy context for review.

Importantly, the initial implementation is read-only. The connected AI application can retrieve and analyse supported information, but it cannot change risk decisions, modify fraud rules, submit fraud feedback or alter watchlists. Human analysts remain responsible for reviewing the evidence and deciding what action follows.

That conservative design matters in financial services because automating the investigation process and automating enforcement are very different risk decisions. Incognia can potentially reduce the manual work required to assemble evidence without allowing an AI model to independently block customers or change fraud policy.

Why are banks being forced to solve agentic fraud before AI payments become mainstream?

Payments companies are moving quickly enough that banks cannot assume agent-led transactions remain a distant problem. Mastercard launched Agent Pay in 2025 and has since extended the programme into machine-to-machine payments and additional trust services. Visa has progressed from agentic-commerce infrastructure into live European transactions where AI agents browse, select products and initiate purchases on behalf of cardholders.

The potential impact extends beyond shopping. Once customers become comfortable delegating financial tasks, agents could compare products, transfer funds, manage subscriptions, optimize cash balances or perform recurring transactions according to predefined goals.

That creates new fraud and compliance questions. A transaction could be technically valid yet exceed what the consumer intended, while a compromised agent might operate faster and at greater scale than a human fraudster. An automated system could also initiate many actions before a customer notices abnormal activity.

Fraud teams therefore need information about identity, authority, context and behavior rather than a binary judgment that an agent is genuine. The industry is increasingly converging around this broader trust model even though the technical standards and commercial ecosystem remain relatively early.

The near-term market opportunity for Incognia depends on how quickly financial institutions move from experimenting with agentic AI to allowing agents to make consequential external transactions. If adoption progresses slowly, agent-specific security spending could remain limited. If agentic payments scale rapidly, banks may need another layer of controls before fraud patterns have had years to mature.

How does Incognia’s existing fraud business support its move into AI agent verification?

Incognia’s core business has been built around cross-device risk intelligence using persistent device recognition, device integrity and location behavior. The company markets that technology to financial services, marketplaces and mobility platforms for applications including new-account fraud, account takeover prevention, scam detection and transaction verification.

Its financial-services proposition emphasizes recognizing trusted customers without forcing additional authentication on every interaction. Incognia says its models can combine device information with location and account relationships to distinguish established users from suspicious devices or fraud networks.

The company has also published customer evidence indicating that its technology can influence both fraud outcomes and operational friction. In April 2026, Incognia said Webull Brazil increased automatic onboarding approval from 75.7% to 92.5% after incorporating Incognia device and location intelligence, while cases requiring manual review fell sharply. Those figures are company-reported customer results rather than independently audited industry benchmarks, but they illustrate the commercial proposition Incognia is now extending into AI interactions.

Incognia has also been studying how artificial intelligence could amplify existing organized fraud infrastructure. Chief Executive Officer André Ferraz recently described one investigation in which roughly 200 devices and more than 4,500 mule accounts were connected to a single apartment, arguing that AI could allow fraud groups to automate more account creation, access and manipulation without proportionately increasing their physical infrastructure.

The new AI agent product therefore fits an existing thesis rather than representing a complete strategic pivot. Incognia has spent years trying to connect online activity to persistent devices and physical-world context, while agentic AI creates another layer between the institution and the person it is ultimately trying to trust.

What does Incognia’s private-company status mean for the commercial story?

Incognia does not publish the quarterly revenue, margins or cash-flow information available from publicly listed cybersecurity companies, making it difficult to measure how quickly its fraud platform is scaling financially.

Its most recent major publicly disclosed financing was a $31 million Series B round announced in January 2024 and led by Bessemer Venture Partners, with participation from FJ Labs and existing investors including Point72 Ventures, Prosus and Valor Capital. The funding was intended to support product development and expansion across financial services, consumer internet and e-commerce.

The company has continued adding customers and expanding product capabilities since that financing, but it has not disclosed revenue expectations associated with AI Agent Detection, pricing, contracted financial institutions or a separate commercial forecast for the product.

That makes adoption the more useful near-term measure. Named bank deployments, evidence that agentic transactions are generating meaningful fraud cases and quantifiable reductions in false positives or losses would provide stronger evidence than the launch itself.

The competitive environment is also likely to become crowded. Payment networks, cloud security companies, fraud vendors, identity platforms and banks themselves all have incentives to build controls around agent identity and delegated authority. Incognia’s differentiation will depend on whether its device, location and cross-channel information adds a layer of trust that other infrastructure cannot reproduce as easily.

Can Incognia create a new fraud category without making agentic banking too cumbersome?

That trade-off may determine whether the product succeeds. AI agents become useful only when they can complete meaningful work without constantly returning to a person for permission.

Banks, however, cannot allow a recognized agent to treat authentication as unlimited authority. Every transaction has a different risk level, customer context and potential financial consequence.

Incognia’s proposed answer is selective human intervention rather than universal approval. Low-risk actions can potentially remain automated, while sensitive activity can reconnect the agentic request to a trusted customer device and require stronger evidence or direct confirmation.

That model mirrors how modern fraud prevention already treats human transactions. Most legitimate activity passes silently, while additional friction appears when the risk engine detects enough uncertainty to justify it.

The difference is that agentic commerce adds another identity into the chain. The bank must increasingly understand the human, the agent, the relationship between them and the specific authority attached to the requested action.

Incognia is betting that this additional trust problem becomes a distinct software market. With Visa and Mastercard already moving agent-led payments into real environments, the question is shifting from whether AI agents will eventually interact with financial infrastructure to how banks will decide which machine-initiated actions deserve the same trust as their customers.

What are the key takeaways from Incognia’s move into AI agent fraud detection?

  • Incognia has introduced AI Agent Detection for financial institutions as agentic AI begins initiating payments, purchases and account actions.
  • The product separates agent identity from transaction risk because a legitimate authenticated agent does not automatically prove customer authorization.
  • Incognia combines signed-request verification, agent-origin classification, bot detection and broader device, account, network and location intelligence.
  • Higher-risk AI actions can be linked back to a trusted customer device for additional verification rather than forcing human approval for every agent interaction.
  • Web Behavioral Biometrics adds mouse, keyboard, click and clipboard signals to Incognia’s existing web fraud intelligence.
  • Incognia is also introducing an MCP Server that allows compatible AI tools to retrieve and organize fraud-investigation evidence using natural-language questions.
  • The initial MCP implementation is read-only, leaving policy changes, enforcement decisions and other actions under human control.
  • Visa and Mastercard are already advancing agentic-payment infrastructure, increasing the urgency of controls around AI-led transactions.
  • Incognia remains privately held, and no revenue forecast, product pricing or named bank customers for AI Agent Detection were disclosed with the launch.
  • The commercial test will be whether Incognia can reduce agentic fraud and false positives while preserving enough autonomy for AI agents to remain useful.

Discover more from Business-News-Today.com

Subscribe to get the latest posts sent to your email.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts