As agentic commerce becomes a reality, retailers must adapt to sophisticated AI-enabled fraud threats and establish new trust frameworks to secure autonomous transactions and protect data integrity.
Agentic commerce is moving from theory to practice, and retailers are already having to adjust to a buying journey in which software can browse, compare and even complete purchases on a customer’s behalf. Adobe’s Digital Trends Report found that 49% of consumers globally say they would use AI for personalised product recommendations, while Deloitte said 74% of consumers in Asia-Pacific already use AI to research products and compare prices. Even so, nearly half of consumers say they would not complete a purchase without stronger security assurances, underlining how quickly convenience is outrunning confidence.
The problem for businesses is that much of the fraud stack was built for transactions driven by a human being, not an autonomous agent. Once a purchase is completed by machine, the window for intervention narrows sharply. TechRadar Pro has warned that retail fraud systems now need to be able to identify legitimate AI agents, confirm that they are acting with permission and distinguish them from malicious bots. Otherwise, security systems risk blocking valid sales while still missing genuinely fraudulent activity.
The larger threat is no longer limited to the checkout itself. As the SMEHorizon article notes, an AI agent depends on the product listings, seller details and recommendations it receives, which means the data becomes the target. A manipulated listing or planted recommendation can steer a machine towards a fraudulent merchant while leaving the final transaction looking routine. TechRadar Pro has also highlighted the rise of AI-enabled fraud rings using synthetic identities and spoofed devices, which makes it harder to rely on single-point checks and easier for attacks to blend into ordinary commerce.
That shift is forcing a rethink of trust. The SMEHorizon article argues that Know Your Customer controls are no longer enough on their own and should be complemented by Know Your Agent, a framework that defines what an agent is authorised to buy, how far that authority extends and how its actions can be traced. Separate but related legal and compliance questions are also emerging. Sheppard Mullin has noted that agentic commerce blurs the line between human- and machine-initiated payments, raising questions over consent, accountability and oversight when software makes financial decisions with limited direct supervision.
For smaller businesses, the challenge is acute but not hopeless. Larger retailers can afford more sophisticated fraud operations, yet SMEs often must defend themselves with fewer staff and less budget while facing the same connected platforms and the same risks. The practical response, according to the SMEHorizon article, is to focus on a few high-value controls: verify sellers, protect product data and watch the systems that move information in and out of the business. Cerbos has similarly argued that policy-based access controls, including limits on spending and refunds, can reduce the risk of abuse when agents are given delegated buying power. The clear message across the sector is that fraud prevention now has to move earlier, act faster and treat the data guiding an agent as something that must be secured as carefully as the transaction it eventually creates.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





