News

Vivox AI at the 6th Financial Innovation Forum: Tim Khamzin to moderate the panel on AI agents in FinCrime

→ Learn more
All

Agentic payments: what financial crime controls need to see

When AI agents make purchases on behalf of customers, a payment can meet every spending limit and still be the result of a manipulated decision. A panel at the Financial Innovation Forum in London explored what this means for consent, identity, fraud and accountability.

When AI agents make purchases on behalf of customers, a payment can meet every spending limit and still be the result of a manipulated decision. A panel at QUBE Events’ London forum explored what this means for consent, identity, fraud and accountability.

Ask an AI agent to book you a hotel. You expect it to find a suitable room, stay within your budget and complete the reservation. But what if it chooses a convincing fake hotel website? Or, in a more extreme hypothetical scenario, finds a way to cancel another guest’s booking to secure the room you wanted?

In the first case, the agent could make a payment you authorised to a fraudulent merchant. In the second, it could achieve your goal through an action you never intended. Both examples show why the final transaction tells only part of the story.

These questions were at the heart of “Agentic Payments: The Companion to Agentic Commerce” at QUBE Events’ sixth Financial Innovation Forum: Payments & RegTech, held on September the 17th at the Montcalm Mayfair in London.

Zainab Shode, deputy director of financial crime at Bank of London, moderated the discussion with Manish Kumar, former head of payment acceptance products at Starling Bank; Priyanshi Mathur, vice president of product management at Mastercard; Kamran Hedjri, group CEO at PXP; and Ainsley Ward, vice president of payments solutions at CGI.

Shode steered the panel through the questions that arise when software can act on a customer’s behalf: what has the customer agreed to, how can that authority be verified and who is responsible when an agent’s actions cause harm?

‍

Consent must have clear limits

“Book a hotel for me” sounds like a straightforward instruction. For a payment provider, it leaves important details unresolved. How much may the agent spend? Which merchants or categories may it use? Does its authority expire? Can the customer change or withdraw it?

The panel discussed consent as a set of specific permissions that can be checked throughout the payment journey. A record showing that a customer agreed to use an agent is valuable only if it also shows what the agent was authorised to do.

The way those permissions work will vary by payment method. Card payments, digital wallets and account-to-account transfers have different rules and processes for authorisation, disputes and liability. Customer permission may also need to sit alongside further checks, particularly for purchases in regulated sectors.

‍

Identity extends beyond the customer

Existing payment controls seek to establish who is making or authorising a transaction. Agentic payments add another question: which agent is acting, and is it the agent the customer authorised?

Participants discussed the need to connect the customer’s identity, the agent’s identity and the scope of its authority. That connection matters while a purchase is being made and if it is later disputed.

A useful record would allow the parties involved to reconstruct the sequence of decisions: what the customer requested, which permissions were granted, what information the agent encountered and what action it took. Without that context, it may be difficult to tell whether a problem began with a compromised agent, an unclear instruction or a failure elsewhere in the process.

Customer control must also work in practice. The panel considered how someone might revoke an agent’s authority, as well as the possibility of changing its limits. A control in an app is only effective if a change is recognised across the payment journey.

‍

Fraud can occur before checkout

A panellist offered the example of a fake hotel website designed to attract an agent searching for accommodation. The discussion also covered fabricated inventories and catalogues, as well as malicious instructions placed in material an agent might read.

In these scenarios, an attacker may try to influence which merchant the agent chooses or how it interprets its task. Participants also raised the risk of interference when the customer first sets the agent’s permissions.

This changes what investigators may need to examine. A payment might appear to fall within the customer’s authorised limits while the agent’s choice of merchant was manipulated earlier. Monitoring the transaction remains essential, but understanding the decisions that produced it could be just as important.

The pace of automated activity adds to the concern. Once attackers find a weakness, agents could be used to exploit it repeatedly and quickly.

‍

Liability remains an open question

If an agent makes an unwanted purchase, responsibility may depend on what happened. Did it misunderstand the customer? Was it compromised? Did a fraudulent merchant deceive it? Were its permissions too broad, or did a control fail?

The panel considered whether existing dispute and chargeback processes offer a starting point for answering these questions. Participants differed on where liability should sit among customers and the organisations providing agents, payments and safeguards. They also discussed the uncertainty around how existing reimbursement arrangements would apply to new agentic scenarios.

There was no single answer. There was, however, a clear need for evidence detailed enough to identify where a failure occurred. Firms will struggle to resolve disputes fairly if they cannot establish what an agent was asked to do and how it arrived at a payment.

‍

Financial crime monitoring must adapt

Shode brought the conversation back to financial crime, asking whether controls developed around human transaction patterns will recognise risks in agent-initiated payments.

Fraudsters often exploit human emotions. When the buyer is an agent, they may instead target the information it relies on, the permissions it receives or weaknesses in how it carries out instructions. Automated purchasing may also produce transaction patterns that differ from those compliance teams are used to reviewing.

The panel raised questions about fraud, money laundering and sanctions controls. It did not present a finished monitoring model for agentic payments. For firms developing these services, the immediate task is to test how well their existing controls can distinguish legitimate automated activity from misuse or compromise, and what additional context reviewers will need.

Agentic payments promise a more convenient purchasing journey. Delivering that convenience responsibly requires more than checking the amount and destination at checkout. Firms need to understand how an agent received its authority, selected a merchant and decided to pay — and preserve enough evidence to challenge those decisions when something goes wrong.

Thank you to Zainab Shode and all the panellists for a thoughtful discussion, and to QUBE Events for bringing everyone together.

‍

Conclusion

Agentic payments promise more convenient purchasing, but they introduce risks that a check at checkout alone cannot catch. A payment can fall within a customer's authorised limits and still result from an agent being manipulated earlier, for example by a fake merchant or planted instructions. The panel agreed that firms need clear, verifiable consent, a traceable link between the customer, the agent and its authority, and evidence detailed enough to show where a failure occurred. Liability and financial crime monitoring for agent-initiated payments are still open questions, and firms should test their existing controls now rather than wait for a finished model.

From the blog

The latest industry news, interviews, technologies, and resources.

Before the payment: where AI can make the difference in stopping scams

A payment can look legitimate even when the customer authorising it is being manipulated. At QUBE Events’ Financial Innovation Forum in London, financial crime leaders explored how AI, behavioural intelligence and human judgement can help stop scams before the money moves.

all

Vivox AI at the 6th Financial Innovation Forum: Tim Khamzin to moderate the panel on AI agents in FinCrime

Vivox AI is sponsoring the 6th Financial Innovation Forum – Payments & RegTech on 17 September 2026 at the Montcalm Hotel Mayfair, London, where our Founder and CEO Tim Khamzin will moderate a panel on AI agents in financial crime prevention.

all

How TELF AG Accelerated Global Due Diligence with AI-Powered Adverse Media Screening

TELF AG, a global commodities trading business operating across multiple jurisdictions, partnered with Vivox AI to automate adverse media screening and due diligence investigations. The result: case review times cut from 60 minutes to as little as 10–15 minutes, with broader global coverage and risks uncovered that traditional providers had missed.

all