← back to the archiveCover illustration for “A legitimate agent can still look like a bot”
POSTday 66·5w ago·by Andy Padia

A legitimate agent can still look like a bot

Visa’s proposed BioCatch acquisition highlights behavioural signals. Agent commerce also needs evidence of who delegated an action and what they allowed.

“Looks automated” cannot be the entire rejection rule for a service designed to accept automated purchases. My acceptance question is whether this particular action falls within a valid delegation.

Visa’s August 3 announcement describes an agreement to acquire BioCatch for $2.4 billion in cash, subject to closing conditions. It characterises BioCatch as a behavioural, multi-signal fraud-intelligence provider and includes AI-agent usage among the signals it observes. The agreement is not a completed acquisition as of this announcement.

The interesting implication is narrower than saying Visa has solved agent authentication. Behaviour can help assess risk. It cannot, on its own, establish what a customer authorised a machine to do.

Automation and permission are different attributes

Imagine two hypothetical shopping agents using the same software. One has permission to reorder a specific household item within a spending limit. The other uses a compromised account to attempt the same purchase. Their interaction patterns may look similar. The relevant difference is the authority behind the action.

Now reverse the example. A legitimate user delegates a purchase to an agent that operates faster and more consistently than a person would. A system treating every machine-like pattern as disqualifying could reject the intended workflow. That possibility does not make behavioural detection obsolete; it changes how the signal should contribute to the decision.

I would want the service to distinguish a recognised actor, the represented customer, the permitted action and the transaction actually attempted. Evidence of one does not automatically establish the others. An authenticated agent can exceed its mandate. A familiar customer account can be compromised.

Those are conceptual requirements for an agent-commerce review, not claims about BioCatch’s internal architecture or the performance of a particular fraud model. The announcement describes multiple signals, so reducing the product to a simple human-versus-bot detector would itself be misleading.

Test a mandate that changes

A useful controlled exercise would begin with a harmless mock checkout and an explicit delegation. Let the agent prepare the permitted purchase. Then change the amount, the recipient or the customer’s permission before final execution.

Inspect which changes require renewed approval and how the service explains a refusal. The test should cover an expired or revoked delegation as well as a valid one. It should also distinguish “we cannot verify the authority” from “we have established fraud.” Those conclusions carry different meanings for the customer and the operations team.

The behavioural signal remains useful in that exercise. An unusual session can justify additional scrutiny even when a credential is valid. The aim is to combine signals with the transaction’s authority, rather than ask either the credential or the interaction pattern to do every job.

I have not tested BioCatch’s agent detection, and the acquisition announcement does not establish accuracy for these scenarios. It also cannot prove a single commercial rationale for the purchase price. Any claim that the deal buys a complete trust layer would outrun the evidence.

The product decision is already concrete enough without that speculation. If agents are invited to act, the acceptance policy has to explain which automation is permitted and how that permission is checked at the action.

Use behavioural signals to assess an agent’s risk, and a separate delegation check to establish what it is allowed to do.

#agents#payments#identity#fraud-prevention
← older drop
An AI security coalition needs evidence from the missing layer
newer drop →
Distilled models inherit their teacher's provenance

related drops

explore all 243 drops →
← back to the archiveday 106