Your customers just gave a bot access to their wallet. Are your controls ready?
Bot customers now need identity trust frameworks, not just fraud detection tools
Nearly all of the identity and fraud control systems companies rely on were built with a human at the centre of the transaction. Verify the person, check the document, run the liveness test. That model is now quietly becoming outdated. Visa, Mastercard, and PayPal are investing heavily in AI-powered commerce capabilities and have completed thousands of transactions.
Businesses are authorising agents to book, buy and transact on their behalf - and the compliance infrastructure underneath most of them was never designed for a customer that isn't a person. The scenario channel partners should be putting to their clients is one many haven't considered yet: what happens when your customer isn’t a human?
Agents don't have passports
Traditional KYC and AML were built around two things a human brings to onboarding: a document and a face. Check the passport, then a selfie or liveness test confirms the person holding it is real and present. An agent has neither - it carries no passport, fails every biometric check by definition, and can't be re-verified mid-transaction because there's no one there to re-verify.
But the deeper problem is ongoing due diligence. Regulation doesn't ask for a one-time check; it asks for continuous monitoring. Most businesses are now retrofitting trust, identity, and fraud controls into systems originally built to keep automation out, and the result is a worse experience for everyone moving through them. In agentic commerce, you don't even get the usual complaints. The only feedback is lost revenue.
Recalibrating behavioural analytics for bot traffic only addresses part of the problem. A business can stop treating automated traffic as hostile by default, adjust the rules around session velocity, device consistency, and transaction cadence, and learn to tell a legitimate purchasing agent from a credential-stuffing script. But that only answers a behavioural question: Does this activity look suspicious? It doesn't answer the compliance one: is this agent authorised to act, on behalf of whom, under what permissions, and are those permissions even still valid?
Identity should never be treated as static. Names and addresses change. Immigration, residency, and professional status can be granted or withdrawn. Real ongoing monitoring involves businesses continuously asking whether the identity, risk profile, authority, and credentials tied to a customer are still valid at the moment you're relying on them.
Agents sit between the customer and the transaction, carrying what is effectively the badge of the person who sent them. A customer lets an AI agent buy software on their behalf. The agent buys, the payment clears, the behavioural data is clean - on every signal traditional monitoring tracks, this is a good transaction. The business still has no idea who actually authorised the agent, what it was allowed to buy, whether that authority still holds, or whether it has drifted out of scope and is renewing licences nobody approved. The question shifts from 'who is the customer?' to 'whose authority is this agent carrying, and is that authority still real?'
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Scale that up, and you're not dealing with one bot you can label good or bad - you're dealing with thousands of them, acting across channels on behalf of different people, companies, wallets, and platforms. The most mature businesses in BFSI are already worried about this, but most SMEs haven’t even started having this conversation.
The channel opportunity: trust infrastructure, not tooling
This is where channel partners are well placed, but only if they change the framing from "which tools do you need?" to "how does your trust infrastructure need to evolve?" Most clients aren't thinking about agentic commerce as a compliance problem at all; they're thinking about AI agents as a productivity win. A channel partner's job is to make sure that as clients move faster, they don't quietly create compliance exposure.
So the conversation that needs to happen now isn't only about detecting automated traffic. Clients need help deciding which automated interactions can be trusted, what evidence is required to support that trust, and how delegated authority is monitored over time. Start by mapping the controls a client already has for bot traffic, then help them capture the commercial upside of agent-driven traffic while reducing the exposure that comes from accepting it blindly.
The businesses doing this well have already moved from siloed, event-based verification to a continuous model that handles humans, devices, and agents together. The partners who understand this will become trusted advisors; those who don't will be stuck reacting rather than anticipating client compliance failures.
The window to act is now
Companies don't need another isolated protocol, another fraud rule, or another bot-traffic indicator to tackle this challenge. They need help stitching the pieces they already have into a trust framework built for agent-initiated transactions: connecting KYC and KYB to delegated permissions, linking wallets and credentials to ongoing monitoring, making sure credentials can expire, be suspended or revoked, and treating agent activity as part of the customer risk lifecycle rather than a one-off access-management event.
The frameworks most businesses rely on were built for a different era. That doesn't make them wrong; it makes them incomplete. Getting ahead of this is still a choice, for now.
Harry Varatharasan is chief product officer at ComplyCube, where he leads cross-functional teams of product managers, engineers, and data analysts to build verification technology that helps businesses prevent fraud and stay compliant with global AML, KYC, and data regulations.
Before joining ComplyCube in 2021, Harry spent over a decade in data science, architecture, and analytics leadership roles at Barclays and Barclays Corporate & Investment Bank, including as VP of enterprise data & insights and lead Big Data engineer for trade analytics.
He holds a BSc in Computer Science from Imperial College London.
-
The perfect SOC: How to boost defencesIn-depth Some security operations centers (SOCs) are more effective than others, according to a recent advisory from the US Cybersecurity and Infrastructure Security Agency (CISA). What lessons can firms learn to build the perfect SOC?
-
The Data & AI Trust Gap reportwhitepaper
-
Why secure behavior management Is becoming the channel's next growth opportunityIndustry Insights Channel partners must shift from just selling tools to capitalizing on secure behavior management
-
The hidden cost of tool sprawl on the channelIndustry Insights Tool sprawl represents major challenges for MSPs, so how can the issue be tackled?
-
Why the MSSP model is broken, and how to fix itIndustry Insights CISOs are struggling to differentiate between MSSPs due to confusing metrics and SLAs
-
How MSSPs can deliver continuous pentesting without hiring more security expertsIndustry Insights MSSPs can scale and strengthen their security posture using AI instead of expanding security teams...
-
The CISO now owns physical security. Here’s what that means for the channelIndustry Insights Physical security budgets have moved to CISOs, and partners must adapt to this important shift
-
Why software supply chain security is the next accountability challenge for channel partnersIndustry Insights Partners need to be able to confidently answer key client questions relating to supply chain security going forward...
-
Sovereignty is the channel’s next trust testIndustry Insights Data sovereignty has become a key channel priority
-
Why MSPs should rethink the browser as the new security control pointIndustry Insights Enterprise browsers simplify security by consolidating multiple security controls