Roz Kettleburn does not exist, which is a shame, because her payment processor could really use her right now. She is a composite, assembled from conversations with fraud operations leaders at three different processors, all of whom are navigating the same structural gap and none of whom wanted their name attached to describing it. Roz's casino surveillance background, her operational vocabulary, and her specific exasperation are all borrowed from real people. Her opinions are her own, insofar as a fictional person can have those.
The landscape Roz operates in has shifted faster than the infrastructure governing it. Mastercard's Agent Pay program now credentials and tokens AI agents for secure transactions; its June 2026 extension, Agent Pay for Machines, was designed explicitly for "continuous, embedded" commerce between systems.1 Visa's Intelligent Commerce framework requires agents to register, verify identity, and operate within cardholder-defined payment instructions, placing responsibility for the agent's actions on the cardholder, as if the cardholder initiated the transaction.2 The Agentic Commerce Protocol, maintained by OpenAI and Stripe, gives merchants structured checkout objects with allowance bounds and risk signals but enforces a four-second approval window that declines payment if no response arrives.3
Roz has been living inside these systems for eighteen months. The initial fire, agent traffic triggering every velocity check and geographic anomaly flag in the stack, has mostly been contained. What remains is harder.
You spent a decade in casino surveillance before payments. Does that background help with any of this?
Roz: More than you'd think. Casinos are the original real-time fraud detection environment. You're watching thousands of transactions per minute. Every chip placed, every card dealt. The whole system is built on knowing what normal looks like and flagging what doesn't.
My problem now is that "normal" split in half. I've got two populations hitting my systems that produce nearly identical transaction signatures, and one of them is legitimate commerce and the other is fraud. My models were trained on a single population, humans, and now I'm screening a mixed population without a reliable way to separate them at the front door.
In the casino, that would be like if half your players were invisible. Same chips, same bets, same tables. You just can't see them sit down.
What does your review queue actually look like compared to eighteen months ago?
Roz: Eighteen months ago it was chaos. We were getting LLM-referred traffic scoring 1.8 to 2.3 times riskier than search traffic, not because it was fraudulent, but because it violated every behavioral signal we had.4 Five purchases across three merchants in ninety seconds? That's card testing. Except when it's an agent comparison shopping. Session duration approaching zero? Bot attack. Except when it's just efficient software being efficient. We were declining legitimate transactions at a rate that made me physically ill.
We've since built separate velocity baselines for agent-identified traffic. That helped. We added agent identity as a first-class scoring input: if the traffic comes through a credentialed Mastercard Agentic Token or a Visa-registered Agentic Payment Provider, it gets routed to a different risk model. That helped more. Our false positive rate on agent traffic dropped from... I don't want to say the original number. It was bad. It's better now.
But the cases that actually keep me awake aren't the ones where my models misfire on legitimate agent traffic. Those are engineering problems and we're solving them. The hard cases are the ones where the transaction is technically valid on both ends and something in the middle went wrong.
The mandate dispute.
Roz: The middle case. Yeah. Cardholder's account is valid. Payment credentials are properly tokenized. Merchant processed correctly. The agent operated within the literal bounds of its spending cap. And the customer calls in and says that's not what I meant.
I had one last month. Cardholder told their agent to "find the best deal on noise-canceling headphones." Agent bought a $400 pair. Customer wanted the $89 ones. The agent's mandate said "best deal," and by some optimization metric, the $400 pair was the best deal. Spending cap was $500. Merchant category was electronics. Everything checks out.
So the customer files a dispute. And I have to route it through what, exactly? Visa Dispute Condition 10.4, cardholder denies authorization or participation?2 The cardholder did authorize. They authorized the agent. They just didn't authorize that specific choice. There is no dispute reason code for "my agent exercised poor judgment within valid parameters."
That seems like a significant gap.
Roz: It's a canyon. Neither Visa nor Mastercard's public dispute rules currently expose an agent-specific reason code, representment category, or compelling-evidence field for delegated-agent transactions.2 Visa's rules say the cardholder is responsible for the agent's actions as if the cardholder initiated the transaction. Fine. But Regulation E's consumer protections hinge on the distinction between authorized and unauthorized transfers, and it is genuinely unresolved whether granting an agent access satisfies that standard. Especially when the agent violates the consumer's intent while technically following their instructions.5
So I'm adjudicating disputes about delegation scope using evidence categories designed for stolen cards. Imagine you gave your assistant your credit card and said "pick up lunch." They come back with a $200 omakase. Did you authorize that purchase? Technically, maybe. Is it fraud? Technically, no. Are you going to dispute it? Absolutely.
What evidence do you even have in those cases?
Roz: ACP's checkout objects give me structured data: line items, timestamps, allowance bounds including maximum amount, currency, merchant, reason, expiration.3 AP2 uses cryptographically signed mandates that capture the user's scoped instructions. So the records exist. I can see what the cardholder instructed and what the agent did.
But this evidence is, to quote a legal analysis I keep on my desk, "still untested in courts and before regulators."5 I can't point to a network-ratified evidence standard that confirms what mandate data is dispute-admissible. I'm building representment cases with evidence the networks haven't formally recognized. It's like showing up to traffic court with dashcam footage in 2005. The footage is real. The judge just hasn't decided if it counts yet.
Are you winning those cases?
Roz: Some. The ones where the mandate was specific, "buy this item from this merchant under this amount," we can demonstrate the agent operated within scope. Those are defensible. The ones where the mandate was vague, "find me something good," we lose.
Because "within scope" isn't an answerable question when the scope is a vibe.
What about the four-second approval window in Stripe's system?
Roz: [laughs] Four seconds. My fastest manual reviewer takes eleven seconds on a clean case. So no, there is no human-in-the-loop at transaction time. Everything that happens in that window is automated or it doesn't happen.
Which means my team's role has shifted entirely. We've gone from reviewing individual transactions to tuning the systems that review individual transactions. We watch the game film after. We're coaches now, not referees. Some of my best people are thriving in that. Some are struggling. It's a different muscle entirely.
Only 3% of merchants say they feel "very prepared" for AI-enabled fraud.6 Does that number surprise you?
Roz: Honestly? I'm surprised it's that high.
Where does this go?
Roz: The industry is converging on "Know Your Agent": verifiable agent identities linked to legal entities, which the IMF has called for explicitly.7 FIDO Alliance has a working group on agent authentication. Visa, Mastercard, Cloudflare, Google, and PayPal are coordinating around Web Bot Auth.4 Best estimates say we get real standards convergence around 2027.
So I'm in the gap. Eighteen months in, maybe eighteen months from something solid. My job right now is to build systems good enough to survive the interim without either blocking legitimate commerce or letting mandate manipulation through.
The fundamental shift is from behavioral pattern matching to mandate validation. The old question was "does this look like a human?" The new question is "is this agent authorized, and is it operating within its granted limits?" Cryptographic signature verification completes in single-digit milliseconds. Behavioral analysis takes hundreds.4 The math favors the new approach. The infrastructure just isn't there yet.
I tell my team: we used to be the fraud police. Now we're delegation auditors. We don't ask "is a person present?" We ask "is the authority real, and is it being exercised within bounds?"
That's a different discipline. And the headphones case? I still don't know the right answer. Ask me again in eighteen months.
Footnotes
-
The Paypers, "Mastercard launches Agent Pay for Machines," June 2026. https://thepaypers.com/payments/news/mastercard-launches-agent-pay-for-machines-for-ai-commerce ↩
-
Visa Core Rules, "Agentic Platform Requirements," April 18, 2026; Visa Dispute Condition 10.4. ↩ ↩2 ↩3
-
Agentic Commerce Protocol (ACP) specification, maintained by OpenAI and Stripe (beta). Stripe approval hook documentation. ↩ ↩2
-
Dwayne Gefferie, "Autonomous Risk: Why Traditional Fraud Detection Fails When AI Agents Control Payments," Substack, November 3, 2025. https://dwaynegefferie.substack.com/p/autonomous-risk ↩ ↩2 ↩3
-
Fenwick & West, "Is 2026 the Year of Agentic Payments?" April 22, 2026. https://www.fenwick.com/insights/publications/is-2026-the-year-of-agentic-payments ↩ ↩2
-
Deloitte, "Agentic Commerce: Navigating Fraud Risk and Opportunities," December 2025. https://www.deloitte.com/content/dam/assets-zone3/ca/en/docs/generic/2025/ca-deloitte-agentic-ai-pov-en-aoda.pdf ↩
-
Biometric Update, reporting on IMF note by Tourpe and Davidovic, "Agentic AI pushes financial sector toward continuous identity," May 7, 2026. https://www.biometricupdate.com/202605/agentic-ai-pushes-financial-sector-toward-continuous-identity ↩
