Mastercard Redesigns Fraud Rules as AI Agents Become the Shoppers
Mastercard's Greg Ulrich explains how AI agents are forcing a rebuild of fraud rules, trust layers, and risk scoring at VB Transform 2026.
Mastercard's fraud engine scores each of its roughly 175 billion annual transactions in under 100 milliseconds, but the system was designed to flag bots as threats. Chief AI and data officer Greg Ulrich told VB Transform 2026 that agentic commerce is inverting that assumption: AI agents are now the buyers, and the network's risk rules need to authorize them rather than block them.
Generative AI has already sharpened the existing fraud stack, letting Mastercard catch 300-400% more fraud in high-risk transaction bands without added friction, part of a Safety Net system that has stopped over 70 billion fraudulent transactions. But agent-initiated purchases require a different kind of trust: verifying not just a consumer but the agent acting on their behalf, and confirming that a purchase matches the original delegated intent.
Mastercard's answer is a five-layer framework spanning identity (know-your-agent), verifiable intent, spending controls, execution via Mastercard Agent Pay (live with Microsoft, OpenAI and Google), and an intelligence layer combining risk models with threat monitoring. Ulrich frames B2B procurement, not consumer checkout, as the bigger long-term opportunity, and warns that guardrails bolted on after deployment are a losing strategy — they have to be built into the architecture from the start.