Trust at machine speed: Why the next era of payments will be won on visibility, not fortification

by Michael Wallis-Brown, Senior Market Specialist, Payments & Banking, FIS

Share this post

As AI accelerates cyberattacks and fraud, payments firms need network-wide intelligence to assess trust and stop threats before settlement.

In July, the European Central Bank did something it had never done before: it wrote to the chief executives of the roughly 110 banks it directly supervises about a technology threat. Claudia Buch’s letter gives significant institutions until 31 October to submit board-endorsed action plans against AI-enabled cyberattacks. The same day, the European Systemic Risk Board raised its assessment of cyber risk to “severe”.

The diagnosis behind both is simple and uncomfortable: frontier AI has collapsed the time between vulnerability and exploitation. Attacks that once took weeks of skilled human effort now run continuously, at machine speed. And what is true of cyber intrusion is increasingly true of fraud.

The asymmetry we have built

Look at the UK, which is the most instructive fraud market in the world because it publishes its data. Losses reached £1.28 billion in 2025. But the detail matters more than the headline. Unauthorised fraud (the traditional, technical kind) fell 5%, and roughly 70 pence of every pound attempted was stopped before it moved. Authorised push payment scams went the other way: up 19% to £576 million, with investment scams up 40%. Banks are winning the fight their defences were built for. Criminals have simply moved to a different fight and are manipulating people rather than breaking systems, with generative AI industrialising persuasion itself.

Here is the structural problem. Fraud at this scale operates as a network. A scam campaign spans social platforms, telecommunications companies and dozens of institutions; mule chains hop across banks; the same synthetic identity probes one firm after another. Yet defence remains stubbornly institutional. Each bank invests in its own models, trained on its own slice of the flow, seeing one hop of a journey that may cross ten. We are fighting network-shaped crime with node-shaped defences, an asymmetry no amount of individual spend can close.

What the UK experiment proved

The UK’s mandatory reimbursement regime, in force since October 2024, has become the industry’s clearest natural experiment. As consumer protection, it works: 89% of in-scope APP losses were reimbursed in the first 15 months, and an independent review estimates the rules have cut losses by around £73 million a year by sharpening banks’ incentives. But UK Finance itself makes the sharper point: reimbursement reallocates losses after the fact. It does not stop the money reaching organised crime.

The durable answer is prevention before settlement, and prevention is a visibility problem. You cannot stop what you cannot see coming, and on instant, irrevocable rails there is no “after” in which to claw the money back.

Then the agents arrive

Now compress the timeline further. Visa expects millions of consumers to let AI agents complete purchases by this year’s holiday season; Mastercard’s Agent Pay is already live in Asia and expanding. McKinsey projects $1 trillion dollars of agent-driven transactions in the US alone by 2030. Agentic commerce will be a genuine convenience revolution, and it moves the moment of trust from a human’s thumb to a machine’s API call.

Verifying the agent (mandates, scoped tokens, revocable credentials) is necessary, and the networks are building it. But credentials settle only the question of identity: is this agent authorised? They cannot settle the question of legitimacy: should this payment, in this context, be happening at all? Identity is a property of the credential. Legitimacy is a property of the flow, and only intelligence, watching the whole flow, can judge it. Intelligence, unlike credentials, compounds with visibility.

That is why the most telling moves of the past two years were acquisitions: Visa buying Featurespace, Mastercard buying Recorded Future. The networks have understood that as rails commoditise, advantage migrates to the layer above them.

What the sector should do

Michael Wallis-Brown, senior market specialist, payments & banking, FIS

Three shifts follow. First, stop treating fraud and cyber as separate control functions; the ECB letter effectively merges them into a single board-level question about resilience at machine speed. Second, move risk decisions before settlement and make them fast enough for agent-initiated, instant flows, milliseconds, not minutes. Third, and most decisively: treat intelligence-sharing as infrastructure, not a compliance gesture. Supervisors are already asking institutions how they participate in collective defence. The firms that scale safely in the agentic era will be the ones that can see beyond their own perimeter.

Trust used to be built over years and verified in days. It now has to be computed in milliseconds, for customers who may be software. No single institution can do that alone—structurally, not for lack of effort. What one institution cannot see, the network can. In payments’ next chapter, trust is a network property—and it will be won on visibility, not fortification.

FIS-LOGO-green-2
Article by FIS

Follow us

Conferences

Networking events

Payments Intelligence

Insights Podcast

Insights Video

Membership

Merchant Community Membership

Are you a member of The Payments Association?

Member benefits include free tickets, discounts to more tickets, elevated brand visibility and more. Sign in to book tickets and find out more.