Every conversation we have with a bank about AI agents starts with a simple question: What are agents actually doing on our platform?
Most banks cannot yet answer that question. They lack the tools to recognize the bulk of agentic activity in real time.
BioCatch is, now, able to detect agentic traffic. And soon, agents logging in, checking balances, and moving money on behalf of real customers won’t just be an outlying novelty for banks and their accountholders but instead a sizeable portion of all digital banking traffic. As that agentic activity continues to grow, the conversation naturally turns to a harder question: Which of these agents will banks need to worry about?
That second question is where things get interesting.
The good agent and the bad agent
A good agent is like someone with a key: The key opens one door, the keyholder opens that door, and they enter a room where they’re welcome. A bad agent is like someone walking down a long corridor, trying every door handle they pass until something opens. To banks, these actions may appear identical. What distinguishes a good agent from a bad agent is what they’re trying to do.
The same attacks, unconstrained by human limits
Fraudsters have reverse-engineered bank controls for decades now, since long before agents entered the picture. None of that reverse engineering is particularly exotic. Fraudsters study and probe the detection thresholds banks use to identify suspicious activity, observing which transactions succeed and which draw unwanted attention. To stay below those limits, they split larger sums into series of smaller transfers that sit under the thresholds that trigger reviews. And they season accounts, keeping mules busy with small, ordinary activity for weeks so that when real money finally moves, it blends into an established history. These techniques work, but up until very recently, they’ve been slow and manual, bottlenecked by human effort and patience. That bottleneck is exactly what an agent removes.
Point an agent at a few accounts and a goal, and it can run that loop on its own: Try something, read the result, adjust, and try again, converging on the bank’s detection thresholds the same way the agent would solve any other problem. Agents can pace themselves to make their activity appear human, working many accounts at once. Crucially, one human operator can run multiple agents across hundreds of schemes in parallel. Nothing these agents do is a new type of attack. They’re the same attacks banks have weathered for years, just freed from the constraints that used to keep them small.
Seeing agents is the start, not the answer
This is why “is this an agent?” is only the first question. Blocking every agent denies customers the legitimate automation they’re starting to expect. Allowing every agent opens the door to everything above. And the agents most worth worrying about are the ones least likely to announce themselves.
What banks need is visibility: the ability to see agentic traffic, understand what it is doing, and read its intent. A good agent paying a bill behaves like it is paying a bill. An agent quietly mapping your controls behaves like it is mapping your controls. Intent (what the agent is trying to do) leaves behind behavioral signals.
While behavior provides the most crucial signals, which tool is driving the session matters too: A consumer assistant working for one accountholder is a different animal than a cloud tool running sessions at scale.
The device from which the session originates also adds much needed context. Have we seen this device run an agent before? Is it a device already tied to fraud elsewhere in the network?
While just one of those behavioral signals, identification of the tool in question, or a single login or device characteristic may not be enough for the bank to recognize an agent’s intent as malicious, all of those signals together over the course of a full session of continuously observed agentic behavior have a greater chance of revealing the agent’s intent.
That depth of understanding is what will let banks build and enforce policies on agentic access, deciding which agents to allow, which to challenge, and which to block.
The window is now
In the next few years, a bank’s ability to recognize and understand agentic traffic will be pivotal to its growth. The banks that learn to identify an agent, read its intent, and decide whether it earns access will move through the challenges of agentic activity without slowing their customers down.
For every session, it comes down to the same question worth asking from the very start: Who is driving the session, and can you trust it?
—
Key takeaways:
- Intent is a critical signal: Banks need to understand what an agent is trying to accomplish, whether its behavior fits an established pattern, what kind of agent it is, what its device history reveals, and whether it is operating within expected boundaries.
- Agentic traffic will make fraud decisions more complex: As adoption grows, banks will need to assess humans and agents simultaneously across legitimate, fraudulent, scam, and mule activity.
- Banks need to build these capabilities before agent volumes accelerate: Institutions that develop agent behavioral baselines and intent analysis now will be better equipped to stop malicious agents without disrupting legitimate customers and their authorized agents.
Resources: