READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Mastercard Rewrites Its Fraud Rules Because Bots Are Now the Customers, Not the Criminals

Mastercard Rewrites Its Fraud Rules Because Bots Are Now the Customers, Not the Criminals
Mastercard built decades of fraud defenses to block automated bots from making purchases. Now that AI agents are supposed to shop on people's behalf, the company says it has to flip that logic and let bots buy things while still catching actual fraud. Chief AI and data officer Greg Ulrich laid out the shift at VB Transform 2026 in Menlo Park.

Mastercard spent years teaching its fraud system one basic lesson: if a machine is making the purchase, stop it. That machine was almost always a criminal script trying to drain a stolen card.

Now the company says that assumption doesn't hold anymore. Greg Ulrich, Mastercard's chief AI and data officer, told the VB Transform 2026 audience in Menlo Park on July 14 that the network is rebuilding its risk models to let AI agents complete purchases instead of automatically flagging them.

"We've built a bunch of risk rules over time that were intended to stop a bot from transacting," Ulrich said, according to VentureBeat. "Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules."

The Math Behind Every Tap

Mastercard's network scored 175 billion transactions last year, according to Ulrich. Each one gets judged in under 100 milliseconds, spit out as a risk score from zero to 999, and handed to the issuing bank to decide whether to approve it.

Generative AI has made that scoring sharper, Ulrich said. By pulling in more data and context, Mastercard says it can now catch 300 to 400 percent more fraudulent transactions in the highest-risk categories, without slowing down legitimate purchases or generating more false declines. The company's Safety Net system has blocked more than 70 billion fraudulent transactions to date, per Ulrich's remarks. Mastercard is also building its own transformer model trained on its transaction data, which it plans to use as the base for future fraud, security and personalization tools.

These figures came directly from Ulrich at a named conference to a live audience of industry professionals, a more substantive source than a corporate press release. Still, these are Mastercard's own numbers about its own product, and no independent audit of the 300-400% fraud-detection claim or the 70-billion-transaction Safety Net figure appears in the available reporting.

Why the Old Rules Break Now

The logic problem is straightforward. For twenty years, "non-human traffic making a purchase" was close to a proxy for "fraud." Card networks built entire detection systems around catching bots, scrapers and automated scripts before they could complete a transaction.

Agentic commerce inverts that. If a consumer deliberately authorizes an AI agent to book a flight, refill a prescription, or restock groceries, the bot isn't a thief. It's doing exactly what it was told to do. But the network has to somehow tell that apart from a bot that's stolen credentials and is trying to do the same thing at 2 a.m. with a stranger's card.

Ulrich framed the entire challenge around trust rather than raw AI capability. "What's going to enable AI to continue to scale is not the capabilities of the agents, it's how much we trust those agents to do on our behalf as a consumer, as a business, as a financial institution, or otherwise," he said.

That's a fair way to state the stakes. It cuts against a common assumption in AI hype cycles that better models automatically mean faster adoption. Mastercard is essentially arguing the bottleneck isn't the AI, it's the plumbing that decides whether to trust what the AI does with your money.

The Skeptic's Case

A reasonable person should ask an obvious question: who's liable when an AI agent makes a bad purchase, an unauthorized one, or gets tricked by a scam merchant into overpaying? Mastercard's existing dispute system was built around a human cardholder disputing a charge they didn't recognize or didn't authorize. It's not obvious that framework translates cleanly when the "buyer" is a semi-autonomous piece of software acting on standing permissions a user granted weeks earlier and may have forgotten about.

Consumer advocates and fraud researchers outside Mastercard have raised versions of this concern about agentic payments generally, though none of the available reporting quotes a critic directly. The available reporting is entirely Mastercard's own framing of its own transition, delivered by its own executive at a tech industry conference. There's no independent fraud researcher, consumer protection attorney, or competing network executive weighing in on whether this transition is being handled responsibly.

The Business Case Underneath It

This isn't purely a security exercise for Mastercard. Ulrich said roughly 40% of the company's business now comes from services rather than core payment processing, including fraud and security services, marketing services, and business intelligence. A third of those service lines are built on AI, he said, and growing faster than the rest of the business.

That means Mastercard has a direct financial incentive to make agentic commerce work smoothly, not just a defensive incentive to avoid new fraud losses. Whether that dual incentive shapes how conservatively or aggressively the company sets its new bot-friendly risk thresholds is an open question nobody outside Mastercard has yet answered publicly.

The company hasn't announced a timeline for when the new risk framework rolls out broadly, nor has it published data on how agentic transactions are performing under the revised rules versus the old ones. That's the next thing worth watching: actual fraud-loss numbers once AI agents start making purchases at scale, not just a conference talk about the plan to let them.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
VentureBeatMastercard spent decades training its fraud system to see bots as thieves. Now bots are the ones doing the buying.
center
VentureBeatMastercard spent decades training its fraud system to see bots as thieves. Now bots are the ones doing the buying.