Tue, 21 Jul 2026

PodChats for FutureCISO: Agentic AI fraud—Can digital trust keep up?

APAC CISOs face an escalating battle as AI agents rapidly outpace traditional defences. Key issues include distinguishing legitimate actions from malicious automation, soaring fraud speeds, and customer attrition from either excessive friction or unreimbursed losses.

The year is 2026, and the financial sector is at an inflexion point. The tools of science fiction are now the instruments of everyday fraud. For CISOs in Southeast Asia and Hong Kong, the question is no longer if agentic AI will disrupt their fraud prevention models, but how fast and how effectively they can respond. Digital trust, the bedrock of the banking relationship, is under siege.

The new reality: Fraud at machine speed

The threat is no longer hypothetical. BioCatch's 2026 report, The Future of Digital Trust, reveals that 80% of banking leaders globally say their institution has already encountered attacks utilising agentic AI.

In the Asia-Pacific region, where digital adoption is sky-high, the convergence of AI and organised crime is creating a perfect storm of vulnerability. Fraudsters in the region's notorious scam compounds are using AI-powered deepfakes, voice cloning, and multilingual chatbots to scale their operations with frightening efficiency.

This new wave of fraud is characterised by its speed and sophistication. "It's unanimously being seen that year-on-year fraud attempts have risen in terms of both the number of attempts, the losses, as well as the speed at which these are getting executed," warns Subhashish Bose, director of global advisory at BioCatch.

While traditional fraud was a game of hit-and-miss, agentic AI industrialises the process. A report from Boston Consulting Group suggests that agentic systems could slash the cost of running a scam by 90%, leading to a twofold—or more—surge in successful attacks.

The authentication crisis: Knowing the agent

The core challenge for banks is a fundamental crisis in authentication. For decades, security relied on verifying a user's identity. Today, that is insufficient. As Bose explains, banks are being forced to distinguish between legitimate AI-assisted customer actions and agentic AI-driven fraud—a task that's becoming nearly impossible to perform with traditional tools. In the BioCatch survey, 72% of leaders believe it will be very difficult to distinguish between legitimate AI-assisted actions and malicious AI activity.

This is what experts call the "dual authentication crisis." It's no longer just "are you who you say you are?" but "did you authorise this agent to do these things?". Bose notes that banks need systems that can identify the presence of an agent itself.

Related:  PodChats for FutureCISO: How to be a successful CISO in 2023

This can be done by detecting "agent signatures" or behavioural anomalies. For instance, an agentic browser might have a distinct window gap or a side panel or show unusual copy-paste behaviour. "These kinds of telltale signals are something that can be used to detect the presence of an agent," Bose states.

Rethinking friction and customer attrition

As fraud attempts surge, the instinct is to add more friction—more authentication checks, more steps—to customer journeys. However, this approach is proving counterproductive. The BioCatch report found that 68% of banking leaders believe their organisation's approach to fraud prevention and reimbursement has resulted in a net loss of customers.

Bose argues that banks are forced into a false choice: security or usability. "They can actually win on both," he insists.

The solution is "intelligent friction." This means using real-time behavioural intelligence to apply friction only when and where it's needed—for example, asking contextual questions during a suspicious transaction to "break the spell" on a scam victim, rather than putting every customer through a cumbersome process.

"Using the signals and using the scores and AI to then intervene more naturally with the victim to kind of try to break that spell... is where the future lies," Bose explains.

The power of collaboration: A collective defence

Given the speed and scale of agentic AI attacks, no single bank can defend itself in isolation. The industry's unique move towards interbank intelligence sharing is no longer a "nice-to-have"; it is an operational necessity. 86% of respondents in the BioCatch survey agree that gaining real-time intelligence sharing on the receiving account would improve their ability to stop scams.

"The receiving account is a very important piece of this problem-solving," says Bose. He points to successful models in countries like Australia and Argentina, where a real-time network of anonymised device and behavioural signals is shared between sending and receiving banks.

"The network shares this intelligence across both sides in real time," he explains. "If there's a scam underway, it gives a much stronger uplift in terms of confirming that it's a scam given that the receiving side is a high potential of a mule."

This collaboration extends to tackling the "mule account" economy—a problem, Bose notes, that is "no longer just an AML team's burden." By collectively identifying and flagging these accounts, banks can choke off the infrastructure that enables fraud to flourish.

Related:  PodChats for FutureCIO: Strategies for more effective real-time security

A call to action for the APAC CISO

For CISOs in the region, the message from industry leaders is clear: digital trust is fragile, and the battle is intensifying. The financial crime landscape is now a "full-blown global crisis," according to the BioCatch report.

Financial institutions are being urged to move beyond static identity checks and invest in behavioural intelligence, device signals, and network-level intelligence to stay ahead.

While 84% of banking leaders view AI agents as the industry's greatest vulnerability, organisations can take concrete steps to build resilient defences. The report emphasises that institutions must prioritise innovation, build adaptive teams, and foster a culture of transparency to protect their customers and preserve the very trust that underpins the global economy. As Bose succinctly puts it, the challenge is real and rapidly evolving.

"It's on our doorstep. It's an inflexion point at this point. So, we really need to sit up kind of and take notice of this." Subhashish Bose

Click on the PodChats player to hear Bose elaborate on what CISOs can do as Agentic AI enter the workflow, and what security teams may need to do to keep digital trust.

  1. What are the key salient points of the future of digital trust report?
  2. How can we distinguish legitimate AI-assisted customer actions from agentic AI-driven fraud in real time?
  3. What behavioural and intent-based signals can replace static identity checks as AI agents mimic human behaviour?
  4. How do we prevent customer attrition caused by either excessive friction or unreimbursed scam losses?
  5. What interbank intelligence-sharing frameworks can we deploy to stop authorised fraud at the receiving account stage?
  6. AI-powered scammers are on the rise. How do we accelerate fraud detection systems to match the rising speed of AI-generated attacks?
  7. What investments are needed to counter agentic AI attacks that 79% of our peers have already encountered?
  8. How should we restructure fraud and scam reimbursement policies to maintain trust without increasing vulnerability?
  9. What metrics will tell us whether our AI defences are reducing fraud losses or merely shifting criminal tactics?
  10. What is your advice for CISOs, CIOs and banking executives in the face of this rising AI-driven fraud?
  11. What is the biggest myth related to financial fraud with AI?

Related Stories

MORE STORIES