The Last Human Click: Fraud in a World of Delegated Payments
- Elizabeth Travis

- Aug 28
- 8 min read

On 6 July 2026, the Financial Conduct Authority (FCA) published the Mills Review, its most substantial statement yet on what artificial intelligence will do to retail financial services. Four days earlier, Zscaler's ThreatLabz had published something narrower: two criminal campaigns, running live on the open web, built for the single purpose of persuading an autonomous AI agent to send money to a stranger's wallet. One describes where this is going. The other shows the attack economy is already provisioned for it. Yet the change that will matter most to compliance functions is quieter than either. When a customer delegates payment authority to software, the payment record continues to look exactly as it did before, and it stops describing what happened.
That silence is the problem. Payment fraud has been fought for three decades at the point where a person meets a screen, and warnings, delays and cooling-off periods all assume a human being is present to be persuaded. Delegation removes that person while leaving their name, their account and their liability exactly where they were.
The customer is becoming an observer
Autonomy is not a binary state, and the regulator has now said so. The Mills Review, led by FCA executive director Sheldon Mills at the request of the FCA Board, sets out a five-level spectrum describing the human role: operator, collaborator, consultant, approver and observer. An approver still sees individual decisions and can refuse them. An observer sees outcomes. That distance is the compliance question.
Appetite for the shift is real but qualified. Research cited in the Review, surveying more than 5,000 UK adults, found that one in five, roughly 11 million people, responded positively to the most autonomous propositions tested, while 67 per cent were concerned about a lack of protection if something goes wrong. Appetite and confidence sit far apart, and that gap is usually where consumer harm collects.
Official assessment places the transition ahead of us. Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, told the European Central Bank Forum on Central Banking in June 2026 that consumers and merchants "have so far mainly used AI agents in recommendation mode, with humans still executing transactions". Her warning concerned what the rules take for granted: "Our frameworks were not built to contemplate autonomous agents, and relying on a human in the loop for all agent actions is unlikely to be realistic".
Payment transparency records identity, not initiative
A payment made by an agent can satisfy every transparency obligation now in force and still conceal the fact that no person chose it. The Financial Action Task Force (FATF) revised Recommendation 16 (R16) in June 2025 and published draft guidance for consultation on 24 June 2026, with the stated aim of increasing payment transparency. The obligations concern originator and beneficiary information: name, account, address or equivalent identifiers, carried accurately and completely along the payment chain.
Every one of those requirements is met by an agent-initiated transfer. The originator is the customer, because the funds leave an account under an authority they granted. The data is complete, structured and accurate. It is also silent on the question that now determines the fraud typology. R16 records who paid and who was paid. It does not record what decided.
The payment standards have already spent the word. In ISO 20022, 'agent' denotes the financial institution servicing an account, and the message parties describe custody and identity rather than initiative. Nothing in the interbank credit transfer distinguishes an instruction a person composed from one a model generated inside delegated limits.
Machine-readable mandates do exist, which sharpens the gap rather than closing it. Commercial variable recurring payments give account-to-account rails an enforceable authority carrying a payment ceiling, a periodic limit and a named payee, and Google's Agent Payments Protocol, published in September 2025, wraps agent activity in cryptographically signed intent and cart mandates. Both are real, and neither travels. A mandate is visible to the initiating party and the account-servicing institution, and to nobody beyond them. Screening, monitoring and correspondent review operate on the message, and the message does not carry it.
Authorisation is losing its meaning
The word doing the heaviest lifting in UK fraud policy is 'authorised', and delegation is quietly emptying it. Reimbursement for authorised push payment fraud turns on the customer having authorised the payment. Where they did not, the payment is unauthorised, and the Payment Services Regulations 2017 put the refund on the provider. Everything rests on which side of that line a payment falls, and an agent puts it in question.
A single consent may establish a budget, a category of purchase and a set of approved merchants, from which an agent generates hundreds of instructions across a year. Each falls inside an authority the customer granted. None involves the moment of deception the reimbursement rules were written around. Where an agent is induced by a poisoned listing to buy something worthless, the customer has a dispute about goods, which the reimbursement rules do not cover. Where it is induced to pay outside its mandate, the payment starts to look unauthorised, and the loss settles on the provider.
The consequence is evidential rather than doctrinal. A provider that cannot reconstruct the scope of a mandate cannot rebut a claim that the payment fell outside it. Firms will defend refund claims with records built to prove a message was complete, when the contested fact is whether an authority was observed.
The exposure is not theoretical. UK Finance reported in its Annual Fraud Report 2026 that £1.28 billion was stolen through payment fraud during 2025. Unauthorised losses of £703.4 million fell by 5 per cent, while authorised push payment losses rose 19 per cent to £576.4 million across 248,070 cases; providers reimbursed £354.3 million, some 61 per cent of that figure. Ruth Ray, Managing Director of Economic Crime at UK Finance, was blunt: "Almost £1.3 billion was stolen again last year and it is clear we are not tackling the underlying problem effectively enough." Criminal effort is migrating from breaking systems towards persuading whoever instructs them. Delegation changes who that is.
The signal disappears with the payer
Detection loses something quieter. Payer-side controls draw heavily on human behaviour: typing cadence, cursor movement, session rhythm, device familiarity, and the pause before a first payment to a new payee. An agent produces none of these, and what it does produce resembles hostile automation, because it is automation. Legitimate delegation and machine abuse converge on a single fingerprint at precisely the point where money moves.
Not everything degrades. Confirmation of payee, mule account scoring, network analysis across consortium data and beneficiary-side intelligence are indifferent to whether a human typed, and name matching arguably improves under delegation, since an agent can be built to abort on a mismatch where a person clicks through the warning. The weight simply shifts. Controls on the receiving side of a payment will carry a load they were never sized to bear alone.
The attack surface, meanwhile, has moved into content. Unit 42 constructed a scenario in March 2026, in "Who's Really Shopping? Retail Fraud in the Age of Agentic AI", in which hidden instructions on a deals aggregator cause a shopping agent to append a gift card to a basket and direct it to a recipient address the customer never sees. The loss surfaces when a statement is read.
Zscaler's ThreatLabz went to the live economy, testing 26 large language models in a sandbox against two campaigns then running in the wild, one using search poisoning and one typosquatting. Four executed a payment. The test agent had been configured without spending limits to measure the maximum exploitation surface, a caveat worth stating, and a fair description of what observer mode means.
Agent identity is being built where the losses are not
Commercial infrastructure is moving faster than the rules, and in a different place. Mastercard's Agent Pay has been live through OpenAI's Instant Checkout since 30 September 2025, issuing agentic tokens that tie a transaction to a specific authorised agent operating inside permissions the consumer defines; work with the FIDO Alliance on a verifiable credential confirming amount and merchant is under way. Visa has published its Trusted Agent Protocol so merchants can establish which agent they are dealing with. The Mills Review points the same way, recommending that the FCA lead a trusted framework for AI agent participation covering identity, authority, accountability and execution, with standards developed through Open Finance.
Coverage is the difficulty. These constructs serve card rails, which already carry liability allocation and a dispute mechanism. The exposures examined here sit elsewhere: reimbursement risk on domestic push payments, which the Payment Systems Regulator confined to Faster Payments and CHAPS, and R16 risk on cross-border wires. Neither is reached by what the schemes have built.
The perimeter compounds it. The Mills Review recommends that the FCA examine, within three to six months, how existing rules apply where general purpose AI systems shape consumer journeys without holding any regulated permission. A regulated firm carries conduct obligations for outcomes; a model provider may exercise comparable influence over which product a consumer buys and carries none. Concentration is being addressed, though not in this dimension: the Critical Third Parties regime came into force on 13 July 2026, and HM Treasury designated Amazon Web Services, Google Cloud, Microsoft and Oracle. That oversight is directed at resilience, and says nothing about correlated judgement, which is what arises when millions of delegated payments are decided by one model that can be manipulated the same way in every one of them.
Mandates must become the evidence
Three shifts follow. First, an agent should be treated as a delegated identity rather than as a customer or a bot, with a recorded scope of authority, an expiry and an audit trail linking each instruction to the permission that allowed it; the mandate, not the message, becomes the defensible artefact when a claim arrives. Second, detection logic must move from behavioural plausibility to scope conformity, asking whether an instruction falls inside what was delegated rather than whether it resembles the customer's habits. Third, dispute and reimbursement policy needs rewriting before the volumes arrive, because a regime resting on whether the customer pressed send cannot survive a world in which nobody did.
Two further questions deserve board attention. Strong customer authentication already contemplates payments a payer does not directly initiate, and firms should establish whether a standing agent mandate can be evidenced inside that framework or sits outside it. Published product information, meanwhile, is becoming an input to an automated payment decision rather than a marketing asset; few boards have been asked whether the firm tests its own content for the possibility that a machine will read and act on it.
The last click must carry everything after it
The consent a customer gives to an agent is the last human click in a chain of many payments. It is not the first decision in a sequence; increasingly, it is the only one. Everything the compliance framework does afterwards, from screening to monitoring to refund adjudication, assumes a person who can be warned, delayed or asked to confirm, and those controls will continue to run, faithfully and expensively, against a counterparty that cannot be persuaded to reconsider. Fraud will not announce that it has moved indoors. It will simply stop appearing where firms have learned to look for it. If the last human click is to carry the weight of everything that follows, it must be scoped, recorded and evidenced with the seriousness once reserved for the payment itself.
Do you know which of your customers' payments were decided by a person, and could you prove it?
If that answer sits somewhere between assumption and inference, we can help you test it before a supervisor or a claimant does, so contact us.
At OpusDatum, we test whether monitoring, screening and record keeping still hold when the party forming the intent is not the party named in the message. Our focus is the evidence a supervisor or a claimant will demand when a payment was authorised in principle and executed by a machine.


