I recently joined Liminal’s Friday Five, a format that runs five questions in a few minutes, for a short conversation about where the identity and fraud market is heading. You can watch the full conversation below, and what follows is the longer version of the answers I gave, with the elaboration the Friday Five format does not allow.
I lead Trulioo, a company that verifies identities and empowers payment providers, fintechs, marketplaces, and banks across more than 195 countries to fight fraud and financial crime. From that vantage point, here’s what I see, and what worries me: despite two years of conversation about AI and fraud, the operational response has not caught up to the awareness. Companies know the risk is coming, but most are not actually changing how they work in time.
That gap, between knowing and doing, is where the next wave of losses will land. Awareness is not preparation, and the industry has been treating the two as the same thing for too long.
What we got wrong about agentic commerce
Filip asked what assumption about our market turned out to be wrong. The honest answer is agentic commerce. A year ago, I would have told you it was about to break wide open. Nine months in, that has not happened, and we were wrong on the timing.
The reason matters. Figuring out a consumer’s intent turns out to be harder than the industry assumed, and so does the merchant-side problem of distinguishing a real agent from a bot pretending to be one. I have spent the past nine months reframing how we think about both, because the wave is still coming, just on a longer fuse than we predicted.
This delay is a window, and it is closing faster than the prevailing investment pace suggests.
The losses coming, and why I don’t think we are ready
When Filip asked what most people aren’t preparing for in the next 12 to 18 months, this is what I told him. People are not prepared for the amount of losses that are going to be incurred thanks to AI, thanks to agentic commerce, thanks to all the fraudsters, mules, and gangs trying to figure out novel ways to attack consumers.
I don’t say that to be dramatic. Deloitte projects AI-enabled fraud losses in the United States could hit $40 billion by 2027, up from $12.3 billion in 2023. That projection assumes companies adapt fast enough. I am not yet convinced most will.
I say that because what I see across borders gives me an earlier read than most individual institutions have. When you process identity at scale across geographies, attacks don’t surface at every bank or fintech at the same time. They first appear in systems that cross jurisdictions, then radiate out. The patterns I’m watching right now are not identical to the ones we saw twelve months ago, and the operational playbooks at most companies have not adjusted.
The more honest version of the problem is this: people are still not fully aware of the full extent of the risk, but more importantly, what they should be doing right now to make it effective for their customers to really handle the situation.
The fix must be something beyond a point solution. It has to be a structural response.
Why siloed detection is the vulnerability
On the trade-off question, the one buyers in our category most consistently underweight, my answer was legacy versus new. Replacing an integrated risk stack is hard, and the cost and time look real, so the default position becomes: keep what we have, bolt something on at the edges, and hope it holds. In my experience, that is the path that causes the most damage.
Where companies are losing the most opportunities is in stitching their processes together so that financial crime becomes something they’re aware of from onboarding through to account closure. Today, it’s just in silos, done inappropriately in a way that I think harms them rather than helps them.
A customer who passes onboarding cleanly can become a mule four months in. A merchant that looks fine in a transaction snapshot will show clear patterns of abuse if you connect onboarding behavior, transaction history, and dispute outcomes. Siloed systems cannot see those signals because they exist only in the connections between them.
If I had to name the single operational shift companies should be making right now, it would be this: stop treating identity as a check at the door and start treating it as a continuous read across the customer lifecycle. The companies that make that shift will absorb the next wave, and those that don’t will be in the loss numbers.
Excellence is the everyday thing
Filip closed the Friday Five by asking what small hill I’d die on that most people would think is trivial. I get laughed at in my company for my answer, but I’ll say it anyway. To me, excellence is all in the small things. If the coffee in our office is bad, I cry blue murder. If there’s no mouthwash in the bathroom, I cry blue murder. It’s not because those things matter on their own. It’s because the spirit of excellence has to be an everyday effort. If you truly care about the small things, the big things tend to take care of themselves.
That same instinct shapes how I think about the wave of fraud I see coming. You don’t get ready for a once-in-a-decade attack pattern by sprinting at the last minute; you get ready by doing the daily work, year after year, when no one is watching.
Key Takeaways
- AI-enabled fraud losses are coming faster than most companies’ operational response, with awareness high but preparedness lagging.
- Agentic commerce arrived later than expected, but the underlying risk has not gone away. The delay is a window, not a reprieve.
- Siloed detection across onboarding, fraud, AML, and transaction monitoring is the structural vulnerability. Integration from onboarding through account closure is the fix.
- The companies that absorb the next wave will be the ones doing the everyday operational work now, not the ones buying point solutions at the last minute.





