I’m on a Jimmy Buffett kick.
Before you contact the authorities, before you revoke whatever “cool” card I’ve got left, before you summon 18-year-old me to lay a beatdown on…30-something, not-quite-40-something-year-old-me…
Hear me out.
In the fall of 1976, Buffett hit the studio with his Coral Reefer Band to record an album for ABC. Leading off the B-side was “Margaritaville,” a song that of course needs no introduction as it rightfully lives on in infamy as one of the most insipid earworms ever committed to wax.
But I’m not here to discuss that one. South Park already sent it up. And we don’t pile on here at the Risk Intelligence Corner.
Instead, it’s the title track to the album ("Changes in Latitudes, Changes in Attitudes") that echoes in my head on this rainy West Texas morning.
Why?
Take a trip down memory lane and revisit the lyrics Buffett penned for the song’s chorus:
It's those changes in latitudes, changes in attitudes
Nothing remains quite the same
With all of our running and all of our cunning
If we couldn't laugh we would all go insane
For the life of me, I can’t think of a refrain in Gulf and Western – or the thousands of genres beyond it – that quite sums up the current state of ecommerce fraud prevention as well as ol’ JB’s linguistic engineering in that hook.
Here’s why:
“Nothing remains quite the same”
Let’s rightfully disperse with the academic maxims, theorems, and truisms here at the jump:
“There is nothing permanent except change.” — Heraclitus
“All is flux, nothing stays still.” — Plato
“All things must pass.” — George Harrison
There ya go: the certified Big Dogs have been summoned to imbue this screed with the requisite level of haughty-taughtyness to make it stick in your heart, dear Reader.
The fraud world, changing?
“No way,” you think to yourself, perhaps spitting out your morning brew in feigned disbelief.
You’ve lived through 3DS, CCPA, VAMP, and dozens of other industry-wide sea changes masquerading in cryptic acronyms.
You’re used to this by now.
But are you buckled up for Agentic Commerce? Bot-driven orders from the likes of Google, Visa, Amazon, OpenAI et. al., executing orders at the behest of humans while bearing none of the traditional markers of humanity?
We talk about this regularly on the Fraudcast (every Wednesday, 2pm ET/11am PT, check it out.)
And from conversations with industry pros at the Fraudcast over the past few months, I’ve identified two burning questions around Agentic Commerce:
How do we evaluate fraud in the absence of human-centric signals?
Exactly who is liable when things go awry?
Let’s tackle those questions in order:
The New Science (Fraud Analysis in a Bot-Driven World)
Bad Actors + Bots = Bread + Butter
Regardless of your stance on the adoption of Agentic Commerce across the broader online buyer population – whether you think regular folks are only going to use AI agents to re-up their annual polo shirt haul, or if they’re going to go as far as allowing AI to dictate where their families spend their summer holidays – a few things are certain:
Agentic Commerce isn’t just coming, it’s already here.
And it’s really just a matter of how much of your overall traffic becomes bot-driven.
And it’ll just keep coming.
And it’ll quickly become a playground for nefarious acts from that same population of neer-do-wells who take pleasure in Ruining Good Things.
So what types of signals do you think would show an AI shopping agent was compromised?
As the great Dr. Antoine Vastel writes:
“Never trust a ‘good bot’ solely based on the User-Agent string.”
Dr. Vastel’s work at Castle is the gold standard in our New Science of fraud detection in a world of AI-driven orders.
And once you peruse Dr. Vastel’s work, you’ll find calls-to-action around IP validation, authentication headers, signed tokens, and bot attestation.
So what does this mean for you on the front lines of ecommerce fraud protection?
Time to learn more about bots?
Sure – we are lifetime learners, after all, which is probably what keeps us in this field.
But I’m thinking a little bit differently here:
It’s time to bring the donuts to your security team.
Whether we like to admit it or not, us Fraud Folks are cross-threaders of the highest caliber. Our findings and insights affect every aspect of our respective organizations.
And in that vein, our Security Engineers and CISOs need to become our new best friends.
Why?
For starters, is your perimeter defense blocking bots holistically?
If so, think of the revenue we’re leaving on the table.
Have you evaluated your API strategy to make your site more crawlable/indexable/accessible to Agentic Commerce?
If not, again: think of the money, honey!
Finally, what does your CISO think in regards to user agents, IP validation, authentication headers, signed tokens, bot attestation, etc…
Remember: your insights are valuable, dear reader.
Grounds for conversation yield collaboration.
Collaboration is king.
And the future is agentic, whether it’s 1%, 10%, or 50% of your traffic.
As Clinton Sparks used to say: “Get familiar!”
The Underwriting Dilemma
By now, we’re all-to-familiar with AI’s penchant for hallucination.
Generating images of human models with eight fingers and three eyes.
Telling you that your favorite nail salon is closed for business when it’s thriving.
Estimating that you’ll need hundreds of gallons of wood stain to finish your chicken run when one gallon will suffice (note: this actually happened to me.)
So what happens when an AI shopping agent goes rogue and sends thousands of blue polo shirts to your house because you requested the lowest possible price and the agent realized that bulk buying yields a significant discount?
What about buyer remorse: the blue shirt I requested is actually mauve.
The “large” is actually “schmedium.”
And naturally: what happens when Amazon’s “BuyForMe” bot is convincingly replicated or otherwise compromised?
Tokenized payment methods fall into the wrong hands.
Thousands of fraudulent orders fulfilled in seconds.
Who is on the hook?
I spoke with fraud legend Coby Montoya on a recent Fraudcast and asked him these questions.
Coby’s fraud experience spans decades. He’s covered the waterfront in the industry, touching merchant/payment network/card issuer/solution provider.
Perhaps no one else has Coby’s perspective. He’s in rare air.
And Coby’s outlook on the underwriting dilemma is clear:
Card brands are profit-driven, conservative by nature.
Profit dictates policy.
As soon as underwriting becomes untenable, liability coverage shifts.
So while there may be promises of protection – similar to the digital wallet world – as soon as chargebacks spike, we can expect the hot potato to be passed back to the merchant.
In which case, the buck stops on your desk.
And you’ll be wishing you brought those donuts to your Security Team and played more Wordle with your CISO.
Paradise (By the Dashboard Light)
Sure, we’re mixing Meatloaf with Jimmy Buffett. And Clinton Sparks. And Plato.
That’s just what we do at the RIC.
But don’t get it twisted – we’re entering a paradisiacal era of fraud prevention.
From your seat, you can see the world.
Your insights span the company, the culture, and beyond.
And you’ve made it this far into the newsletter – you’re an astronaut.
Crossthread and conquer, my friends.
I’m always here to help.
🍔 Hungry for more Risk Intelligence and Ecommerce insights?
Make sure you check out the Risk Intelligence Corner!
🗓️ Also, join us every Wednesday at 2 PM ET for The Weekly Fraudcast, where I lead a casual conversation on the most relevant trends in ecommerce and risk intelligence between dozens of passionate professionals.

