# Visa Warns AI Fraud Is Surging Just as Shopify Lets Agents Complete Checkout

> Source: <https://startupfortune.com/visa-warns-ai-fraud-is-surging-just-as-shopify-lets-agents-complete-checkout/>
> Published: 2026-09-29 14:56:44+00:00

*Visa handles about a third of global card payments. Its own fraud chief now says generative AI has turned scamming into a prompt-level skill.*

Visa's Spring 2026 Biannual Threats Report puts a number on a trend the company has been watching build: nearly $1 billion in scam-related activity identified between July and December 2025, making scams the fastest-growing source of consumer payment fraud. Michael Jabbara, Visa's global head of fraud solutions, said what once required deep technical skill can now be executed with a prompt. The report comes out the same week Shopify opened checkout to autonomous shopping agents.

That's not a hypothetical. Visa's Payment Fraud Disruption unit tracked a more than 450% jump in dark-web posts discussing "AI Agent" tools over a six-month stretch, according to Visa's own research covered by Digital Commerce 360. Criminals are using generative AI to build synthetic websites, spoof brands, and run fake customer-service chatbots convincing enough to keep a victim on the phone for days, discouraging them from calling their bank while the fraud plays out.

Here's the tension. While Visa was publishing that warning, Shopify was busy expanding exactly the kind of AI agent access that makes fraud teams nervous. On September 28, Shopify's developer changelog rolled out WebMCP support for checkout across its roughly two million stores, adding four tools, including get_checkout, update_checkout, and complete_checkout, that let AI agents read a shopper's cart, change the delivery address, and submit an order inside the buyer's own browser session. TechCrunch covered the rollout the same day. Shopify insists this isn't autonomous purchasing: the tool that finalizes an order is labeled "submit checkout after buyer confirmation," and the company has struck direct partnerships with agent platforms including Muse and Instinct.

Not everyone is convinced the guardrail matters yet. Amazon has blocked Meta's Muse agent from its retail site entirely, and Adidas has reportedly taken steps to keep AI agents from buying on its platform, according to Bloomberg's reporting in September. Shopify went the other direction. That split tells you the industry hasn't agreed on how much autonomy an AI agent should get near a checkout button, even as the technology to give it that autonomy already ships.

[Shopify lets AI agents finish checkout on its two million stores](https://startupfortune.com/shopify-lets-ai-agents-finish-checkout-on-its-two-million-stores/)

Shopify expanded its WebMCP protocol on September 28 so AI agents like Meta's Muse and Instinct can complete checkout, not just browse and add to cart, across its more than two million merchant stores. The move outruns any settled answer on who is liable when an autonomous agent, not a human, submits the order. - [AI agents completing checkout on Shopify stores](https://startupfortune.com/shopify-lets-ai-agents-finish-checkout-on-its-two-million-stores/) - [how Shopify WebMCP agents submit orders automatically](https://startupfortune.com/shopify-lets-ai-agents-finish-checkout-on-its-two-million-stores/)

Visa isn't just complaining from the sidelines. Back on October 14, 2025, it introduced the Trusted Agent Protocol, an open specification that signs an AI agent's identity into HTTP request headers using HTTP Message Signatures under the emerging Web Bot Auth standard. A merchant's server can cryptographically check a Visa-run directory of Ed25519 public keys and answer one question: is this a legitimate shopping agent or a bot pretending to be one. Twelve launch partners signed on, including Shopify, Coinbase, Stripe, Microsoft, and Cloudflare as co-developer. Akamai joined later to bolt its bot-detection layer on top.

It's a real technical answer to a real problem. But a verification badge only stops fraud at merchants who actually check for it, and adoption across two million Shopify stores and however many other platforms racing into agentic commerce won't happen overnight. In the gap, Visa's own numbers say the fraud is already scaling faster than the defense.

The money is moving on parallel tracks that make the stakes higher, not lower. The same week as Shopify's checkout news, Citi and Coinbase expanded a partnership announced back in October 2025, letting Citi's institutional clients accept stablecoin payments through the Spring by Citi platform, with Coinbase converting digital assets into fiat for settlement, as The Block reported on September 28. Coinbase is also a Trusted Agent Protocol launch partner, which means the same company helping route stablecoin payments for corporate clients is also on the list of firms trying to keep bad actors out of agent-driven checkout. Block's Cash App and other payment players are chasing similar AI integrations. Everyone building the convenience layer is, to varying degrees, also building the security layer, often at the same time, often with the same partners.

For founders and investors building fintech and payments tools, this isn't a footnote. Any startup pitching an AI checkout, an autonomous shopping agent, or an AI-driven payment rail is now walking into a compliance conversation that didn't fully exist a year ago. Visa's fraud data gives banks, card networks, and regulators a concrete number to point to when they ask how a new agentic product handles authentication, and "the agent confirms with the buyer first" is likely to get more scrutiny, not less, as the dollar figures climb. Frankly, a pitch deck that treats agent autonomy as a pure UX win without addressing how it gets verified is going to have a hard time in this environment.

None of this means agentic commerce stalls out. Visa itself is betting on it, having launched AI-transaction infrastructure with AWS in December 2025 and continuing to expand Trusted Agent Protocol partnerships into 2026. The company that processes a third of global card volume clearly believes agents completing purchases is where payments are headed. It just also has the clearest view of anyone into how much fraud is riding along for that ride, and its own numbers say the criminals got there first.

**Also read:** [Inside PRAAMS, the Investment Infrastructure Bringing Research, Risk and Portfolios Into One Workflow](https://startupfortune.com/inside-praams-the-investment-infrastructure-bringing-research-risk-and-portfolios-into-one-workflow/) • [Google sues the EU to stop opening Android to rival AI assistants](https://startupfortune.com/google-sues-the-eu-to-stop-opening-android-to-rival-ai-assistants/) • [Microsoft folds Copilot into one app and bets its AI future on business, not consumers](https://startupfortune.com/microsoft-folds-copilot-into-one-app-and-bets-its-ai-future-on-business-not-consumers/)

[MSCI Splits the AI Trade Into Layers So Wall Street Can Hedge It Piece by Piece](https://startupfortune.com/msci-splits-the-ai-trade-into-layers-so-wall-street-can-hedge-it-piece-by-piece/)

MSCI launched 14 AI Value Chain Indexes in late August, splitting AI exposure into layers like infrastructure and applications instead of treating AI stocks as one basket. The move comes as Nvidia decouples from broader chip stocks and Bain warns the industry needs $6 trillion in revenue by 2031 to justify its data-center spending. - [how to hedge AI sector exposure strategically](https://startupfortune.com/msci-splits-the-ai-trade-into-layers-so-wall-street-can-hedge-it-piece-by-piece/) - [MSCI AI Value Chain indexes for institutional investors](https://startupfortune.com/msci-splits-the-ai-trade-into-layers-so-wall-street-can-hedge-it-piece-by-piece/)

*This article is posted in [AI News](https://startupfortune.com/category/ai/), check it out for more related stories.*

## Join the discussion

[Open in the community →](https://startupfortune.com/community/)

Almost there. Sign in and your reply posts straight away.
