Product2 publishersAlso reported elsewhere3 min readPublished
Darwinium starts judging AI agents by their path to payment and the tools they call
Darwinium's new fraud tools judge AI agents by their steps and MCP calls, as only about one in four agent transactions on its network self-declares. Agent purchases there are rejected nine times as often as other purchases, so the pitch is about passing good agents as much as stopping bad ones.
The Product Desk
What happened
- Journey Transition Probability flags unusual changes in the steps a person, bot or AI agent takes on the way to a login, account change or payment.
- MCP Protection ties each tool call an agent makes to the journey that led to it and lets a business verify the agent's credentials while it works.
- Agent tool calls now sit in the same journey as the customer's web and mobile activity, one model scores every step, and decisions run through the business's existing CDN.
- In a Darwinium survey of 500 US and UK fraud, risk and security leaders, 97% reported more AI-driven attacks and 36% believed they had effective coverage across the full customer journey.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint A rule that relies on agents declaring themselves catches only about a quarter of agent transactions on Darwinium's network, which leaves three in four to behavioral checks.
- cost When a merchant rejects agent purchases wholesale, customers whose agents did exactly what they were asked lose the purchase along with the fraudsters, and the merchant loses the order.
- decision Fraud teams now have to pick which agent steps, such as payments or account changes, get held for a second check while the rest of the session goes through.
Take a customer who tells an agent to pay a bill. The agent logs in and pays it, and somewhere between those two steps it changes the email address on the account. A rule that checks one step at a time sees nothing wrong. Darwinium's case is that a step which looks ordinary on its own can look suspicious once the whole path is in view [15]. An authorized agent "can start out doing exactly what a customer asked, then take an unexpected turn," said Michael Rodriguez, Darwinium's chief operating officer [8]. He said the same holds for authenticated human customers, who can still be coached into sending money to a scammer [14].
A lot of bot rules assume that a well-behaved agent will announce itself, so anything that stays quiet can be blocked. On Darwinium's network, most agents stay quiet [16]. The company's Agent Intent Detection, launched in March, already exists to spot agents that do not announce themselves [9]. One customer goes further. Apollo.io's senior manager for fraud prevention and application security, Jon Ferrari, said "user-agent declarations and even statements of intent are becoming moot" [10]. His team has to check whether behavior matches stated intent over time, he said, including in aggregate, where many requests add up to an outcome no single request disclosed [11].
Under the label "intent intelligence" [1], the product does two things. It scores the order and timing of steps, and it holds the risky one [4][5]. The score's baseline is the customer's typical behavior, so a customer with little history gives it less to compare against. The business's own traffic and the type of journey also go into the score [4].
Darwinium, a venture-backed startup that announced an $18 million round in October 2023 [12], supplies every figure behind the launch. The one-in-four and nine-times ratios describe its own network [2][3], and it ran the survey itself [7]. The report does not say how many rejected agent purchases were fraud, or how many payments held for a second check turned out to be legitimate. The company says businesses need to recognize legitimate agent activity without giving risky actions a free pass [13]. Those two numbers would show whether its tools do that.
For the person rolling this out, I'd sort agent traffic on two axes: whether the agent declared itself, and whether the step moves money or changes the account. A declared agent on a low-risk step can pass. When it reaches a payment or an account change, it gets the hold for extra checks that MCP Protection is built to apply [5]. An undeclared agent on a low-risk step is where path scoring belongs, because blocking it turns away activity that has not yet done anything risky. The fourth box, undeclared and high-risk, is the one blanket blocking already covers. I'd pilot the tool there first and compare it with the current rule on one count: rejected orders that came from real customers. The tradeoff is friction, since every hold on a payment also slows the declared agents a merchant wants to keep. A team that cannot say how many of last month's rejected agent purchases came from real customers has nothing to judge any vendor against.
What to watch
- Any count from Darwinium or its customers of how many rejected or held agent purchases came from legitimate customers.
- Movement in the share of agent transactions on Darwinium's network that self-declare, now about one in four.
- Whether other fraud vendors begin scoring MCP tool calls inside the customer journey, or this stays a Darwinium feature.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence30
- Adoption15
- Hype gap+30
- Incentives75
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Fraud prevention startup Darwinium UK Ltd. launched two new capabilities, Journey Transition Probability and MCP Protection, that make intent intelligence the foundation of its platform.
- [2]
Only about one in four agentic transactions on Darwinium's network self-declares.
- [3]
Purchases involving agents are rejected nine times as often as others.
- [4]
Journey Transition Probability flags unusual changes in the steps a person, bot or AI agent takes on the way to a login, account change or payment. It measures the order and timing of actions against the customer's typical behavior; the business's own traffic and the type of journey underway also factor in.
- [5]
MCP Protection links each tool call to the journey that led to it. Businesses can verify an agent's credentials and keep watch on what the agent does once it is working. A payment or other higher-risk action can be held for additional checks.
- [6]
The update folds the tool calls an agent makes over the Model Context Protocol into the same journey as a customer's web and mobile activity. One model assesses every step. Risk decisions run through the content delivery network the business already uses for its website traffic.
- [7]
In a survey Darwinium ran of 500 fraud, risk and security leaders in the U.S. and the U.K., 97% reported an increase in AI-driven attacks. Only 36% believed they had effective fraud coverage across the full customer journey.
- [8]
An authorized AI agent "can start out doing exactly what a customer asked, then take an unexpected turn," said Michael Rodriguez, chief operating officer at Darwinium.
- [9]
Darwinium launched its agent intent tools in March, and the existing Agent Intent Detection product already identifies AI agents even when they do not announce themselves.
- [10]
Jon Ferrari, senior manager of fraud prevention and application security at Darwinium customer Apollo.io, said web traffic has reached "an inflection point where user-agent declarations and even statements of intent are becoming moot."
- [11]
Ferrari said his team needs to track whether behavior matches stated intent over time, including activity in aggregate, where many requests can add up to an outcome no individual request disclosed.
- [12]
Darwinium is a venture capital-backed startup whose investors include U.S. Venture Partners, Blackbird Ventures, Airtree Ventures and Accomplice; it announced an $18 million round in October 2023.
- [13]
Darwinium argues that businesses need a way to recognize legitimate agent activity without giving risky actions a free pass.
- [14]
Rodriguez made the same point about authenticated human customers, who can still be coached into sending money to a scammer.
- [15]
A step that looks ordinary on its own can look suspicious once the full path is taken into account.
ReportedSupportedSource: Darwinium's description of Journey Transition Probability, as reported by SiliconANGLEView cited source - [16]
About three in four agentic transactions on Darwinium's network do not self-declare.
Sources
2 independent publishers whose own reporting we read for this story.
- siliconangle.comDarwinium launches two intent intelligence capabilities to catch fraud by AI agents
1 article · October 8, 2026
- thepaypers.comDarwinium launches two new intent-based fraud prevention features
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.