Build1 publisher3 min readPublished
Incognia splits AI agent payment checks into who sent the request and who authorized it
Incognia launched AI Agent Detection on October 6, checking separately whether an AI agent is genuine and whether the customer authorized its action. Banks screening agent payments now have a named product for the second question, built on Incognia's existing fraud signals.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- To judge the agent itself, Incognia verifies signed requests and classifies where the agent originates, then adds bot detection and its existing risk intelligence on top.
- For more confidence, a bank can compare the agent's request against the customer's trusted devices, account activity, device integrity, network and location.
- A new MCP Server lets AI tools pull fraud evidence for investigators, but its first release is read-only and leaves enforcement decisions with human analysts.
- Experian announced its own Agent Trust framework in April 2026, describing a verifiable link between consumers and the agents acting for them.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Banks have to choose where the customer-context comparison sits: on every agent request, or only on requests that pass the agent check and still look risky.
- constraint The authorization check depends on the bank's existing view of the customer's devices, so a customer with no trusted device on record leaves it nothing to match against.
- capability Fraud teams can put a language model on investigations, tracing links between devices and accounts, without giving it authority to change a risk outcome.
Incognia co-founder and CEO André Ferraz [6] said in the launch announcement: "Knowing that a request came from a legitimate agent isn't the same as knowing that a specific action should be allowed." [5] The product is built around that split [2]. Signed-request verification and agent-origin classification [3] answer a question about software: is this agent who it says it is. Runtimewire, which reported the launch, notes that a positive answer still does not establish that the human customer authorized a particular purchase, payment or account change [19].
The second check takes its evidence from somewhere else. The request arrives from the agent, but the comparison runs against the customer's own context [4]. That context is Incognia's existing business. The company already sells location analysis, device recognition and tamper detection for fraud prevention [14]. Its approach is to judge whether an interaction fits a user's established device and location patterns, including when the person changes devices or sessions [15].
For that comparison to work at a given bank, the bank must already collect Incognia's signals from the customer's devices, so a baseline exists. The customer needs at least one device the bank treats as trusted. And the agent's request must name the customer and the action precisely enough to match against that baseline. Incognia describes the customer-context comparison as the step a bank takes when it needs more confidence [4]. I'd expect most banks to run it as an escalation for agent requests that pass the first check and still trip a risk threshold.
Web Behavioral Biometrics follows the same pattern for browsers. It layers how a user moves the mouse, uses the keyboard and copies and pastes on top of Incognia's location, automation, device and browser signals [7]. When a web session needs more verification, Incognia says it can connect that session to a trusted mobile device [8].
The MCP Server has the most careful default in the launch. Compatible AI applications can use it to retrieve fraud evidence, trace links across devices and accounts, and organize findings from natural-language questions [9]. An investigation assistant that can read everything and change nothing is the version I would let near a fraud queue first. Runtimewire gave the regulatory reason: "In a regulated fraud operation, the audit trail and the decision-maker are part of the product." [20]
Other vendors are building links between people and agents. IBM announced an MCP-based capability for fraud detection and investigation in March [12]. Runtimewire judged that the IBM and Experian launches address trust problems that overlap with Incognia's, but that the products are not directly comparable from their public descriptions [13]. Incognia's stated focus is the risk around one specific consumer action, read through that customer's devices and behavior [21].
The launch announcement does not provide customer deployments or adoption figures [16]. The underlying signals are older than the agent pitch. Ferraz and CTO Alan Gomes began developing the location technology around 2010, starting with indoor location [18]. Incognia announced a $31 million Series B in January 2024, led by Bessemer Venture Partners [17].
What to watch
- A named bank deployment or adoption figures for AI Agent Detection, neither of which the launch included.
- A later MCP Server release that adds write actions, such as changing a risk outcome, and how Incognia logs who approved them.
- Whether banks pair Incognia's action check with an agent-identity framework such as Experian's Agent Trust, or treat them as substitutes.