Multiple outlets reported growing adoption of agentic AI—systems that can autonomously execute multi-step workflows—across commerce and the public sector, raising new security, fraud, and accountability concerns. In e-commerce, AI “shopping” agents are increasingly able to initiate purchases and interact with merchant sites; reporting highlighted merchant complaints that automated agents can scrape product data without consent, generate inaccurate listings or images, and create fulfillment/pricing errors that damage customer trust while leaving merchants to absorb the operational and reputational impact.
In financial services, commentary on stablecoin payment fraud argued that because many crypto transactions are effectively irreversible, fraud controls must shift “left” to pre-authorization blocking using real-time AI models tuned for high recall, supported by layered defenses and use of open blockchain telemetry. Separately, state and local government IT leaders are exploring agentic AI to improve productivity and citizen services, implying a need for stronger governance over autonomous actions, auditability, and risk controls as these systems move from pilots into operational workflows. One reference was a vendor/platform announcement and another was a broad societal-risk article on AI (deepfakes, opacity, labor disruption) that did not materially add to the specific agentic-payments/fraud/government adoption thread.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
In a March 5 interview, Donald Kossmann said enterprises should not assume an AI agent's authorized transaction reflects true user intent and warned of risks such as intent drift, decision-integrity failures, and agent-to-agent marketplace abuse. He recommended granular and revocable permissions, detailed audit logs, human override, and post-transaction evidence capture before connecting agents to procurement systems or payment methods.
In a March 4 interview, Sean Ren argued that stablecoin fraud prevention must rely on AI operating in milliseconds before authorization because transactions are effectively irreversible. He recommended layered defenses optimized for high recall and said open blockchain transaction data can strengthen fraud-detection models.
Reporting on the rise of AI-driven shopping and payments said agentic commerce is introducing security, fraud, and liability problems for merchants and platforms. The coverage cited concerns over unauthorized scraping, incorrect orders, customer-trust damage, and unclear responsibility when AI-initiated transactions go wrong.
A National Association of State CIOs report described agentic AI as an emerging frontier for state IT and warned that agents accessing multiple systems and databases expand the security and governance risk surface. The report recommended using frameworks such as NIST's AI guidance as a starting point for oversight.
U.S. state governments started cautiously exploring agentic AI beyond generative AI, with about eight states reporting initial use. Examples include Alaska evaluating agentic AI in the myAlaska portal, Tennessee considering agentic features in next-generation ERP, and Virginia piloting a tool to speed regulation review.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
datainnovation.org
Open sourcehelpnetsecurity.com
Open sourcecio.com
Open sourcebankinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.