
How AI shoppers are forcing merchants to rethink fraud with Riskified’s Jeff Otto
In this episode of Payments Unfiltered, Theo Spyrides, Head of Product at Primer, sits down with Jeff Otto, CMO at Riskified, to explore what happens when software starts acting on behalf of customers and what that means for risk, fraud, and merchant exposure. They discuss how agentic commerce changes who initiates a transaction, how trust is established, and why introducing an agent into the flow raises new questions around risk ownership and liability.

Theo Spyrides
Host of Payments Unfiltered

Jeff Otto
CMO @ Riskified
Theo Spyrides (TS): Well, welcome Jeff. Thanks so much for joining us. Maybe to start, could you give everyone an introduction to who you are and your current role?
Jeff Otto (JO): Yeah, Theo, thanks for having me on the show. Jeff Otto. I'm the Chief Marketing Officer of Riskified. Background — I've been in financial services, fintech, and e-commerce enablement for the last 22 years. Been at Riskified for about three years. The simple way to think about what we do is we're using a lot of data — about half a trillion orders in the last four years — to decision on orders at checkout. So all the big merchants across the world use us to help them drive higher growth rates, make sure every customer gets the right decision, and we block out the fraudsters.
TS: Awesome. Today we're going to be talking about agentic commerce and the impact it can have on fraud. I'd love to pick your brain on all these topics. So let's not assume anything — from your view, what is agentic commerce?
JO: This is software becoming the customer. In simple terms, what we're talking about is an AI agent that's being trained to know you — to understand your sizes, your preferences, what concert tickets you want to buy. Over time we're going to see more empowerment of these agents to make purchasing decisions based on the intent you give them. Right now we're in the early stages — the assistant phase. It's about large language models, and you're asking them prompts like, "help me figure out how to solve this problem." They give you nicely curated product offerings, and then you can link out and go buy that on the merchant site. That's phase one. What we're starting to see as this evolves is more of a true agentic shopping experience, where the agent says, "I'm going to go a step further." "You want me to buy this for you, here are the terms and conditions — if you trust me with your payment method, I'll do this on your behalf." Then the final state, the fully delegated world — that we can all see on the horizon is a world where you've got this sidekick, this agent, doing all these things for you, entrusted with your identity and payment methods. It knows your intent and your life situation, and can do more of those activities for you. The easiest use case is e-commerce purchasing, but you can get more advanced things like financial services — "help me rebalance my portfolio." There's a huge opportunity as these capabilities mature and move into other industries and services.
TS: Since today's AI shopping assistants redirect users to merchant sites for payment, are they already impacting fraud, or does the risk primarily emerge when agents directly handle payment processing?
JO: The short answer is: the way certain new protocols have been developed — I'll pick on agentic commerce protocol, which is OpenAI and Stripe's new protocol — they went to market very quickly and are creating a great experience for shoppers. But honestly, a lot of the important signal that determines whether this is a good actor or bad actor is missing. If you think about the typical payload a mature fraud or risk intelligence platform uses, we're detecting whether the user's using a proxy server. We're fingerprinting the device data. We've got IP and geo features and other machine learning features testing the security of that IP address. We're looking at card details and linking that across. A lot of that data isn't being passed through in the instant checkout process. The result is you're losing somewhere around a third of the signal that most platforms use to make informed decisions — to make sure good customers get approved and fraudsters get denied. That's the surgical precision you want on every order. What they've done is rush the protocol out a little, and in its current state, it's missing that. We've tested this — we have red team folks at Riskified who create synthetic IDs and run orders through. We did a side-by-side with one of their early merchant partners, doing the instant checkout through ChatGPT. We were able to put through an order with a fake, newly-created email address, an incorrect billing address, and a VPN to shift the IP — and the order was approved. We then went to that merchant's website with a similar synthetic order. Not only was that order declined, but the account was blocked. So you can see the difference in security between the current state of this new agentic commerce protocol and a more mature storefront. Those are things we're considering, but it's not just OpenAI — other protocols are being developed. I'm quite impressed by what the team at Google has done with AP2, and the thoughtfulness they've brought to that new protocol. What we're excited about is there are some great working groups — they've got a risk working group kicking off. That's an opportunity for the ecosystem to come together and say, "we've got this exciting new channel, everybody wants this." This is a consumer capability everybody wants. We've got to make sure it's set up in a way that protects it — that we're not going to hurt the small businesses that end up using the channel.
TS: So if I try to play it back to you: if I'm a merchant playing in this space today, I'm exposing myself to risk. What would you advise a merchant to do? Should I play in this space, should I wait and risk being late to the party? How should I navigate this and start building my mental model around it, especially around the risk I'm willing to take on?
JO: Yeah, well, the first thing is I think it's very prudent for merchants to be testing, sandboxing, figuring out how they can turn on these new avenues of growth. This new channel is exciting, and you don't want to ignore it. But I'd approach it with thoughtfulness. Ask good questions of the partnership, depending on which protocol you engage with or which orders you want to decision upon. That requires identity-aware infrastructure — you want to be able to detect whether somebody is a human, an agent, or a malicious bot. Being able to tell the difference between the three is important, and there are great players out there that can get you perimeter defense on that. Then at checkout, be very clear on what data and signal you're getting passed through, and what you can pass on to your third-party provider. Or if you're doing it in-house, decide how you want to treat that cohort of orders, just to make sure you don't end up in a situation where you're being attacked. Fraud attacks — and the velocity of fraud attacks — are impressively fast these days. The bad guys are early adopters of AI too. They're using tools to card-test, using agents on their side to make things run faster. So you've got to protect yourself there. One thing we found that you might find interesting. The same team that does the red team work, we also have an insights team that looks for emerging threats — clear web, dark web, marketplace sites, fraud community sites. One example a colleague found recently was an emerging — not one of the big players — AI shopping platform. It had two ways to check out. It would curate a product based on your prompt, and you could say "shop now," which would direct you to the retailer site. That security setup isn't that different from what we have today — an LLM shopping assistant approach. But the other option was "go ahead and buy with our shopping agent." A fraudster took the time to write a detailed blog post on how to exploit — that situation, step by step, with screenshots and examples of orders they'd put through. It's out there on a site called BlackBones — I can't believe they haven't shut it down — and it has a bunch of these exploits. So imagine scenarios in the future where you're talking about ChatGPT with 800 million monthly active users, Gemini at around 650 million — when you get to that scale and volume, we've got to be prudent and make sure we're not ingesting a whole bunch of fraudulent orders.
TS: So what I take away is: tread with caution, go in with your eyes wide open. You've also talked about a lot of protocols. As a merchant, am I going to have to reason about every protocol, more fragmentation to think about? Do you have any insights or thoughts there?
JO: This space is evolving so fast. We were talking to our customer advisory board, a group of a dozen or so of the largest merchants in the world, and we swap notes on this evolving landscape. They share what they're seeing and testing. Every time we get together, and it's fairly frequent, the landscape has changed insanely. This stuff is moving fast. You've got the agentic commerce protocol I mentioned earlier, the agent payments protocol, which is what Google is doing, Visa Intelligent Commerce, Mastercard's Agent Pay — a lot of players, a lot of emerging protocols and ways of doing this. And then a lot of skunkworks projects we probably don't know about. So, depending on the size of your shop, having a team that wakes up every day looking at these new channels holistically — putting together a capable payments leader, someone from the fraud team, someone from the e-commerce team, and creating a little SWAT team to test the sandbox — I think that's not a bad idea. You want to understand the possibilities down the road, because I think it's a — logical conclusion that a good chunk of e-commerce is going to move to this. McKinsey estimated something like $3 trillion by 2030. They could be slightly wrong, or maybe too conservative. Who knows?
TS: Given the rapid R&D in agentic commerce alongside rising fraud risks, how should merchants determine their role? Are some opting out due to liability, similar to Amazon’s legal action against Perplexity? Any thoughts or hot takes on merchants choosing to opt out due to the risk exposure increase?
JO: Yeah, it's fascinating to see the lawsuit against Perplexity from Amazon. If you visualize this as three paths, or a couple of forks in the road. On one end you have a very LLM-centric future, where a lot of this is controlled by the protocols driven by the OpenAIs, the Geminis, the Anthropics. If I were a merchant, what I'd worry about in that scenario is the loss of reputation, brand trust, and loyalty when you're separated from your loyal consumer. Brands don't want that. They want to create experiences and loyalty that bring people back and keep them purchasing. So that's one path. There's a middle road of compromise — I mentioned Google AP2, a protocol that's been well thought out, with working groups trying to enable this agentic commerce channel in a way that's elegant for the consumer and secure — for the merchant. That's a middle road, and as it evolves, I think that's a great way to do it. Then there's the third way — the very merchant-centric approach — which is the Amazon side: "Perplexity, you can't do this on our site, we're going to sue you." At the same time, Amazon has rolled out Rufus, and quick results after Black Friday/Cyber Monday showed consumers engaging with Rufus — Amazon's AI shopping agent — were converting at an order of magnitude higher than consumers who weren't using it. So if I were another large e-commerce merchant, I'd be looking at what Amazon accomplished and thinking about my roadmap — a merchant-centric AI shopping assistant experience. One I can control, feeding it into my product catalog and loyalty data, understanding what offers and terms to give based on the consumer, and using my existing fraud and risk intelligence tech stack to make the right decisions on those orders. So that merchant-centric path is definitely one we tell merchants it's not a bad idea to take a look at like Rufus.
TS: That's a compelling opportunity for merchants to own their unique shopping experience. Since you noted that agentic flows currently lose about a third of the data needed for fraud prevention, how is Riskified navigating this challenge? Are you retraining models, influencing protocol providers to pass more signal, or finding other ways to regain that data depth?
JO: Yeah, it's a multi-pronged approach honestly. On the influencing front, we spend time having conversations with OpenAI, with the Google AP2 team, and other players in this space. We try to help them see this through our lens — through the massive identity graph and the half a trillion in GMV we've decided on in the last few years. We can see the trends and a potential future where, if we don't fix some of these data gaps, the bad guys will find out and take advantage. We want to prevent that future. At the same time, we're investing in R&D. We have a large R&D team, since we're a public company, and a large data science team. We're always surfacing and training machine learning features based on data elements — industry, geography, all kinds of vectors — to get better, more precise decisioning. So uncovering what other signals we can get, what we need from the various protocol providers for a minimum viable decision. We're talking with a lot of our merchants engaged in early pilots, usually bigger players figuring out whether to build a merchant-controlled shopping agent experience, and we're advising them on how to best secure it.
TS: Another often overlooked factor is liability. With a new third-party AI agent in the mix, or even in Amazon's case, who holds the risk if an agent-initiated transaction turns out fraudulent? Is there an established answer to this yet?
JO: It depends on the payment method, whether they're using a tokenized wallet. The way I like to reframe that question is: we've got to think about total conversion here. Say you think, "I don't have to worry, they'll use Apple Pay, it'll flow through to the issuer." Well, if the issuer has liability and is more blind than even the merchant, what's their approval rate going to look like? We have to be careful when we think about this, because even shifting liability using tokenized payments, the issuer still has a decision to make on their side. What we want is to collaborate as an ecosystem to drive payment success and e-commerce growth. This is a new, exciting channel, but we have to think about it comprehensively — even if liability shifts from merchant to issuer, someone still has to accept it. And if we have the right data across that entire flow, we're going to have more payment success.
TS: Agentic commerce is inevitable, yet presents risks for merchants. What practical steps can fraud and payment leaders take to prepare, and how should business leaders treat payments and fraud as strategic organizational levers?
JO: Yeah, a couple of practical things I advise our merchant customers to do. One, as I mentioned — get the SWAT team going: a capable payment leader, someone from the fraud and risk intelligence team, someone from e-commerce, and start playing in the sandbox with some of these protocols. See what your e-commerce product team could do — if we want a merchant-owned agent shopping experience, what would that look like, what data would we need from the product catalog and the customer data platform to make that successful? That's one practical thing. Second, get in the conversation with your peers — use organizations like the MRC and NRF to get into these conversations, learn from one another, see what's working.I always advise that — learn from the peers, the front-runners. But the thing not to do is sit and wait too long, because this is moving fast.
TS: Excellent advice. In the fraud and payments community, collective minds often outweigh going it alone. To wrap up, what’s your "bull case" for agentic commerce over the next few years?
JO: Alright, I'll give you a bright, exciting future, and I'll give you a terrifying downside. Trying not to be redundant — look at the brain trust from the McKinseys and BCGs of the world, taking out their crystal ball: what's the size of the opportunity here? Within a short period of three to five years, they're saying trillions of dollars of volume could be going through these agentic shopping experiences. And not just e-commerce, like agents helping with financial services, portfolio rebalancing, money movement, optimizing yield. All things unoptimized today because we're just busy. But if you've got a 24/7/365 AI agent sidekick helping you out, it opens the door to all kinds of optimization that doesn't exist today. Think about banks that rely on people being a bit lazy about their cash management. How that could change. That could be huge for the banking industry. So the exciting future: maybe our money grows faster, maybe we get the best deal on products and services because our AI sidekick is doing that for us, freeing up more time for the things we're passionate about. That's a bright future, and huge on the merchant side too — revenue growth, e-commerce growth. Think of the conversion rate from the Rufus story on Black Friday/Cyber Monday. How many times have you stopped a purchase because you weren't sure you wanted to think about it more? If the agent makes a crystal-clear, compelling case for the purchase, you'll convert more, and that's more revenue for merchants. Exciting on both the consumer and merchant side.
The terrifying dark side, to be an alarmist for a moment. I follow pretty closely the growth over the last five years of what The Economist calls "Scam Inc." Basically organized crime, mostly out of Southeast Asia but in pockets around the world, exploiting people — romance scams, crypto scams, identity theft, sophisticated spearfishing to steal account information, credit cards, bank accounts. There are estimates of this being in excess of $100–200 billion a year in wealth transfer, especially from victims losing life savings. We see it downstream when our teams go onto the dark web and clear web and see compromised identities being resold – marketplace data, cards, bank accounts. A lot of Scam Inc. has been powered by human labor, often human-trafficked labor. There are fascinating groups like Operation Shamrock bringing light to that. That labor is basically sitting in what looks like a contact center, scamming people all day. Imagine a world where open-source AI agent models and other tech is available. The infinite scalability of that to do the same thing more effectively using AI is a truly terrifying prospect. Identity security is going to be paramount to make sure we don't have a world where more wealth transfer happens — where money is stolen out of our economy and bank accounts by more sophisticated AI-powered criminal organizations.
TS: Well, I don't know if I should be more terrified or excited, but I feel both after that.
JO: Sorry to close on such a note.
TS: No, I think there are real threats to this technology, and it's important to talk about them, but that doesn't nullify how innovative the technology is and the opportunity it has. With any great technology, you approach it with caution, maximize the upside, mitigate the downside, and don't be naive. There are fraudsters out there using this technology before consumers are. I think that's a fitting way to end the podcast. Jeff, thanks so much for coming on and sharing your insights — it's been super fascinating. Thanks a lot, take care.
JO: Thanks, Theo. Cheers.
Meeting with the best in the business
Primer puts you in control of how money moves across the business. With our unified infrastructure you can orchestrate every flow, reduce friction, and capture more revenue everywhere.
Latest episodes

February 11, 2025
Buyer liars, AI fraudsters & lost revenue with Galit Shani-Michel
Featuring:
Theo Spyrides
&
Galit Shani-Michel
Fraud is evolving, and merchants can’t afford to fight it alone. In this episode of Payments Unfiltered, our host, Theo Spyrides, speaks with Galit Shani-Michel, VP of Payments at Forter, to discuss the rise of AI-powered fraud, the growing threat of friendly fraud, and why false declines cost businesses more than they realize. They also discuss why traditional fraud rules no longer work, how merchants can leverage data-sharing networks, and the real impact of 3DS on fraud prevention and conversion rates.

October 8, 2024
How partnerships power payments with Michaela Weber
Featuring:
Theo Spyrides
&
Michaela Weber
Join host Theo Spyrides as he dives deep with Michaela Weber, SVP & GM of Payments & Global Business Development at BigCommerce, to reveal how partnerships are reshaping the payment ecosystem. Discover how these alliances are fueling innovation and unlocking massive value for merchants. Theo and Michaela also discuss the breakthrough ecommerce trends and cutting-edge tactics merchants use to redefine their customers' checkout and payment experience.

August 7, 2024
Driving change in fintech with Parvinder Dahri-Cooper
Featuring:
Theo Spyrides
&
Parvinder Dahri-Cooper
Join host Theo Spyrides as he sits down with Parvinder Dahri-Cooper to explore her extensive experience in the payments ecosystem. Parvinder shares insights from her pivotal role in taking Worldpay to IPO and discusses her impactful efforts in driving diversity, equity, and inclusion (DE&I) within the fintech industry. Discover why fintech must champion diversity and how it can lead the charge in supporting underserved communities. This episode also delves into the challenges of balancing product innovation with regulation and the potential for fintech to drive social good.

April 25, 2024
Behind the scenes with a Fintech VC, featuring Rob Moffat
Featuring:
Theo Spyrides
&
Rob Moffat
Rob Moffat, a partner at Balderton Capital, joins Theo Spyrides to discuss his journey into the VC space and his passion for payment and fintech innovation. He also discusses the trends He believes have shaped the payment industry in the last five years, how He spots and evaluates promising payment startups, and the essential skills and traits that payment entrepreneurs need to thrive.

February 22, 2024
The Founder's Story with Gabriel Le Roux
Featuring:
Theo Spyrides
&
Gabriel Le Roux
Primer CEO & Co-Founder Gabriel Le Roux speaks on the Payments Unfiltered Podcast about his journey in payments, his experiences founding a successful start-up, and the evolution of the payments ecosystem over the past decade and where it’s going.



