Incognia Launches AI Agent Detection to Secure Autonomous Financial Transactions
By Lauren Towner · 7 October 2026

Incognia has launched AI Agent Detection to help financial institutions verify whether AI-initiated transactions are actually authorized by the human account holder. As agentic AI begins managing payments and account changes, this capability addresses the critical gap between identifying a legitimate bot and confirming the underlying user's intent, protecting against unauthorized automated activity.
What was announced
Incognia has introduced AI Agent Detection, a tool designed to help financial institutions differentiate between legitimate AI-driven actions and unauthorized automated requests. The system addresses a growing vulnerability where AI agents, acting on behalf of consumers, perform sensitive tasks like making purchases or changing account settings. The capability works by evaluating the agent and the specific action as two distinct entities. It utilizes signed-request verification, agent-origin classification, and bot detection, which are then cross-referenced with Incognia’s broader risk intelligence.
To increase confidence in high-risk transactions, the platform can verify actions against signals from a customer’s trusted mobile devices, historical account activity, and network location. Alongside this, Incognia expanded its web risk intelligence through Web Behavioral Biometrics. This adds new signals to its browser and device intelligence, including mouse movements, keyboard interactions, and copy-and-paste activity. If a web session appears suspicious, the system can link it to a trusted mobile device to confirm the user's identity.
Furthermore, the company launched an MCP Server to integrate this intelligence into AI-assisted fraud investigations. This allows fraud analysts to use compatible AI applications to retrieve evidence and identify connections across accounts using natural-language queries. To ensure security, the initial MCP experience is read-only, maintaining human control over final enforcement decisions. These tools are aimed at global companies across mobility, marketplaces, and financial services.
"AI agents change the trust problem for financial institutions. Knowing that a request came from a legitimate agent isn't the same as knowing that a specific action should be allowed. Businesses need to connect that request back to the real customer and the context surrounding the action so they can support legitimate agentic experiences without giving up the risk controls they've spent years building."
André Ferraz, CEO and Co-Founder at Incognia.
The companies involved
Incognia is a risk intelligence provider specializing in cross-device authentication and fraud prevention. The company distinguishes itself in the market through the use of apartment-level location intelligence, which it combines with device and behavioral signals to recognize trusted users across different sessions and devices. Its technology is designed to support global enterprises across several sectors, including financial services, mobility, and digital marketplaces. By focusing on high-precision location and device integrity, the firm aims to reduce the friction legitimate users face while blocking sophisticated fraudulent activity.
The company’s approach centers on the concept of "trusted environments," moving away from static passwords or easily intercepted one-time codes. In the context of the current announcement, Incognia is positioning itself as a governance layer for the emerging "agentic economy," where software agents act as intermediaries for human users. Supporting this industry shift is Datos Insights, a firm represented by Jim Mortenson, who serves as a Fraud Strategic Advisor. Datos Insights provides analysis and advisory services to the financial industry, focusing on the evolution of control infrastructures and the necessity of distinguishing between human and automated actors.
What FF News has reported before
FF News has previously tracked Incognia’s efforts to map the evolving landscape of automated and industrial-scale fraud. In the report Incognia Exposes How Overseas Scam Cities Target Global Financial System, published in September 2026, the company detailed the rise of "fraud farms." That investigation highlighted how organized criminal entities utilize specialized infrastructure to target the global financial system, often operating out of specific geographic hubs to bypass traditional security perimeters. This prior research underscores the company’s focus on identifying the origin and integrity of digital interactions, a theme that continues with its latest focus on agentic AI detection and web behavioral biometrics.
What this means
The introduction of AI-specific detection marks a pivot in the cybersecurity industry from "identity verification" to "intent verification." As consumers delegate financial authority to AI agents, the traditional security perimeter—which relies on a human being physically interacting with a screen—is becoming obsolete. This announcement puts pressure on traditional fraud vendors who rely on legacy multi-factor authentication (MFA) that agents cannot easily navigate. The industry now faces a critical question: how to maintain a "human-in-the-loop" for high-value transactions without destroying the efficiency that AI agents are supposed to provide. This move suggests that the future of fintech security will depend less on what a user knows and more on the verifiable origin of the automated request.
Companies in this story: Incognia
People in this story: Jim Mortenson, André Ferraz