Socure, one of the larger identity fraud vendors, argues the human or bot question is being replaced by an authorization question: who sent the actor, and what is it allowed to do?
The question every fraud check was built to answer is the wrong one now. Money moves through accounts opened by software; decisions get made by systems that take a natural-language instruction and execute it. The entity on the other end of a transaction is increasingly an authorized AI agent, not a person and not a bot. Identity infrastructure, built for decades around the assumption that the actor is human, is being asked to answer a different question: who sent this actor, what is it allowed to do, and is it still inside that authority.
That flip is the argument Socure chief product officer Chung-Man Tam is putting on the record. Socure is one of the larger identity-fraud vendors, working with banks, fintechs, and government programs to verify that a person opening an account, moving money, or completing a transaction is who they say they are. In a recent interview with Biometric Update, Tam framed autonomous AI agents as a structural shift for identity verification, not a hype cycle, and used that framing to argue that identity infrastructure has to start treating authorized AI agents as first-class actors, not as bots to be filtered out and not as humans in disguise.
The mechanism Tam describes is an authorization-stack inversion. Traditional identity verification asks whether a human is who they claim to be, then attaches a permission to that person. Agent-era identity has to authenticate the agent, attest to who delegated authority to it, scope what it can do, watch whether its behavior stays inside that scope, and revoke the delegation cleanly when needed. The fraud surface is no longer \"did a human trick us?\" It is \"is this authorized actor still authorized, and is the action inside the scope it was given?\"
A bot that spoofs a human is a fraud event. An authorized agent that misfires, or one that acts inside its scope but in a way the principal didn't intend, is an authorization and governance event, and the bank, platform, or principal who delegated the authority is on the hook. Risk teams that have spent a decade building human-authentication stacks are now being asked to also build delegation, scope, and revocation, with no settled standard for any of it.
Socure's bet is visible in product. The company expanded its RiskOS AI Suite in October 2025 to add AI agents for identity, compliance, and risk decisioning on top of its existing Sigma Synthetic Fraud, Sigma Synthetic Signals, and Digital Intelligence components. The product documentation describes an agent-readable surface for those decisioning components. The pitch is that risk decisions themselves, not just the identity check at the door, should be agent-operable inside a defined scope, and that Socure's existing identity graph becomes the substrate that authorizes and constrains them.
This is a vendor thesis, and it should be read as one. Socure's incentives favor declaring a structural shift; its product roadmap benefits if the industry treats authorized-agent identity as a new infrastructure layer. Tam's framing, \"structural shift, not hype cycle\", is a useful position, not a settled fact. Fraud has clearly evolved from stolen credentials and account takeover to synthetic identities, deepfakes, and AI-generated documents, and the share of transactions initiated by software rather than a person is rising. What is not yet settled is whether the agent-attestation problem is a category shift on the scale of mobile or cloud, or a narrow enterprise-workflow problem that standards work and existing authentication can absorb.
What would settle it is convergence in three places that aren't converged yet. An agent-attestation standard, a way for one system to prove to another that a given agent was authorized by a specific principal with a specific scope, has to exist in a form multiple vendors and platforms will adopt. The current proposals are vendor-shaped. Regulators have to decide how liability flows when an authorized agent misfires inside its scope: is it the principal, the platform, the vendor that issued the attestation, or the deploying bank? The answer isn't written. Runtime enforcement has to be cheap enough to run on every transaction; if attesting an agent costs more than the transaction, the market won't adopt it.
Until those three land, the practical question for a bank, fintech, or platform is narrower than the thesis. Identity teams have to treat an agent-initiated transaction as a different surface from a human-initiated one: same authentication, additional delegation proof, narrower default scope, and a faster revocation path. That is the move a Socure, an Okta, a Persona, or a Plaid is asking their customers to make, and the move the next agent-identity headline will be measured against.