
CXOInsights by CXOCIETY · 2026-06-29 · 24 min
Key moments - from our scoring
Substance score
50 / 100
Five dimensions, 20 points each
Subashis Bose of BioCatch addresses the critical challenge facing AAPAC CISOs: agentic AI fraud is accelerating faster than traditional defenses can respond. The BioCatch Future of Digital Trust report reveals 86% of banking leaders view AI agents as their greatest vulnerability, with fraud attempts rising in both frequency and execution speed. Bose distinguishes between two threat types - agentic browsers like Comet and Atlas, and browser extensions such as Claude integration - and explains how to detect them through agent signatures and behavioral signals like pointer pressure anomalies and window gaps. Rather than sacrificing security for usability, banks can deploy intelligent friction: real-time behavioral intelligence that triggers contextual interventions (step-up authentication or anti-scam messaging) at the moment of fraud. The conversation covers Australia and Argentina's real-time intelligence sharing networks that monitor both sending and receiving accounts for mule activity, the hidden costs of mule accounts ($800-$1,200 per profile), and why reimbursement policy reform depends on investing in prevention technology. Bose emphasizes that metrics must track the entire fraud lifecycle across all channels, not just transactions, and warns that many banks underestimate agentic AI's impact.
Banks must detect agent signatures (like Comet, Atlas, or Claude extensions) through behavioral signals including pointer pressure anomalies, window gap differences, and device spatial analysis, then assess intent by checking user familiarity with the agent and cross-bank intelligence on device-agent combinations.
Agentic browsers like Comet and Atlas that automate form-filling and task execution, and browser extensions and integrations like Claude-Chrome combinations that extend AI capabilities within existing tools.
Networks like those deployed in Australia and Argentina share anonymized device and behavior signals in real time across sending and receiving banks, allowing fraud on the sender side to confirm mule activity on the receiver side and vice versa.
Two-thirds of banking leaders surveyed believe their fraud prevention and reimbursement approach has resulted in a net loss of customer relationships, with half attributing losses to unreimbursed scam losses and half to excessive friction.
Mule accounts cost between $800 to $1,200 per profile in operational expenses, not counting their role in facilitating fraud schemes.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a handful of genuinely useful operational specifics - behavioral telltales for agent detection, phone spatial analysis, and the mule-account cost-per-profile figure - but much of the runtime is consumed by broad restatements of the report findings and generic advisory language. The idea-per-minute rate is moderate, not dense.
if you think of a uh, agentic based browsers, you will always see that there's a panel on the side on which you would instruct that takes away some of the space from the window
device spatial analysis, for example, which tracks the behavior of the phone, uh, in terms of the movement of the phone when the person is using it. It can suggest whether a human is on the other End
The reframing of mule accounts as a portfolio health and cost problem rather than purely an AML burden is a fresher angle, and 'intelligent friction' is a useful label. However, the episode leans heavily on vendor-report statistics and well-worn analogies, and the overall argument follows a standard industry playbook.
mule accounts are no longer just an AML team's burden
instead of creating a friction which is, you know, just bare kind of rules based using the signals and using the scores and AI to then intervene in a more natural way with the victim
Subashis Bose is a practitioner-adjacent expert at a credible behavioral-biometrics vendor (BioCatch) with real deployment experience in Australia and Argentina, but the role is advisory/pre-sales rather than an operator who has run fraud defenses at a bank at scale. The interview is also structurally a vendor report promotion, which limits candor.
for one of our customer banks in Australia, what we have realized and what we have uncovered, and they have told us this, that mule accounts are costing them between US dollars 800 to as much as 1200 per profile
The network which has then been enabled by biocatch in these countries, it shares this intelligence across both the receiving side and the sending side in real time
The episode scores above average on specificity: named agentic browser tools (Atlas, Comet), named integrations (Claude/Chrome), specific geographies (Australia, Argentina, Singapore), concrete survey percentages (86%, 79%, two-thirds), and an actual dollar range for mule-account servicing costs. The weakness is that most data comes from BioCatch's own proprietary report, so independent verification is limited.
Countries like Australia and Argentina, they have adopted a uh, real time intelligence sharing network
86% viewing AI agents as the industry's greatest vulnerability
The host's question set covers the sensible territory (detection, metrics, reimbursement policy, call-to-action) and the metrics question shows some structural thinking, but there is no pushback, no follow-up drilling when answers stay abstract, and the guest's vendor framing goes entirely unchallenged throughout. The transcript also shows the host mistakenly alternating names, suggesting limited editorial rigour.
What metrics will tell us whether our AI defenses are reducing fraud losses or merely shifting criminal tactics
What is the single biggest. Okay, the one big myth regarding agentic AI fraud when it comes to banking
Computed from the transcript - who did the talking, and the words that came up most.
APAC CISOs face an escalating battle as AI agents rapidly outpace traditional defences. Key issues include distinguishing legitimate actions from malicious automation, soaring fraud speeds, and customer attrition from either excessive friction or unreimbursed losses. The Biocatch report, the future of Digital Trust, concluded that with 86% viewing AI agents as the industry’s greatest vulnerability, leaders urgently need real-time behavioural insights and interbank collaboration to preserve trust. To know more about this and to help CISOs at the region’s banks find solutions to this rising AI-driven fraud incidents, we are joined by Subhashish Bose , Director of Global Advisory, BioCatch. 1. What are the key salient points of the future of digital trust report? 2. How can we distinguish legitimate AI-assisted customer actions from agentic AI-driven fraud in real time? 3. What behavioural and intent-based signals can replace static identity checks as AI agents mimic human behaviour? 4. How do we prevent customer attrition caused by either excessive friction or unreimbursed scam losses? (intelligent friction?) 5.
Transcribed and scored by The B2B Podcast Index.
Speaker A: AAPAC CISOs face an escalating battle as AI agents rapidly outpace traditional defenses. Key issues include distinguishing legitimate actions from malicious automation, soaring fraud speeds and customer attrition from either excessive friction or unreimbursed losses. The BioCatch report the Future of Digital Trust concluded that with 86% viewing AI agents as the industry's greatest vulnerability, leaders urgently need real time behavioral insights and and interbank collaboration to preserve trust. To know more about this and to help CISOs in the regions find solutions to this rising AI driven fraud incidents, we are joined by Subashi's boss, Director of global advisory at BioCatch to talk to us a bit about agentic AI fraud. Bose, welcome to Podchats for Future CISO.
Speaker B: Thanks Helen, glad to be here.
Speaker A: What are the salient points of the Future of Digital Trust report?
Speaker B: I would say at a very high level there are three main themes that are uh, emerging from this report. First and foremost, I think it's unanimously being seen that year on year fraud attempts have risen in terms of the number of attempts, the losses as well as the speed at which these are getting executed. The second theme that is emerging is that increasingly it is being felt that the interbank kind of real time intelligence sharing on the receiving account is a very important piece of this problem solving in terms of these scams and fraud reduction. And lastly on the theme of AI, what we are seeing is that both AI enabled and then fully autonomous agentic driven AI led fraud is increasing dramatically as well as the AI led banking channels in a way has reduced the effectiveness of traditional controls as it is very hard to distinguish between what is a legitimate and um, what's a genuine agent take or AI led activity.
Speaker A: How can we distinguish legitimate AI assisted customer actions from agentic AI driven fraud, especially in real time?
Speaker B: To answer that question Alan, let me take a step back a bit and talk about the agentic threat in itself. When we talk about AI led fraud attempts we are talking about two different types of themes. One is the agentic browsers. So the things like Comet or Atlas, which are fully automated browsers that enable people to perform tasks automatically. So instead of having to do it manually, you just give it some instructions similar to the what we are used to from a conversational AI perspective. And the browser does all the browsing, filling up forms, et cetera for you. And then the second part of that is browser extensions and integrations like Claude and Chrome. And then there are things like developer tools as well which are emerging in this area. So then to answer your Question. To distinguish between legitimate and agentic AI driven fraud, I think we need to understand two things. First and foremost we need to be able to identify and detect the presence of agents, which is both these browser based or agentic extensions or the developer tools. And second is then to understand the intent. Can that intent be really trusted?
Speaker A: Speaking of intent, what behavioral and intent based signals can replace static identity checks? As AI agents start become really good at mimicking human behavior?
Speaker B: As I mentioned from the perspective of detecting agents, first and foremost we have to be able to detect the presence of an agent. Obvious methods are detecting the agent signatures. What type of an agent is it? Is it an atlas, is it a comet or some other extension, etc. Often we also rely on behavior based signals which indirectly tell us that something unusual is happening which is not very human. Like for instance, what is the pointer pressure? Is there a mismatch between the regular ways someone copies and pastes versus what is happening and what the agent is driving right now? What are the differences in terms of the window gaps? So for example, if you think of a uh, agentic based browsers, you will always see that there's a panel on the side on which you would instruct that takes away some of the space from the window. These kind of telltale signals are something that can be used to detect the presence of an agent. Second, to answer the of whether that intent can be trusted, that is where we have to then tie up uh, the user familiarity. Is this the first time that we are seeing this agent for the user or is this the first time that this agent is being seen for this device? We can also bring in cross bank intelligence. Has this agent or this device and agent combination been seen before and stuff like that.
Speaker A: How do we prevent customer attrition caused by either excessive friction or unreimbursed scam losses?
Speaker B: On this point Alan, I wanted to share one finding that we did in the survey. We found that almost 2/3 of the banking leaders when were surveyed, they believed that their organization's approach to fraud prevention and the reimbursement policy, which is related with that, has ultimately led to a uh, Net loss of 2/3 of customers. And then out of that half of them attribute the loss to unreimbursed uh, losses. And then the second part, the same 50%, almost half of it. They believe that the attrition is result of too much friction. One thing though is that when we think of attrition we have to think of it both as the ultimate consequence where a customer actually switches the bank as a result of a scam and unreimbursed deposits to sometimes just little bit reduced share of wallet or sometimes just abandoned transactions. In all of these scenarios, I think one thing that we have to understand is that banks do not need to sacrifice or choose between security and usability. They can actually win on both. And real time behavioral intelligence and device signals. What they can do today is that they can reasonably predict whether there is a likelihood of fraud. And then what is the likelihood of that fraud to be of a certain type. Whether it's an unauthorized session that the customer is unaware of or whether the customer is being tricked into making a scam payment. M believing that the person who is talking to is actually a family member under some distress, this intelligence can actually trigger the right intervention. So either the customer can then authenticate, given if it's an unauthorized type of a session versus the user can then be intervened. We call it intelligent friction. What that means is instead of creating a friction which is, you know, just bare kind of rules based using the signals and using the scores and AI to then intervene in a more natural way with the victim to kind of try to break that spell when it comes to scam, right asking the right questions at the right time with the context of the payment or the event that is underway.
Speaker A: One of the things that's probably unique to the banking industry, there's been this driving force to encourage sharing of intelligence among competing banks to protect everybody. And uh, this is almost, I could say unique to the industry with the exception maybe governments because they also have something similar. What interbank intelligence sharing frameworks therefore can we deploy to stop authorized fraud at the receiving account stage?
Speaker B: I would agree. Government and central banks in many countries have come up with some registries of uh, known fraudsters, mule account databases and so on. Uh, this has definitely helped to some extent because the negative lists always help. But at the same time we have to realize that in today's world, mule infrastructure, MULE accounts are almost like an independent industry. And to that industry their end customers are the other fraudsters and scammers who are going to their and loan or rent these MULE accounts to perform a scam transaction. So from that perspective, new MULE accounts are being constantly fed into the system. So definitely more needs to be done. Additional layers of intelligence have to come up. I wanted to share an example. Countries like Australia and Argentina, they have adopted a uh, real time intelligence sharing network that consists of sharing standardized but anonymized device and behavior signals relayed in real time across both the Sender and the receiving bank. So on one hand the sending bank account is being constantly monitored, uh, for any signs of fraud or scam or additional kind of, you know, security kind of signals on that account. On the other hand, the receiving account is also being monitored, uh, from the perspective of whether there are any signs of mule activity by virtue of the behavior which we typically see in mule accounts. The network which has then been enabled by biocatch in these countries, it shares this intelligence across both the receiving side and the sending side in real time, which basically then on the scam side, like on the sending side, if there's a scam underway, it gives a much stronger uplift in terms of confirming that it's a scam, given that the receiving side is a high potential of a mule and vice versa. Uh, on the mule side, it then helps confirm the uh, receiving bank account that, you know, the probably this account is a mule. Given that there is a scam underway,
Speaker A: AI powered scammers are on the rise. How do we accelerate fraud detection systems to match the rising speed of these AI generated detects the text that to some point you can't really distinguish whether they're legitimate or not. Because technology is so far advanced these days.
Speaker B: I would say that layering additional signals within the existing fraud detection systems is a proven approach that is working across, uh, many countries today, globally. So these signals are obviously a combination of multiple things. There is device intelligence, there is behavior intelligence, and as we talked about, some kind of a network intelligence also, which kind of comes in together and then that risk based, you know, amplification, um, of what the traditional fraud detection systems are doing can happen. So a payment or a transaction is just one data point, right? I mean, in reality there's a lot that actually happens from the moment the customer launches the app on his mobile device, for example, or uh, logs into the browser on a website and all the way through the payment. A strong device identification capability, which is monitoring, which is kind of capturing information all throughout the session of the user, you know, isolates anomalies and also helps gather insights from the global network, like whether there has been a mule activity on the device at some other bank. Similarly, behavior is the foundation of this as well. We have often seen that signature based methods to detect threats, for example the presence of malware, often have failed. And multiple things like, you know, device spatial analysis, for example, which tracks the behavior of the phone, uh, in terms of the movement of the phone when the person is using it. It can suggest whether a human is on the other End a genuine user who is normally using the phone versus if there is a remote session which is ongoing when the device is lying flat next to the bed. So these kind of signals have strongly helped traditional FRAU systems to kind of amplify and develop, you know, much more accuracy in fraud detection.
Speaker A: What investments are needed to counter agentic AI attacks that per your survey, 79% of them do, they have already encountered?
Speaker B: I think first and foremost, um, and if we kind of talk through several layers of, you know, kind of areas to look at, uh, first and foremost comes the detection capability and the infrastructure. I think definitely banks would require systems that can understand the agent signatures as well as being able to predict that intent, whether there is a behavioral manipulation underway versus there is any unauthorized kind of brute force kind of event that is happening. Of course the infrastructure should be capable of handling several thousands of concurrent sessions per second. I think that's very key when it comes to tackle this kind of attacks. Post detection actions also matter significantly. What we have seen, as I was talking about earlier as well, an intelligent customer friction, which is basically deploying AI for intervening at the right time, asking the right contextual questions. Right. Are you being guided by someone? Has someone asked you to send this payment to a safe account? And stuff like that can be very useful in breaking that spell which the customer is under when somebody is actually trying to manipulate him into making payment. Right. Which is a scam. Obviously. Uh, you know, technology is not the only thing that the C suite people have to kind of look at. You also need teams that understand and respond to these kind of threats, uh, be able to constantly adapt and learn. Right. I think is also very critical as, ah, these things are evolving, banking channels are evolving in making these payments happen in the first place. So so must our defenses. So it's a constant learning, continuous improvement monitor, uh, learn and adapt kind of framework that banks must adapt to.
Speaker A: How should banks restructure our fraud and scam reimbursement policies to maintain trust with our customers and with our community without increasing vulnerability for the organization?
Speaker B: So, um, I would say first and foremost we must acknowledge that the cost of fraud far exceeds the actual fraud laws or any kind of monetary laws that the bank is incurring, uh, by virtue of a reimbursement. Of course, there is a direct deposit wipeout that is happening when, uh, customers are losing money to scam sometimes their entire life savings. And this has a direct impact on the bank as well, because that is fundamentally how the bank is making money using the deposits to, you know, Kind of make more money and the spread on the margins and stuff like that. So that has an effect obviously. But also at the same time there are other costs that are much more significant. So for example, if you look at the receiving side, mule accounts, right? As I said, mule accounts are constantly being fed into the system. New ones are being created all the time. Mule accounts are not something which is good from a health of a portfolio, even if you consider outside the aspects of fraud and scam. The reason is that these mule accounts typically don't carry a lot of deposit amount. They constantly transact, right? Money comes in, money goes out. From that perspective, it has a cost of servicing and maintaining these mule accounts without actually adding any profits. From that perspective, for one of our customer banks in Australia, what we have realized and what we have uncovered, and they have told us this, that mule accounts are costing them between US dollars 800 to as much as 1200 per profile, right? So when you multiply it by the number of mule accounts, typically a large bank has, we're talking of millions of dollars locked away in unnecessary costs that the banks are taking on. Similarly, there are costs associated with fraud analysis, str, suspicious transaction reporting, legal and so on and so forth, right? So when you look at all of these factors, I mean it's imperative that something must be done. Uh, it kind of uh, definitely outweighs the requirement from purely a fraud reimbursement perspective. So if banks are already thinking around these lines, I think if they are investing in technologies or capabilities that can help them to detect and stop the these scams as they happen, I think automatically the reimbursement policy can follow because the requirement for reimbursement will not be that much given that a lot of these scams could be stopped. And then the second part of that is that banks and institutions also need to be shifting from the approach of blaming the customer, which is often the case in terms of hey, you gave out your details, you fell in for this, why didn't you verify? Rather than from that to a customer protection where the customer was feels safe, customer feels trustworthy when it, when it comes to banking and continues with the long term relationship with the bank.
Speaker A: Let's talk about metrics. What metrics will tell us whether our AI defenses are reducing fraud losses or merely shifting criminal tactics.
Speaker B: Think of this, and I think we say this all the time. Fraud is always like a whack a mole game, right? You hammer one monster down and then another one pops up, right? And we always see this happening. Fraud always moves it Always moves towards the path which has the most vulnerabilities, the path of least resistance. So metrics need to consider the entire fraud attack surface. So for instance, if controls on real time fraud, transaction monitoring kind of controls, et cetera, they have been able to help you stop payment frauds. Right. Or reduce the payment frauds to a certain extent. It shouldn't mean that at the same time you have kind of ignored the account opening channels and then suddenly a synthetic identity based new account opening fraud spikes. So the problem has now pivoted towards mules. So from that perspective, obviously it has to be an all encompassing kind of a, uh, metric in terms of both uh, the customer life cycle throughout from the account opening to account maintenance to account closure sometimes as well as all your channels. Right. All the banking channels, the various systems etc, the integrations, open banking APIs, all of that needs to be considered. The second aspect of that is that you know, and I was uh, mentioning this earlier in terms of the cost of fraud being much broader than the actual fraud itself. Right. So to measure that effectively, what I think is that banks could start studying the correlations between fraud metrics and business portfolio kind of metrics. For example, we can look at the portfolio health and then based on various risk classifications of the underlying accounts, deposit accounts, whether they are deposit tending towards a mule account versus you know, good accounts that are giving healthy, uh, maintaining healthy deposits. And what kind of metrics do those mean? That's another way to look at it. The third thing I would say is that uh, to your point also earlier, Alan, that higher fraud prevention rates should not come because of a higher friction. Like you know, there's so much of friction in the entire journey that customers are at writing for example, or customers are declining, uh, you know, or abandoning sessions halfway. I think that's also not something desirable. Real time false decline rates, that's another metric that I think um, banks should be kind of looking at when uh, it comes to monitoring the performance of fraud and overall kind of health as well.
Speaker A: What is Your advice for CISOs, CIOs and banking executives themselves in the face of this rising AI driven and fraud. What should they be taking away from our discussion here so that they could bring those as uh, their call to arms or call to action from their perspective.
Speaker B: First and foremost I would like to reiterate the point that there can be a middle ground when it comes to fraud prevention. Friction as well as the trust that the customer associates with banking. We do not need to sacrifice anyone entirely. Right? That's something which is very important. Second point, which often gets ignored and I think increasingly we are happy to see that banks are not ignoring that anymore to some extent is that mules are actually everybody's problems. Mule accounts are no longer just an AML team's burden. Given all the regulatory action that is going on, the enforcement of that. We have seen that pretty heavy in Singapore as well as well as the realization that you know, the, these mule accounts are not healthy for the portfolio. I think that's very important as well. The third thing I would say is that with fraud there is never a single uh, silver bullet. We don't need to kind of see existing fraud detection systems. Oh, they're not working. So I must replace it with a new system. It's not always that. It's also layering it with additional signals, amplifying as I was explaining earlier, some of the signals that a device or a behavior LED network, LED kind of, you know, signals can help. Right. So those things can be layered into your existing traditional fraud systems for much better results. And lastly I would say the orchestration of the whole thing. Right. I think it's important that we architect that in such a way that it is based on this whole real time intelligence from the sessions based on device behavior and risk and let that drive actions and treatments. By treatments I mean whether it's an unauthorized fraud or a scam, right. Appropriate actions, be it an authentication, step up authentication or AI led customer intervention to break the scam spell. I think those are important add ons to then think about right through the entire journey of the sessions.
Speaker A: What is the single biggest. Okay, the one big myth regarding agentic AI fraud when it comes to banking.
Speaker B: I would say that the strongest one for me is the thought process that we are actually seeing from a lot of banks today is that it's not something that will have a dramatic impact. I think a lot of banks are saying that either their customers, they're not seeing this kind of thing or they're unaware of it that's happening or they're also thinking that you know, whatever it is, it is not going to be such a, such a big problem that their existing systems can't solve. But at the same time I think the survey results are also pointing to that is that it's very hard to detect this. Right. And, and it's a vast unknown out there. We have seen a lot of these deepfake enabled attacks that are happening from an agentic perspective as well. Many people getting fooled thinking that it's a real person. It's a, uh, relative or a, uh, bank employee or some other employee of the. Someone that person is working with to kind of, you know, forcing them to make these payments. Indeed, it's not. These things are much more real, I would say. It's on our doorstep, I think. You know, it's, uh, a inflection point at this point, I would say. Right. So we really need to kind of, um, sit up and take notice. Uh, Alan, for this, Bose, as always,
Speaker A: thank you for joining us on Podcasts for Future ciso.
Speaker B: Thank you, Alan. Pleasure to be here.
Speaker A: That was Subashis Bose, director of Global Advisory at bycatch on the topic of agentic AI fraud. Can digital trust keep up? You are listening to Podcasts for Future ciso. As always, if you have a topic you'd like us to cover in this channel, simply email us@editorsociety.com we'd also like to invite you to sign up for a free weekly newsletter so you you won't miss an episode of Podcast for Future ciso. In the meantime, stay safe, have a great day, and see you on the next episode of Podcast for Future ciso. Bye for now.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.