Executive Conversations by The Paypers
Executive Conversations by The Paypers brings together senior industry executives and leading voices in global payments and fintech for high-level discussions on the trends, tensions, and opportunities shaping the industry today.
Each episode is a genuine on-the-record exchange on relevant conversations with the people driving change in payments, fintech, and more. Hosted by Dwayne Gefferie, the series gives listeners direct access to the thinking of the executives and experts who are defining where the industry is headed next.
Produced by The Paypers, a leading global online publishing platform for the payments and fintech industry, and distributed via major platforms including Spotify, Apple Podcasts, and YouTube.
Subscribe and follow to stay ahead of the conversation.
Executive Conversations by The Paypers
Executive Conversations by The Paypers with Incognia | Episode 1: APP Fraud
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Welcome to the first episode of Executive Conversations by The Paypers, a new podcast series that brings together C-suite leaders and senior executives to discuss the biggest developments shaping financial services and payments.
In this debut episode, we explore one of the industry's fastest-growing challenges: Authorised Push Payment (APP) fraud.
Dwayne Gefferie is joined by Andre Ferraz, Co-founder and CEO of Incognia, and Joe Wilson, Board Member at bunq. Together, they discuss how APP fraud is evolving, why traditional fraud controls are struggling to keep pace, and what financial institutions can do to better protect customers.
About Executive Conversations by The Paypers
Executive Conversations by The Paypers is a podcast series that brings together senior industry executives and leading voices in global payments and fintech for high-level discussions on the trends, tensions, and opportunities shaping the industry today.
Each episode is a genuine on-the-record exchange on relevant conversations with the people driving change in payments, fintech, and more. Hosted by Dwayne Gefferie, the series gives listeners direct access to the thinking of the executives and experts who are defining where the industry is headed next.
Welcome to Executive Conversations by the Papers. I'm Dwayne Jeffrey. In this episode, I'm joined by Andre Farraz, CEO of Incne and Joe Wilson, board member at Bunk. And we're going to be talking a little bit about fraud, especially APP fraud. So Andre, I want to talk start with you. Um, maybe in plain terms, for those who don't know, what is APP fraud and why is it different from fraud that most bank professionals already know um how to stop?
SPEAKER_02Alright. Well, so APP fraud stands for authorized push payment fraud. So basically it's the kind of fraud in which the end user is convinced to move money um thinking that they're um trying to protect their funds or something like that. So it's usually related to social engineering scams in which uh a scammer would call them and say, for example, like, oh I work for the bank, there's something wrong with your account and I need you to send money to this secure account here uh so that uh you you don't lose your money. And then that secure account was actually the account of the fraud street, right? So the end user logged into their bank account from their device, probably went through some form of biometrics or MFA, right, authenticated to their account, did the transaction, and then they realized, oh, I sent the money to to the wrong person that was in the bank. It was it was a scammer.
SPEAKER_03Yeah, absolutely. So, Joe, of course, working at a bank, right, um, you see a lot of those different types of interactions. You see what's happening when it comes to fraud, and this is of course a fraud that's been on the rise. But when that customer authorizes the payment, as uh Andre already mentioned, like the normal fraud book playbook would probably does not fire, right? How did this change the way that a bank like Bunk is actually approaching this um and trying to solve it?
SPEAKER_01Yeah, by the way, thanks for the initial Dutch pronunciation of the word bunk. Uh look, I think maybe your question is like, how we evolved or what do we do now because these things are on the rise and progressing? What I would he refers to in a really good way, I think of as this dark art of convincing people, right? They do this. Um these are things you have to put in place, right? You have to take your time and energy and you have to focus it not just on the back-end systems and catching things after they happen, but you have to start to focus out forward, like when it could happen, where might it happen, how do you educate people? We have a feature that we recently implemented called Safety Shield, which basically we keep a like we run a constant scan against your patterns and your behaviors. And then when we send something that's out of the ordinary or above a threshold you might normally do, we might freeze that for 24 hours and give you a chance for a second thought on some of those and even announce it to you and let you know. So that's one example. I'm not saying it's the perfect all answer, but those are the types of things we have to start doing now. I think we have a responsibility in that trust relationship to try and put technology to work even out at the human error side where we can.
SPEAKER_03Absolutely. So um I think maybe, Andre, for to help the audience maybe get a better size of this, right? Like how big is the APP fraud? You know, how big is it? How how fast has it grown? And what moved so that this can actually happen?
SPEAKER_02Yeah, I'd say right now, I don't have exact figures, but I would estimate like in the hundreds of bidens per year across the entire financial services industry. Um, and one of the key challenges is that right now this is for many financial institutions the top fraud issue. And a lot of regulators, for example, are currently discussing like what to do, right? Who should should be liable? Is it the receiving end, the sending end of the transaction, for example? So there's a lot of discussion right now in multiple jurisdictions about who who's responsible for this and who should be liable. So yeah, major, major problem and one that the industry hasn't really found the really solid solution.
SPEAKER_03Absolutely. And you just mentioned liability, right? I think um we we see the liability aspect, especially in this particular uh fraud. Who's actually responsible? Like, do you already have an answer to that, or is it still a debate between it's either the bank or the customer?
SPEAKER_02Yeah, I want all of this. There's a debate, right? Um, there are some places, like I think the UK, for example, currently has um the receiving end of the transaction being liable. And basically that's because like on that side of the transaction, um, it's kind of the bank didn't really run proper KYC um to ensure that that account was is being used by the right person. So that account is probably a Mule account or a fake account that's receiving those funds. So they're being held liable. In other places, you have the the other side being liable. Um I don't know which approach is is vast, to be honest. Um there are other places that are discussing having both sides being partially liable. Um, and and in other areas no one is liable.
SPEAKER_00It's like depends on the country there. That's a that's a country-based answer too, as well, right?
SPEAKER_02Yeah, yeah. So I mean, um it's still open uh discussion right now. Uh I I don't think there's a a perfect model, but in the end, like there's there are multiple parties in involved in this. Like in some places there's even discussion about like, for example, having the social media companies being liable and for for some of this, because it's like, oh, the conversation originated on social media and it led to this kind of scam, etc. Which I I think it's probably a bit too far, in my opinion. Um, but it it has to be like more in between like the the financial institutions and probably having the financial institution like sharing more intelligence so that they can like identify and blot these these scam networks.
SPEAKER_03Absolutely. And I believe it's in the UK where actually banks are actually responsible for paying back they have to reimburse the reimbursement. So maybe for you then, when when you look at that, do you think that paying back victims sounds right? Or uh does it just guarantee that reimbursement risk makes people much more less careful?
SPEAKER_01I think I gotta separate um liability and responsibility. And I know they sound kind of similar, but I want to split the hair a little bit. Because in a sense, I think we're all, we're both sides of this quite responsible. Like we as a an institution, a banking institution, responsible to educate people on what this is, what the risk is. I mean, I'll give you a very basic cultural example. Go to my LinkedIn, go look at my picture. You'll see my picture, but behind my picture, you're gonna see a banner. And it looks like the bunk banner. Read the words, and it's gonna say, bunk will never call you. Well, so it's that basic. The first day you start in our company, you basically get this package that you, if you're gonna announce anything, if you're gonna represent yourself on LinkedIn, you have to put that up. So it's every employee. So you're just trying to make you as a company, you have a set of cultures. So we're responsible. That's a very simple one, right? But we're also responsible to basically say, look, if this looks weird, we should tell you. You might still say, No, I want to do this anyway, right? I still, yes, yes, yes. I might make you say yes 40 times. And so then I'm slicing responsibility and liability. So, but I do think we have a responsibility to educate, we have a responsibility to use technology to prevent and to and to sort of put up some blockers. And also the KYC thing is really important. I can tell you the I band doesn't match the name of the person that you're sending it to, right? Um, but you might still want to send it. So there is those two things. So, do I think that um, you know, I don't have a hard answer to that. And I and I don't think I want to publicly decide for the world what that answer is, but I do think we should look at that at least in more than one direction.
SPEAKER_03Absolutely. No, I I absolutely agree. I think there's one thing, and that's maybe the form of personal anecdote where I think it might be a little bit overbearing, is when um, just as an example, I was trying to move some money to somebody else, but I was on the phone with the person, and then my entire accounts got shut down, right? Just for the fact that I moved some money, I did it was uh still a answer to all of the questions, but then still my whole account got shut down. And I think that might be a little bit too overbearing as well, because and I think a lot of consumers might might agree with that. Have you had any pushback on that or are you even utilizing those uh uh technologies?
SPEAKER_01So I mean, anything that has an element of anti-fraud to it, especially the sort of agentic AI components where you can go and sort of try and find these things before they happen. Um, yes, we'll utilize those technologies. We we really use them deeply in that space. Have we had pushback from people where we held up a transaction because we thought that it had suspicion to it? Yeah, we have. Like it happened to me. I mean, I was booking a holiday house, right? And it was out of whatever my normal patterns were, and my and my payment got frozen by bunk, and I was like, but then you know, it wasn't something that had to be done within 24 hours. Once 24 hours was over, which is the safety shield I mentioned, it was fine. So I didn't mind it. Um, I'd rather have the protection than to have the problem. So for me, it was it was okay. But yeah, we see, I mean, all sides of this conversation, I promise you, uh, from a user perspective, we're seeing absolutely no, I think that's great to see.
SPEAKER_03So maybe you can take us, uh Andre, maybe you can take us through a scam, right? Like, um let's say I'm a victim on that side, from start to finish. What makes a normal, careful person actually hand over money in a case like an APP scam?
SPEAKER_02I'm sorry, I didn't.
SPEAKER_03Sorry, let me rephrase that. So let's walk through a scenario of this particular scam taking place, right, from start to finish. What makes a normal, careful person always think that they're pretty well secure, they know their passwords, they know how to work with that? Uh what makes them actually hand over money at this case?
SPEAKER_02Yeah, I'd say the key thing that fraudsters do in those cases is is to put the the victim in a like psychological situation in which they they become a lot more vulnerable. So for example, they would try to attack your weak spots. So for example, there there's the classic scam of like people find your picture in social media, try to identify like family members, create a phone number, reach out to you on on a uh a chat app like WhatsApp, for example, and say, like, hey mom, I need some money, got a new number, can you help me? Right. That puts that mom in the emotional state in which they're like, Oh, I need to protect my child. I I need to help him. And they don't think like, oh, is this the right person? Right? Like, they they maybe don't think, like, should I call my son to identify if if this is real? Right. No, the the emotional state in which the fraudster puts that person in forces them to do things um much more quickly and and being like a lot more reactive, for example. Another one is is the bank impersonation scam, right? Which the bank would call you, not the bank, right? But they would spoof the phone number to make it look like the bank's number, but maybe the area code is likely uh different. If you search on Google, for example, for that phone number, you're gonna see that, oh yes, that is the right number from from my bank. Um, and and then they start guiding you through all this um story about like your account is compromised, we're here to help you, and they have all this like verbiage to make it look like they're serious and and they really represent the bank. Um, so they're again putting you in that emotional state that in which you're concerned, and you're gonna do whatever they they ask you to do. So so basically they try to exploit those things and and those those weak spots and and users, and it's a it's a numbers game. Yeah. So it's it's not like 100% conversion. They're probably gonna call like 500 people during a day and and scan like 20. But if they're able to make a lot of money from each individual transaction, that's a pretty good business for them, right? So I'd say it's a mix of putting the end user in an emotional state in which they're vulnerable, plus a numbers game.
SPEAKER_01Can I add to that? Please, I so um Andre's doing a great job covering the space. I think the thing to remember here is that we're in an arms race, a technical arms, a technology arms race when it comes to the the how this is being done. Let's take his example of you know your son, you think it may be your son calling you. What's what they've also done is they've taken these low-cost, no-cost AI tools, they've gone online, they've gone through the Instagram accounts, they've found out who your son is, they've recorded their voice off of videos that they posted for 20, 30, 40 times, they then recreated that voice and put it through the phone, and then they've called you from this number or they've contacted you through Instagram on an account that sort of looks less very similar to what your son's looks like, and maybe even took their photos and should put them up there. And now you're doing your best to check these things out. But like again, the emotional state, the panic, the energy, the the the you know, the fear that gets put in place is where they you're getting a hole. So you have to be able to somehow in that moment be like, well, hold on, wait, wait, wait. To sort of know, first off, they have to realize that that possibility of it being that close and being that sophisticated exists at an incredibly low barrier to entry right now. I mean, companies like his exist because this this barrier entry, they have to fight this all the time. We have to fight this. So that's why I tend to call this an arms race.
SPEAKER_03Yep. Yeah, like if you just look back a couple of years ago, just spotting a an email, right? Like had a bunch of you know, see who it's from. See who it's from, it's coming from a Gmail account, it had misspellings in it. And indeed, now you're you're you're absolutely right, is that the level of sophistication of trying to imitate or trying to be that person, and then adding on the psychological aspect of it as well, right? Putting you in a state of fear or having to react at that moment, those two combined can be a dangerous combination. So um, is it even fair to to look at it and say, hey, we're just common sense or my gut is going to protect me? You need solutions basically out of that.
SPEAKER_01I mean, it works because it works, right? Yeah, they know that.
SPEAKER_02So I'll give you one example on on that, um, on how like smart these these fraudsters are when they're trying to impersonate any company. Um, it was one scam in which uh the fraudsters were impersonating Microsoft's support, and they bought this domain, which was not really Microsoft, it was RN Icrosoft. And if you type it, it and and you don't look carefully, it looks like Microsoft. That's it. Oh, yes, say we're at the end. Yeah, yeah. So when when you when you were reading that email, it's like, oh yeah, Microsoft sent me an email. I'm gonna click. That's legit. So so they they really think through everything uh to make it look legit.
SPEAKER_03Absolutely. So banks, of course, run awareness programs all the time, right? Like in the Netherlands, you had the three times knocking, and then you you had to go through different checks, of course. And in the UK, you have different ones, in the UK, US they run different programs as well, and they help, but they do have a limit. So, where does education stop working once somebody is, you know, like you mentioned, emotionally manipulated in into that particular moment?
SPEAKER_01I think there's a couple of things. First, I think you have to know, I think as a bank technology company with a banking lesson, um, you need to be clear. First off, we focus on a particular audience. That audience is quite tech savvy. Um, that doesn't give them any greater defenses, by the way. Um, but we also have to position in message what it is that we stand for, what we do and we don't do. So this thing that I mentioned about LinkedIn, like this whole, like that is constant message that comes out of us, right? We will never call you under any circumstances we ever call you. So you can establish that relationship as truth. You can sort of start to rely on it. I would say just beginning. So there's a little bit of like basic. Let's start with basic things. Um, where do we go from there? Well, then you have to start to employ technology, right? You you have to assume that people will make mistakes, and and you have to assume that they will do these things that Andre describes that will happen. So then what can you do? I mentioned things like Safety Shield. There's other methods. Can you there's this is where the arms race is on the positive side. Like the good guys are going after this with technology to sort of prevent it as and see it as soon as possible and early as possible. Maybe we can give you a chance to take it back when you realize you've made a mistake. Maybe we can work with you on those things. Maybe we can go find them and get this solved. Like there's ways that we can partner together. As an industry, I actually would argue that if we were to connect a bit better and sort of think of this as a not just my problem or your problem or their problem, but everybody's problem that's sort of harming the industry, we probably could even get a greater uh ability, a greater defense going. I don't know exactly what that looks like, so I'm not going to articulate. Andre might have a better clear picture of that. But I do think that there's a way that we could anonymously share more that would create a larger conjoined defense that we don't necessarily do without an exent. Yep.
SPEAKER_02Yeah, it does. It does. And one one of the things we're doing in some markets where we have like a very strong penetration is we are enabling financial institutions to exchange data through our platform so that they're able to identify, especially meal accounts, which is like usually what's used to receive the funds from these scams, right? So whenever there is a transaction and we we have visibility into the receiving ends and we're able to say, like, this is a meal account, we've seen it before. Um, they're they're gonna stop the transaction right there. Um, and we're able to do this without ever sharing any PII between organisation institutions because basically anonymous, but it's a fact. Exactly. Yeah. So so the the reason why like not sharing PI is important is because prior to this, the banks were like, no, I'm not gonna share like my customers' like personal information because then this other bank can use that data and advertise to these people and steal my customer, right? But if we're just saying, like, okay, this is a meal account and that's it, and they have the visibility into um who they're sending to, but that's it just for that specific account, then they feel a lot more comfortable sharing the kind of information. So embedding this into a like privacy preserving way is is probably the best way to enable this kind of data sharing.
SPEAKER_03Yeah, absolutely. So, and look, especially in the fraud space, if you go look at it, you go you go search for solutions as a financial institution or as a bank, there's already plenty of tools, right? Like there's a number of different tools that are actually trying to fix fraud overall. Um, why is looking at the signals around APP fraud so interesting? Um, and on and why is there a different approach that can actually help solve this?
SPEAKER_02Yeah, well, the the tricky part about APP fraud is that if you look at the traditional signals, everything is gonna look fine, right? You're authenticated to your account, you use your credentials, it's the device that you typically use. You're probably at a trusted location, uh, you're probably connected to your home Wi-Fi, something like that, right? So at a high level, everything looks fine. What's unusual, and and these are the auto signals that we try to focus on are things like is this user actively on a call? Is there any kind of like remote access tool being used at that moment? Is this a new pay? Is the like transaction like is is it too big compared to the normal transactions that this user typically does? When you see all these factors, that's a red flag. But then if you're able to analyze the receiving end of the transaction and verify like this is a Mule account, then you're like 100% sure this is ABP fraud. So so this last mile here, I'd say is the most important. The otters are like important signals, but the last one is is really when you when you nail it. Absolutely.
SPEAKER_01In in his description, one of the elements that we're we're spending more time on is that moment of the call. So we are encouraging any user who is on a call and actively on a call and unsure to get on get get with our get in the app customer support right now. Get a user support, contact us instantly, and we will walk you through how to check and test and walk this thing and even whether you should or shouldn't do this, we will move it. So we're looking at that moment because the more that we can stop before it happens, of course, um, the better it will be. The backward signals of what happened um are are useful and you will use them, and the technology will help inform other things, but they're not as good as the moment of a bad thing happening where you can prevent it from happening. Absolutely.
SPEAKER_03And you mentioned mule accounts several times, right? I think maybe for those who are not as familiar with what a mule account is, um what is a mule account and why does it why does catching it depend on uh banks working together?
SPEAKER_02Yeah, so it's a very challenging um issue because the Mule account is is basically the one that's used by the fraudster, and the fraudster is not gonna use their own information, right? So they're basically like convincing other people to give them access to their accounts, and usually they're paying these people or they're coercing these people to give their their accounts. And the tricky part about it is that during the onboarding stage, during the KYC, everything will fine because it's the actual person creating that account. But then they transfer that account to the fraudster. They even like give their credentials or even like give the device that has access to that account. And then that fraudster starts using that account going forward. So the tricky part is identifying that handover process because most of the verification happens at the account opening stage, not continuously. So the way in which many financial institutions are evolving now is that they're starting to continuously verify this account over time versus just at the front door. So this is this is how you would identify this kind of behavior. And particularly identifying the behavior of the device that uses that account versus the behavior of the device that opened that account in the first place. If those behaviors don't match, the likelihood that this is a new account is extremely high. And then there's a second layer to it which is if you're able to identify that the second device is associated to other accounts or other devices then you identify what we call the device farm. And this is where there's a high concentration of accounts. So to give an example we had a financial institution that was testing this this capability and we were able to find in a single apartment 200 devices that were connected to 4500 accounts.
SPEAKER_03So wait 200 devices that were connected to 4500 accounts. Exactly wow all in one place and you were able to detect that in a single apartment.
SPEAKER_01Very easy so not apartment building but apartment apartment. Exactly what he's saying like you know someone could track the electric power usage of that apartment you would notice they get the heat signal coming out of that right?
SPEAKER_03Yeah absolutely well and then bunk of course being a digital only bank you don't have any locations in it. So the device is actually the customer's device device and the the contact bars and the it could also be a business device both of those are possible. Yeah yeah so the you could have a user that has multiple has a personal account in a business on one device or you could have multiple devices. You could this as one so how are you using the information that you're gathering of course when it comes to uh preventing yourselves from those mule accounts or those mule account takeovers.
SPEAKER_01Yeah I think one of the uh we put out an annual report just in the last few days so there's some good data in there if you want to check it uh for the facts behind the conversation and one of the big areas of focus was the preventing the incoming fraud right so that's coming in and we've been able to reduce that by something I had to look at number I think it's the 80% in a lot. So we're reducing that coming in part of that is that you are running a constant again agenti component or an AI component on the behavioral patterns the the if you will the stats. I mean I can use it in whatever term you find most comfortable but I mean like you're running the numbers at a 24-7 to look at the patterns and the behaviors and what's happening. And so you can look at the devices and I think you did an eloquent way of describing it like is a device changing its pattern? Is a group of devices changing their patterns? Is what's happening with this account with that and re-verification I think is also a one of the ways that you you will be able to do that. So we're employing very similar um technologies and techniques to go after this but we feel like I said there's a responsibility to also on the front end make that education make that moment of something going bad as best as we can stop it when we can. But it's it's all it this is all data this is all information. This is like massive spreadsheets in the sky just to be simple that we are all running through constantly and trying to pick the pattern so that we can go find the uh the the the evil the darkness out there before it can occur that's that's exactly as as Andre described it.
SPEAKER_03Absolutely but I think even for brink especially you've been one of the banks that has actually been proactive in not just utilizing data but utilizing AI in sure on boring processes and other things as well so how are you currently utilizing order point I doubt it's going to be spreadsheet but it's probably please no everyone that was a metaphor.
SPEAKER_01Okay perfect yeah so how are you using AI now to help the great tables out there right? So how is like so yes so fraud prevention um so there's an AI component to our fraud prevention of course of course of course because we're battling the AI components that sit on the outside um there is a AI component to KYC there's an AI component to I mean really we're a generative AI company so there's an AI component to everything that we do but I would sort of reel it all back to like getting started with who the user is who are they where do they come from not just what we talk about in this conversation that's KYC that's an internal bank conversation but I mean who are they what do they want where are they heading what are they trying to do we're an entire bank built around a user and our entire obsession and focus of all time is to what does the user meet and what do they want? So we build everything. We make every decision every feature every expansion everything we do is based on what the users are asking of us or what they want. So we have to gut check that and then AI plays a role there we also have AI as 97% of all of our customer support inquiries are answered through AI with a 90% plus satisfaction rate. Tapman gives us magnificent amounts of data that we can then turn back into these other conversations, right? So one of the advantages of having a sophisticated AI customer support ability is that that is then data. It's not just a recorded conversation it is an AI analyzed and capability that you can then recycle into proactive information to go fight fraud with so that is there's an upside to that and I'll be honest anybody who's running an institution like ours, this isn't something you do overnight. People don't just flip this on like we've been we've been doing generative AI as a company for more than a decade and we've had we got there's a lot of mistakes that happened in that to get this to where it's at these satisfaction rates. So it is you guys are in this industry you it this is something it takes time to do right and it can be done wrong and you can feel still feel good about it. But you have to be able to capture this information and reuse it for prevention. And that's how we want everyone to feel safe and secure and that is our responsibility.
SPEAKER_03Absolutely and in in cogne of course like you're you're you're providing a solution of course to help with a lot of that how are you utilizing AI uh how has it helped you to evolve the company as well yeah well pretty much everywhere.
SPEAKER_02So from the like device IDs that we generate using transformer based architecture to how we predict what users are um expected to do and then we compare this to the real-time data to see like okay if there's a good match the likelihood that this is the right person is higher um to AI assistance in which like the the users of our platform the the the customers they're able to for example run like very big and sophisticated queries on like what's going on the anomalies in the data identify like new fraud patterns etc um all the way to for example readjusting how each individual data feature is is weighted in in our models by um basically talking to our system um so so yeah it's pretty much all over the place um helping both the customers but also the underlying technology that helps us identify the users correctly is is is all powered by AI.
SPEAKER_03Absolutely so it's more than just the well everybody uses AI very broadly of course but I've heard you talk about generative AIs of course in the chat bot being able to take language and actually have responses but then connecting that into your internal sources and helping uh customers to solve problems uh directly to all the way to applying machine learning in in different ways and and going beyond that as well.
SPEAKER_01Like maybe maybe to sidetrack that a little bit as far as I'd love to add to that if we do think it's important when people are listening to separate generative and agentic. Yeah in terms of let's just in all simple terms if this is the first time you ever heard of it generative is like you know you give it a prompt you give it some information and it does something. Agentic is you've given it agency. So it has a set of uh let's say pre-decided uh behaviors or capabilities and it's making a decision has agency it's going and doing something on its own. I find as a bank I find we find agency agency capable AI is very good. I mean AML fraud prevention you can really use these technologies there because your risk level of getting something wrong is you're actually out there in data trying to get something right. When it comes to say um uh user support or access to a user account it's a very different story right you this isn't something right now we're ready to just turn agents loose on so that's not we don't think that's the right time for that but it can inform that inform that data is collected and can inform what you can educate talk about and and engage from a generative AI user support scenario. I know that's a little bit of what we would say in US inside baseball but um it is very much like to good to separate those two things. And then for anyone who talks about AI in our space, we should very much separate and I think Andre will be with me on this the lab and the factory because there is a lab where we're out token maxing we're talking about how much we can do and like how far AI can go. And then there's I think you and me and we're running businesses on AI right so the day-to-day usage of this is running of the business which is very much we're in the factory and we're delivering on a day-to-day basis which isn't the the perfect uh PR scenario but it's the hard and difficult work of keeping people safe.
SPEAKER_03Yep I agree absolutely so maybe there's even that extension of that right and maybe a topic that um nowadays at payments conferences, banking conferences here all the time, which is agente commerce. So what are your views on agentic commerce? Because then all of a sudden we don't just have a user anymore we don't have a person or a business or a business person, but we have an agent on itself shopping with either a card or the access to the bank account.
SPEAKER_01Well let's assume in a best case scenario that it's in an agent with rules but I think let's start with agentic commerce. So actually I think of agentic commerce less than the way you do which is sort of maybe an agent out shopping I think of it as more as um agent-to-agent commerce right so this is this is commerce that's passing between different agents one's like uh on one side one's on another and so this agentic commerce is actually happening you know without humans being involved because both of the agents have been given agency and they've been given rules that they play by um and I think in a best world scenario where the rules are set in those things this thing I'm a lumber company and I sell seven types of lumber and there's rules about what I sell and what the SKUs are and then I'm a buyer and I have an inventory I have to keep and I have a budget. Well that seems pretty simple maybe we could agent that the agent agent who says here's my credit card I want something new that sounds like a bad idea to me. So I think there's uh there's rules that still have to be put in place. I think it's very brand new but I do think it's an industry that's headed our way and at one time or another we will all have the same conversations we're having today about human fraud that we will once at some point we will engage in well we have a genetic fraud already but an agent to agent fraud let's say we will have to find you know we'll have to be smarter and better when the time comes but I just don't know exactly when that is now maybe for you Andre like of course you have know your agents and all these different protocols that are being launched as well how do you see that changing or maybe expanding your business when it comes to preventing that type of fraud as well yeah I'd say the there are two challenges here right one is the know your agents which I believe this one is more straightforward like each agent can have like a cryptographic signature and you're able to authenticate it that's all fine.
SPEAKER_02The tricky part is is establishing the um connection between like the agent and the user and doing that in a continuous way because what if that session is hijacked right what if I take over your account and your account has an agent that has for example your payment credentials and your login credentials to your bank account for example that could be a huge problem right um so this part I'd say is is the most challenging and this is where we are acting more um right now which is finding ways to basically create like a a way to bind the end user to the agent continuously the way we're doing it is by focusing on pretty much the same things that we do with with otter uh customers which is focusing on the device and its location and if anything changes here we need to make sure that at least one of these two uh remains consistent so for example if it's the device that you always use and you always use to connect to that agent that's all good if it's a new device the location behavior of that new device should match the old device otherwise there's a risk that this is something else someone else uh impersonating you for example so we focus on like look into these two things specifically and and I'd say like at a at a higher level it's thinking about like what is vulnerable today and pretty much every signal to like represent a user in the digital world that um can be fake by AI is no longer reliable. So for example if you think about like remote biometric authentication defakes are destroying that document verification probably in five years that's not going to happen anymore. OTPs very easy to fish passwords same thing right so all of these like digital signals are are becoming less and less reliable over time. So we're taking approach that which is much more like about grounding the user's digital identity into physical reality because that's probably the only thing that AI won't be able to fake so so that's what we're we're betting on.
SPEAKER_01Absolutely there's an opportunity there's a technology opportunity here right there's no what it's this isn't so much a technical problem we can build if we know what to go after. It is a trust verification type of issue. So there's a which leaves there's a technical gap for greater technologies uh to address the things that Andre just described what is the next level of if we're if he's going back to the old world what's your address and are you at your address uh what is the what is the technology opportunity there is something we don't I don't know what it is but I know there's something.
SPEAKER_03Yeah absolutely so I like to look into the future always and I'm a very upbeat and positive person when it comes to that. However I think what we're seeing around us nowadays is very challenging right there's AI of course there's regulations also not just in in Europe but also across the world um and other things are coming in that what is something in maybe your perspective that you believe needs to change for at least let's just keep it to APP fraud or fraud overall as a bank that allows us to grow further, to do more transactions, to grow as businesses as well. What needs to change? Is that regulations? Is that the adoption to AI, adopted to stable coins? What might that be?
SPEAKER_01There's a lot of ways we can go with this and it sounds like I'm gonna end on the same place I started which is um I think the opportunity on the human end is our challenge. I think uh responsibility uh not necessarily liability but responsibility to develop the technologies and the capabilities to better secure the human end of a transaction. What does that mean? I I mentioned Safety Shield a few times. Andres mentioned some different ways that they do it but I think the we're exploring the both in a different way how we go and affect this, if I may say weak end of the problem in a sense. So I think what needs to change is I think A, it would be great if the whole world at the same time raised its acumen around how dangerous this is, but that probably won't happen and we'll still make mistakes. So we have to be responsible to continue on a company by company basis to really educate and create technologies that can prevent people from making mistakes without of course handcuffing them like let's say what happened to you on a completely legit transaction. So how do you balance between the two? I'm sure that we're gonna still make some mistakes along the way but I think that's the thing that needs to change is we need to help people understand the breadth and the depth of this and provide technologies that are seamless so that they're not you know stuck with nothing nowhere to go and nothing to do about it.
SPEAKER_03Thank you very much. Now over to Andre.
SPEAKER_02Yeah I'd say my my goal is to enable the financial institutions to get to a point in which they don't need to worry about educating their users about security anymore because the tech is so good that they don't need to worry about that. So for example think about um account takeovers driven by social engineering right um a lot of that was because OTPs was one of the main um forms of multifactor authentication and an OTP can be easily fished right like if someone is calling you trying to impersonate the bank and they're saying like oh I'm from the bank we're going to receive a six digit code on your phone um please tell me that six digit code okay I got your account right but if we're able to replace that with better technology that the fraudster is not able to say like oh there's there's there's a code that you're gonna receive you you shut down that door right um so basically like continuing to upgrade the technology to a point in which even the last like tech savvy user is still protected because like the tech is working for them.
SPEAKER_01In the meantime obviously we need to invest a lot in in educating uh the users but um I I believe you're gonna agree with me sometimes it's frustrating right you you try a lot how could it be possible and you're like oh my god you can't I can't believe someone did that you guys have those factors it does but you know I don't think it's it's it's a you can't blame the victim here like it's still someone is preying upon and we have to be smart enough to like understand who the who the bad guy and the good guys are here. Yeah.
SPEAKER_02So so my goal is to like help the FIs get rid of this problem and not have to to worry about uh running campaigns to educate their users anymore.
SPEAKER_03Perfect. Well I want to thank the both of you for joining us here at Executive Conversations by the papers. Thank you very much. Thank you. Thanks a pleasure to be here. If you like this episode hit like follow and subscribe for more