Fraud and BSA/AML infrastructure for the agentic economy

Your next customer is an AI agent. So is your next fraudster.

A valid agent can still make an unauthorized payment. FLINT decides before settlement, and leaves evidence for the fraud team and the regulator.

Agent arrives

Skyline’s invoice agent requests $1,450 USDC on Circle.

agt-skyline-88af3c12
Six-check scanAgent received
Decision gateTrust 18
ALLOWSTEP-UPREVIEWBLOCK

Payment intercepted before settlement.

AWAITING SIGNATUREES256 + ML-DSA-65
SHA-256pending decision
$1.5T

Agentic-commerce spend projected by 2030

Juniper Research

109:1

Machine identities for every human identity

Palo Alto Networks, 2026

+25%

Rise in malicious bot-initiated transactions in six months

Visa

+450%

Dark-web posts mentioning “AI Agent” across underground channels in a six-month comparison

Visa

Built for the agentic commerce stack

Agent protocolsMCPA2AAP2Payment and settlementx402CircleStripe + BridgeFireblocksStablecoinsSkyfireCoinbase x402 BazaarRisk and operationsBSA/AMLSIEMMITRE F3
The agentic fraud surface

Your agent can already act.
Make sure it still acts for you.

You already let the agent in. The next question is who it is working for.

You gave it tools, a wallet, or a seat on the network. Credentials will still look fine after someone, or something, else is steering. FLINT checks the action before it happens and leaves a record if you have to explain it to yourself, to a bank, or to a regulator.

What FLINT catches

Click any threat vector to inspect live decision telemetry.

FLINT evaluates observable identity, authority, provenance, behavior, and transaction context at the decision boundary.

Live verificationsigned proof
One checkoutinvoice-bot
invoice-bot paying Acme supplier
$847
$950 capUSDC$103 remaining
FLINT decisionMandate matched
AuthorityWithin $950 mandate
Behavior / environmentExpected runtime and wallet
ALLOWPass to settlement

Same agent. Authorized spend.

Decision signed to the record
Your path through FLINT

Start with the risk you need to own.

Choose your responsibility. FLINT assembles the shortest path from exposed agent action to accountable, verifiable control.

You accept agent payments

Accept the new demand without accepting blind trust.

Recognize legitimate agent buyers, verify available authority, and decide before settlement without treating every automated checkout as hostile.

Recognize

Recognize the agent

Separate supported shopping agents from undifferentiated bot traffic.

Check

Check purchase authority

Confirm the identity, mandate, amount, merchant, and transaction context available for this spend.

Decide

Decide before settlement

Return ALLOW, STEP-UP, REVIEW, or BLOCK while the payment can still be controlled.

Keep proof

Keep the proof

Preserve a signed record of what FLINT checked, observed, and decided.

Immutable execution receipt
Status: EnforcedProof: ES256 + ML-DSA-65Audit: Locked
Good agent demand moves. Unauthorized spend leaves evidence instead of loss.

A BLOCK decision returned before settlement. The evidence is signed to the transaction record.

Receipt hash: locked to record
FAQ

What teams ask before an AI agent can act or pay.

What does FLINT do?

FLINT is fraud and financial-authority infrastructure for the agentic economy. When an AI agent attempts a consequential action or payment, FLINT checks the available identity, principal, mandate, runtime, wallet, and reputation evidence, returns a verdict, and signs a record of the decision.

What is agentic fraud?

Agentic fraud is abuse in which an AI agent, its credentials, tools, delegation chain, or transaction context is manipulated to take an action its principal did not authorize. The agent can remain valid while its behavior, payee, amount, or purpose changes, which is why authentication alone is not enough.

What is Know Your Agent (KYA)?

Know Your Agent is the practice of establishing which agent is acting, which person or organization is accountable for it, what authority it holds, and whether the current action fits that authority. KYA complements human KYC; it does not replace customer identification or legal compliance obligations.

Why isn’t a verified agent automatically an authorized transaction?

A signature can prove which agent sent a request, but not that its principal approved this payee, amount, tool, or moment. A hijacked, misconfigured, or over-delegated agent may keep valid credentials. FLINT checks the action against the mandate at execution time.

What does FLINT verify before an agent acts or pays?

Six layers: Principal Identity, Agent Identity, Wallet Provenance, Authorization Scope, Environment Identity, and Cross-Merchant Reputation. Evidence may be verified, observed, unavailable, or conflicting; FLINT preserves those distinctions instead of treating missing data as fraud.

How can merchants accept legitimate AI agents without weakening bot defenses?

Keep the bot controls. Agent protocols and signatures can identify recognized automation; FLINT adds financial authority and transaction context so a merchant can distinguish an agent with permission to buy from a valid agent making an unauthorized purchase. FLINT Sentry provides advisory agent-commerce intelligence for Shopify merchants.

What do FLINT's four verdicts mean, and does FLINT block automatically?

ALLOW means the evidence supports the action; STEP-UP asks for more proof; REVIEW identifies signals needing human or policy review; BLOCK means strong evidence says the action should not proceed. FLINT Verify returns the decision to the integrating system, which chooses enforcement. FLINT Sentry never stops or modifies Shopify orders.

Does an AI agent need a FLINT Passport?

No. FLINT can evaluate an agent without one. A Passport provides durable agent identity, binds it to an accountable principal and declared mandate, and gives trust evidence a stable place to accumulate across sessions, deployments, and counterparties.

What is a signed verification record?

A signed verification record is a tamper-evident receipt of what FLINT checked, what was observed or unavailable, which rules ran, and which verdict was returned for a specific action. FLINT uses hybrid signing (ES256 plus ML-DSA-65) so the record can be independently verified through the post-quantum transition. It is evidence, not a guarantee of a chargeback, insurance, or regulatory outcome.

Does FLINT replace payment rails, fraud tools, IAM, or BSA/AML systems?

No. FLINT sits between agent identity and financial action. It is rail-agnostic, holds no funds, and is designed to work alongside card and stablecoin rails, x402, API and MCP flows, device intelligence, blockchain analytics, IAM, sanctions screening, and transaction monitoring. FLINT adds agent authority, execution-time context, and signed evidence; regulated institutions remain responsible for their risk-based programs and filing decisions.

Founding design partner program

Bring us the agentic system you cannot afford to get wrong.

Bring the workflow: an agent that spends, a business accepting agents, a fintech opening a new rail, or a company governing an agent fleet. Together, we'll turn it into a safer launch, a clearer operating model, and a system your team can explain when the stakes are real.

Founding cohortDirect access to the FLINT teamBuilt around a real use case
ACCESS: FULL SUITE

Build with the full FLINT suite

Get early access across Passport, Verify, Sentry, and Command. Use only what your workflow needs.

ENG: DIRECT ARCHITECTURE

Shape the system around yours

Work directly with FLINT on architecture, controls, integrations, and the shortest path to a live pilot.

LAB: THREAT SIMULATION

Test the threats before launch

Exercise identity, mandate, runtime, wallet, and transaction-abuse scenarios against your real use case.

PROOF: IMMUTABLE AUDIT

Make every decision defensible

Build signed evidence, review paths, and governance practices in from the beginning, not after an incident.