Forter’s Doriel Abrahams on How AI Agents Are Reshaping E-Commerce
In the Techstrong.ai Leadership Insights video, Doriel Abrahams, principal technologist for Forter, dives into for better or worse the impact artificial intelligence (AI) agents are having on e-commerce.
Transcript
Hello, I'm Mike Fazar and welcome to the latest edition of the Techstrong AI Leadership Insight series. We're here today with Dole Abrahams, who's principal technologist for Forter, and we're talking about the impact AI agents are gonna have on e-commerce. Dole, welcome to show.
Well, thank you so much. Thanks for having me. Excited to, to take part, I think everybody and his brother's talking about agen AI in some form or another, but I don't think we've actually kind of walked through, well, our AI agents gonna buy stuff for us.
Are they gonna sell stuff for us? And how might they actually negotiate and how do we know that the AI agents are authorized to do whatever it is they're supposed to be doing Anyway, so start from the beginning. I mean, what role will AI agents play in e-commerce?
So, first of all, I think AI agents already do buy stuff for us. I mean, sometimes you would ask Alexa to refill your, um, whatever the paper towels in the kitchen, 'cause you just run out. I mean, that is a very beginning, initial, um, you know, AI agentic abilities, right?
Because Alexa has to choose which type of the white papers you wanna buy, and then maybe you're going to ask, uh, hair or it to be, uh, you know, cost conscious or not. So this is the beginning, but today we're already seeing even, you know, cha GPT features of your compare flights, uh, and, and make a purchase for you. So if you're starting to talk about, uh, what you mentioned, um, and negotiate in our name.
So these things are already out there. I think what you alluded to at the end of your question, uh, was super important, is how do we know that this specific agent has the authority to use someone's identity or potentially payment instrument to actually go ahead and complete the transaction? And this is something that the world or the e-commerce world is, is definitely dealing with today, both from the functional aspect of how to make it work, but also on the other side.
That's what, you know, we do at, for, uh, try to validate that there isn't any fraud happening or any manipulation of identities or someone's using someone else's credit card without them authorizing them. Dive into a little bit more, though. The e-commerce providers will each have a series of AI agents and me as the purchaser or the consumer will also have AI agents.
So how will these AI agents kind of interact with each other? And, and I guess at some point they might even have to negotiate. So how does, how will that all manifest itself?
Uh, so that it is interesting and I think we also, um, you know, Walmart's, uh, declaration, I think last week ago, two weeks ago, about them starting to integrate AI agents to, you know, pick and choose for consumers what they need, um, at the, the interaction between different AI agents is, is always interesting. And I think there there is more, um, more of a guessing or, uh, I know we can assume what's going to happen than what I can actually speak to. But yes, what you said is exactly right.
Um, stores or retailers are going to start offering some AI agents to help with, uh, price compare or functionality comparison already to help you identify what you need at this point. And on the other side, as consumers have today, AI agents that are trying to do the same, but optimized for the consumer and not for the merchant, will there be a point in time where two AI agents negotiate in our name? Probably, it's probably al already happening today.
Um, I think very much so is happening when you think about, um, algo trading, uh, functionalities. So not very much for the consumer retailer relationship, but more in stock market. Um, it is happening today and I can say too much about how it's going to work 'cause I'm not an expert in that front, but it definitely worries me.
So it seems to me at least there's two aspects of securing these things. One is the AI agents themselves, after they've been created, somebody may try to compromise them and take them over and essentially commandeer whatever process that they've been authorized to complete. So how will we know when the AI agent that you or I created has suddenly been, um, stolen essentially by somebody else for a nefarious purpose?
The question is, how do we know when it's being compromised? The answer is we don't always know. And, and what, what, what I'm dealing with on our side.
So just to say a little bit, share about a little bit what we do. So we prevent fraud from happening for retailers. And for the most part in the near history, when you see someone or something, um, transactioning on your website or even scrolling your website, you would have to make a decision on whether they're good or bad based on whether it's a bot, as we used to call AI agents up, up to very recently or a human being where for the most part, bots consider a bad thing human being.
Consider the good thing. Today, one of the key problems we're dealing with is that we are going to see, like you said, good bots or AI agents that are actually, um, sent by humans to perform their actions. And you'll run the risk of declining their activity based on the fact that it's not a human, but what you do, you, you'd actually turn away good customers.
What you are referring to is the next step. So even now that we've established that there is such thing as good boss or good AI agents that transacts for people, how can we identify that these are not compromised bots who are taking advantage of the delegated authority that was given to them? The short and easy answer would be to understand the behavior.
When I say behavior, I, you know, I, I've mean a lot of different things that you can do, um, with the cyber intelligence. Identify the device from which, um, you see an activity, you can identify the location, you can measure all sorts of things in terms of like the latency to try and as to try and assess where the activ activities coming from, um, and what types of operating systems, uh, what versions of browsers or et cetera. So these are things that we call, um, behavioral analytics.
And you can understand if statistically what you're seeing is good or bad activity based on all, all, all these features you run, uh, machine learning models, uh, and some AI or old AI features to determine, uh, those factors. Um, whether a good bot turns back to be a bad one. That is another thing that you can assess using statistical mythologies and, and really to validate the behavioral activity.
And again, when I say behavioral, sometimes people think that I'm referring to how long they spend on the site or where on the side, uh, on the site they clicked, what pages they they looked into, it's this and more. 'cause we're also talking about the actual device identifiers, which are an indication of the behavioral, uh, that, that you can see. And secondly, won't the nefarious actors out there create their own AI agents that will, uh, behave like they are trusted AI agents for a little while and they have gained your trust and then maybe strike and do something malicious as well, right?
Uh, absolutely. This is a fear and a major concern in all, you know, cybersecurity industry and also, uh, fraud and payments fraud industry that I'm part of. Um, one thing that I think is important to remember, um, about ai, I I'm not sure if I'm, I'm sure you have had your attempt with, uh, cha Gt or any other tools of just trying to generate emails or do all sorts of tasks.
It's almost always not enough to ask the AI agent or the LLM to do something for you without having a very clear idea of what you ask them to do. Um, and I say that because I think when you think about nefarious activity or fraud, AI is not a good fraud or scam generator. It's a great accelerator if you have a very clear idea, it can save time, it could do things, uh, automatically.
The scale is unfathomable, but it would never replace, um, honestly, a good, you know, common sense, uh, and, and human creativity. So, you know, when I think about I have seen, uh, AI generated songs or poems of stories, it, it always, it's not that good. You know, you can always tell that there's something to it.
It's the same with fraud. If you're just asking AI to come up with, with ways to do stuff, uh, it would wouldn't be perfect. It's, it's only based on things that it's seen from the corpus of whatever, you know, internet access that it has.
But you always need to actually be, it's gonna be a word phrase, but you need to be a good fraudster to tame the AI to your needs. So that's something that's important to remember on both sides, by the way. So we are still people who are leveraging, uh, technology, um, you know, bad people who, you know, bad people on one side and good people on the other side who are trying to, uh, attack and protect, uh, the tools and technology changes, but it's still not something that I think is, uh, life changing.
And in the sense of, um, the fraud types we're going to see, or unimaginable fraud attacks. Um, the scale and automation is significant, but there are tools that, you know, that can help contain that as well. Essentially, uh, I would imagine that the same way that we are monitoring for anomalies with human fraudsters, we can also kind of apply that to any kind of AI agent that somebody creates.
Uh, that, that is correct. And, uh, and, and again, important, remember, uh, human fraudsters, uh, took advantage of AI tools, maybe not agentic or language models, AI tools and automated scripts and bots. Ever since these, these things were invented, now the barrier of entry maybe is lower.
So, you know, I can now, I I I, I cannot code, I cannot build apps alone, but now I can leverage AI agents to do that for me, frauds, amateur fraudsters who never had the skillset that allows them to take advantage of, of bots or even all sorts of, uh, IP spoofing or masking technologies now have an easier access to these via AI agents. Um, so that is something that, that is somewhat changing. Uh, but at the heart of the thing in, in my opinion, um, we're not seeing fraud that we've never seen before, per se.
Um, again, scale is significant, automation is significant, but it's not, And to your point is one of the dead giveaways maybe that there always seems to be, when somebody wants you to do something that is being driven by fraud, there's always some sense of urgency in it where I'm supposed to do something unusual or different because there's some sort of crisis at hand. And, and is that kind of a dead giveaway? Uh, correct.
This is when we're talking about, uh, scamming personal like individuals and not, and when you're not trying to steal from a retailer, this is something that is, i, I I would agree with you, almost dead giveaway. You're getting a phone call or text messaging saying someone you know has been hurt and that you need to wire money somewhere, for example, um, it's, you know, the old, um, I'm, I'm, uh, you know, I'm an African prince who want to donate all my money to you, but you need to provide your bank number first, whatever, no, um, bank account number first. These things were always seem like you just get a stupid email that's not written correctly, and it's always looks bad today.
Fraudsters have tools that allows them to send very eloquent messages. They can actually have a conversation with you if they're texting with you. For example, you, you would think you're texting with a human being and they can come up with, with a lot of ways to make it seem urgent.
I will say to any of the listeners here, if you, if you are a target of a scam, a it's not your fault. It's almost as if you're being like, you know, mugged at gunpoint in the street. It's, it's out of your control.
The one thing you can do is try to, you know, manage how you react to it. Um, but, you know, we can all, all be victims, even myself as an expert, sometimes find myself almost clicking on things just because it seems too real. Uh, but a good piece of advice I've heard once is to try to get yourself out of the loop.
So if you have someone you trust, text them, tell them, Hey, this is what, you know, someone's telling me that they kidnapped my mom and they need payment like this. Does that sound right to you? Like, or I need help.
And often just even taking a step back, get you out of the loop and you can, you know, start thinking straight. Because the one thing that a lot of scam victims say, I mean, it's, it's outside of ai, but AI definitely contributed to that and skill things. One thing that scam victims always say whenever they do the thing, the second they wire the money or the second day, you know, find themself do something, it's almost always they're like, what just happened?
And as clear as daylight, I was just scammed. So try to get to that clarity a second before, and not a second after is always good. And, and, and again, one good way of doing it is, is try to take yourself out of the loop, talk to someone else, take a breather, move away from your phone, go get a glass of water or think through the things.
Um, it's, it's always helpful, uh, but, but again, of course, if you are being put in the position when you are convinced to believe that something bad is happening to someone you love, it's it's not, it's not easy you or expected to be able to control your emotions at that point. So how is fraud different for the retailer? It sounds like for consumers it's one thing, but for the retailers, what are they struggling with?
So there's a lot of different types of, of fraud for retailers that you, you might never have thought of. Uh, but you know, uh, some retailers offer you a discount when you open an account with them, um, like $10 off your know, what prevents you from creating a thousand different accounts that might Avis one, vis two might Avis three. Um, you can, you know, generate as many emails as you want and you can get a lot of freebies.
AI or Agen AI can help you generate thousands of accounts in seconds. Um, this is something that for a retailer, I mean, you'll think, oh, it's a write off, it's $10 off. It's nothing.
This could have a significant impact on a retailer's, uh, on a retailer's margin. As you know, margins are, are key to a profit profitability of the company. The entire C-suite is being comped on the margins they're making.
It sounds stupid, but $1,010 off coupons can actually move the needle on the stock price. Uh, and on executive compensation, this is a big deal, uh, for, uh, for a lot of, for a lot of companies. There's also the risk of accounts being taken over.
So, you know, some, uh, retailers offer loyalty, uh, loyalty perks and benefits. So you can, uh, accumulate points and then you can apply these to purchases. You can transfer points between different accounts.
Uh, if you are for think about hotel chains, these points can actually buy you, um, future stays in hotels. Um, there's a lot of things you can do when you take over an account. I mean, these are tangible things like loyalty points, but also untangible things like if I access your account, uh, at a Marriott, I now know your name, your address, your payment information, even if I've, even if I stole nothing per se, I have a lot of information I can then use against you or to, to, you know, to present myself as if I'm you.
And account takeovers are also something that agen AI in the wrong hands can help scale of things. At the end of the day, you need to guess a lot of passwords. Um, and with the right, uh, set of, uh, technology that helps you automate things at scale, you can do that, um, pretty easily.
Those are just two examples of where retailers can actually be impacted, um, and significantly impacted, um, um, by fraud. The, a lot of instances where the retailer is, is trying to provide you with the specific tailored experience based on who you are. If you are considered a good wanted user, if you're considered this new user, the cost of acquisition is so high, they wanna make sure they maintain, maintain you as a customer.
They might offer you unique experiences, discounts, uh, promos or whatnot. Uh, and fraud on identity fraud can significantly, uh, deter, you know, the, the purpose of, of these, uh, of these unique experiences. So retailer challenge is always to understand who they are dealing with when they see someone opening an account, trying to transact, trying to make a purchase, even when they reach out to customer support to either initiate a claim or or a complaint.
All these things can be manipulated by fraudsters. And of course, until now the scale was not significant. With agen ai, again, in the wrong hands, this could become an extremely significant problem for a lot of merchants, retailers, organizations.
Well, folks, you heard it here, we have yet to see something that is maybe uniquely different than somebody created as fraud for ai. But the level of scale is gonna be a lot different and a lot more challenging for sure. Dole, thanks for being on the show.
Yeah, of course. Thank you so much, Varga. All right.
And thank you all for watching the latest episode of the Techstrong AI Leadership Insight series. You can watch this episode and others on our website. We invite you to check them all out.
Until then, we'll see you next time.