ai agent fraud in 2026: what the adjudicated record actually shows
Banks are warning that AI shopping agents will get you scammed. The AI-agent fraud that regulators have actually charged runs the other way: the agent itself was the fraud.
A group of major banks spent September 2026 warning that letting an AI agent shop for you could get you scammed. NatWest, Bank of America, Capital One and others flagged agents that request card details directly, steer buyers toward weaker payment protections, or get impersonated outright [source].
The warning treats AI agent fraud as a future risk: real agents, turned against the people who use them. That is the obvious reading, and it is only half the story.
The AI agent fraud that regulators have actually charged runs the other way. In every case brought so far, the agent was not weaponized. The agent did not exist. The fraud was selling an autonomous AI agent that was, in fact, people doing the work by hand.
What ai agent fraud means
AI agent fraud is fraud that turns on the claim that software acts autonomously for a user. It has two directions: an agent used against a victim, and an agent that is itself the lie, sold as autonomous while humans do the work. Only the second direction has produced charges.
The proof: the agent that ran on people
The cleanest case is the shopping agent itself. On 9 April 2025 the DOJ charged Albert Saniger, founder of the AI shopping app Nate, with securities and wire fraud; the SEC filed a parallel civil action. Nate pitched an app that could “transact online without human intervention”, but the indictment alleges its actual automation rate “was effectively zero percent” and that hundreds of contractors in a Philippines call center completed the purchases by hand. TIN’s case file on the Nate charges verifies both figures against the DOJ release and the SEC litigation release. Saniger raised over $40 million on the AI claims (the charges are allegations in a pending case).
The same shape appears in the drive-thru. The SEC found that Presto Automation’s voice AI “required human agent intervention, including entering the order, in all instances” on its original version, while filings claimed it “eliminat[es] human order taking” and reported 95% to 99% automation. Even the advanced 2023 pilot needed a human on roughly 70% of orders. TIN’s Presto case file verifies the settled order against the primary filing.
And in investing, the SEC charged advisers for AI that was not running the money. Rimar Capital raised nearly $4 million for a platform “falsely described as having an AI-driven platform for trading securities” that had no such application, settling for $310,000 in penalties, per TIN’s Rimar case file. The SEC’s first two AI-washing settlements, against Delphia and Global Predictions, closed at $400,000 combined for capabilities that were advertised but not used, per TIN’s Delphia case file.
Has anyone been prosecuted for AI agent fraud?
Yes, and the pattern is consistent: every case punished a claim of autonomy the product could not back, never an agent that autonomously did harm. The chargeable fraud so far is the gap between “our AI agent does this” and what actually did it.
| Case | The autonomy claim | What actually ran it | Outcome |
|---|---|---|---|
| Nate (DOJ/SEC, 2025) | Buys online “without human intervention” | Contractors in a Philippines call center | Securities + wire fraud charges; $40M+ raised |
| Presto (SEC, 2025) | “Eliminat[es] human order taking”, 95% to 99% automated | Off-site agents on nearly every order | Cease-and-desist order |
| Rimar Capital (SEC, 2024) | AI-driven securities trading platform | No such trading application | $310,000 in penalties |
| Delphia + Global Predictions (SEC, 2024) | AI/ML trained on client data; “expert AI-driven forecasts” | Data not used; forecasts nonexistent | $400,000 combined |
What the bank warning misses
The banks are right that a real agent is a new attack surface. John Lewis reported that searches from AI agents rose to 2.5% from 0.3% in a year, so the surface is growing fast [source]. But a buyer worried only about agents being compromised is guarding one door while the adjudicated fraud walks through the other: the agent that was oversold in the first place.
Both risks reduce to the same unverifiable claim. You cannot see the automation. “AI agent” is a statement about what happens after you hand over the task, and the four cases above are what it looks like when that statement is false and nobody checked.
The bottom line
The defense is identical for a fake agent and a compromised one: refuse to treat autonomy as a fact until it is measured. Ask any vendor selling an AI agent for its automation rate in writing, with the measurement window and who counts as a human in the loop. Presto’s filings reported 95% to 99% while the real figure was the reverse.
A number a vendor will not put in writing is a number a regulator may later measure for them.
Sources
- 01Insurance Journal (Reuters), “Banks Warn AI Shopping Bots Raise Scam, Fraud and Data-Privacy Risks”, 2026-09-23. https://www.insurancejournal.com/news/national/2026/09/23/886472.htm
- 02U.S. Attorney’s Office, SDNY, “Founder Of AI Shopping App ‘Nate’ Charged In Scheme To Defraud Investors” (25-082), 2025-04-09. https://www.justice.gov/usao-sdny/pr
- 03U.S. Securities and Exchange Commission, “SEC Charges Founder of AI Shopping App Nate with Fraud” (Litigation Release No. 26282), 2025-04-11. https://www.sec.gov/litigation/litreleases/lr-26282
- 04U.S. Securities and Exchange Commission, “In the Matter of Presto Automation Inc.” (Securities Act Release No. 11352), 2025-01-14. https://www.sec.gov/files/litigation/admin/2025/33-11352.pdf
- 05U.S. Securities and Exchange Commission, “SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of AI”, 2024-03-18. https://www.sec.gov/newsroom/press-releases/2024-36
- 06U.S. Securities and Exchange Commission, “In the Matter of Rimar Capital USA, Inc., et al.” (Order Release No. 33-11316), 2024-10-10. https://www.sec.gov/enforcement-litigation/administrative-proceedings/33-11316-s
Questions
What is ai agent fraud?
AI agent fraud is any fraud that runs through the claim that software acts autonomously on a user's behalf. It has two directions: an agent used to defraud someone, which banks are warning about, and an agent that was itself the fraud, where a company sold autonomous AI that was actually run by humans. So far only the second direction has produced charges and penalties.
Has anyone been charged for AI agent fraud?
Yes, but for selling fake agents, not for weaponizing real ones. The DOJ and SEC charged the founder of the AI shopping app Nate over an automation rate the indictment calls 'effectively zero percent', and the SEC settled AI-washing cases against Presto, Rimar Capital and Delphia. Every one punished a claim of autonomy that the product could not back.
Are AI shopping agents safe to give my card details to?
Treat it as unproven. A 2026 group of banks including NatWest, Bank of America and Capital One warned that AI shopping agents can request card details directly and steer users toward weaker payment protections. Their proposals to policymakers include mandatory disclosure whenever an agent is involved in a transaction.
This is analysis, not a verified outcome. It carries no verification badge and never will. The proof lives in the case files, where every figure is checked against the public record and the method is printed on the page.