top of page

The Agent in the Treasury: How Autonomous AI Is Reshaping B2B Payment Operations and the 2026 Fraud Risk Model

  • Writer: TrustSphere - GTM
    TrustSphere - GTM
  • Jul 2
  • 5 min read

Agentic AI's most consequential 2026 footprint inside financial services is not consumer shopping — it is the quiet move of autonomous agents into corporate treasury and accounts-payable operations. Mid-market and large corporates are now running AI agents that ingest invoices, reconcile to purchase orders, batch payment runs, initiate ACH and SEPA disbursements, and orchestrate intra-day liquidity decisions. The agent does not click "approve" once; it executes the operational rhythm of a treasury team, at machine speed, against scoped mandates set by humans who increasingly oversee at the policy level rather than the transaction level.


This is the corporate-banking analogue of the agentic-payment-protocol race playing out in consumer commerce, and it is materially more consequential. A consumer agent buying a pair of trainers is a small loss-event when it goes wrong; a treasury agent in a corporate making payment runs is a high-velocity, high-value channel whose compromise or manipulation can produce eight-figure losses in a single cycle. The traditional BEC and payment-fraud playbook — fake invoice, manipulated bank details, social-engineered approver — does not disappear in this world; it adapts, and the agent becomes the new locus of compromise rather than the human approver.


For TrustSphere clients on the corporate-banking and commercial-payments side, the implication is that 2026's payment-fraud risk model has to include the agent as a first-class actor: a non-human authoriser whose mandate, behaviour and decision logs need to be understood, instrumented and challenged with the same rigour as the human controls it has begun to replace. Banks that approach this only by tightening payment-channel controls will miss the larger architectural shift.


Regulatory and Market Context


The supervisory direction on agentic activity in corporate treasury is still forming, but the relevant frameworks are already in motion. The UK's "failure to prevent fraud" offence under the Economic Crime and Corporate Transparency Act, the FCA and PRA's expectations around operational resilience and material outsourcing, and the EBA's guidance on outsourcing and ICT third-party risk all apply to agentic deployments — whether or not the agent is technically a "supplier" in the narrowest sense. Boards and risk committees are being pressed to treat autonomous-agent activity inside finance functions as a material operational risk, with proportionate governance, mandate design and monitoring.

The wider market context is fast-moving. ERP and treasury-management platforms have built native agent capabilities into their 2026 releases, payment infrastructure providers and banks have launched agent-friendly APIs, and the corporate appetite to compress treasury and AP headcount is real. The risk-management lag is also real: most corporates running agents in treasury operations have not redesigned their fraud and payment controls around the new actor, and rely on policies and oversight structures that were written for a human-only operating model.


What the Data Is Showing


TrustSphere's 2026 corporate-payments operations review across mid-market and large enterprises shows that agent-driven payment activity is concentrated in invoice-to-pay, expense management, intra-day liquidity moves and routine supplier disbursements, with adoption rising fastest in the segments where AP and treasury teams were already under headcount pressure. The benchmark also shows clear bifurcation in control maturity: a small leading group has redesigned controls around the agent as a non-human authoriser, and a much larger group is operating agents against legacy human-approver controls.


Where agent operations have been compromised — through manipulated source data, prompt-injection-style attacks against the orchestrator, or over-broad mandate design — the losses cluster in classic BEC-adjacent patterns: changed beneficiary details on a recurring supplier, an out-of-pattern but credible-looking disbursement, a batched payment with one anomalous line. The agents themselves accelerate the throughput of these losses dramatically; what an attacker might have extracted across days of social engineering can now be lost in a single payment cycle if the agent has the mandate to execute and the control plane has not adapted.


Implications for Financial Institutions


The control surface for agent-led treasury and AP operations is mandate design, behavioural monitoring and segregation of duties between agents, not channel hardening alone. The corporates and banks getting this right are designing narrowly scoped, time-bound, value-bound mandates; instrumenting agent behaviour as a first-class telemetry stream (with anomaly detection on payment patterns, beneficiary changes and batch composition); and requiring a separate, independent control point — a second agent, a human, or both — to clear high-risk operations. The reference architecture treats the agent as an authoriser whose decisions must be challengeable on the same evidentiary basis as a human's.


For banks providing services to corporates running treasury agents, the diligence model has to evolve in parallel. KYB and credit decisions need a clearer view of which corporates are operating autonomous agents against which mandates, the bank-side fraud and payment-anomaly engines need agent-aware signals in addition to user-behaviour signals, and the partnership conversation with corporate clients needs to include explicit guidance on mandate design, anomaly thresholds and exception handling. The advantage in 2026 sits with institutions that have stopped treating agent activity as "just another API client" and started treating it as a new class of authoriser whose risk profile, behavioural baseline and control requirements differ from anything in the pre-agent operating model.


Conclusion


The arrival of autonomous agents in corporate treasury and accounts-payable is the most consequential 2026 development in B2B payment fraud risk, and the institutions winning against it are the ones who have stopped retrofitting human-era controls and started designing for the agent as a non-human authoriser. Narrow mandates, instrumented behaviour, segregation of duties between agents, and a bank-side risk model that recognises agent activity as a distinct authoriser class together form the defensible 2026 posture — and the corporates and banks that build it now will avoid the high-velocity payment-fraud incidents that agent-led operations make uniquely possible.


Suggested Next Steps


  • Design narrowly scoped, time-bound and value-bound agent mandates for treasury and AP operations, and treat the agent as a non-human authoriser whose decisions must be challengeable on the same evidentiary basis as a human's.

  • Instrument agent behaviour as a first-class telemetry stream, with anomaly detection on payment patterns, beneficiary changes and batch composition, and feed those signals into both corporate fraud controls and the bank's payment-anomaly engines.

  • Enforce segregation of duties between agents — a second agent, a human approver, or both — for high-risk operations such as new beneficiary set-up, large or out-of-pattern disbursements and intra-day liquidity moves.

  • Update KYB, corporate-banking diligence and the supervisory conversation to include autonomous-agent operations as a material operational risk under "failure to prevent fraud", operational resilience and outsourcing-and-ICT third-party frameworks.


Sources: UK Economic Crime and Corporate Transparency Act "failure to prevent fraud" offence; FCA and PRA expectations on operational resilience and material outsourcing; EBA guidelines on outsourcing arrangements and ICT third-party risk; 2026 vendor releases on agentic capability in ERP, treasury-management and accounts-payable platforms; FBI Internet Crime Complaint Center (IC3) BEC reporting; TrustSphere corporate-payments operations review (2026); TrustSphere Risk Index — April 2026.


TrustSphere Risk Index — Vendor Spotlight: Modern Treasury


Modern Treasury scored 63% in the April 2026 TrustSphere Risk Index in the B2B Payment Operations & Agentic Treasury category, ranking in the top tier for instrumented, programmable payment operations across bank, ACH, RTP and SEPA rails.


The platform's 2026 release extended its native support for autonomous-agent activity by combining programmable payment workflows with mandate-aware approval logic, segregation-of-duties controls and operational telemetry that lets a corporate or bank treat agent decisions as a first-class, instrumented authoriser stream.


For institutions building a defensible control surface for agentic treasury and accounts-payable operations, Modern Treasury's combination of programmable payment workflows, approval-graph design and operational visibility is increasingly cited as a practical way to give the AI agent in the treasury room a mandate, a leash and an audit trail.


TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai

 
 
 

Comments


Recommended by TrustSphere

© 2024 TrustSphere.ai. All Rights Reserved.

  • LinkedIn

Disclaimer for TRUSTSPHERE.AI

The content provided on the TRUSTSPHEREAI website is intended for informational purposes only. While we strive to provide accurate and up-to-date information, the data and insights presented are generated from a contributory network and consolidated largely through artificial intelligence. As such, the information may not be comprehensive, and we do not guarantee the accuracy, reliability, or completeness of any content.  Users are advised that important decisions should not be made based solely on the information provided on this website. We encourage users to seek professional advice and conduct their own research prior to making any significant decisions.  TruststSphere Partners is a consulting business. For a comprehensive review, analysis, or support on Technology Assessment, Strategy, or go-to-market strategies, please contact us to discuss a customized engagement project.   TRUSTSPHERE.AI, its affiliates, and contributors shall not be liable for any loss or damage arising from the use of or reliance on the information provided on this website. By using this site, you acknowledge and accept these terms.   If you have further questions,  require clarifications, or requests for removal or content or changes please feel free to reach out to us directly.  we can be reached at hello@trustsphere.ai

bottom of page