top of page

When Shopping Agents Open Accounts: Autonomous AI Is Industrialising Synthetic and Duplicate Sign-Ups in 2026

  • Writer: TrustSphere Network
    TrustSphere Network
  • Jul 14
  • 5 min read

Fake and duplicate accounts are an old problem with a new engine. Fraudsters have always wanted more accounts than they are entitled to — to farm sign-up incentives, launder value, evade bans, or stage later attacks — but doing so at scale meant either laborious manual effort or brittle bot scripts that defenders could fingerprint and block. The economics of mass account creation depended on how cheaply an attacker could look like many different plausible new customers.


In 2026 agentic AI has changed those economics. Autonomous shopping and browsing agents can now navigate a sign-up flow the way a person would: reading the page, filling forms, solving light challenges, varying their behaviour, and completing onboarding across many "identities" without the rigid, detectable signature of a traditional bot. When an agent can realistically impersonate a first-time human customer end to end, the cost of standing up a synthetic or duplicate account collapses, and the volume an attacker can generate rises sharply.


For merchants and financial institutions this reopens a threat that many considered largely contained. Sign-up bonuses, referral schemes, free trials and new-customer pricing all assume that a new account represents a genuinely new person, and that assumption is exactly what agentic account creation defeats. The accounts arrive looking human because a human-like agent made them, blurring the line between a real customer onboarding and a machine manufacturing plausible identities at scale.


Regulatory and Market Context


The rise of agentic commerce is prompting the payments ecosystem to define how autonomous agents should identify and authenticate themselves, with the card networks and standards bodies working toward frameworks for agent-initiated activity. Visa and Mastercard's work on agentic and delegated commerce, alongside PSD2/SCA principles, points toward a future in which agents act under scoped, attributable authority rather than by impersonating a human — but onboarding and account-creation flows were largely designed before agents existed, and remain a soft target in the meantime.


The market reading is that account creation is becoming an agentic battleground where the old signals of automation no longer hold. Volume-based and simple-bot defences struggle against agents that behave like people, so the emphasis shifts to identity assurance, device and network intelligence, and detecting the coordination between accounts rather than the crudeness of any single sign-up. Distinguishing a genuine new customer from a machine-made one becomes the central control for any programme that rewards being new.


What the Data Is Showing


TrustSphere's engagement data shows agentic account creation revealing itself less in any single sign-up than in the relationships between many. Bursts of new accounts sharing subtle infrastructure, device or behavioural fingerprints, onboarding completed with human-like but improbably efficient timing, and clusters of "new" customers that immediately converge on the same incentive, referral or promotional benefit recur across merchants regardless of how convincingly each individual account was created.


The behavioural markers are those of coordination and intent rather than obvious automation. Accounts that pass individual bot checks yet cluster around shared signals, synthetic or lightly-varied identity details reused across sign-ups, and a population of new accounts whose only activity is harvesting a sign-up benefit before going dormant together separate machine-manufactured accounts from genuine onboarding — even when each account, viewed alone, looks like a plausible human customer.


Implications for Financial Institutions


The practical implication is that account-creation defences must move from spotting crude bots to assessing identity and coordination. Institutions and merchants should strengthen identity assurance at onboarding, lean on device, network and behavioural intelligence that survives an agent's human-like navigation, and analyse new accounts as a connected population rather than in isolation, so that clusters converging on the same incentive surface even when each sign-up passes on its own. Incentive and referral programmes in particular need controls that assume some share of new accounts are agent-made.


There is a design dimension that follows the direction of agentic commerce. Rather than trying only to keep every agent out, institutions can prepare for a world in which legitimate agents identify themselves under scoped, attributable authority, and treat unattributed, human-impersonating sign-ups as the higher-risk case. Building onboarding that can recognise and accommodate declared agents, while flagging agents pretending to be first-time humans, positions firms for agentic commerce without leaving new-customer economics exposed to machine-scale abuse.


Conclusion


Agentic AI has collapsed the cost of creating synthetic and duplicate accounts, letting autonomous agents impersonate first-time human customers convincingly enough to defeat the assumption that a new account means a new person. The individual sign-up looks human because a human-like agent made it; the fraud shows in the coordination between accounts and their single-minded pursuit of new-customer benefits. Firms that respond well will strengthen identity assurance at onboarding, analyse new accounts as a connected population, protect incentive and referral programmes against machine-scale abuse, and prepare for a future in which legitimate agents declare themselves rather than pretend to be people.


Suggested Next Steps


  • Strengthen identity assurance at account creation with device, network and behavioural intelligence that survives human-like agent navigation.

  • Analyse new accounts as a connected population, surfacing clusters that share infrastructure or converge on the same incentive.

  • Harden sign-up bonus, referral and free-trial programmes against machine-scale duplicate and synthetic account abuse.

  • Prepare onboarding to recognise legitimate agents acting under scoped, attributable authority while flagging agents impersonating first-time humans.


Sources: Visa and Mastercard initiatives on agentic and delegated commerce; PSD2 and Strong Customer Authentication principles; industry reporting on synthetic identity and new-account fraud; card-scheme guidance on account-creation and incentive abuse; TrustSphere Risk Index — April 2026.


TrustSphere Risk Index — Vendor Spotlight: Socure


TrustSphere's April 2026 Risk Index, Socure scored 65% in the Identity Verification & Synthetic Identity Detection category, reflecting strong identity-graph capability weighed against the challenge of scoring agent-driven sign-ups that are engineered to look like plausible new humans.


Socure's core strength is identity verification and synthetic-identity detection drawing on a broad graph of identity signals, which is directly relevant to the central control in agentic account creation: telling a genuinely new person from a manufactured or duplicated identity. For institutions defending onboarding and incentive programmes, robust identity assurance at the point of account creation is the layer that agentic automation is specifically trying to get past.


The watch-item is that agentic account creation shows itself as much in coordination between accounts as in any single identity, so identity verification works best alongside device, network and behavioural intelligence and population-level analysis that catches clusters passing individual checks.


As legitimate agents begin to act under declared, scoped authority, verification will also need to accommodate attributable agent activity rather than treating all automation as hostile. Buyers should weigh how identity assurance integrates with device intelligence and connected-account analytics, treating it as a foundational layer rather than a standalone answer to agentic sign-up abuse.


TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai

 
 
 

Comments


Recommended by TrustSphere

© 2024 TrustSphere.ai. All Rights Reserved.

  • LinkedIn

Disclaimer for TRUSTSPHERE.AI

The content provided on the TRUSTSPHEREAI website is intended for informational purposes only. While we strive to provide accurate and up-to-date information, the data and insights presented are generated from a contributory network and consolidated largely through artificial intelligence. As such, the information may not be comprehensive, and we do not guarantee the accuracy, reliability, or completeness of any content.  Users are advised that important decisions should not be made based solely on the information provided on this website. We encourage users to seek professional advice and conduct their own research prior to making any significant decisions.  TruststSphere Partners is a consulting business. For a comprehensive review, analysis, or support on Technology Assessment, Strategy, or go-to-market strategies, please contact us to discuss a customized engagement project.   TRUSTSPHERE.AI, its affiliates, and contributors shall not be liable for any loss or damage arising from the use of or reliance on the information provided on this website. By using this site, you acknowledge and accept these terms.   If you have further questions,  require clarifications, or requests for removal or content or changes please feel free to reach out to us directly.  we can be reached at hello@trustsphere.ai

bottom of page