Mastercard spent decades training its fraud system to treat bots as thieves. Now the network is rewriting those rules so bots can become customers. Greg Ulrich, the company's chief AI and data officer, told the VB Transform audience in Menlo Park on July 14 that the risk framework built to stop automated traffic must be inverted to let AI agents transact on behalf of consumers and businesses.

The score that moves the network

Every tap of a Mastercard triggers a judgment in under 100 milliseconds. The network scored 175 billion transactions last year, assigning each a zero-to-999 likelihood of fraud before passing the result to the issuing bank. Ulrich said generative AI has widened the aperture of that score: the company can now identify 300 to 400 percent more fraudulent transactions in high-risk bands without adding friction or false positives for consumers. Its Safety Net system has stopped more than 70 billion fraudulent transactions to date, and Mastercard is training its own transformer model on that transaction history as a foundation for new safety and personalization products.

AI already drives a third of services revenue

The stakes extend beyond fraud prevention. Services now account for about 40 percent of Mastercard's business, spanning marketing, fraud and security, and business intelligence. Roughly a third of those services are predicated on AI, Ulrich said, and they are growing at a materially faster clip than the rest of the portfolio. The implication is straightforward: the company's next growth engine depends on the same trust infrastructure that lets a stranger's card payment clear in a tenth of a second.

Five layers for agentic trust

Agentic commerce changes the object being secured. Instead of a single atomic transaction, a consumer or business delegates authority to an agent, creating a more complicated trust problem. Ulrich outlined five layers Mastercard has built to solve it. Identity comes first: know-your-agent registration that validates the technology and links it to the human principal. Verifiable intent comes next, designed to settle the "wrong-Nikes" problem, ensuring the agent's actions match the constraints the user actually set. The remaining three layers were not detailed in the session, but the framework makes clear that Mastercard views agentic payments as an identity and intent problem, not merely a new checkout flow.