Riskified announced Agent Identity Risk Intelligence on October 8, a new capability designed to identify the AI personal assistant behind an order or a customer service request, connect it to a real consumer identity, and return a real-time risk signal, according to the company's announcement carried by Business Wire.

The NYSE-listed digital fraud and risk intelligence company is extending its AI intelligence platform to a new actor in commerce: the consumer's own personal AI agent. Assistants such as Meta's Muse, Instinct, and dots in ChatGPT are moving from product discovery to action. They check out, keep working after the user closes the app, compare prices across sites by design, and proactively hunt for price-drop refunds and no-fee returns. Behaviors that were occasional for human shoppers can become routine when an agent does them every day for every order. The question merchants face is no longer whether an interaction is automated, but who the automation acts for — and whether what it does on that person's behalf is something the merchant would accept from the person themselves.

What Agent Identity Risk Intelligence does

Agent Identity Risk Intelligence recognizes when an order or customer service request arrives from a personal AI assistant. Where an assistant or commerce platform provides a verified agent credential, Riskified accepts it. Either way, the system connects the request to the person behind it, drawing on network knowledge built from billions of orders, claims, and chargebacks, according to Riskified's release.

Recognition will first be available to merchants on Shopify, where orders placed through Meta's Muse already arrive tagged as agent-originated, and will extend to other platforms as agent identification standards take hold. When an assistant acts for a shopper, much of the device and browser telemetry merchants have relied on goes missing. In those cases, Agent Identity Risk Intelligence leans on identity and network history plus the behavior of the agent itself, which signals intent.

For post-checkout interactions such as refund requests, Agent Identity Risk Intelligence can engage the assistant directly — confirming details or applying step-up friction that a legitimate assistant can satisfy and a script cannot. The result is a risk decision that reflects both the identity behind the agent and the agent's own behavior, according to the company's announcement.

Authenticated is not the same as trusted

New standards such as the Personal Agent Protocol — introduced this month by Sierra and Meta together with Shopify, Stripe, Walmart, and others — give merchants a secure way to confirm that an AI assistant is authorized to act on an account. Authorization, however, answers only the first risk question. An agent authorized through a stolen account is still account takeover. An agent authorized through a throwaway fake account is still first-order promotion abuse. And an agent authorized by a refund-as-a-service ring, whose members hold real accounts and grant real permissions, is still fraud — now running at machine speed through support channels built for humans, according to Riskified.

Refund fraud rings already sell scripted claims of empty boxes and missing deliveries against retailer support teams. In April 2026, a U.S. federal court sentenced eleven co-conspirators of the Artemis Refund Group, which ran refund fraud as a subscription business placing thousands of fraudulent orders against major retailers. Hand those schemes a tireless, always-on AI agent, and the scalability of refund fraud changes drastically.

Assaf Feldman, Riskified's chief strategy officer for technology and co-founder, told the company's release that agent protocols give merchants a secure way to let a customer's assistant act for them but do not answer whether that customer should be trusted — and that Riskified sits on top of those protocols to answer the harder question, using what its identity engine already knows about the person behind the agent, so merchants can welcome a good customer's assistant, decline a bad actor's, and spot the moment a real customer's agent starts doing something the customer never would.

Where merchants will see the signals

Agent Identity Risk Intelligence will ship in three surfaces. Riskified Decision Studio will support policies by agent type — auto-approving low-risk agent orders from verified identities while routing high-risk agent-originated refund claims for review. Control Center will report approval, fraud, and claim-abuse rates for agent-originated traffic alongside the rest of the business, broken out by assistant where one can be identified. And the same identity risk category will flow into Riskified's Zendesk integration, so both human agents and Zendesk's Specialized AI Agents can see when a refund or return request arrives through a consumer AI assistant, according to the announcement.

Agent Identity Risk Intelligence will be available through Riskified's existing APIs and the AI Agent ApproveMCP server on AWS Marketplace. A limited beta for enterprise merchants opens in December 2026, with general availability expected in 2027, according to Agile Brand Guide's coverage of the October 8 announcement.

The launch continues a position Riskified has held since August 2025, when it first introduced AI Agent Intelligence: rather than inserting itself between merchants and the platforms building agentic checkout, it invests in the layer every protocol, assistant, and support channel ultimately depends on — knowing who is on the other side of the interaction. The theme has momentum. Earlier genznewz coverage explored the "know your agent" race as agent identity became a competitive front, argued that agent identity security is the agent era's next race, and noted that holiday shoppers are already letting AI hunt for deals this season. Agent Identity Risk Intelligence is what happens when the fraud industry starts grading that behavior at scale.