Mastercard's fraud detection system faces an unexpected challenge as legitimate bot transactions become commonplace. The payment network processes 175 billion transactions yearly, making fraud judgments in less than a tenth of a second. Its risk framework was built over decades to block bot activity, treating automated purchases as inherently suspicious.
That logic no longer works. As e-commerce automation expands, legitimate bots now conduct routine purchases for businesses and consumers alike. Greg Ulrich, Mastercard's chief AI and data officer, acknowledged the fundamental problem at VB Transform 2026: the company must reverse course on its core security rules.
"We've built a bunch of risk rules over time that were intended to stop a bot from transacting," Ulrich said. "Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules."
The shift reflects a broader tension in payments infrastructure. Mastercard's current system treats bot behavior as a red flag because fraudsters historically used automation to probe card numbers, conduct rapid-fire transactions, and exploit rate limits. Legitimate bots behave similarly, making distinction difficult.
Mastercard must now retrain its machine learning models to differentiate between fraudulent and legitimate bot behavior. This requires new signals beyond transaction velocity and patterns. The company needs to evaluate bot identity, the legitimacy of the requester, and transaction context.
The challenge carries real stakes. Blocking legitimate bot transactions disrupts supply chains, delays business payments, and frustrates API-driven commerce. Permitting fraudulent bots costs cardholders and merchants money. Mastercard's thousands of risk rules must evolve rapidly as bot adoption accelerates across payment flows.
This transformation reveals how legacy fraud systems struggle when their core assumptions reverse. What protected consumers for decades now creates friction. Building new safeguards for a bot-driven payment world requires rethinking security
