マスターカード、ボットによる不正購入の増加を警告
本文の状態
日本語全文を表示中
詳細モードで約11分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
VentureBeat AI
マスターカードはボットを単なる脅威として扱う従来のリスク管理から、信頼できる取引主体として扱う枠組みへ転換し、生成AIによる検知精度の向上とエージェント型決済への対応を表明した。
AI深層分析を開く2026年8月3日 23:05
AI深層分析
キーポイント
リスク管理パラダイムの転換
マスターカードは長年ボットを「止めるべき脅威」として扱ってきたが、現在では信頼できる取引主体として扱う方針へ転換し、リスクフレームワークとルールの見直しを迫っている。
生成AIによる検知能力の飛躍
新技術の導入により、高リスク帯域における不正トランザクションの検出率が300〜400%向上し、顧客への摩擦や誤検知を増やすことなく安全性を確保している。
エージェント型決済への対応
AI エージェントが消費者に代わって取引を行う「アジェンティック・コマース」の普及に伴い、信頼性の構築がスケーリングの鍵となることを強調した。
アジェンティック・コマースにおける5層防御の構築
マスターカードは不正対策として、ID(KYA)、検証可能な意図、制御、実行(Agent Pay)、インテリジェンスという5つの層を設けた。これにより、消費者や企業が権限を委譲する複雑な取引でも信頼性を確保できる。
B2B調達エージェントが次なる成長の鍵
消費財向けから始まり、在庫管理や予算制約を理解する自律的なB2B調達エージェントへの展開が大きな機会となる。企業間での信頼構築には、IDや意図に関する明確な標準化とスケーラブルなインフラが必要である。
重要な引用
"We've built a bunch of risk rules over time that were intended to stop a bot from transacting. Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules."
"What's going to enable AI to continue to scale is not the capabilities of the agents, it's how much we trust those agents to do on our behalf..."
"The only way it's going to work with trust is if we can identify what was the intent, what are the behaviors, what are the constraints that were intended in that transaction."
"You need clear standards for identity, you need clear standards for intent, you need these to work across."
編集コメントを表示
編集コメント
決済業界におけるAIの役割が、単なる防御手段から積極的な取引主体への転換を遂げる重要な転換点である。マスターカードの戦略変更は、今後普及が進む自律型エージェント経済における信頼基盤の再構築を示唆している。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Mastercard の決済がタップされるたびに、同社のネットワークは不正取引の可能性を判断する時間が 0.1 秒未満しかありません。昨年は約 1750 億件の取引でこの判断を下しました。
しかし今、その判断の対象となる「買い手」の姿が変わりつつあります。Mastercard の最高 AI・データ責任者である Greg Ulrich は、7 月 14 日にメンローパークで開催された VB Transform 2026 で、その変化がもたらす影響を語りました。
「これまで私たちは、ボットによる取引を阻止するためのリスクルールを積み重ねてきました。しかし今後は、ボットに取引を許可する体制へと転換する必要があります。つまり、リスク管理の枠組みやルール自体を見直す必要があるのです」と Ulrich は述べました。
Ulrich 氏は 11 年前、自身が所属していた分析会社が Mastercard に買収されたのを機に入社しました。入社初日から同社の「信頼」の重要性に強く感銘を受けたといいます。
「取引先と面識がない店舗でも決済を受け入れられるのは、この信頼があるからです。また、消費者として安全かつ確実な方法で取引を行い、支払いが確実に完了することを保証できるのも、この仕組みのおかげです。万が一トラブルが起きた場合にも、紛争処理や解決のための安全なルートが存在します」と彼は説明しました。
1750 億件の取引を、100 ミリ秒未満のスコアリングで判断
彼は聴衆に、それぞれの通話内容を詳しく解説しました。「マスターカードで商品やサービスの支払いをする際、私たちはその取引に対してスコアを付与しています」と同氏は語りました。「不正か正当かを判断し、0 から 999 のスコアを付与するまでには、100 ミリ秒未満しかありません。このスコアは発行銀行に引き継がれます」。
生成 AI は、このスコアが捉えられる範囲を広げました。「新しい技術により、より多くのデータや文脈を取り込めるようになりました。その結果、高リスク帯域における不正取引の検出数が 300% から 400% も増加していることが分かっています」とウルリッヒ氏は述べています。この増加分は、消費者にとっての手間や誤検知(偽陽性)を増やすことなく実現されたものです。同氏の説明によると、マスターカードの「セーフティネット」システムはこれまでに 700 億件以上の不正取引を阻止してきました。また、マスターカードは自社の取引データを用いて独自のトランスフォーマーモデルを構築しており、これが新たな安全性、セキュリティ、パーソナライゼーションソリューションの基盤となっています。ベンチャービートの「Beyond the Pilot」ポッドキャストでは、今年早些にこの生産向け不正検出スタックの詳細な分析が行われました。
サービス事業の 3 分の 1 がすでに AI で稼働している
不正対策の枠を超え、ビジネス上の stakes も大きくなっています。ウルリッヒ氏によると、マスターカードの事業のうち約 40% がマーケティング、不正・安全・セキュリティ、ビジネスインテリジェンスといったサービスに依存しています。「そのうち 3 分の 1 は AI に依存しており、他の分野よりもはるかに速いペースで成長している」と同氏は語っています。
あるセッションで彼は繰り返しこう述べました。「AI がさらにスケールし続けるために必要なのは、エージェント自体の能力ではなく、消費者や企業、金融機関として、あるいはそれ以外の立場において、私たちがそのエージェントにどれほど信頼を置けるかです。」
エージェントとネットワークの間には5つの層が存在します。
アジェンティック・コマース(代理取引)は、守るべき対象そのものを変えます。ウルリッヒ氏は「単一の原子取引、『何かを買って』という指示を出すのではなく、実際には権限を委譲していることになります。消費者が権限を委譲し、企業が権限を委譲するのです。それが起きると、取引ははるかに複雑になります」と説明しました。そして信頼には前提条件が必要です。「信頼を持って機能させる唯一の方法は、その取引において意図されたもの、つまり何を目指していたのか、どのような行動が取られたのか、どのような制約が設けられていたのかを特定できることです。」
ウルリッヒ氏は、この課題に対抗するためにマスターカードが構築した5つの層について解説しました。まず重要なのはアイデンティティです。「消費者が誰かだけでなく、エージェントが誰かも理解し、両者を結びつける必要があります。KYA(Know Your Agent:あなたのエージェントを知る)を実現し、それが正当な技術であり、正当なエージェントであることを検証します。そして、それを当社のシステムに登録するのです。」
検証可能な意図は「間違ったナイキ」の問題を解決します
次に重要なのは、検証可能な意図です。これは取引に付随する、元の指示内容の改ざん防止 cryptographic レコード(暗号化記録)です。「サイズ 12 のナイキブラックを注文したのに、最終セール品として購入し返品不可になった場合、その情報が当初の指示に含まれていなかった」といったケースでも、バックエンド側で客観的かつ明確に確認できる仕組みがあります」と彼は説明しました。
3 つ目の層は「制御」です。エージェントがどの業者から購入可能か、上限はいくらか、どのような制約があるかを定義します。実行は Mastercard Agent Pay を通じて行われ、ここにはトークン化、認証、および組み込まれた受入フレームワークが含まれています。Ulrich 氏によると、この仕組みはすでに Microsoft、OpenAI、Google などと連携してローンチされています。
5 つ目の層は「インテリジェンス」です。リスクルールや、パーソナライズされた推奨のために「同意または許可された形で洞察へのアクセス権を与える」インサイトトークン、そして Recorded Future を活用した監視機能(システム内の脅威アクターを特定)が含まれます。
最大の狙いは、予算管理可能な調達エージェントの実現です。
消費者向け購入はアジェンティック・コマースの始まりでしたが、Ulrich 氏はその先にある B2B 調達こそがより大きな機会だと指摘しました。具体例として、常時稼働する生産ラインを維持したい製造業者が挙げられます。この場合、在庫レベルを管理し、在庫切れを検知して自動補充を行い、予算と承認済みサプライヤーの知識を持つエージェントが必要です。「こうした機能を可能にするには、同様の取引に対して前述の 5 つの層すべてが必要になります」と彼は述べています。
企業間での運用を可能にすると、相互信頼が必要な関係者が指数関数的に増えます。「明確なアイデンティティの基準と、明確な意図の基準が必要です。これらが横断して機能し、調達エージェント、サプライヤーエージェント、銀行エージェントが自律的に連携できるようになるには、大規模な信頼インフラが不可欠です。」
強力な新モデルでも、セキュリティ対策の基本は変わらない
Mastercard は Anthropic の Mythos モデルや OpenAI の GPT-5.5-Cyber など、Project Glasswing の初期段階から参加し、これらのモデルを活用してきました。Ulrich 氏は「両方のモデルが示したことは、以前は検出が難しかった生態系内の新たな脆弱性を発見する能力であり、これは新しい『動き』ではなく、新しい『ツール』だ」と述べています。
社内ではセキュリティ責任者がこの取り組みを主導しています。専任チームが最も重要な資産に優先順位をつけ、定期的にモデルでスキャンし、深刻度に応じて高・中・低のレベルで見つかった問題を追跡します。また、同じ技術を用いてパッチ対応も実施しています。Ulrich 氏は「このアプローチはすでに社外にも拡大されており、Mastercard は他社にも同様のアーキテクチャとパッチング手法を提供できるよう取り組んでいる」と説明しました。
14 ヶ月を経て Mastercard が変えたい点
「ガードレールやセキュリティといった要素は、すべてフロントエンドに組み込まれている必要があります。これらは後からバックエンドに追加するものにしてはいけません。これが教訓の第一です。第二に、スケーラビリティを考慮した運用が不可欠であり、第三に、観測可能性と説明責任も知能そのものと同等に重要です」とウルリッヒ氏は語り、マスターカードで内部構築を進める過程でチームが学んだ点を挙げました同社は彼が「アジェンシー・ファクトリー」と呼ぶものを構築しました。これは各エージェントごとにコンプライアンスや観測可能性、ガードレールを後付けするのではなく、最初から組み込まれたオペレーティングシステムです。モデルのドリフト(性能の低下)は、以前は専任チームが手動で追跡していましたが、現在は同ファクトリーに自動化されています。
ある聴衆者から「注意すべき点」について質問されたウルリッヒ氏は、パイロット段階から本番環境への移行における落とし穴を甘く見ない姿勢を示しました。「拡張を進めながら、その後にガードレールを追加しようとするなら、すでに構築してしまった後でそれを追加するのは失敗に終わるでしょう」と彼は断言しました。
マスターカードは昨年、4,000 名のコンサルタント向けに一連のエージェントを構築しました。対象は深層調査、テキストから SQL への変換、Excel 操作、PowerPoint 作成などです。ウルリッヒ氏によれば、これらはマスターカードが必要とするレベルでは当時存在しませんでした。もし今日から同じことを始めるとすれば、根本的に異なるアプローチで構築するでしょう。「14 ヶ月前にものを構築した時点で、すでに基本アーキテクチャやアプローチを見直すことになるなんて予想していませんでした」と彼は述べました。
アジェンシー・アイデンティティは KYB(Know Your Business)と KYC(Know Your Customer)に加わる
ウルリヒが次に市場の焦点となるべきだと見ているのは、ID(アイデンティティ)レイヤーです。『Agent Pay』では、従来の e コマースと同様に消費者を認証し、そのエージェントを特定の個人に紐づけています。「この枠組みの外側でも、エージェントが誰なのかを特定し、消費者と結びつけるためのオープンスタンダードが生まれるでしょう」とウルリヒは語ります。「そして、それを検証可能な意図(verifiable intent)と結びつけることが可能になります。」
VentureBeat が 2026 年 6 月に実施した『Pulse』調査でも、同じ課題が浮き彫りになっています。対象となった 107 の企業関係者のうち、各エージェントに個別のスコープ付き管理 ID を付与しているのはわずか 32%にとどまり、エージェント用 ID プロダクトを検討段階に含めているのは 12%だけでした。
ウルリヒ氏は、ID が「最も成長が速いエコシステムの一角」であると指摘。マスターカードはここ数年、有機的・非有機的な両方の手段で展開を続けており、現在では従来の KYB(Know Your Business)や KYC(Know Your Customer)に加え、「エージェント ID」の領域にもその活動範囲を広げています。ネットワークからボットを排除するためのリスクルールは、過去 20 年以上にわたり AI をこれらの取引に応用してきた結果生まれたものです。今、マスターカードが導入しようとしているエージェントに対応するルール改訂は、昨年に 1,750 億件のトランザクションを処理した同じネットワーク上で既に進行中です。
原文を表示
Every time a Mastercard gets tapped, the network has less than a tenth of a second to judge how likely the purchase is to be fraudulent. It made that call across 175 billion transactions last year. Now the buyer on the other side of that judgment is starting to change, and Greg Ulrich, the company's chief AI and data officer, spelled out the consequence for the VB Transform 2026 audience in Menlo Park on July 14. "We've built a bunch of risk rules over time that were intended to stop a bot from transacting," Ulrich said. "Now we need to enable the bot to transact, so that requires a change to our risk framework and our risk rules."
Ulrich joined Mastercard eleven years ago when an analytics company he worked at was acquired, and said trust struck him from day one on the job. "It's what enables a merchant that's never met you to accept payment and ensure that they're going to get paid. It's what enables you as a consumer to transact and ensure that things are going to work out in a trusted, secure way. And if something goes wrong, there's a safe and secure path for a dispute and to resolve this," he said.
175 billion transactions, scored in under 100 milliseconds
He took the audience inside each of those calls. "When you tap your Mastercard to pay for a product or service, we're providing a score to that transaction," he said. "We have under 100 milliseconds to look at that and give a score from zero to 999 about how likely is that to be fraudulent or real. And we pass that on to the issuing bank."
Generative AI widened what that score can see. "Because we have new technology, we can bring in more data, we can bring in more context, and now we're finding that we can identify 300, 400% more fraudulent transactions at those high-risk bands," Ulrich said, without adding friction or false positives for consumers. The company's Safety Net system has stopped more than 70 billion fraudulent transactions, he told the audience, and Mastercard is building its own transformer model on its transaction data as a foundation for new safety, security, and personalization solutions. VentureBeat's Beyond the Pilot podcast took that production fraud stack apart in detail earlier this year.
A third of the services business already runs on AI
The business stakes reach past fraud. About 40% of Mastercard's company is now based on services, Ulrich said, including marketing services; fraud, safety and security; and business intelligence. "A third of those are predicated on AI, and those are growing at a much faster clip than everything else," he said.
One line he returned to all session went further. "What's going to enable AI to continue to scale is not the capabilities of the agents, it's how much we trust those agents to do on our behalf as a consumer, as a business, as a financial institution, or otherwise," he said.
Five layers stand between agents and the network
Agentic commerce changes the object being secured. "Instead of a single atomic transaction where I say go buy something, I'm effectively delegating authority, or a consumer's delegating authority, a business is delegating authority," Ulrich said. "And when that happens, it's a much more complicated transaction." Trust, in turn, has a precondition. "The only way it's going to work with trust is if we can identify what was the intent, what are the behaviors, what are the constraints that were intended in that transaction."
Ulrich walked through five layers Mastercard has built against that problem. Identity comes first. "I want to make sure I can understand not just who the consumer is, but who the agent is, that I combine them together and that I have KYA or know your agent, that I'm validating that it's legitimate technology, that it's a legitimate agent," he said. "We can register it into our system."
Verifiable intent settles the "wrong-Nikes" problem
Verifiable intent is second, a tamper-proof cryptographic record of the original instructions that travels with the transaction. "If you've asked for Nike black Nikes in size 12, but you got them on a final sale and they're not returnable and that wasn't in your instruction, there's a way to look at that in an objective and clear way on the back end," he explained.
Controls form the third layer, defining which merchants an agent can buy from, at what limit, and under what constraints. Execution runs through Mastercard Agent Pay, which carries "the tokenization, authentication, the acceptance framework embedded within it" and has launched with Microsoft, OpenAI, Google, and others, Ulrich said. Intelligence is the fifth layer, spanning risk rules, insight tokens that grant "consented or permissioned access to insights" for personalized recommendations, and monitoring through Recorded Future to identify threat actors in the system.
The bigger prize is a procurement agent with a budget
Consumer purchases are where agentic commerce started. Ulrich pointed the room past them, to business-to-business procurement as the larger opportunity. His example was a manufacturer that wants an always-on assembly line, with an agent that manages inventory levels, tracks when stock runs low, replenishes automatically, and understands the budget and the approved suppliers. "When you can start enabling that, you require those same five layers for that type of transaction," he said.
Making it work across companies multiplies the parties that have to trust each other. "You need clear standards for identity, you need clear standards for intent, you need these to work across. You're gonna have a procurement agent, a supplier agent, a banking agent. They're all gonna need to communicate to enable this to happen in an autonomous way, and that's gonna require really scaled trust infrastructure."
Powerful new models, same security motion
Mastercard sat in the early wave of Project Glasswing with Anthropic's Mythos model, and worked with OpenAI's GPT-5.5-Cyber, he said. "What we've seen from both of those is incredibly powerful models finding new vulnerabilities in the ecosystem that were difficult to detect previously, but it's really a new tool as opposed to a new motion," Ulrich said.
Inside the company, the chief security officer leads that work. A dedicated team has prioritized the most critical assets, runs them through the models routinely, tracks findings by high, medium, and low severity, and uses the same technology to handle patches. Ulrich said the approach has already been extended out, and that Mastercard is working to make the same architecture and patching available to others as well.
What Mastercard would build differently after 14 months
"The guardrails, the security, all this stuff has to be embedded at the front end. These can't be things that we're adding on at the back end. That's lesson one. Lesson two is you have to be operating for scale, and the other one is around observability and accountability matter as much as the intelligence," Ulrich said, counting off what building inside Mastercard taught the team. The company built what he described as an agentic factory, an operating system with the compliance, the observability, and the guardrails built in rather than bolted on per agent. Model drift, once tracked manually by dedicated teams, is now automated into that factory.
Asked by an audience member about the gotchas, Ulrich did not soften the pilot-to-production trap. "If you're trying to extend that and then add guardrails in as you're extending it, once you've already built it, I think you're doomed to fail," he said.
Mastercard built a series of agents last year for its 4,000 consultants, covering deep research, text to SQL, Excel, and PowerPoint, tools that by his account did not exist at the level Mastercard needed. Were the company starting today, Ulrich said, it would build them fundamentally differently. "I don't know that we anticipated when we built things fourteen months ago that we would be rethinking the fundamental architecture and the approach already."
Agentic identity joins KYB and KYC
The identity layer is where Ulrich expects the market to move next. Inside Agent Pay, Mastercard authenticates the consumer the way it does in traditional e-commerce and binds the agent to that person. "Outside of that framework, I think there will be open standards to identify who an agent is and bind the agent with the consumer," he said. "And then we can tie that with verifiable intent."
VentureBeat's June 2026 Pulse research points at the same gap. Only 32% of the 107 qualified enterprise respondents give every agent its own scoped, managed identity, and just 12% include an agent-identity product in their consideration set.
He called identity "one of the faster-growing ecosystems," noting Mastercard has been expanding there organically and inorganically for about six or seven years, with the work now spanning "agentic identity as well as the traditional KYB and KYC identity." The risk rules that keep bots off the network came out of more than two decades of applying AI to those transactions. The rewrite, for the agents Mastercard now wants to let in, is already underway on the same network that scored 175 billion of them last year.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み