Table of Contents
How AI agents are reshaping fraud and financial crime
Don't have the time to read the entire post? Our human writers will be sad, but we understand. Summarize the post with your preferred LLM here instead.
On July 27, 2026, Gartner published its Hype Cycle for Fraud and Financial Crime Prevention, 2026, a research note that helps bank CIOs and fraud-prevention leaders prioritize the technologies shaping how they detect and stop financial crime. We're proud to share that Descope is listed as a Sample Vendor in two categories: CIAM for AI Agents and Journey-Time Orchestration.
This is the second 2026 Gartner Hype Cycle to name Descope in both of these categories, following the 2026 Hype Cycle for Digital Identity published on July 6, 2026. Seeing the same two capabilities recognized in a report written for banking and fraud teams points to where the market is heading. In our view, agentic identity and journey-time orchestration are becoming central to how financial institutions fight fraud.
Here is where Descope appears on this year's Hype Cycle:
Gartner places CIAM for AI Agents in the On the Rise phase, with an Emerging maturity level and a High benefit rating.
Journey-Time Orchestration sits at Early mainstream maturity, also with a High benefit rating.
This inclusion follows Descope’s Honorable Mention in the 2025 Gartner Magic Quadrant for Access Management, continuing a year in which we have closely tracked Gartner’s guidance on agentic identity.
This blog will share our reflections on the two categories in which Descope is named, what the report says about each, and how we believe Descope continues to align with the direction charted by Gartner.
How AI agents are reshaping fraud and financial crime
The report frames a shift that we see across our own customer base. Real-time payments have raised transaction velocity, customers are beginning to experiment with agentic payments, and fraudsters are using the same AI tools that everyone else is. Bank CIOs now have to tell legitimate customers apart from bad actors in a world where a growing share of activity is initiated by software rather than a person at a keyboard.
Gartner groups the report's innovations into four themes, and agentic AI is one of them. The report says:
"Banks must address the rise of autonomous AI agents that can initiate and execute payments and account actions on behalf of customers. They must secure the agentic transaction life cycle through tailored customer identity and access management (CIAM) for agents, strong authentication and authorization, device attestation, and continuous monitoring to detect compromised or malicious agents in real time."
We believe the two categories where Descope is named map directly onto that guidance. CIAM for AI Agents covers the identity of the agent and the customer behind it, and Journey-Time Orchestration is how banks assess and act on risk at each step of a session. Our reading is that the two reinforce each other. Stopping account takeover in an agentic world depends on securing agent identity, and securing agent identity at scale depends on orchestrating risk across the journey.
Nowhere is this better explained than the OWASP Top 10 for Agentic Applications: each threat description cites at least one identity-related mitigation. Read our full analysis of the OWASP recommendations and see how Descope addresses every threat to agentic applications.

CIAM for AI Agents in a fraud-prevention context
CIAM for AI Agents is a new entrant on this year's Hype Cycle, with a High benefit rating and Emerging maturity. The category name is Gartner's, and in our view it describes the extension of customer identity and access management (CIAM) beyond human users to the AI agents acting on their behalf. Gartner defines the category this way:
"Customer IAM solutions are engineered to manage diverse, large-scale customer identities and ensure a frictionless digital experience. Cybersecurity leaders must adopt IAM capabilities to securely manage AI agent identities in customer-facing contexts given the emergence of use cases where customers send AI agents to interact with organizations."
For a banking or fraud audience, the stakes are concrete. The report ties weak agent controls straight to fraud loss and data exposure. Gartner says:
"CIAM for AI agents ensures that businesses stay competitive as customers increasingly expect engaging UX such as AI-agent-based chatbots and shopping assistants. Furthermore, as customers begin to use their own AI agents for tasks such as purchases or account management, businesses that cannot securely and seamlessly support this agent activity risk missing out. A lack of effective CIAM controls for AI agents exposes businesses to account takeover risks, theft of sensitive data and poor CX."
The core technical challenge, according to the report, is delegation with binding. Gartner says:
"Use of AI agents in customer-facing scenarios presents a range of cybersecurity challenges that will need to be addressed using CIAM for AI agents. These include managing authentication and authorization mechanisms, delegating access from customers to AI agents, and verifying the identity of customers behind AI agents and being able to bind the two securely. Prevention of account takeover will be a key priority in a customer agentic context."
We built the Descope Agentic Identity Hub to solve exactly this. Customers authorize agents through OAuth 2.1-based consent flows, each agent receives its own short-lived, scoped credentials linked back to the authorizing user, and the credential vault (Descope Connections) keeps raw user credentials out of the agent's hands. Because every agent action traces back to the customer who authorized it, a bank can scope, audit, and revoke that access, which is the foundation for preventing account takeover in agentic sessions.

Consent is a first-class concern in the report, and the example Gartner uses lands squarely in financial services. Gartner says:
"As AI agents from service providers begin to interact with customers, these systems must incorporate consent management models that allow users to maintain trust by determining the scope and limits of an agent's actions. For example, a user might grant an AI agent permission to access certain customer data for personalized recommendations but restrict it from handling sensitive financial information."
The report is candid that fine-grained authorization at scale is still hard. Gartner says:
"The challenge of balancing trust, cybersecurity, and CX is complex. Managing the fine-grained authorization needed for customer interactions (e.g., 'You can book flights to here, but not to there') without constant prompts to users for permission has yet to be demonstrated at customer scale."
These are the problems the Agentic Identity Hub was designed around. Agents are managed as first-class identities with their own attributes, including their associated user, tenant, and granted scopes. Teams get flexible agent registration through pre-registration, Dynamic Client Registration (DCR), and Client ID Metadata Documents (CIMD), a policy engine that reads user, tenant, and JWT claim context, per-agent and per-tool scopes, and scope-aware step-up authentication for sensitive operations. That combination is how "book flights here but not there" becomes a policy rather than a prompt on every action.
Read more: AI Agent Credential Management Best Practices

On the build-versus-buy question, the report's recommendation is direct. Gartner says:
"Look to vendor-provided capabilities rather than attempt to build CIAM tooling in-house in order to manage costs and demands on resources. In the first instance, evaluate whether your existing CIAM vendors can meet requirements to support agent interactions. If your incumbent CIAM vendor is incapable, look for a dedicated vendor that can manage the agent interactions and integrate with your incumbent platform."
Alongside familiar CIAM requirements, banks now face niche infrastructure like DCR, CIMD, consent management, per-agent scopes, and Model Context Protocol (MCP) authorization flows. In our experience, few teams want to become an identity company on top of running a bank, and the agentic era raises that bar further.
Production-ready agentic identity
Gartner places CIAM for AI Agents early in its journey, but the Agentic Identity Hub is already production infrastructure. It powers hundreds of MCP servers and millions of agentic transactions today. A few of the teams running Descope agentic identity in production:
You.com protects their MCP server with OAuth 2.1, secure client registration, and token management, without rewriting their backend APIs.
WisdomAI took MCP auth from concept to production in roughly a day and a half, freeing their team to focus on core AI capabilities.
Token Security extended the same roles and tenants that govern human access to control what AI clients can do on their MCP server.
That work is why Descope was named a Leader in the 2025 Frost Radar for Non-Human Identity Solutions, and why we remain one of the few CIAM platforms with native MCP and AI agent identity support built in rather than bolted on.
Journey-Time Orchestration for risk across the customer journey
Journey-Time Orchestration (JTO) appears at Early mainstream maturity with a High benefit rating, which reflects a discipline that has proven its value and is heading toward broader adoption. This is familiar territory for us. Descope was also named for its JTO capabilities in the 2025 Hype Cycle for Fraud and Financial Crime Prevention, so this is a category where we have tracked Gartner's guidance across multiple reports. Gartner defines JTO this way:
"Journey-time orchestration (JTO) solutions improve risk management along digital user journeys and deliver optimized user experience (UX). Most organizations manage multiple identity verification, authentication and account takeover (ATO) prevention tools, and adjacent capabilities such as user registration. A JTO solution manages the integration of these tools, simplifies assessment of risk at each event in the journey, and facilitates tailored and risk-appropriate UX delivery."
Most identity stacks accumulate separate tools for identity verification, authentication, account takeover (ATO) prevention, and registration, and by default none of them talk to each other. Risk gets assessed at isolated checkpoints instead of as a continuous stream, with one blunt threshold applied to every user. Gartner describes why that becomes a problem for fraud teams:
"Securing digital user journeys and offering strong UX is the foundation on which digital transformation is built. Organizations without available developers struggle to manage the broad range of capabilities that this requires, including identity verification, user authentication, user registration, ATO prevention, service resilience and A/B testing."
Descope Flows, our visual workflow builder, is Journey-Time Orchestration plugged natively into a CIAM platform. In our view, this is one of the main drivers behind our inclusion as a Sample Vendor.

The report describes the JTO layer as the connection between risk analytics and the user interface:
"Security teams and app developers are both seeking more tailored, risk-appropriate UX, which is easier to achieve with a JTO solution due to the fine-grained user journey control intrinsic to such solutions. The JTO solution optimally acts as the connective thread between the analytics solutions and the UI layer to reduce fraud risk while enabling a great UX."
Flows weaves risk data from 50+ third-party connectors directly into the journey, including signals from Forter, Fingerprint, and reCAPTCHA, so a suspicious session can be challenged or blocked on combined intelligence rather than a single vendor's score. Because Flows is a cornerstone of the platform rather than an acquired add-on, journey logic, risk assessment, and auth methods share one control plane.
The report also calls out A/B testing as a driver of JTO adoption. Gartner says:
"The need to facilitate A/B testing in DevOps is pushing the adoption of JTO. Optimization of a risk management strategy is facilitated by a strong JTO platform in the form of A/B testing. For example, traffic could be split across two different identity verification vendors to assess which delivers better conversion rates."
Descope Flows lets teams visually A/B test user journeys with phased rollouts, so a bank can measure which verification path delivers better conversion and lower fraud before committing to it.

The report's final user recommendation on JTO says:
"Distill the complexity of managing multiple vendor integrations by leveraging a JTO solution to deliver a marketplace of readymade connections to identity verification, authentication and ATO prevention solutions."
Descope ships 100+ best-practice journey templates and the connector ecosystem to back them, so teams assemble journeys from ready-made building blocks instead of custom integration code. Teams can modify user journeys without touching their codebase, all while staying in sync through CI/CD integrations (GitHub, GitLab, Terraform, Pulumi) for software development life cycle (SDLC) alignment.
Orchestration at consumer scale
Descope Flows is proven in the market; thousands of organizations run Descope in production, managing hundreds of millions of identities. The vast majority of them use Flows to orchestrate their user journeys.
Two examples from financial services and adjacent sectors:
Branch Insurance, a cloud-native home and auto insurer, augmented its existing auth with phishing-resistant passkeys using Flows, routing users to passkeys where their hardware supported them and to fallback MFA where it did not. Branch reduced authentication-related support tickets by 50% while meeting compliance requirements for its 12,000+ independent agents.
GoFundMe, which processes tens of millions of donations a year, moved from a homegrown system to workflow-based journeys, wiring in reCAPTCHA for login risk detection and migrating millions of users with no disruption through just-in-time migration.

How Descope aligns
The table below maps themes from the two categories where Descope is listed to the platform capabilities that, in our view, address them.
Hype Cycle Theme | How Descope Aligns |
|---|---|
Delegating access from customers to AI agents and binding the two securely | • OAuth-based consent and delegation • Agents receive short-lived, scoped credentials tied to the authorizing user, with raw tokens kept in Descope Connections |
Managing authentication and authorization mechanisms for agents | • AI agents managed as first-class identities with their own attributes: associated user, tenant, and granted scopes • Flexible agent registration (pre-registration, DCR, CIMD) and grant support (authorization code, client credentials, JWT bearer) • Per-agent and per-tool scopes • Policy engine with user, tenant, and JWT claim context |
Account takeover prevention across agentic and human contexts | • Adaptive MFA based on journey logic • Native risk factors like impossible traveler and trusted device • Third-party risk connectors (Forter, Fingerprint, reCAPTCHA) |
Reducing the complexity of multiple vendor integrations along the user journey | • Native Journey-Time Orchestration implementation (Descope Flows) unifying actions across frontend and backend • 100+ journey templates • 50+ third-party connectors |
A / B testing to optimize risk strategy and conversion | • Visual A / B testing of user journeys with phased rollouts • Journey-time analytics dashboard to show step-by-step conversions and dropoffs • CI / CD integrations for SDLC alignment |
What the Hype Cycle for Fraud and Financial Crime Prevention means for Descope
We feel this Hype Cycle is a valuable resource for banking and fraud leaders deciding where to invest as AI agents reshape financial crime. Being listed as a Sample Vendor in both an emerging category and a maturing one is, in our view, a signal that Descope's approach fits where financial services is heading: build for the customer agentic era that is arriving, on orchestration foundations that are already proven in production.
That production track record matters most in regulated environments. More than 1,000 organizations run Descope today, and the platform is backed by SOC 2 Type II, ISO 27001, and FedRAMP High authorization, the kind of assurance a bank CIO needs before moving auth off custom code. If you're interested in trying out Descope, sign up for a Free Forever account. If you have an active project for fraud prevention, customer identity, or agentic AI and MCP systems, book a demo with our auth experts to learn more.
FAQs
Gartner, Hype Cycle for Fraud and Financial Crime Prevention, 2026, By Vatsal Sharma, 27 July 2026.
GARTNER is a registered trademark and service mark of Gartner, Inc., and/or its affiliates in the U.S. and internationally, and HYPE CYCLE is a registered trademark of Gartner, Inc. and/or its affiliates, and are used herein with permission. All rights reserved.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner's business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

