What SHAP Can't Explain About Agentic AI Fraud
| Source: Towards Data Science
Tags: fraud detection, SHAP, agentic AI, Experian, explainability, machine learning, financial crime, autonomous agents
Experian's 2026 Fraud Forecast names AI agent transactions a new fraud category — 'machine-to-machine mayhem' — exposing a foundational flaw: every fraud detection model assumes a human is transacting, and SHAP-based explainability cannot fix a model that was never trained to distinguish human from autonomous-agent behavior.
Details
Experian's 2026 Future of Fraud Forecast gives a name to something fraud teams have been quietly grappling with: AI shopping and payment agents transacting on behalf of users are now a real driver of financial fraud, and legitimate agents and fraudulent bots look statistically identical in transaction logs. This practitioner analysis digs into why that breaks the entire fraud detection stack. The core problem is an unspoken assumption in virtually every fraud model deployed today: that a human is on the other end of the transaction, leaving behavioral fingerprints. Signals like typing cadence, device switching patterns, transaction timing, and behavioral velocity were trained to detect when a human stops acting like themselves. An AI agent, by design, produces none of those signals — or produces artificial versions that a model trained on human behavior has no frame of reference for. SHAP (SHapley Additive exPlanations) has become the standard explainability layer for fraud classifiers, allowing teams to surface ranked feature contributions for any flagged transaction. The author argues this creates a false sense of auditability in the agentic era: SHAP tells you why a Random Forest flagged a transaction based on features like amount, timing, and velocity — but cannot reveal that the underlying model was never designed to reason about whether the actor was human or automated. The author illustrates the gap with their own Random Forest classifier trained on the PaySim dataset (benchmarked against XGBoost and LightGBM), noting that when asked whether a CEO and a student making identical transactions would be treated the same, SHAP attribution provided an answer — but the question itself pointed to a deeper identity problem that feature importance cannot resolve. Fraud teams will need agent identity signals (delegation tokens, API behavioral fingerprinting, agent attestations) rather than human behavioral proxies to address this gap.