For Issuers · Card Networks · Heads of Fraud · CISOs

The payment carries authority the cardholder signed. The agentic era isn’t next. It’s here.

Social engineering is the headline loss of 2025. Agent-initiated action is the headline loss of 2027. Yuthent is issuer-side Execution Authority Infrastructure for both: the payment does not leave unless the cardholder signed for it, or signed the mandate an agent is spending inside.

The Problem

Per UK Finance H1 2025, £372M of the £629.3M UK banking fraud total sits in the unauthorized category: account takeover, session hijack, remote-access trojans, SIM swap, credential theft, card-not-present fraud, and stolen cards used with a known PIN. Every one of these attacks succeeds because the authentication primitive in production today cannot answer a single question: was the enrolled person present on their bound device at the moment this action was authorized?

The authorized-payment category (£257.5M in the same report) is a different problem and Yuthent is explicit about it. Investment, romance, purchase, and advance-fee scams rely on the victim themselves authorizing the transfer with their legitimate biometric. No cryptographic primitive stops that.

Agent-initiated actions (autonomous systems executing on behalf of users, third-party agents with delegated API scope, prompt-injected LLM workflows that read an email and transfer a sum) produce no device fingerprint, no behavioral pattern, no velocity anomaly.

What Yuthent Provides

One primitive. Two commitments the industry has not made.

First commitment: per-action signing, not session trust. A session cookie, a stolen OTP, a hijacked cookie jar: none of them produce a Yuthent-valid signature without the human present.

Second commitment: no recovery path weaker than the enrollment. If a cardholder replaces a device, re-binding requires the same enrollment strength as the original. That is a deliberate cost: it asks more of the cardholder on the one path where the industry asks least.

For AI Agents

You decide what the agent may do. We prove the human at the edge.

01

You set the policy

In policy, you map which agent actions run freely (balance reads, routine reconciliation), which require a human's fresh proof (a wire above a threshold, a new beneficiary, a mandate change), and which are denied outright.

02

A human authorizes at the edge

When an agent reaches an action that needs a person, the server pushes a signed request to the authorizing human's enrolled device. No proof, no execution.

Attack Surface

Where the defense actually lives.

Account Takeover (ATO) of the banking app

The pattern

Attacker obtains credentials through phishing, reuse from a third-party breach, or malware. Initiates wire, payment, or internal transfer.

Why current defenses fail

Every control that re-validates the session (cookie, JWT, refresh token) passes. SMS and email OTP are attacker-controlled or intercepted.

Where Yuthent stops it

The attacker's session produces no signature. There is no OTP to steal.

Agent-initiated action without a human in the loop

The pattern

An autonomous system (internal automation, a third-party agent with delegated API access, or a prompt-injected LLM workflow) executes a high-value action on behalf of a user. No human reviewed the specific action at the specific moment.

Why current defenses fail

Every detection system trained on human-behavior signals degrades against agent traffic. OAuth-delegated API keys and service tokens carry broad scope.

Where Yuthent stops it

The agent cannot produce a fresh biometric signature. A deterministic answer, not a score, separates human-authorized actions from agent-initiated ones.

Capability Surface

What the SDK and the backend produce on day one.

OS-handled biometric, no custom ML

Yuthent ships no face-matching model of its own and stores no biometric template on any server. Under GDPR Article 9 no special-category biometric data is processed by Yuthent at all.

Regulatory Alignment

What each framework will not let you run without.

EU AI Act · Meaningful Human Oversight

Cryptographic proof that the enrolled person authorized a specific action, as opposed to a logged click inside an autonomous workflow.

Alongside Your Stack

Yuthent does not replace your fraud stack. What changes is that one dimension of uncertainty (was it this human?) becomes a deterministic binary field in real time.

Deployment Readiness

Integration ships on Android, the reference implementation.

Questions

Answered plainly.

Can an AI agent move money on its own?

What your policy lets through is then checked against the mandate the cardholder signed, with its own amount ceiling, counterparty list and expiry. An action inside those bounds settles without interrupting anyone. One over the ceiling or against an unlisted payee stops and goes to the cardholder for a fresh approval. An expired or revoked mandate fails outright.

Do you see our transaction data?

No. Yuthent receives action metadata, the amount and payee hashed into the signature, an action identifier, a counter, and the proof, never account records or business payloads. It is the decision point your systems call, not an inline interceptor of your traffic.

What does it not stop?

Persuasion and authorized-push-payment scams, where the genuine cardholder authorizes the transfer, the signature is valid because the intent, at that moment, is real. There we bind amount and payee (PSD2 dynamic linking) and enforce a second-signer flow above threshold, but we are honest that it is signal, not solution.

See it on your own flow.

Your app, your call, our SDK.

Access details within one business day, from a person.