By Ann Marie van den Hurk, Mind The Gap Cyber Advisory

 

Machine-to-Machine Fraud and the Quiet Collapse of Authority

As leaders gather in Davos this week to discuss AI, automation, and resilience, one risk deserves far more attention than it is currently getting.

Machine-to-machine fraud.

Financial institutions and fraud experts are already flagging this as a top 2026 exposure. Not because bots exist. Not because automation is new. But because bots are now transacting with other bots inside normal banking, commerce, and operational flows.

This is the shift most organizations have not fully absorbed.

When automation interacts with automation, long-standing assumptions break down quickly:

  • Intent becomes distributed rather than attributable to a single actor

  • Liability becomes unclear across systems and counterparties

  • Accountability blurs just as impact accelerates

These incidents do not announce themselves as fraud. They look like ordinary activity. Transactions clear. Systems behave as designed. Nothing immediately triggers alarms. Losses often surface later, after activity has already compounded, when leadership is suddenly expected to explain outcomes they did not consciously approve.

This is why machine-to-machine fraud is not primarily a technology problem. It is a governance problem.

Most crisis, fraud, and incident response playbooks are built around a human trigger. A mistake. A malicious actor. A clear moment when something “went wrong.” They also assume time: time to investigate, time to verify intent, time to escalate decisions.

Machine-driven incidents collapse that margin entirely. Decisions must be made before facts are complete. Sometimes before leadership even realizes authority is being tested. By the time an issue is visible externally, silence looks like confusion and speed without clarity looks reckless.

The uncomfortable reality is this: many organizations have deployed autonomous systems faster than they have redesigned decision authority to govern them.

Contracts rarely specify responsibility for agent-driven actions. Escalation paths still assume human pacing. Stop conditions are often technical rather than executive. When two automated systems collide, governance is left catching up to behavior that already occurred.

The organizations that will hold up under this shift are not waiting for regulation to catch up or vendors to solve the problem for them. They are doing quieter, more difficult work in advance:

  • Defining who has authority to intervene when automation behaves “as designed” but produces unacceptable outcomes

  • Establishing escalation thresholds for machine-driven incidents

  • Clarifying when and how systems can be halted, overridden, or constrained

  • Stress-testing scenarios where no one “did” anything wrong, but leadership is still accountable

This is not about slowing innovation. It is about ensuring authority keeps pace with speed.

Automation does not fail loudly. Authority does.

For leadership teams assessing whether their authority can keep pace with autonomous systems, the CrisisOS5™ Executive Crisis Readiness Diagnostic is a practical starting point.

Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com

Share This