The fraud-friction paradox: Why stronger security should feel invisible

August 21, 2026
Written by
Anurag Dodeja
Contributor
Opinions expressed by Twilio contributors are their own
Reed Mcginley-Stempel
Contributor
Opinions expressed by Twilio contributors are their own
Reviewed by

AI generated summary
  • Security is changing as customers deploy autonomous AI agents to complete tasks.
  • Strong security should be invisible and seamless, not a user hurdle.
  • Twilio simplifies security by utilizing a unified trust layer for continuous permissioning.

This summary was generated by AI.

The fraud-friction paradox: Why stronger security should feel invisible

For decades, the industry has operated under a weary lament: that you can have a secure product or a seamless one, but never both. It’s the ultimate zero-sum game.

The prevailing logic suggested that if you wanted to protect your users, you had to make them jump through hoops: complex passwords, distorted CAPTCHA images, and multi-step verifications that felt more like an interrogation than an onboarding flow. Conversely, if you wanted a "seamless" user experience, you had to accept a higher degree of risk.

As we navigate the mid-2020s, that premise hasn't just aged poorly. It’s become a dangerous liability. The fraud-friction paradox is a false choice. In fact, the very measures we once thought were protecting users are often the exact vulnerabilities attackers exploit today.

To build a competitive advantage in a digital-first economy, we have to stop asking how much friction our users can tolerate and start asking how we can make security invisible. 

What is the fraud-friction paradox?

For decades, the fraud-friction paradox has been the fundamental tension at the heart of digital commerce. It is the belief that security and user experience exist on a balancing scale: to increase one, you must inevitably sacrifice the other. Every complex password, SMS code, or CAPTCHA served as a speed bump driving away real customers. 

In the agentic era, that traditional trade-off is obsolete.

Software no longer sits idle, waiting for a human to type, tap, or click. Autonomous AI agents now execute complex, multi-step tasks across systems on a user's behalf. This shift fundamentally redefines both sides of the security equation. The entity navigating your platform is increasingly an automated assistant, not a person sitting at a keyboard. High-friction security designed to test human patience (like CAPTCHAs) completely fails to govern autonomous logic.

Friction is no longer measured in user annoyance or abandoned shopping carts. Today, friction means establishing precise guardrails, identity contexts, and real-time permission boundaries for AI agents operating with delegated authority. The threat isn't just an unauthorized login; it is an over-permissioned agent tricked into taking rogue, irreversible actions across multiple integrated APIs.

The historic choice of trading customer frustration for manageable fraud loss no longer holds. Modern security cannot simply balance ease against access. It must govern autonomous agency, granting AI assistants the freedom to act while ensuring they remain safely within bounds.

The unintended consequences of high-friction security

To understand where we’re going, we have to look at why we got stuck. Historically, the industry believed that increasing security meant increasing the burden on the human at the keyboard. We demanded passwords with specific strings of numbers, special characters, and capital letters. When forced to navigate dozens of websites with high-friction requirements, users create their own shortcuts. They reuse the same complex password across most sites they visit. 

This creates an insecure chain of connected credentials. An individual might use a complex password for their high-security bank account, but because it’s hard to remember, they use that same password for a less secure e-commerce site. When that smaller site suffers a data breach, the attacker doesn't just have a shopping login; they have the keys to the user's email and financial life. Suddenly, the security of a global institution is indexed to the weakest, most unreliable link in a user’s digital footprint.

The irony of the password reset flow

We’ve actually had the answer in front of us for years. Think about the password reset experience. When you forget a password, the flow is often lower friction: you receive a one-time password (OTP) or a magic link, and you’re in. This works because the security heavy lifting happens in the background, using intelligence to validate the user’s identity without making them jump through unnecessary hoops. 

However, we must stop treating login codes as the end of security. Instead, the new standard is to use continuous risk checks during the session and leverage phone channels to ask users for instant permission when AI agents take major actions.

However, treating security like a "front door" checkpoint is no longer enough. Logging in with an OTP or magic link only proves who someone is at the start. Security needs to keep running in the background (continuous trust) because risks change as session activity unfolds. A single check at login breaks down when an AI agent or user tries to do something mid-session. Trust needs to adapt dynamically based on what actions are happening in that moment. 

In the agentic era, we need to upgrade how we think about texting and calling, too. Businesses can use Twilio’s messaging and voice capabilities as an active safety line as well. When an AI assistant wants to perform a big task, the system reaches out to the user’s phone in real time to ask for explicit human permission. 

By removing static passwords and shifting from one-time logins to continuous, event-triggered verification, platforms achieve both seamless access and total control over autonomous actions.

Letting good customers in vs keeping bad actors out

When security teams talk about fraud, the language is usually defensive. It’s about keeping bad actors out. But if you talk to a CEO, the priority sounds different: How do I get my good customers in faster?

Fraud affects the business in two ways. First, it’s a massive liability on the balance sheet. Second, and more importantly, if you spend too much effort (and friction) trying to reduce that liability, you hurt your revenue. 

The modern compliance and security experience often feels like:

  • Endless checklists that frustrate users

  • Fragmented systems that create blind spots

  • A one-size-fits-all approach to verification

We need to move to a world where we give our best customers the easiest experience. As we gain more information about a user’s legitimacy through background signals, we should be opening the doors wider, not adding more locks.

Automation in an agentic world

In the next evolution of identity, businesses need to shift their perspective away from thinking of all automated software as the enemy. Old school security tools assume that any non-human visiting a website is a malicious bot trying to break in. Modern security needs to abandon this "all bots are bad" mindset because businesses now want helpful AI tools to visit. 

This begins by learning to differentiate between good and bad AI.

An example of bad automation is scammers using software to test stolen passwords or scrape private data. On the other hand, good automation can look like helpful AI assistants (like ChatGPT, personal agents, or customer service bots) doing legitimate work on behalf of real people.

The rise of invisible intelligence

If passwords and CAPTCHAs are failing us, what is the alternative? The answer lies in the ability to verify a user’s legitimacy across their device, phone, and email without introducing any actions required by the user. 

Invisible checks, which include analyzing a divide type, phone history, or email reputation, are great but running them only once before a user logs in is no longer enough. There is a new need for a continuous fraud risk engine. 

What does that look like? Upgrading from a single check at the front door to real-time security that stays on throughout the user’s entire visit. That means security clues like device health, network signals, communication history, and chat behavior become the meaningful signals. These signals are continuously re-evaluated while a user chats, browses, or completes tasks. If anything looks suspicious mid-session, the security adapts instantly.

Introducing agent identity and Know Your Agent (KYA)

In the Agentic Era, authenticating the human is only half the battle. Once a user proves who they are via biometrics, a critical question remains: who is operating on their behalf?

This is where agent identity and KYA  transform the security framework.

Biometrics like FaceID or passkeys prove device ownership and verify human presence at the front door. Agent identity, by contrast, governs delegated authority. It establishes what an autonomous AI assistant is allowed to do once inside, defining strict permission boundaries, 

contextual rules, and time-bounded scopes for every action it executes.

Just as Know Your Customer (KYC) regulations prevent fraud by verifying human identities, KYA establishes a verifiable chain connecting an AI agent to the business or entity that deployed it. When an agent places a call, sends a message, or triggers an API workflow, KYA ensures external systems and communication channels can instantly verify its origin, ownership, and legitimacy.

While biometrics confirm who gave the command, Agent Identity and KYA govern how the software executes it in order to ensure autonomous agents operate with verifiable trust across every digital interaction.

How Twilio helps you close the gap with unified trust

At Twilio, our role is to simplify your security burden. We handle the foundational complexity so builders can focus on the user experience:

Twilio delivers a trust layer by unifying customer data, security intelligence, AI governance, and global communication channels into a single platform. Rather than passing a user between isolated software tools, every part of Twilio's platform shares real-time signals to manage safety and convenience during the interaction.

We’ve spent decades optimizing for the fraudster and punishing the customer in the process. It’s time to flip the script. By leveraging device signals and seamless biometric standards, we can finally stop treating our best users like suspects. True leadership in this space means making security so sophisticated that it effectively disappears, leaving nothing but a clear path for your users to engage, transact, and trust.

The most successful brands of the future will be the ones that recognize a user instantly and protect them silently. We are moving toward a world where the password is a relic and friction is a choice. The question for every leader today is simple: Is your security a hurdle your customers have to clear, or is it the invisible foundation that allows them to move faster?