Connect with us

NEWS

Enterprise AI Agents Are Copying the Internet’s Worst Loops

Firms are racing to put AI agents in 40% of apps by late 2026, cloning loops that stall opt-outs and approve fake invoices.

Published

on

Gartner projects that 40% of enterprise apps will carry task-specific AI agents by the end of 2026. Microsoft’s security team, on September 10, described more than a million AI-assisted CEO impersonation emails from early August, each pressing accounts payable for an ACH of nearly $50,000.

The public internet already runs on loops no person ever opens. Companies are now installing the same machinery inside vendor pay, identity checks, and privacy queues, which is how the agentic internet stops being a consumer nuisance and becomes an internal fraud path.

Gartner’s 40% Deadline Lands on a Live Fraud Wave

On August 27, 2025, Gartner said forty percent of enterprise applications would be integrated with task-specific AI agents by the end of 2026, up from less than 5% at the time of that note. Anushree Verma, a senior director analyst at the firm, said agents would move “from task and application specific agents to agentic ecosystems.” The same briefing warned that calling a chatbot an agent is “agentwashing.”

Gartner’s best-case path has agentic AI driving about 30% of enterprise application software revenue by 2035, a slice it put above $450 billion, up from 2% in 2025. By 2027 it expects one-third of agentic implementations to combine agents with different skills inside one environment. The forecast is a procurement signal. It is also a map of where a fake invoice will land once the human click disappears.

Between August 3 and 5, Microsoft detected a campaign of more than a million emails aimed at enterprise users, 87.7% of them in the United States. The lure impersonated a CEO, CFO, or president in the display name, the reply-to field, and the signature, then asked accounts payable to process an ACH of nearly $50,000. Under the signature sat a fabricated “ServiceNow Platform, Annual Subscription” invoice and a short fake thread with a spoofed ServiceNow president. Microsoft said ServiceNow and the named companies were not breached. The actor had registered service-nowinc.com and domainlify.net on July 31.

The templates carried the usual tells of machine-written HTML, including verbose comments and identical invoice IDs across targets. The people on the receiving end were still human. The next buyers of this traffic are the task-specific agents Gartner says will sit in those same finance apps.

THE NUMBERS ALREADY ON THE DESK

Measure Figure When
Enterprise apps with task-specific agents (Gartner forecast) 40% End of 2026
Same share at Gartner’s August 2025 note Less than 5% August 2025
AI-assisted CEO impersonation emails (Microsoft) More than 1 million August 3-5, 2026
Share of that campaign sent to U.S. inboxes 87.7% Same window
ACH asked on each lure Nearly $50,000 Same campaign
U.S. job and employment scam losses (FTC) $501 million 2024
U.S. imposter-scam losses (FTC) $3.5 billion 2025

Those rows are not a coincidence of calendar. The same quarter that finance teams are being sold agents for approvals is the quarter attackers learned to ship a finished-looking approval in the first packet.

The Opt-Out Loop Was Built for Attrition

Before an agent can rubber-stamp a wire, a broker has usually already sold the name, title, and home address that make the lure feel local. The Consumer Financial Protection Bureau proposed in December 2024 to treat many of those brokers as consumer reporting agencies under the Fair Credit Reporting Act. On May 15, 2025, it withdrew “Protecting Americans from Harmful Data Broker Practices (Regulation V).” Russell Vought, then the bureau’s acting director, said the draft was not aligned with the bureau’s reading of the statute.

In August 2025, Sen. Maggie Hassan, a New Hampshire Democrat and ranking member of the Joint Economic Committee, sent demands to five registered brokers: Comscore, Findem, IQVIA Digital, Telesign, and 6sense Insights. The letters followed reporting that some firms had used no-index code to hide opt-out pages from search. On February 27, 2026, her committee said identity theft tied to four large broker breaches had already cost U.S. consumers more than $20 billion.

“As international criminal syndicates increasingly use scams to target Americans, data brokers shouldn’t make it harder for people to protect themselves,” Hassan said in that release. Four of the five firms had, by then, taken steps to make opt-outs easier to find. Findem had not. A May 15, 2026 committee update said Findem later changed its process after the inquiry.

The loop itself is simple enough to script. An email request is bounced to a form. The form issues a denial that cites a state law that may not apply. The denial invites an appeal to the same inbox, which replies that it does not handle privacy requests and points back to the form. Nothing in that circle has to fail for the record to stay on sale. Multiply it across hundreds of resellers and a privacy right becomes unpaid night work.

HOW THE ACCOUNTABILITY GAP OPENED

  1. December 2024: The CFPB proposes bringing data brokers under Fair Credit Reporting Act duties.
  2. May 15, 2025: The bureau withdraws the proposal.
  3. August 2025: Hassan writes five brokers over hidden opt-out pages.
  4. August 27, 2025: Gartner publishes the 40% agent forecast.
  5. February 27, 2026: The Joint Economic Committee puts broker-breach identity theft above $20 billion.
  6. May 15, 2026: Findem changes its opt-out process after the inquiry.
  7. August 3-5, 2026: Microsoft logs the million-email CEO invoice wave.
  8. September 9, 2026: House members introduce the Stop Rogue AI Act.

Each date is a choice to leave a human out of a step that still moves money or personal data. The agent wave did not create that habit. It inherits it.

LinkedIn Already Removes Tens of Millions of Fakes

LinkedIn’s community report for January through June 2025 put fake-account takedowns at roughly 83.8 million. The later report, covering July 1 through December 31, 2025, does not need a fresh total to show who is doing the work. Automated defenses blocked 97.8% of fake accounts the company stopped in that half-year, with 2.2% coming from manual investigations, and 99.7% of those accounts were stopped before a member filed a report. Spam and scam removals in the same window were 98.6% automated. LinkedIn says it now has 1.3 billion members in more than 200 countries and that members can ask for a second look. Almost none of the fake-account pile ever reaches that desk.

Attackers do not need all 83.8 million to survive. They need a handful of executive lookalikes, scraped photos, and overlapping connections, then a message that reads like an internal note. The Federal Trade Commission said job-scam losses of $501 million in 2024, up from $90 million in 2020, with reports nearly tripling over that span. In June 2026 the commission said people reported losing $3.5 billion to imposter scams in 2025, nearly one in three fraud reports. Business impersonators accounted for nearly $1 billion of that. Government impersonators accounted for about $920 million, up from $789 million in 2024.

A report filed into a bulk queue is treated like the first and only complaint, even when it is the fiftieth against the same pattern. That is the product design. It is also the training data for whatever agent a platform or a bank next assigns to “triage.”

Why Invoice Agents Inherit the Same Blind Spot

Once a task-specific agent can read an invoice, call a payments API, and mark a bill paid, it inherits every weakness of the loop it was trained to finish. Microsoft’s August lures already arrived with a paper trail, a fake approval, and a vendor logo. An agent hired to clear a queue will see finished work, not a puzzle. That is the second failure, and it sits inside the company rather than on a social network.

Trustmi, a payment-fraud firm, said it reviewed 597 intent-driven payment-fraud attempts in the first half of 2026, up from 119 in the first half of 2025, a fivefold rise. It named two patterns. Ghost Executive Fraud, about 255 of those cases, inserts a fabricated executive thread or a forged approval so the payment looks already decided. Deadline Deception pairs fake paperwork with a past-due clock so the checker has no time. Seven of nine tracked patterns included a fake invoice. The most common pairing, 193 incidents, was a fake invoice plus a fabricated email.

Security shops are already watching the next variant: malicious instructions buried in a vendor PDF, aimed at a procurement agent rather than at a person. On X, practitioners keep returning to the same mechanic, hidden text inside an invoice that tells an agent to change a destination account or dump a directory, which never trips a firewall rule written for malware attachments. A separate September 9, 2026 catalog from Cyera described 188 production incidents in which an autonomous system caused harm with no attacker in the chain, including money moving between wallets on a close-position command the user did not give.

Agentic AI is different. It extends beyond output generation by acting autonomously, making decisions across multiple steps, using tools, retrieving information and taking real-world actions with minimal human oversight.

Kimberly Nyitray, founder of Founders Counsel, IAPP analysis, June 10, 2026

Nyitray’s point is the privacy version of the same hole. Most governance still assumes a purpose you can write down in advance, a data flow you can map, and a person who approves how personal data is kept. An agent that breaks a goal into subtasks and calls other tools does not live in that drawing. The IAPP has also flagged that agents blur who counts as a data controller and who counts as a processor, because the system decides and executes with little human input.

HOW A FAKE APPROVAL IS BUILT

  • The identity: A CEO name in the From display, the reply-to, and the signature, copied from public pages and broker files.
  • The document: An itemized invoice with real logos, a billed-to line that matches the target firm, and a bank account the attacker owns.
  • The history: A short “forwarded” thread that makes the purchase look already debated and signed off.
  • The pressure: A due date, an ACH instruction, and a request not to copy anyone else.

Aaron Levie, the CEO of Box, put the enterprise version of this in plainer words on September 5. There is no easy button for most workflows, he wrote, and the important ones cut across functions, so nobody is empowered to walk into finance and cut a 14-step chain to five. Teams instead apply AI to the chain they already have. Allan MacGregor, a CTO who replied in that thread, said the documented happy path is never the real path; the exceptions live in email, spreadsheets, and side deals. Bolting an agent onto that mess does not invent judgment. It runs the weak steps faster, which is the same failure as agents that drift until processes break.

Fake Approvals Already Look Like Finished Work

Ghost Executive works because the employee is not being asked to decide. They are being asked to execute. An agent with a standing instruction to “pay approved invoices within terms” is in a worse seat, because the approval is the input, not a person it can walk down the hall to check. Cloud Security Alliance researchers have described a procurement agent whose goal is hijacked through instructions sitting in a vendor invoice, then sending a wire before monitoring flags the outlier.

Prompt Injection Rides In on the Invoice

The file is the exploit. It does not need a malicious macro if the reader is a model that treats every token as an instruction. People building agent payment rails have started asking a narrower question than “did the API respond”: did the amount, the wallet, or the endpoint change after the human thought they had approved the offer. That check is still rare in production queues. Invoice-chasing agents are already being stood up to draft the awkward “you still owe us” mail overnight, which means the same systems will soon be on the receiving end of mail that only looks like collections.

Congress Wants an Inventory of Every Agent

On September 9, 2026, Rep. Josh Gottheimer, a New Jersey Democrat, and Rep. Mike Lawler, a New York Republican, introduced the Stop Rogue AI Act. The House text would direct the National Institute of Standards and Technology to write NIST standards for AI agents, then have CISA fold those rules into federal cyber guidance. Federal agencies and contractors would have to buy and deploy against that bar. NIST would have one year after enactment, if the bill becomes law, to publish.

Gottheimer said AI agents are running loose in networks, and that nobody can see them or verify who built them, which makes them hard to stop. Lawler, posting the same bill, said the country needs to know who is behind the technology and what it is doing. Supporters listed by Gottheimer’s office include Palo Alto Networks, GoDaddy, Infoblox, the AI Policy Network, and the Alliance for Secure AI. GoDaddy’s note backed open standards that show which agent is acting, who stands behind it, and whether its credentials are valid.

WHAT THE STOP ROGUE AI ACT WOULD REQUIRE

  • An inventory: Find and track every AI agent on a network in a continuous, readable list.
  • Provenance: Verify who built and who operates each agent, not only what a vendor claims.
  • Live watch: Monitor in real time, including prompt injection, data theft, and agents acting outside approved limits.
  • A human brake: Allow, deny, or revoke an agent’s access and actions at any time.

That is not law yet. Gartner’s 40% date does not sit on the same calendar as a one-year NIST clock that has not started. Insurers, meanwhile, have begun asking renewal questions that sound like the bill’s checklist: whether agents hold credentials, whether they can execute a payment, and whether those steps are auditable and reversible. Coverage will price the gap if Congress does not.

Who Pays When an Agent Approves a Fake Bill

The person who still gets the call is the accounts payable clerk, the privacy lead stuck in a broker form, or the executive whose face is on a fake LinkedIn page while a client wires money. The company that deployed the agent will be asked to treat that action like an employee’s. Privacy counsel at the IAPP have been blunt that roles flip at runtime, a plugin that is a processor on one call and a controller on the next, which is a poor fit for a contract reviewed once a year.

Security teams used to measure this as phishing. It is now a workflow problem. If the agent can pay, the attacker will speak the agent’s language, a PDF, a thread, a ticket, rather than a suspicious From line. If the agent can close a privacy ticket, the broker-style denial becomes a system default with a log line that says a policy was applied. The people in those logs are not abstractions. They are the employee who will be told the invoice was in the queue, and the customer who will be told no violation was found.

The House bill gives NIST a year after enactment to write the standards, and that clock starts only if the House and Senate pass it.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending