Banks have spent years chasing the best login method. Passwords gave way to one-time codes, and one-time codes are now giving way to FIDO passkeys, a cryptographic model where the credential never leaves the customer’s device.
But according to a recent webinar from The Paypers and Outseer featuring Gagan Bhatia, Chief Information Security Officer at Outseer, and Susann Gäbler, Head of Risk Steering Fraud at Santander Deutschland, moderated by Dr Ruth Wandhöfer, solving the login problem doesn't solve fraud. It just moves the problem somewhere else.
Here are the key takeaways from the session.
A secret between a bank and a customer, replaced by cryptography
For decades, authentication has relied on shared secrets – a PIN, a code, a password – anything that could, in principle, be phished, intercepted, or handed over under pressure. FIDO changes that mechanism entirely: instead of a secret both sides need to know, it uses a cryptographic key pair where the private key stays on the customer's device. That's what makes it phishing-resistant in a way earlier methods structurally couldn't be.
Both speakers treated this as a genuine hygiene factor - the baseline a bank now has to get right, not a differentiator in itself. Getting authentication right is necessary. It just isn't sufficient.
Authentication success isn't the same as legitimate intent
This was one of the session’s core tensions. As Gäbler put it, banking is ultimately about customer trust - and trust doesn't stop at the login screen. Authentication can confirm a real customer on a real device using valid credentials, yet the bank can still process a transaction that the customer never should have made.
That's the shape of modern fraud: less account takeover, more social engineering. A customer that is under psychological pressure, feeling panicked, coached, or manipulated in real time, can pass every authentication check while still being defrauded. As Gäbler noted, in that state a customer can’t follow security protocols, no matter how well designed. The harder part was never getting a customer through the door; it's knowing whether the transaction they're about to make is one they actually intend.
Bhatia framed this as reordering the entire question a bank needs to ask. It's no longer 'can this user authenticate?' It's 'should this transaction be authorised at all?', a change from verifying identity to verifying intent.
Fraud prevention never stops; it just moves
A recurring theme was that closing one vulnerability doesn't end the problem; it redirects it. Once device recognition and geolocation controls go in, fraud patterns shift to work around them, typically within months rather than years. That has a direct implication for how banks should think about investment: fraud controls are not a project with an end date; they're a capability that must keep evolving as attackers adapt.
This extends well beyond the payment moment itself. The same trust logic - is this really the customer, and does this action reflect genuine intent - applies to loan applications, onboarding, and changes to account details, anywhere a banking journey has become instant enough that there's no realistic window for manual review.
What's coming next: agentic activity and verifiable intent
Looking ahead, both speakers pointed to agentic AI as the next real test of this framework. The industry has historically treated bots and automated agents as threats to block outright. But as legitimate AI agents begin transacting on a customer's behalf, that stance has to shift from blocking to enabling, while still preventing fraud.
The emerging answer is verifiable intent: rather than simply handing a customer's credentials to an agent, banks need frameworks where a customer explicitly authorises an agent to act within defined boundaries - specific amounts, contexts, and purposes. Standards bodies are already drafting three-party trust models to support exactly this kind of agent-based commerce, and FIDO's cryptographic foundation was described as a solid base to build that authorisation layer on, without requiring a wholesale rebuild of existing systems.
The takeaway
FIDO is the right foundation, and banks should keep rolling it out. But the session's message was consistent throughout: authentication is one signal, not the verdict. The banks that get ahead on fraud prevention won't be the ones with the strongest login screen; they'll be the ones that combine that strong login with context, behavioural intelligence, and continuous orchestration to answer a harder question than "who is this," namely: does this transaction make sense?
This webinar recap only highlights the key points of the discussion. For the full insights, watch the webinar recording here.
About Paula Albu

Paula Albu has experience in content writing and editing, as well as being a creative storyteller. As a Junior Editor at The Paypers, she investigates Web3 technologies along with the latest trends and regulations in banking and fintech. Paula is committed to turning complex industry topics into engaging, accessible content that resonates with readers and creates a meaningful connection. She is available via LinkedIn or at paula@thepaypers.com.
About Outseer
Outseer is a leader in All-Cause Fraud Prevention™, helping financial institutions detect and stop digital banking and payment fraud. Its platform combines device intelligence, behavioral biometrics, transaction data, and global fraud signals to protect over 450 million accounts and 100 billion transactions annually for customers in more than 50 countries.