Google Cloud has launched Fraud Defense, a security platform aimed at the emerging agentic web, where autonomous AI systems can reason, plan and complete transactions on behalf of users. The announcement, published on April 22, 2026, frames the shift as a change in the way websites must evaluate digital activity: the question is no longer simply whether traffic comes from a human or a bot, but what an automated system is attempting to do and whether its identity and behaviour can be trusted.
Fraud Defense is presented as the next evolution of reCAPTCHA. Google Cloud says the platform is designed to verify the legitimacy of bots, humans and AI agents, giving businesses a way to measure and control automated activity across their websites and digital commerce journeys. The company says it uses the same global signals that protect Google services, combined with controls intended for agentic interactions.
From bot detection to agent identity
The first major capability is agentic activity measurement. Google Cloud says its new dashboard helps organisations understand how much agentic traffic reaches their sites and what that traffic is doing. The system is intended to identify, classify and analyse automated activity using traditional detection methods alongside industry standards such as Web Bot Auth and SPIFEE.
That approach reflects a more complicated online environment. A conventional bot-management system can focus on whether a request looks automated, but an AI shopping assistant may be authorised to search for products, compare options or initiate a purchase. A malicious agent could imitate a legitimate workflow while attempting account takeover, abuse promotions or manipulate checkout. Separating those cases requires more context than a simple human-versus-machine decision.
Google Cloud says Fraud Defense can also connect agent and human identities to improve its understanding of risk and trust. The announcement does not describe every signal or identity provider involved, so organisations should treat the capability as a new control layer to evaluate against their own authentication, privacy and fraud-monitoring requirements.
Policies across the customer journey
The second central component is an agentic policy engine. According to Google Cloud, businesses can allow or block agents and users at different stages of an interaction using conditions that include risk scores, automation types and agent identity. The controls are designed to apply across the full journey rather than only at a single login or API endpoint.
This matters because fraud campaigns often move through several connected steps. Registration, login, account recovery, product discovery, payment and checkout can each appear legitimate when inspected in isolation. A policy engine that correlates decisions across those stages could give security teams a way to apply different levels of scrutiny as risk changes, while preserving lower-friction access for trusted automation.
For defenders, the practical implication is that agent traffic should become an explicit part of security policy. Teams will need to define which automated actors are permitted to browse, which may create accounts, which can access customer data and which must stop before a transaction. Those decisions should be backed by logging, ownership and a clear process for reviewing false positives.
A human checkpoint for suspicious requests
Fraud Defense also introduces what Google Cloud calls an AI-resistant challenge. When the platform identifies potentially fraudulent behaviour from an agent, an application provider can request that a human come back into the loop through a QR-code-based challenge. The stated goal is to make automated fraud more expensive and difficult without placing the same interruption on every visitor.
The design is significant because it treats human presence as a targeted security control rather than a universal test. That can reduce unnecessary friction, but it also creates operational questions for site owners. A challenge must be accessible, understandable and compatible with the organisation’s account-recovery and fraud-response procedures. It should not be treated as a substitute for strong authentication, transaction monitoring or limits on high-risk actions.
What changes for existing reCAPTCHA customers
Google Cloud says reCAPTCHA will remain the core bot-defence pillar of the broader Fraud Defense platform. Existing reCAPTCHA customers are automatically considered Fraud Defense customers, with no migration required, no action needed and no change to pricing. The company also says existing site keys and integrations remain unchanged.
That continuity may make the announcement easier for current customers to assess, but it does not remove the need for governance. Organisations should establish who can create or modify agent policies, how risk decisions are audited and how legitimate AI assistants are distinguished from unauthorised automation. They should also confirm the precise capabilities available to their deployment through Google’s current product documentation rather than assuming that every announced feature has the same scope in every environment.
Google Cloud’s announcement positions Fraud Defense as infrastructure for a web in which both people and AI systems are legitimate participants. The security challenge is therefore moving from blocking automation by default to establishing verifiable trust, limiting risky actions and preserving a human decision point when signals indicate possible abuse. For businesses preparing for agent-mediated commerce, that is a more durable framing than treating every automated request as either safe or malicious.
