Fraudsters didn't wait for a governance framework. Autonomous agents are already probing payment rails, spinning up synthetic identities and running social-engineering scripts at machine speed, while many institutions still triage alerts in batches. With instant payments and agentic commerce scaling fast, the window between attack and response is now measured in milliseconds. The panel looks at where real-time controls are keeping pace and where they are structurally behind. It also covers how to tell a legitimate customer's agent from a malicious one, and what defending with agents looks like when regulators still expect a human in the loop.