>>
Industry>>
Fintech and Financial Services>>
Karina Portugal: Your Agent Ha...FINTECH AND FINANCIAL SERVICES
Karina Portugal is Director of Banking, Marketplaces, Strategic Partnerships and Agentic Trust at Prove Identity. She works with major banks, fintechs and marketplaces in the United States, Brazil and Latin America, at the intersection of digital identity, fraud, artificial intelligence and business strategy. The conversations she is brought into tend to start the same way. An institution has a number it does not like. Fraud losses are climbing, or onboarding conversion has fallen, or a launch is running late.
What Portugal does first is decline to take that question at face value.
“Most of the time the problem an institution describes is a symptom of a decision made three years earlier about identity,” she said. “If you solve the question they arrive with, you buy them six months. If you find the question underneath it, you change how the business works.”
A decade across different layers of one problem
Portugal has more than ten years in enterprise financial services, specialising in fraud prevention, AML, KYC and digital identity, built across companies attacking the problem from different angles: behavioral risk and AI-driven fraud detection, transaction monitoring in banking and payments, and anti-money laundering.
“The ones that treated fraud as an isolated problem owned by one team kept buying tools and kept losing,” she said. “The ones that treated identity as shared infrastructure, used by onboarding and payments and servicing at the same time, started to get ahead. That is not a product observation. It is an organizational one.”
Verification as a state, not an event
Her argument is that identity has to stop being a gate. For most of the last decade institutions tested the assumption behind a transaction once, at the front door, through a one-time passcode sent to a phone, and the rest of the relationship inherited trust from that single moment.
A one-time passcode proves only that a code arrived somewhere. It does not prove that the phone number belongs to the person using it, that the number has not been ported to a new SIM that morning, or that the person is still in control of the session an hour later. Account takeover happens after onboarding. Authorized push payment fraud involves a legitimate customer, correctly authenticated, sending money to a criminal. Those risks are not fully addressed by a gate that opens once and stays open. The alternative is authentication that persists, built on phone-centric identity: the number itself, the tenure and history behind it, possession of the device, and the binding between the two.
Why the right question is rarely about fraud
Institutions usually arrive asking how to stop more fraud. Portugal’s reframing is that most verification friction is applied indiscriminately, because the institution has limited confidence about anyone. Better identity signals concentrate certainty where it belongs. Established customers are challenged less often, and scrutiny is reserved for cases that deserve it. Prevention, friction and conversion stop being competing goals and become outputs of the same system.
That reframing changes who belongs in the room. A fraud discussion sits with risk. A conversion discussion sits with product and growth. A multi-year infrastructure commitment sits with finance and legal. Portugal describes her role as that of a high-impact individual contributor, a model common in technology companies for people who lead through scope, influence and execution rather than through a reporting line. In practice she runs a cross-functional operation across commercial strategy, technology, product, finance and legal, from the first exploratory conversation through the business case and into negotiation of complex, high-value enterprise contracts.
Who owns identity inside the institution
The organizational version of the problem is harder than the technical one. Identity touches onboarding, payments, servicing and disputes, which in most institutions means it is owned by nobody in particular and budgeted for in four places at once.
“Every team ends up buying its own point solution for the piece it can see,” she said. “You get four contracts, four sets of signals that do not talk to each other, and a customer who has to prove who they are four separate times inside the same bank. Nobody designed that. It is what happens when identity has no owner.”
The question she is asking now
Pressure is rising from two directions. The first is that the credential most institutions still rely on, a code delivered to a phone, has become the weakest link, attacked through SIM swap, porting and interception, and through social engineering.
The second direction, and the one Portugal finds more consequential, runs the other way. Software agents have begun acting on behalf of people: booking travel, filling carts and paying with the customer’s card. Each is a transaction someone has to authorize. Agentic commerce creates a transaction type existing identity infrastructure was never designed to represent.
“We spent a decade building Know Your Customer,” she said. “What the industry needs now is Know Your Agent, and it asks something harder: is the thing acting on your behalf still the thing you trusted this morning. Authorization granted once, at deployment, tells you nothing about that. An agent that has been hijacked does not look hijacked.”
Her answer is continuous trust rather than static trust: authority that is scoped to a task, credentials that are short-lived, and verification that holds at every layer and every action instead of resolving once at the bottom of the stack.
Her current title includes Agentic Trust for that reason, and she is increasingly working on the identity and trust questions emerging around these systems, close to the founder, startup and AI communities in San Francisco, Palo Alto and New York where much of the experimentation is happening.
The through line in her work is not a product or a market. It is a conviction that identity is infrastructure, that infrastructure decisions made under pressure become expensive later, and that the institutions best prepared for the next generation of fraud will be the ones that asked the harder question early. On current evidence, that generation will not be entirely human.
Comments