Artificial intelligence does not create fraud, but it increases its speed, scale, and credibility. The rise of AI agents has created a new attack surface: the AI itself. For companies, the challenge is now double: protect their customers from impersonation and secure agents capable of acting at the heart of customer relations. Fraud in customer relations is not new, with methods such as phishing, smishing, number impersonation, fake advisors, or social engineering existing long before generative AI. What has changed today is the ability to automate these attacks, to personalize them, and to make them much more credible on a large scale. Voice and video deepfakes further complicate the distinction between a legitimate interaction and an impersonation attempt. Gartner estimated that by 2026, 30 percent of companies would consider that identity verification and authentication solutions are no longer sufficiently reliable when used alone, particularly due to AI-generated deepfakes. For customer relations, the consequence is direct. A phone number, a voice, or even a face no longer necessarily establish trust. Companies must therefore solve a new problem: continue to effectively reach their customers while traditional signs of trust have become imitable. With AI agents, the attacker no longer targets only the customer. The second change is even more profound. Until now, companies mainly sought to protect their customers from fraudsters who impersonated them. With AI agents, a new attack surface appears within the customer relationship itself. A chatbot responds, an AI agent can act. It can consult a file, access data, trigger a workflow, call an API, or modify information. This autonomy explains its potential, but it also explains the risk. Gartner estimates that 80 percent of common customer service requests could be resolved autonomously by AI agents by 2029. The more these agents take on actions, the more their misuse will become interesting to fraudsters. Prompt injection illustrates this evolution. The objective is no longer solely to make AI produce an incorrect response. An attacker may seek to make it reveal information, bypass a business or security rule, access a resource, or execute an action that should not be authorized. Security must therefore evolve alongside autonomy: the agent's identity, the rights granted, the scope of action, client authentication, control of accessible tools, and traceability of decisions become an integral part of service design. The response involves demonstrable trust and continuous control. In the face of these risks, the objective is not to seek a single protection against fraud or against prompt injection. It is necessary to multiply controls and position them correctly within the interaction. On the AI agent side, this means testing their behavior before deployment, simulating adversarial scenarios, limiting their permissions, monitoring conversations and actions performed, and then using observed incidents to continuously enrich test scenarios. An AI agent should not be considered secure once and for all: its control must accompany the evolution of the model, the prompt, the tools it accesses, and the uses entrusted to it. The same logic must apply to the relationship with the customer. A brand must be able to prove who is calling, notably through Branded Call; prove who is writing, with channels such as verified RCS; and strengthen authentication when the requested action becomes sensitive. As interactions blend humans, automation, and AI agents, the challenge will be less about recognizing a voice or a number than having verifiable evidence of each person's identity and rights. This is where AI orchestration becomes strategic. It is no longer simply about choosing a channel or routing an interaction. It must allow deciding which agent can intervene, which data is accessible to it, which actions it can perform, when additional authentication is necessary, and when control must return to a human. Fraud thus leads us into a new phase of customer relations: trust can no longer be implicit. It must be built, verified, and controlled throughout the interaction.