An AI assistant can move money on your customer's behalf. Handshake holds the action until a live human says yes out loud, and checks that the voice is real.
Websites can now let AI assistants take real actions inside a logged-in session. There is currently no way for a website to insist that a human authorised one.
It is inside the session. Whatever the customer could do, it can do. Add a payee. Approve a payment. Reset multi-factor authentication. Change a registered address.
A dishonest website can hide instructions inside the actions it offers. Published research in 2026 achieved this against current models at rates reaching 100 per cent for some techniques.
You can label an action as read-only, which is advisory and any site can lie about. Or you can hope the assistant chooses to ask the user first. Neither is a control you could show an auditor.
The session is already authenticated. The question is not who logged in an hour ago. It is whether a live human is behind this specific action, right now.
You decide which actions are consequential. Everything else runs at full speed.
Almost none of it is new. This is a control we already run on live phone calls, moved to the browser.
Payment approval, payee changes and account amendments are exactly the actions a manipulated assistant would be pointed at, and exactly the ones a reimbursement regime makes expensive.
Password resets and multi-factor changes are the most attacked workflow in the business. An assistant that can perform them is a new way in.
If your site offers AI assistants a list of things they can do, and any of them matter, you currently have no way to require a human. Handshake drops in as a component.
Priced per protected workflow. Early-access pricing is set with our first design partners.
We are taking a small number of design partners now. The fastest way to understand it is a fifteen-minute call where we show you the clone being caught.