By
Stuart Kerr, Technology Correspondent, LiveAIWire
Financial fraud is no longer a crime of opportunity. It has become
a sophisticated, technology-driven industry, and the criminals running it
have access to the same artificial intelligence tools that banks use to catch
them. The result is an escalating arms race in which each advance in
detection is matched by a new mutation in attack, and the stakes are hundreds
of billions of dollars annually across the global economy.
The UK’s payment industry body, UK Finance, reported losses of
1.17 billion pounds to fraud in 2023, a figure that the organisation’s
analysts expect AI-enabled fraud to increase significantly in coming years.
In the United States, the Federal Trade Commission documented consumer fraud
losses exceeding 10 billion dollars in 2023, the first time that threshold
had been crossed. These are not the losses of a problem under control. They
are the losses of a problem accelerating.
How Generative AI Has Changed the Fraud
Landscape
The introduction of accessible generative AI tools has altered the
economics of financial fraud in ways that are still being absorbed by the
institutions tasked with preventing it. Creating a convincing fraudulent
document, voice, or video once required significant skill and time.
Generative AI has democratised that capability. A sophisticated deepfake
audio clip impersonating a CEO, used to authorise a wire transfer to a
fraudster’s account, can now be produced in minutes by someone with no
technical background and a basic laptop.
Europol’s 2024 report on the criminal use of artificial
intelligence documented the emergence of fraud-as-a-service operations in
which criminal groups offer AI-powered fraud tools to other criminals on a
subscription basis. These operations provide deepfake generation, AI-written
phishing campaigns tailored to specific targets, and even automated customer
service bots that handle victim communications on behalf of scammers. The
professionalisation of fraud infrastructure is accelerating, and the entry
barrier for new participants is falling.
Synthetic identity fraud, in which AI is used to construct
plausible but fictitious individuals complete with fabricated credit
histories and supporting documentation, has become one of the fastest-growing
categories of financial crime. The US Federal Reserve has estimated that
synthetic identity fraud costs lenders over six billion dollars annually, and
detection is particularly challenging because the victim does not exist to
report the crime.
The AI Counter-Response from Financial
Institutions
Banks and payment processors have not been passive in the face of
this threat. The application of machine learning to fraud detection predates
the generative AI wave, and institutions that invested early in these
capabilities have built detection infrastructure that is genuinely powerful.
Transaction monitoring systems now process millions of events per second,
evaluating each against behavioural baselines, device fingerprints, location
data, and network analysis to assign real-time risk scores.
The OECD’s
analysis of AI in financial services found that institutions using
machine learning for fraud detection had reduced false positive rates by up
to 80 percent compared with rules-based systems. That reduction matters
enormously in practice: false positives mean legitimate customers whose
transactions are declined or accounts are frozen, generating complaints,
regulatory scrutiny, and customer churn. A detection system that is too
aggressive costs institutions money and trust even when it is technically
correct.
Behavioural biometrics represent one of the more innovative
applications of AI in fraud prevention. These systems analyse how a user
interacts with a banking app or website, measuring typing rhythm, mouse
movement patterns, screen pressure on mobile devices, and the sequence and
timing of navigation actions. The profile of how a legitimate account holder
uses their bank is highly distinctive, and deviations from that profile, such
as those that occur when a criminal has stolen credentials and is accessing
the account, generate alerts even before any suspicious transaction is
attempted.
What This Means for You
For consumers, the most visible consequence of AI in fraud
detection is the occasional declined transaction or account lock that is
triggered by unusual but entirely legitimate activity. Travelling abroad,
making an unusually large purchase, or logging in from a new device can all
generate false positive alerts. While frustrating, these interventions
represent AI systems doing what they were designed to do, and the
alternative, systems that never trigger false positives, would be systems
that also miss genuine fraud.
The more significant consumer impact is on the other side of the
ledger: AI-powered fraud that targets individuals directly. Deepfake phone
scams in which criminals impersonate bank security teams, family members in
apparent distress, or government officials demanding immediate payment are
increasingly convincing and increasingly prevalent. The Europol
digital hydra report on AI-enabled crime identified voice cloning
as one of the highest-priority emerging threats, noting that the quality of
synthetic voices had reached a point where most listeners could not reliably
distinguish them from authentic recordings.
Protecting yourself requires awareness of the tactics rather than
technical counterficiency. No bank will ask you to transfer money to a safe
account to protect it from fraud. No government agency will demand immediate
payment by gift card. Any communication that creates urgency, asks for
secrecy, or requests an action you would not normally take should be verified
through a channel you initiate independently, not through contact details
provided in the suspicious communication itself.
Regulatory Pressure and Liability Questions
Regulators on both sides of the Atlantic are intensifying their
engagement with AI in financial services, and the direction of travel is
toward greater accountability for both fraud prevention failures and for AI
systems that cause harm to consumers. The European
Commission’s consultation on AI in financial services published in
2024 identified a governance gap in which powerful AI systems were being
deployed without adequate frameworks for explaining, auditing, or challenging
their decisions.
In the UK, the Payment Systems Regulator introduced requirements
in 2024 obliging banks to reimburse customers for authorised push payment
fraud in most circumstances. This shift in liability is significant because
it creates direct financial incentives for institutions to invest in better
fraud prevention, rather than simply deflecting losses onto customers. Banks
that cannot prevent APP fraud will bear its cost, which concentrates minds on
the effectiveness of detection systems.
The US Federal Trade Commission’s Operation AI Comply, launched in
September 2024, signalled that American regulators are prepared to pursue
enforcement actions against companies that deploy AI in misleading or harmful
ways, including in fraud schemes that exploit consumer trust. The combination
of regulatory pressure, liability shifts, and reputational risk is driving
investment in fraud prevention infrastructure at a rate that the industry had
not previously seen.
The Explainability Problem in Fraud Detection
One underappreciated tension in AI-powered fraud detection is
between effectiveness and explainability. The most accurate fraud detection
models are typically the most complex: deep neural networks that identify
patterns across hundreds of variables simultaneously, producing risk scores
that cannot be translated into simple human-readable reasoning. These models
work, but they cannot easily explain why they flagged a particular
transaction.
This matters for two reasons. The first is regulatory: frameworks
including the EU’s General Data Protection Regulation give consumers the
right to an explanation of automated decisions that affect them. A bank that
freezes an account on the basis of an AI decision it cannot explain is
potentially in breach of that requirement. The second reason is operational:
fraud teams investigating a flagged account need to understand why the alert
was generated in order to assess whether it warrants escalation. An opaque
score provides less information than a model that can articulate its
reasoning.
The financial industry is investing significantly in explainable
AI approaches that aim to preserve accuracy while generating interpretable
outputs. Progress has been made, but the fundamental trade-off between model
complexity and human comprehensibility remains a genuine constraint. The
ideal fraud detection system would be both maximally accurate and fully
transparent; in practice, institutions are managing a compromise.
The Cross-Border Dimension
Financial fraud does not respect national borders, and this
creates significant challenges for both detection and prosecution. Criminal
networks operating fraud schemes across multiple jurisdictions can exploit
inconsistencies in regulatory frameworks, legal assistance requirements, and
the willingness of different governments to cooperate on enforcement. A fraud
operation run from one country targeting victims in another may involve
financial flows through a third, making asset recovery and prosecution
extraordinarily complex.
International financial intelligence units share information
through networks including the Egmont Group, and AI is being applied to
cross-border transaction analysis to identify networks of accounts involved
in money laundering and fraud. But the pace of information sharing remains
slower than the pace of criminal adaptation, and differences in privacy law between
jurisdictions constrain what data can be shared and how.
As LiveAIWire has examined in analysis of AI
in tracking trafficking and dark networks, the structural challenge
is consistent across domains: the tools exist, but the international
cooperation frameworks needed to use them at full effectiveness are lagging
behind. Building those frameworks is a diplomatic and legal task that
technology alone cannot accomplish. The parallel with legal AI adoption,
covered in LiveAIWire’s
examination of AI in courtroom proceedings, is instructive:
technical capability consistently outpaces the governance structures designed
to keep it accountable.
About the Author
Stuart Kerr is the Technology Correspondent at LiveAIWire,
covering artificial intelligence across society, policy, and industry. About
LiveAIWire.