AI Is Now Both a Shield and a Weapon in Financial Crime. Here's Why Banks Are Losing Ground.
Artificial intelligence is creating a peculiar symmetry in financial crime: the same machine learning tools that help banks detect fraud are now helping criminals commit it at scale. Banks have used AI for years to score transactions and spot unusual behavior, but generative AI is now arming the criminal side with comparable automation. The result is not a simple story of AI making fraud worse; it is an accelerating arms race in which both defenders and attackers become faster simultaneously.
How Are Banks Currently Using AI to Fight Fraud?
Financial institutions have already made substantial investments in AI-powered fraud detection. In March 2026, the European Central Bank reported that nearly 90% of significant euro-area banks were using AI, with fraud and cybercrime detection the most common use case, deployed by more than half of banks. This is no longer experimental technology; it has become part of core risk infrastructure.
Traditional fraud controls rely on known patterns: a card used in an unusual country, a login from a new device, or a transfer far larger than normal. But criminals learn these rules too. Machine learning changes this by combining many weak signals that rules-based systems miss. A payment may not look suspicious in isolation, but its device, counterparties, timing, velocity, account history, and links to other accounts can form a revealing pattern.
The BIS Innovation Hub's Project Hertha demonstrated the potential at the payment-system level. In a synthetic dataset covering 1.8 million accounts and 308 million transactions, payment-system analytics helped banks and payment service providers identify 12% more illicit accounts than they would otherwise have found. For previously unseen criminal behaviors, the improvement reached 26%.
What New Threats Are Criminals Creating With Generative AI?
The most disruptive use of generative AI in fraud may not be technical intrusion at all. It is persuasion at scale. Generative AI lowers the cost of producing convincing stories in the language, tone, accent, and visual format most likely to succeed. FINRA's 2026 regulatory oversight report warns that generative AI can now generate false identification documents, deepfake audio and video, polymorphic malware, and malicious tools that allow people without advanced technical skills to conduct more sophisticated attacks.
The 2026 INTERPOL Global Financial Fraud Threat Assessment found that AI-enhanced fraud was 4.5 times more profitable than traditional methods in the activity assessed, and warned that agentic AI can increasingly automate whole fraud workflows. A separate Operation First Light 2026 involved 97 countries and territories, led to 5,811 arrests, and intercepted $293 million in illicit assets linked to social-engineering scams and associated laundering.
This technology also broadens the labor pool available to criminals. If a generative model can produce working code, translate scripts, personalize phishing messages, and create synthetic media, capability diffuses to a larger number of attackers. The economics of cybercrime depend partly on scarce expertise; generative AI is democratizing that expertise.
Steps Banks Are Taking to Defend Against AI-Enabled Fraud
- Multi-Signal Identity Verification: Banks are moving away from single-point identity checks toward risk models that test identity through multiple independent signals, including document provenance, device reputation, account history, behavioral patterns, trusted data sources, liveness checks, and transaction context.
- Network-Level Pattern Recognition: Payment systems are aggregating data across institutions to spot criminal activity that individual banks cannot see. Criminals frequently distribute activity across many accounts; a single bank sees fragments, while a payment system can see relationships.
- Behavioral Monitoring and Anomaly Detection: AI systems combine transaction behavior, KYC (Know Your Customer) information, and network patterns to find combinations that rules-based monitoring may miss, enabling faster detection of emerging fraud tactics.
- Continuous Feedback Loops: The decisive advantage will belong to the side that combines data, identity, behavioral intelligence, and rapid feedback most effectively, requiring banks to continuously update their models based on new attack patterns.
The Financial Crimes Enforcement Network reported in November 2024 that it had observed an increase in suspicious-activity reporting describing suspected deepfake use, particularly fraudulent identity documents intended to bypass verification and authentication. By 2026, the European Banking Authority was likewise warning that AI could be used to forge documents, generate deepfakes, automate laundering schemes, and evade detection.
Why the Advantage May Shift Toward Criminals
Banks have richer transaction histories, regulated identities, network visibility, and the ability to delay or stop money. But criminals can iterate cheaply, attack outside bank perimeters, and increasingly manipulate the customer rather than the account. The strongest identity architecture will increasingly resemble a risk model rather than a one-time check, but this requires constant evolution.
Fraud is shifting from stealing credentials to manipulating the customer. Strong customer authentication remains effective against the fraud types it was designed to prevent, but as defenses improve, attackers move to social engineering and deepfake-enabled impersonation, which operate outside the technical security perimeter.
What Role Does AI Governance Play in Cybersecurity Strategy?
Beyond fraud detection, cybersecurity leaders are recognizing that AI itself creates new categories of risk. Threat actors are leveraging AI to develop more sophisticated phishing attacks, automate malware creation, conduct deepfake-enabled fraud, and execute highly targeted social engineering campaigns. The growing adoption of AI introduces challenges related to data privacy, model security, algorithmic bias, intellectual property protection, and regulatory compliance.
"AI will be both a powerful defensive capability and a new attack surface. Organizations that establish strong AI governance and risk management frameworks will be better positioned to harness its benefits whilst minimizing emerging risks," stated Madan Mohan, Director at BDO UAE.
Madan Mohan, Director at BDO UAE
Organizations must address risks such as unauthorized AI usage, data leakage through AI platforms, and manipulation of AI models through adversarial attacks. As AI adoption accelerates, cybersecurity programs must evolve to include AI governance, model risk management, secure AI development practices, and continuous monitoring of AI systems.
The contest between defenders and attackers is becoming less about who has AI and more about whose data, feedback loops, and controls learn faster. Banks that can aggregate insights across their networks, update their models in real time, and maintain multiple layers of behavioral verification will maintain an edge. But the window for establishing that advantage is narrowing as generative AI tools become cheaper and more accessible to criminal organizations worldwide.