Banks race to unite teams as AI fraud outpaces controls
The gist
Banks are scrambling to unite siloed anti-fraud, AML, and KYC teams as AI-powered scams outstrip traditional controls, forcing a radical rethinking of financial crime defense.
What to know
- AI-driven scams like deepfake social engineering and authorized push payment fraud have exploded since 2022, shrinking banks’ fraud detection windows to as little as 30 seconds.
- 97% of financial institutions are moving toward convergence strategies—integrating teams and sharing intelligence—which has delivered a 3.4x boost in fraud prevention performance.
- Regulators from Australia to Southeast Asia now demand near real-time fraud monitoring and personal accountability, while banks are teaming up with telecoms and social media giants to battle increasingly sophisticated AI-enabled financial crime.
Breaking Down Data Silos
Banks are dismantling traditional barriers between compliance teams, building shared intelligence layers to spot hidden fraud patterns that siloed approaches routinely miss.
By mid-2026, it became clear that traditional siloed approaches to AML, fraud, and KYC were increasingly inadequate against sophisticated financial crime networks that exploit gaps between these isolated controls. Scott Nice, CRO of Label, emphasized that financial crime 'does not operate in silos,' warning that independent teams often miss risk patterns that only emerge through shared intelligence across functions. This recognition sparked growing momentum for convergence strategies aimed at integrating compliance frameworks to reveal hidden threats and improve risk decision-making.
However, convergence is not about dismantling specialist teams but connecting them through a shared intelligence layer, enabling experts to leverage a unified understanding of risk rather than fragmented data. Taami Tamkivi, CEO of Salv, highlighted the practical benefits of this approach in combating scams and authorized push payment (APP) fraud, where victim feedback loops create transactional pressure that integrated AML, fraud, and KYC monitoring can effectively address. Yet, Tamkivi cautioned that over-focusing AML efforts on fast-return areas like scams risks overlooking complex, large-scale money laundering cases such as the Swedbank scandal, which lacked obvious victim complaints or feedback loops.
The push for convergence is further propelled by rapid technological advances, economic pressures, and the accelerating evolution of AI-enabled criminal tactics that exploit isolated controls. Jon Elvin noted that the speed at which bad actors adapt demands a holistic, cross-channel risk management approach, prompting many institutions to transition from monolithic platforms to modular, AI-driven architectures capable of agile responses. This shift marks a proactive reassessment of compliance structures, moving beyond the historical pattern of reactive organizational changes triggered by fraud losses or AML failures.
Despite the enthusiasm for integrated models, there remains no consensus that full convergence is the singular solution; both integrated and siloed frameworks can succeed or fail depending on execution quality. This nuanced view underscores that while convergence offers promising advantages, institutions must carefully balance integration with the preservation of specialist expertise to effectively combat the evolving landscape of financial crime.
AI Scams Redefine Risk
AI-powered deepfakes and social engineering have forced banks to abandon static fraud controls, driving a shift to behavioral analytics and real-time intervention for threats that now bypass legacy defenses.
By mid-2026, AI-driven fraud had escalated from a nascent threat to a pervasive operational crisis for banks worldwide, with incidents and losses surging by triple- and quadruple-digit percentages since 2022. Fraudsters increasingly leveraged AI to bypass traditional authentication mechanisms at scale, rendering once-reliable security gates ineffective. This shift compelled financial institutions to adopt sophisticated graph and network analysis techniques to detect complex fraud rings by mapping relationships among accounts, devices, and beneficiaries—an approach essential for uncovering patterns invisible to isolated transaction reviews.
Authorized Push Payment (APP) scams emerged as the most vexing challenge in 2026, exploiting the very trust banks place in legitimate user credentials and devices. Because these scams involve customers authorizing transactions—often under manipulation—traditional fraud controls fail to flag them, as the transactions appear normal from the institution’s perspective. This vulnerability was starkly illustrated by a lawsuit against PNC Bank, where employees overlooked clear behavioral deviations during large transfers, underscoring the urgent need for real-time intervention protocols and advanced behavioral analytics capable of detecting subtle signs of coercion or manipulation.
The rapid rise of AI-powered deepfakes and synthetic identities has transformed fraud tactics from direct system breaches to sophisticated social engineering attacks that manipulate customers into authorizing fraudulent payments. According to the American Bankers Association, criminals increasingly rely on AI-generated audio and video to impersonate trusted parties, making social engineering more effective than traditional hacking. In response, banks have had to move beyond static authentication methods like passwords and one-time codes, embracing layered defenses including behavioral biometrics, continuous authentication, and real-time fraud analytics to maintain digital trust in an environment where detection windows have shrunk dramatically.
The acceleration of payment technologies such as real-time payments and stablecoins has compressed fraud detection windows from 15 minutes to as little as 30 seconds, intensifying operational pressures on banks to detect and halt fraudulent transactions almost instantaneously. This rapid execution leaves little room for error or delay, forcing financial institutions to significantly increase fraud detection budgets—68% year-over-year—and invest heavily in AI-driven behavioral analytics and network-based monitoring. However, banks face a delicate balancing act: introducing friction to slow payments risks degrading customer experience, yet insufficient controls invite escalating fraud losses, creating a precarious tightrope for fraud prevention strategies.
Collaboration Supercharges Defenses
Operational convergence—integrating fraud and cybersecurity teams with shared data—has delivered a 3.4x boost in fraud prevention, outpacing the benefits of structural reorganization alone.
By mid-2026, empirical research from Accertify and Liminal demonstrated that fraud-cyber convergence dramatically enhances financial crime prevention, with organizations embracing four key operational pillars—shared accountability, integrated data platforms, board-level engagement, and formal team integration—achieving a 3.4x performance advantage in approved transactions per dollar of fraud lost. Crucially, data sharing between fraud and cybersecurity teams emerged as the foundational driver of improved precision and reduced chargebacks, surpassing the benefits of structural reorganization alone. Maryling Yu, CMO of Accertify, emphasized that operational collaboration and shared workflows must precede formal restructuring to realize optimal outcomes, underscoring that 97% of organizations are already pursuing convergence driven by operational necessity rather than top-down mandates.
In a parallel organizational innovation, the Accredited Standards Committee X9 launched the Payment Fraud Forum in September 2023 to tackle the longstanding fragmentation in fraud data sharing across payment types. By shifting focus from institution-centric detection to network-wide recognition, the forum—backed by key players like the Federal Reserve Financial Services and The Clearing House—aims to standardize fraud definitions and reporting, thereby enhancing interoperability and detection precision industry-wide. This initiative builds on the Check Fraud Industry Forum’s legacy, expanding from single-rail to cross-rail fraud models and incorporating corporate treasury data such as supplier and invoice information to enrich fraud intelligence and fortify B2B payment security.
Governance Faces the AI Test
Regulators are holding executives personally accountable as AI-driven scams outpace legacy controls, prompting sweeping governance reforms and record penalties for cyber risk failures.
The emergence of AI-driven financial crimes such as voice cloning and deepfakes has catalyzed a fundamental shift in governance responsibilities within financial institutions, particularly in the Philippines and broader Southeast Asia. Carlo Lazatin highlights that AI's influence on credit decisions and fraud detection elevates these issues beyond IT departments to the realm of leadership accountability, necessitating governance frameworks that enable swift, clear decision-making and risk control. Mel Migriño further underscores the urgency as AI-powered scams proliferate, demanding institutions adapt their governance to counter increasingly sophisticated fraud tactics.
Globally, governments and regulators are grappling with how to effectively regulate and govern AI to close the widening gap between AI-enabled fraudsters and public sector responses. New governance obligations emphasize proactive prevention, requiring institutions to verify citizen identity, behavior, and devices before payments are made, rather than relying solely on detection. However, public agencies face challenges around data privacy, auditability, and AI biases, which slow large-scale AI deployment despite its potential to enhance fraud prevention and accountability. Successful governance models prioritize departmental autonomy for rapid data access and action, sidestepping protracted enterprise-wide transformations.
In Australia, regulatory frameworks are evolving rapidly to address AI-enabled financial crime through collaborative enforcement and comprehensive governance reforms. Agencies like AUSTRAC, ASIC, and APRA are actively working with industry and law enforcement to combat AI-driven mortgage fraud, while the Cyber Security Act 2024 establishes stringent cybersecurity requirements for products and incident response. The Financial Accountability Regime (FAR), effective since March 2025, introduces personal civil penalties for accountable persons, underscoring that cybersecurity is a core governance obligation. Enforcement actions, such as the $2.5 million penalty against FIIG Securities for cyber governance failures, signal escalating regulatory consequences for inadequate AI risk management.
Regulatory bodies worldwide are tightening fraud monitoring rules to mandate comprehensive, risk-based, and data-driven detection capabilities that extend beyond payments to include logins, device changes, and session anomalies. Boards are now expected to actively oversee fraud risk appetite, review aggregate metrics, and ensure independent challenge is properly resourced. Frameworks like India’s RBI Master Directions and the EU AI Act exemplify this trend by requiring near real-time monitoring, explainable AI models, and human oversight. In Australia, the upcoming Scams Prevention Framework and AFCA’s proposal to raise scam-loss compensation caps to A$1.263 million reflect a broader shift toward institutional accountability and consolidated complaint handling to combat AI-enabled scams effectively.
Global Push for Real-Time Controls
Countries from South Africa to the Asia-Pacific are mandating real-time intelligence sharing and AI-powered monitoring, but legacy systems and privacy concerns threaten to slow the transition.
South Africa’s COFI Bill represents a bold attempt to dismantle the country’s fragmented financial crime compliance landscape by uniting AML, fraud risk, and prudential risk teams under a single regulatory framework. This integration mandates real-time monitoring and audit trails for boards of accountable institutions, compelling them to provide the Financial Intelligence Centre with precise evidence of control measures. By encouraging real-time intelligence sharing powered by embedded AI and RegTech partnerships, COFI aims to match the coordination of sophisticated criminal networks, although many firms still face significant challenges due to legacy, siloed AML processes.
Across the Asia-Pacific region, governments are grappling with AI-enhanced fraud that outpaces traditional detection methods, prompting a strategic pivot from reactive 'pay and chase' tactics to proactive prevention. Agencies are empowering individual departments with direct data access to accelerate fraud prevention, leveraging AI tools like machine learning, network graph analysis, and natural language processing to uncover complex illicit networks and high-risk transactions. Yet, despite AI’s promise, concerns around data privacy, auditability, and bias temper large-scale adoption, underscoring the delicate balance between innovation and governance.
The Asia-Pacific’s regulatory landscape is evolving rapidly to address AI-driven scams, with frameworks such as Australia’s forthcoming Scams Prevention Framework elevating scam prevention to a core governance and business resilience priority. Leaders like Harshvendra Soin warn against static incident playbooks, advocating for dynamic, regularly tested response plans involving senior decision-makers to effectively counter increasingly sophisticated AI-enabled attacks. Meanwhile, clarity around accountability for AI’s role within business systems remains critical, as Allan James Waddell emphasizes the need to understand where AI operates and who bears responsibility when failures occur.
Emerging sectors such as EMIs and FinTechs face acute challenges from fragmented AML and fraud detection systems, which hinder visibility into complex layering schemes exploited by criminals. Many EMIs are transitioning from patchwork point solutions to unified AML platforms that centralize customer risk profiles and automate workflows, reducing false positives and operational overhead. Similarly, FinTechs are urged to build strong KYC foundations and integrate fraud detection via APIs into unified compliance stacks, enabling continuous monitoring essential for managing evolving risks in fast-growing payments, lending, and crypto businesses.
People: The Weakest Link
Despite advanced tech, human error and low financial literacy remain prime targets for AI-driven fraud, with banks ramping up behavioral analytics and education to close the gap.
Human behavior remains a pivotal factor in scam prevention, as fraudsters increasingly exploit social engineering to manipulate customers into authorizing transactions. Despite robust authentication processes, banks like PNC have struggled to intervene effectively when customers deviate from their usual patterns under external influence, highlighting operational challenges in acting on behavioral warnings. This underscores the necessity of understanding user actions deeply, as James Roberts of Commonwealth Bank emphasizes that by the time a payment is made, the deception has already succeeded.
Financial literacy emerges as a critical frontline defense against sophisticated scams, especially those powered by AI and deepfakes, where a significant confidence gap exists between consumers' perceived and actual ability to detect fraud. Visa's Yevgen Lisnyak stresses that many frauds succeed not due to weak security but because of human susceptibility, advocating for enhanced financial education and regulatory cooperation to empower users against evolving threats.
The escalating complexity of fraud schemes has driven financial institutions to boost fraud detection budgets substantially, with 68% increasing investments year over year to counteract the rise in sophisticated attacks reported by 46% of institutions. This urgency has catalyzed the adoption of behavioral analytics and AI, utilized by over 60% of banks, enabling a shift from reactive to proactive fraud defenses that detect subtle anomalies beyond fixed rules.
Combatting fast-moving AI-enabled scams demands ecosystem-wide collaboration that transcends traditional banking boundaries, integrating social media, messaging platforms, telecoms, and identity systems. Commonwealth Bank’s innovative ‘Pollen Team’ exemplifies this approach by deploying AI agents to engage scammers in over 350,000 interactions, extracting real-time intelligence to thwart fraud attempts. Similarly, Visa leverages its global payment network to share fraud intelligence across markets, partnering with regulators like the Central Bank of Uzbekistan to disseminate protective rules and promote financial literacy, illustrating the critical role of cross-sector cooperation in safeguarding consumers.



