Calls grow for unified response to AI-enhanced fraud

Experts say fraud now targets human psychology; AI-enhanced scams are 4.5x more profitable and fragmented rules plus limited data sharing block coordinated responses.

Industry experts at a webinar hosted by payments firm Ecommpay reported that fraudsters have shifted from exploiting technical flaws to targeting human psychology, using personalised messages and AI tools that make scams harder to spot. Interpol warned during the event that AI-enhanced fraud is about 4.5 times more profitable than traditional methods and is widening the scale and sophistication of attacks.

The online event featured Willem Wellinghoff, UK chair and chief compliance officer at Ecommpay; Anne Leslie, head of cloud risk EMEA at IBM; and Pallavi Kapale, senior financial crime officer (FIU) at Bank of China. Teresa Connors moderated the session.

Panel participants described how scammers use data and automation to craft highly specific messages aimed at individuals and staff, increasing the chance of success for both consumer-facing and business-targeted fraud. They said that because attacks now exploit behaviour as much as systems, individual consumers and single firms cannot reliably stop them alone.

Speakers outlined regulatory hurdles that limit a coordinated response. Multiple oversight bodies have roles that touch on fraud prevention, leaving no single authority with end-to-end responsibility. Differences in rules on data sharing, privacy and competition create conflicts that complicate cooperation across sectors. The panel also pointed to limited and inconsistent sharing of fraud data among banks, payment providers and other firms, which can lead to duplicated effort and detection gaps.

Participants discussed regulatory and industry measures that could help. Ideas raised included a common framework to set baseline standards for reporting and information exchange, obligations scaled to firm size, legal safe harbors for sharing threat indicators and clearer lines of oversight to reduce overlap between agencies. The group also examined standardised industry processes such as common response playbooks, shared detection rules and uniform data formats to speed responses and reveal broader attack patterns.

Panellists identified practical barriers to those proposals. They cited diverging national regulations, strict data-protection laws, competition rules that limit collaboration, commercial sensitivities and the cost and technical burden of implementing uniform systems for smaller firms. On the proposal for a systemic non-profit body to pool resources, speakers said legal limits on cross-border data exchange and uneven resources across firms would need to be addressed. Suggested incentives included subsidised access to shared tools for smaller firms and regulatory carve-outs to allow pooling threat data for defence purposes without breaching privacy rules.

The webinar framed the discussion around options regulators and firms can consider to improve coordination, data sharing and detection, but participants did not present a single solution.

Articles by this author