Industry urges unified rules to curb AI-enabled fraud

Webinar experts warned AI-enhanced financial fraud is about 4.5x more profitable and called for industry-wide regulatory reform and improved data sharing.

In a webinar hosted in association with Ecommpay, industry experts said fraud has shifted from technical exploits to targeting human psychology. They referenced an Interpol assessment and reported that AI-enhanced attacks are roughly 4.5 times more profitable than traditional methods.

The panel included Willem Wellinghoff, UK chair and chief compliance officer at Ecommpay; Anne Leslie, head of cloud risk EMEA at IBM; and Pallavi Kapale, senior financial crime officer at Bank of China. Teresa Connors moderated the session.

Panelists described how fraudsters use social engineering combined with AI tools to create scams that are difficult for consumers and institutions to detect. Examples cited included phishing, deepfakes and automated social manipulation that scale quickly and can appear normal to trained reviewers.

Speakers said firms are developing separate controls and detection systems, which fragments defences across the ecosystem. They pointed out that multiple oversight bodies-from banking regulators to data protection authorities and law enforcement-have responsibilities that touch fraud prevention, and no single authority holds end-to-end responsibility. That, the panelists argued, produces inconsistent rules for reporting, information sharing and response.

Suggested regulatory changes included interoperable reporting standards, legal frameworks to enable safe and timely sharing of fraud indicators, and proportionate requirements that scale with a company’s size and risk profile. Panelists said a standardised process could speed detection and response, reduce duplicate investigations and allow smaller firms to benefit from pooled intelligence.

Experts identified legal and practical barriers to information sharing, including data protection laws, cross-border transfer restrictions, competition rules and liability concerns. They discussed options such as anonymised data exchanges, trusted non-profit platforms and regulatory safe harbours, and noted that establishing trust, governance and sustainable funding for any shared platform would be difficult and time-consuming.

On implementation, the panel said standardisation could enable faster cross-sector alerts and a common taxonomy for classifying incidents, but cautioned standards may lag behind attackers and could conflict with national regulations. The speakers recommended international regulatory coordination and starting with focused pilots that involve banks, payment firms, technology providers and law enforcement.

Teresa Connors closed the session by warning that individual action is no longer sufficient to address modern financial crime and that safer ways to share fraud intelligence will be needed to counter human-targeted and AI-enabled attacks.

Articles by this author