Regulators, Industry Must Unite to Fight AI-Driven Fraud
Panelists warned fraud now targets people over systems and urged shared standards, data sharing and regulatory reform after a webinar hosted with payments firm Ecommpay.
Industry experts at a webinar hosted with payments firm Ecommpay said financial fraud has shifted from exploiting technical gaps to targeting human vulnerabilities. Panelists cited an Interpol assessment that describes financial fraud as one of the world’s most severe and rapidly evolving transnational crimes and noted that AI-enhanced fraud can be about 4.5 times more profitable than traditional methods.
Speakers explained that social engineering and automated tools make scams harder for both consumers and institutions to spot. The panel included Willem Wellinghoff, UK chair and chief compliance officer at Ecommpay, with Teresa Connors serving as moderator.
Panelists identified three main barriers to system-wide prevention. First, responsibility for fraud prevention is split across multiple regulators and oversight bodies, leaving no single authority with end-to-end oversight. Second, companies develop separate fraud controls and data rules, which fragments response efforts and limits timely sharing of threat information. Third, legal and operational limits, including privacy rules, competition concerns and technical incompatibilities, block rapid data exchange and coordinated action.
Recommendations for regulatory reform focused on clearer roles and standards that scale to different firm sizes and risk levels. Proposed elements included rules that enable cross-industry data sharing, common incident reporting formats, safe-harbour protections for organisations that share threat intelligence in good faith, and proportional compliance requirements to reduce the burden on smaller firms.
The panel examined the merits and limits of standardised fraud processes. A common set of procedures and data standards could speed detection, cut duplicated effort and let firms act on shared signals more quickly. Panelists also noted drawbacks: a single standard could become the lowest common denominator across sectors, implementation could be costly for small companies, and data protection and competition laws would need resolving before any protocol could work across borders.
Speakers considered a non-profit, centralised model that would host anonymised data feeds, coordinate incident responses and maintain baseline standards. Obstacles discussed included governance, funding, cross-border legal compliance and the reluctance of some firms to share commercially sensitive signals.
Panelists recommended a layered response that keeps consumer education while changing structures. They urged stronger authentication and transaction monitoring, improved public-private information flows, and regulatory incentives for cooperation. They also cautioned that consumer awareness alone will not stop scams that imitate legitimate communications and exploit routine behaviour.
The webinar closed with a call for coordinated pilot programmes to test standard processes and legal frameworks on a limited scale. Panelists recommended pilots include regulators, large and small firms and non-profit groups to assess technical feasibility, legal constraints and costs before broader implementation.








