Regulators and industry urged to tackle AI-enhanced fraud
Panelists at an online webinar warned fraud now targets human vulnerabilities and urged regulatory reform and wider data sharing; Interpol says AI-enhanced fraud is 4.5 times more profitable.
An online webinar hosted in association with Ecommpay brought together industry specialists who warned that fraud is shifting from technical attacks to targeting people. The panel cited Interpol’s assessment that AI-enhanced fraud is 4.5 times more profitable than traditional methods and called for broader industry action.
The online panel featured Willem Wellinghoff, UK chair and chief compliance officer at Ecommpay; Anne Leslie, head of Cloud Risk EMEA at IBM; and Pallavi Kapale, senior financial crime officer (FIU) at Bank of China. Teresa Connors moderated the discussion.
Panelists described increased use of social engineering, identity spoofing and automated interactions that imitate legitimate users, which they said make scams harder for consumers and frontline staff to detect. They argued these tactics reduce the effectiveness of rule-based detection and of investigations confined to a single organisation.
Regulatory fragmentation and limited data sharing were identified as major obstacles to an industry-wide response. The panel noted that multiple oversight bodies cover different aspects of fraud prevention, leaving no single authority with end-to-end responsibility. Overlapping mandates, divergent national data-protection rules and concerns about competition and liability were listed as reasons organisations hesitate to share intelligence.
Speakers discussed a graduated regulatory framework that would require baseline reporting standards for all firms while imposing more advanced controls on entities with larger transaction volumes or systemic reach. They said such an approach could create consistent minimum standards without imposing the same compliance burden on smaller firms.
The panel examined a potential standardised fraud process. Expected benefits included faster cross-institution detection through shared indicators and common reporting formats that ease law-enforcement work, plus pooled resources to develop advanced detection tools for smaller firms. The group also flagged risks: a centralised solution could become a single point of failure or an attractive target, and uniform processes may not fit all business models or legal regimes.
Panelists outlined hurdles to creating a single non-profit system: establishing governance, securing sustainable funding, ensuring cross-border legal compliance, and building trust among competitors. They said technical interoperability and standard data taxonomies would be required for disparate systems to share and act on threat intelligence effectively.
As immediate steps, the panel recommended developing common definitions and reporting templates, building privacy-preserving data-sharing mechanisms, and creating secure channels for sharing high-fidelity indicators of compromise. They proposed industry-led pilot projects that pair smaller firms with larger institutions to test shared tools and processes before wider rollout.
Panelists argued any effective response should combine improved detection technology, controls focused on human-directed attacks and clearer regulatory alignment. The webinar invited attendees to register for follow-up sessions that will include case studies and further discussion.








