Fraud has always chased the edge of technology. In 2026, that edge has shifted decisively toward artificial intelligence. Scammers are no longer limited by human capacity; they are deploying AI agents, deepfake voices, synthetic identities, and fraud-as-a-service toolkits that probe payment systems around the clock at negligible cost.
At the same time, agentic AI, which allows a software agent to browse products, compare prices, and complete a purchase entirely on a user’s behalf, is moving from pilot into mainstream adoption. The result is a collision course: autonomous buying agents on one side, autonomous fraud agents on the other, and payment infrastructure caught in the middle.
The Scale of the Problem
According to a 2026 report by Darwinium, drawing on 500 fraud and risk leaders, 97% of organisations report an increase in AI-driven attacks; 75% say more than a quarter of their fraud is already AI-assisted; and the average annual loss from AI-enabled fraud stands at $4.5 million per organisation. Enterprise losses now average $11.4 million per year, a 7.5% year-on-year increase, per Ravelin’s Global Fraud Trends 2026.
Yet 30% of enterprises still use no AI or machine learning in their anti-fraud defences at all. That asymmetry explains why losses keep rising.
Agentic Commerce
Agentic activity on commerce platforms has soared by more than 2,100% in recent months, according to Forter, while automated fraud attempts rose 202% over the same period. The two curves are causally linked.
A fraud agent browsing, comparing, and purchasing looks identical to a legitimate shopping agent. Traditional bot detection relies on behavioural signals like unusual speed or click patterns; those signals no longer distinguish good automation from bad. When an AI agent authorises a payment, liability questions also become complex; there is no human memory of the interaction to support an investigation.
For context on how embedded finance infrastructure underpins these agentic payment flows, see: Banking as a Service: Meaning, Examples, Benefits and Future.
The Main AI Payment Fraud Tactics in 2026
Synthetic identities. Open-source AI models let criminals manufacture complete fake identities, including deepfake KYC videos, in minutes. These lie dormant, building a credit score, before being used to extract funds.
Deepfake impersonation. Voice and video cloning now requires only a short audio sample. Fraudsters impersonate bank staff or executives to instruct victims, or their AI agents, to authorise transfers, and they can run the attack across thousands of targets simultaneously.
Fraud-as-a-service. Subscription fraud kits on criminal marketplaces include pre-built phishing flows, automated account-takeover modules, and even customer support. Sophisticated attack capability is no longer limited to organised criminal groups.
AI-targeted social engineering. AI tools ingest a target’s social media activity, professional history, and transaction data to craft personalized phishing messages. The old tell-tale signs, generic greetings and grammatical errors, have largely disappeared.
How AI Fraud Detection is Fighting Back
As of 2026, 68% of banks are using AI to fight fraud, and 83% of anti-fraud professionals plan to incorporate generative AI into their systems, per Radial. The most effective approaches share a common principle: moving from detecting automation to understanding intent.
Intent-based behavioural analysis evaluates whether a non-human actor has legitimate authority over the account, not just whether it is a bot. Real-time ML scoring considers hundreds of variables per transaction, learning continuously so it can catch novel patterns without waiting for a manual rule update. Graph neural networks map relationships between entities, shared device IDs, overlapping contacts, correlated application timing, making synthetic identity farms visible at the network level even when each identity passes individual checks.
The push toward open banking APIs has expanded the data available for real-time fraud scoring. See: What is Fintech? for a primer on the infrastructure layer.
The Challenge of False Positives
The cost of fraud is visible on a balance sheet; the cost of over-blocking is not, but it is just as real. Every legitimate transaction declined represents a customer who may defect to a competitor, a merchant who loses a sale, and a payment provider whose conversion rate quietly erodes. Darwinium’s 2026 survey found that false positives and lost revenue from unnecessary friction are now factored into the true cost of fraud calculation by leading organisations.
This tension is driving a shift away from binary allow/block decisions toward graduated friction models. Rather than rejecting any transaction that crosses a fixed risk threshold, AI systems now apply friction proportional to the risk level: a low-risk transaction clears seamlessly; a medium-risk session triggers a soft step-up authentication; only genuinely high-risk events reach a block or a human review queue. The result is a significantly better experience for the vast majority of legitimate users, while concentrating scrutiny where it actually belongs. Getting this balance right is one of the defining challenges of AI payment fraud detection in 2026.
Regulatory and Liability Implications
The regulatory landscape has not kept pace with the technical reality of AI payment fraud. In the UK, the Payment Systems Regulator’s mandatory reimbursement framework for authorised push payment (APP) fraud, which took effect in late 2024 and was subsequently revised in its scope, has fundamentally changed the incentive structure for banks. Where liability falls on the institution rather than the customer, AI fraud prevention stops being a compliance cost and becomes a direct P&L issue.
The agentic commerce liability question, however, remains largely unresolved. If an AI agent acting on a user’s behalf is deceived into authorising a fraudulent transaction, who carries the loss? The user, the agent provider, the bank, or the merchant? Legal frameworks are only beginning to address this, and in the interim, most payment providers are treating agent-initiated transactions with heightened scrutiny as a precaution. This is an area where regulatory clarity is urgently needed, and where early internal governance frameworks will separate prepared institutions from exposed ones.
What Institutions and Organisations Should Do Now
The gap between organisations deploying AI fraud prevention effectively and those still running static rule engines is widening fast. The highest-impact priorities in 2026 are: replacing rule engines with adaptive ML scoring; adopting intent-based analysis to distinguish legitimate from fraudulent agentic activity; deploying graph analytics to catch synthetic identity schemes; and joining consortium intelligence networks that pool anonymised fraud signals across institutions.
Agentic commerce is not a threat to block; it is a capability to enable safety. The question is no longer “can we detect the bot?” but “can we understand what the bot is trying to do, and whether it has the right to do it?” That is where the battle for fraud detection in digital payments is being fought right now.
Stay Ahead of Fintech Fraud Trends
The fintech fraud landscape is evolving faster than ever. Stay informed with the latest news, analysis, and insights on AI payment fraud, digital payments, and fraud prevention strategies.
Read more articles on Fintech in Shorts and keep up with the developments shaping the future of financial technology.