AI News Feed
Market watch
Policy & Regulation

TechRadar Analysis Questions Whether FCA Is Underestimating AI Fraud Threat

A TechRadar analysis argues that AI is making fraud cheaper and faster, widening the gap between criminal tactics and bank defenses. It warns synthetic identity fraud deserves more attention and says banks should red-team their own controls.

The article, by Trend Micro's technical director for the UK and Ireland, says AI can make financial processes faster, spot suspicious activity earlier and help banks handle fraud at a scale impossible for human teams alone. But it warns that this optimism risks obscuring a more immediate problem: criminals do not have lengthy procurement cycles, legacy technology to integrate or regulatory processes to work through. They can experiment, fail and try again, creating a growing gap between the speed at which AI-enabled fraud develops and the speed at which financial institutions can adapt.

The analysis says many identity verification controls were built around the assumption that a human being is pretending to be somebody else. Measures such as video liveness checks, voice callbacks and one-off document verification each created another hurdle for fraudsters. Generative AI changes that challenge because the person, voice or document being presented may never have existed. A convincing voice can be generated, faces can be created or manipulated, and identity documents and supporting paperwork can be produced quickly and consistently. What once required specialist skills and considerable effort is becoming cheaper and easier.

Existing controls are not useless, the article says, but firms need to stop assuming that passing them proves what it once did. A liveness check is only valuable if it can reliably distinguish between a real person and the latest generation of synthetic media, which is now a moving target.

The analysis argues that synthetic identity fraud deserves much more attention. Traditional identity theft usually has a real victim who eventually discovers an account they did not open, a transaction they did not make or a credit application they know nothing about. Synthetic identities are different. Fraudsters can combine genuine information with invented details to create an apparently legitimate individual, pairing a real identifier with a false name, fabricated employment history or invented address. AI can help create the documentation and digital footprint needed to make that identity appear credible. The worrying part, the article says, is that there may be nobody to complain because the person does not exist. That makes synthetic identity fraud difficult to identify early. A synthetic customer can behave normally, establish a financial history and build trust before committing fraud much later.

The article compares synthetic identity fraud to account takeover a decade ago. Account takeover is now well understood, with mature systems, shared intelligence and established behavioral indicators designed to detect it. That maturity took time. Synthetic identity fraud is not there yet, and AI risks accelerating the problem before the industry's collective ability to recognize it has caught up.

The answer cannot simply be to buy another AI-powered fraud product, according to the analysis. Financial institutions need to use the same technology offensively against their own systems. If criminals are using generative AI tools to test what gets through, banks should be doing exactly the same thing. Security teams have red-teamed networks and applications for years, and identity and onboarding processes now need similar treatment. The article asks whether an AI-generated voice can pass a callback process, whether a synthetic face can beat a liveness check, whether fabricated documentation can survive onboarding and whether a convincing synthetic identity can be created across several data points without triggering an alert.

Firms should answer those questions themselves rather than waiting for a fraudster to provide the answer, the article says. Every successful attempt should become a lesson. If a synthetic document passes, firms should understand why. If a generated voice fools a control, they should change the control and test it again.

The analysis also calls for moving away from excessive reliance on one-off verification. Proving someone's identity once at onboarding becomes less reassuring when that moment can be convincingly fabricated. Behavior over time matters more: how an account is used, how a customer interacts with services and whether activity is consistent.