

AI can review 10,000 transaction data before I've finished my morning coffee. That is the good news and part of what companies aim for with the increased usage and adoption of AI. The bad? It can also help a fraudster write 10,000 convincing phishing emails with perfect grammar just as efficiently. According to the FBI’s 2025 Internet Crime Report, losses from Business Email Compromise (BEC) in 2025 alone amounted to a staggering $3.04 billion making it the second most rampant internet crime.
With the playing field evened for everyone, it really is a race between defensive AI vs offensive AI. Therefore, the need for strategic and timely intervention to disarm an attack from an opponent is now.
Here is the ugly truth of where we are in 2026. AI has multiplied the Lokis of the world by allowing anyone with a bad intention to master the art of deception.
Traditionally, banks required thumbprint and/or physical presence to open a bank account. To keep up with the growing demands of the booming digital banking industry, AI truly became an exciting addition (or in some cases, substitute) to the traditional onboarding process. However, the emergence of deepfakes forces organizations to press the brakes and reassess their AI driven processes.
In March 2026, A 34-year old man used stolen identity documents that were collected through a fake tenancy listing to open 46 fraudulent bank accounts at Netherlands’ ABM AMRO Bank. He used deepfake technology to create images resembling the stolen IDs and managed to bypass the bank’s face recognition software, which automates the comparison between an applicant’s photo ID and selfie (a very popular measure in many payments platforms. The scheme came to light when an officer flagged an anomaly which launched an investigation.
This is an interesting case for compliance as it highlights one of the defining paradoxes of recent times: AI being leveraged to undermine the very AI driven controls designed to enhance security and efficiency.
Perhaps 10 years back, someone who has worked in a company for 20 years could say “I know my manager’s voice” with certainty. In today’s world, we have technology that questions our instincts.
Fraudsters are now weaponizing AI by automating social engineering attacks by leveraging human emotions and trust.
The 2024 Arup Scam in Hong Kong is a landmark case that serves as a stark reminder that lowering scepticism and vigilance can cost you a fortune. An employee in Arup was manipulated into wiring USD $25 million to fraudster. The employee first received a phishing email from the company’s CFO and was later invited to a video conference call where familiar colleagues were present authorizing the transactions, except they were digital replicas. The images, audio were all AI-generated deepfakes.
With the collapse of trust as a control mechanism, it truly drives home the point that no actions should be conducted based on “The CFO asked, and therefore I executed” but rather “What does our Zero Trust Policy say?”
Many current deepfake laws such as the TAKE IT DOWN Act provides protection against non-consensual (authentic and computer generated) intimate imagery on online platforms, which is definitely a step forward in the right direction. However, corporations will still very much need to rely on existing fraud, cybercrime, intellectual property laws against the adversarial use of AI.
In reality, operational controls are stronger defence than legal protections as they prevent the damage in the first place.
For all high-risk checkpoint approvals, there must be a combination of one or two of the following:
Penetration testing is not just a yearly procedure for ISO compliance. We should be genuinely curious about how strong our defences are.
Periodic strain tests should include simulations designed to test whether the deepfake can bypass human judgment and manipulate workflows. This exercise is to assess the baseline on how the team would respond to these simulations and how we should reinvent training.
FATF’s Horizon Scan recommends deployment of advanced ID verification tools, including advanced “liveness checks” and combining traditional investigative methods with advanced technologies such as AI powered forensic tools, deepfake detection, and blockchain analytics to combat AI enabled deepfakes. But AI alone is not sufficient. As recommended by the EU AI Act, human intervention is still key in detecting anomalies. AI should support, rather than replace, human verification integrity and anti-corruption functions.
AI is neither a compliance tool nor a fraud tool. A modern approach to compliance and governance will be not to discourage the adoption of AI as it is inevitable. Rather, it should reinforce the need for responsible implementation, constant vigilance and healthy scepticism.
A quick compliance pulse check will be to ask the following questions:
Stay safe!