Skip to main content
AI Fraud Detection Just Got Real NumbersFraud Detection Analytics
4 min readFor Fraud Risk Managers

AI Fraud Detection Just Got Real Numbers

A joint study from the Bank for International Settlements and the Bank of England tested AI fraud detection against real-time payment data from millions of accounts. The findings confirm what many fraud teams suspected: AI outperforms rule-based systems in identifying novel fraud patterns. However, the research also reveals why AI can't be your only line of defense.

What the Data Shows

Project Hertha simulated real-time retail payment environments to measure AI's fraud detection capability against traditional controls. The results are clear:

  • AI detected 26% more suspicious activity than conventional fraud defenses.
  • AI analytics identified 12% more fraudulent accounts than existing methods would have caught.
  • Separate FIS research found 78% of respondents reported measurable improvements in fraud detection after deploying AI.

These aren't minor gains. A 26% lift in detection means you're catching threats that would have bypassed your existing controls. The 12% increase in fraudulent account identification directly translates to prevented losses and reduced exposure.

However, there's a challenge: SailPoint research found that 96% of tech professionals now consider AI agents themselves a growing security threat. Your fraud detection tool is also the adversary's weapon.

Five Findings That Change Your Strategy

1. AI excels at pattern recognition in novel fraud schemes

Traditional rule-based systems flag known behaviors. AI models identify deviations and correlations your rules don't anticipate. This is crucial in real-time payment environments where you can't afford a learning curve. When attackers shift tactics, your rules lag. AI adapts.

2. False positives remain a material risk

The BIS study warns that AI models can generate false positives or miss fraud instances. You're trading rule brittleness for model opacity. A 26% detection improvement doesn't mean 100% accuracy. It means you're catching more fraud while potentially flagging more legitimate transactions.

3. Attackers already use AI at scale

Cybercriminals deploy AI without privacy constraints, compliance overhead, or reputational risk. They're running deepfake authentication attacks and AI-generated phishing campaigns while your procurement team evaluates vendor questionnaires. The advantage isn't technical; it's operational speed.

4. Agentic AI introduces new attack surfaces

AI agents that autonomously handle fraud review tasks can be manipulated. If your AI agent has authority to approve transactions, freeze accounts, or escalate cases, it's a target. Nearly all respondents in the SailPoint study plan to expand agentic AI use despite recognizing the threat. You're about to hand more decision authority to systems that attackers are learning to exploit.

5. AI is a supplement, not a solution

BIS concluded that AI is insufficient as a standalone control. This matters for your control framework documentation. AI detection is a detective control that enhances your preventive and corrective controls. It doesn't replace transaction limits, MFA requirements, or manual review queues for high-risk transactions.

What This Means for Your Fraud Team

You're facing a deployment decision with incomplete information. AI improves detection rates, but you don't have visibility into model decision logic. Your existing rules are transparent but brittle. The fraud landscape is evolving faster than your quarterly rule reviews.

Here's the operational reality: you can't wait for perfect AI explainability, but you also can't retire your existing controls. Your fraud detection architecture needs layered defenses where AI supplements rule-based systems, not replaces them.

Consider your real-time payment flows. Traditional velocity checks and device fingerprinting catch known fraud patterns. AI models catch novel account takeover techniques that don't trip your existing rules. But when the AI model flags a transaction, you still need human review protocols and escalation paths.

The 96% of tech professionals who view AI agents as a security threat aren't wrong. They're recognizing that autonomous AI systems become attack targets. Your fraud detection AI needs the same security controls you'd apply to any privileged system: access restrictions, audit logging, model validation, and integrity monitoring.

Action Items by Priority

Immediate (this quarter):

Deploy AI as an additional detection layer, not a replacement. Run AI models parallel to existing rule-based systems. Flag discrepancies where AI catches fraud your rules miss, and where rules catch fraud AI doesn't flag. This parallel operation gives you ground truth for model performance.

Establish human review requirements for AI-flagged transactions. Don't grant AI models autonomous transaction blocking authority until you've validated false positive rates in your specific transaction mix.

Near-term (next two quarters):

Document AI's role in your fraud detection control framework. If you're subject to regulatory examination, examiners will ask how AI fits into your three lines of defense. Be explicit: AI is a detective control that enhances, not replaces, preventive controls like transaction limits and MFA.

Implement model monitoring for your fraud detection AI. Track detection rates, false positive trends, and model drift. When attackers shift tactics, your model performance will degrade. You need metrics that surface this degradation before losses spike.

Build adversarial testing into your AI deployment. Red team your fraud detection AI the same way attackers will. Test whether model inputs can be manipulated, whether the AI can be trained to ignore specific fraud patterns, and whether adversarial examples can evade detection.

Strategic (six to twelve months):

Develop innovation capacity beyond AI deployment. The BIS study concluded that organizations need to "think outside the box and innovate new approaches" because you can't fully rely on AI. This means dedicated resources for fraud pattern research, threat intelligence integration, and control experimentation.

Evaluate your real-time payment fraud exposure specifically. The Project Hertha simulation focused on real-time retail payments because that's where fraud speed matters most. If you're operating faster payment rails, your detection latency requirements are tighter than batch processing environments.

PCI DSS requirements

You Might Also Like