AI regulation tracker · Topic hub

AI fraud detection in banking: the warnings, the rules, the practice.

Last updated Sep 19, 2026 · 50 of the 100 largest US banks with a recorded AI fraud use case

Fraud is where AI cuts both ways for a bank, and where regulators have been most specific. On the threat side, FinCEN, the FDIC, New York's DFS, the OCC and the ECB have all put in writing that generative AI now produces deepfake documents, voices and video that defeat identity checks and lowers the cost of attacks. On the defence side, the rules mostly encourage AI: the EU AI Act exempts fraud detection from its high-risk credit category, US agencies have encouraged AI in monitoring since 2018, and Treasury credits machine learning with $1 billion of its own fraud recoveries in a year. 50 of the 100 largest US banks profiled on this site record an AI fraud or scam-defence use case, 47 of them in production. What still binds: model validation in proportion to materiality, adverse-action duties when a fraud score declines a customer, and governance of the data the models learn from.

How are banks using AI in fraud detection?

AI in fraud detection at a bank means machine-learning models that score transactions, logins, applications and payments in real time, flag the anomalous ones and route them to a block, a step-up check or an investigator, and increasingly generative tools that help investigators work alerts. The bank records on this site show the range: machine-learning monitoring of payment flows at JPMorgan Chase and Wells Fargo, anomaly detection with behavioural and network analytics at U.S. Bancorp, generative AI for undefined threats at Truist, behavioural biometrics at Barclays US, agentic dispute handling at Old National and Seacoast, and customer education on deepfake and voice-clone scams almost everywhere. It is the AI use case regulators are most comfortable with: the EU AI Act carves it out of high-risk credit scoring and FinCEN's 2026 proposal counts effective use of AI in a bank's favour.

The largest with a recorded fraud use case: JPMorgan · Wells Fargo · U.S. Bank · PNC · Truist · Schwab · TD · Fifth Third. All 50 banks, with what each has disclosed ↓ Related: how fraud models are validated and AI chatbots in banking.

How is AI changing fraud against banks?

Regulators describe the same shift from three angles. Generative AI produces deepfake identity documents, voices and video good enough to defeat onboarding and authentication, which FinCEN, the FDIC and New York's DFS have all put in writing. AI lowers the cost and raises the speed of attacks, which the OCC, the ECB and DFS say changes the cyber threat landscape rather than any one scheme. And AI itself is used as bait, with trading bots and guaranteed-return schemes that the CFTC has warned customers about since January 2024.

RuleAuthorityWhat it requiresApplies
FinCEN Alert FIN-2024-Alert004 (deepfake media)FinCENDeepfake IDs, images, video and audio used to defeat identity verification; red flags, phishing-resistant MFA, live verification, SAR key term FIN-2024-DEEPFAKEFRAUD.In force from Nov 13, 2024
FinCEN Alert FIN-2026-Alert004 (federal student aid)FinCENAI-generated synthetic identities and chatbots that keep 'ghost students' enrolled; SAR key term FIN-2026-FSAFRAUD.In force from Jul 24, 2026
FDIC 2024 Risk ReviewFDICGenerative AI used to circumvent identity- and authentication-based controls through deepfakes, voice cloning and forged documents.Published May 22, 2024
DFS AI cybersecurity letterNY DFSAI-enabled social engineering and AI-enhanced attacks must appear in Part 500 risk assessments, training and MFA design.In force from Oct 16, 2024
OCC Semiannual Risk Perspective, Spring 2026OCCAI 'significantly transforming' the threat landscape: lower barriers to entry, more speed, scale and sophistication in attacks and fraud.Published May 7, 2026
ECB 'Dear CEO' letter SSM-2026-0301ECBAI models that find vulnerabilities and generate exploits at unprecedented speed; action plans due to supervisors.Plans due Oct 31, 2026
CFTC AI scams customer advisoryCFTCAI-branded trading bots, signal services and crypto schemes promising guaranteed returns.In force from Jan 25, 2024

What rules govern a bank's own use of AI to detect fraud?

Fraud detection is the AI use case regulators are most comfortable with, and the rules mostly encourage it. The EU AI Act exempts systems used solely to detect financial fraud from its high-risk credit-scoring category; FinCEN's 2018 innovation statement and its 2026 AML programme proposal reward 'effective use of artificial intelligence' in monitoring; and US model-risk guidance treats a fraud model as a model, validated in proportion to its materiality. The constraints come from elsewhere: a fraud model that blocks or declines a customer can trigger adverse-action and UDAAP questions, and the data it learns from sits under BCBS 239 and privacy law.

RuleAuthorityWhat it requiresApplies
EU AI Act, Annex III 5(b) carve-outEU AI ActAI used solely to detect financial fraud is excluded from the high-risk credit-scoring category.In force
2018 Joint Statement on BSA/AML innovationFinCENAgencies encourage innovative approaches, including AI, to meet BSA/AML obligations; pilots will not be penalised for themselves.In force
2026 AML/CFT Program Proposed RuleFinCEN'Effective use of artificial intelligence, federated learning, or other advanced monitoring tools' counted in favour of an institution.Proposed; comments closed Jun 9, 2026
SR 26-2 / OCC 2026-13Federal ReserveFraud models that are 'complex quantitative methods' are models: validation, monitoring and outcomes analysis scaled to materiality.In force from Apr 17, 2026
ECOA / Regulation B adverse actionCFPBA fraud-driven decline of a credit application is still an adverse action needing specific reasons.In force
ECB Supervision Newsletter on credit scoring and fraudECBDecision trees dominate, neural networks used mainly for fraud, no self-learning after deployment; gaps on explainability and data standards.Published Nov 20, 2025
EBA report on AI adoptionEBAAML/CFT and fraud detection among the dominant AI uses at EU banks; fraud alerts the most common consumer-facing generative-AI use.Published Sep 25, 2025

Does AI fraud detection work at scale?

The best public number is Treasury's: machine learning that expedites identification of Treasury check fraud accounted for $1 billion of the $4 billion in fraud and improper payments prevented or recovered in fiscal 2024, across about 1.4 billion payments a year. The same Treasury found a 'fraud data divide' that leaves smaller banks without enough data to train comparable models, which is why data sharing and vendor models matter more to community banks than to the largest.

RuleAuthorityWhat it requiresApplies
Treasury $4B fraud-prevention announcementU.S. Treasury$1 billion of FY2024 recoveries attributed to machine-learning check-fraud detection; $2.5 billion from prioritising high-risk transactions.Published Oct 17, 2024
Treasury AI cybersecurity risks reportU.S. TreasuryA 'fraud data divide' between large and small institutions; proposals for data sharing and vendor-AI 'nutrition labels'.Published Mar 27, 2024
Treasury AI in Financial Services reportU.S. TreasurySector-wide findings on AI use, including fraud detection, from the 2024 request for information.Published Dec 19, 2024

Which fraud-related documents has each authority published?

AuthorityFraud documents in the tracker
Federal ReserveSR 26-2 In force · 2021 Interagency AI RFI Final · SR 11-7 Superseded
OCCOCC Semiannual Risk Perspective, Spring 2026 Final · 2021 Interagency AI RFI (OCC Bulletin 2021-17) Final
FDICFDIC House testimony on AI and innovation (Mar 2026) Final · FDIC 2025 Report on Cybersecurity and Resilience Final · FDIC 2024 Risk Review Final · FDIC FIL-29-2023 In force · FDIC FIL-20-2021 Final
NCUAHauptman Senate testimony (Feb 2026) Final · NCUA Letter 26-CU-01 In force · 2021 Interagency AI RFI Final
CFPBCFPB comment to Treasury on AI in financial services (2024) Final · FCRA adverse action and credit-score disclosures (15 U.S.C. 1681m, 1681g(f)) In force
SECDivision of Examinations FY2026 Priorities In force · Division of Examinations FY2025 Priorities Superseded
CFTCJohnson Statement on AI in Derivatives Markets (Dec 2024) Final · CFTC AI Scams Customer Advisory In force
FinCENFIN-2026-Alert004 (Federal Student Aid Fraud) In force · FIN-2024-Alert004 (Deepfake Media) In force
U.S. TreasuryFSOC AI Innovation Series (Mar–May 2026) Final · FSOC 2025 Annual Report Final · Treasury AI in Financial Services report (Dec 2024) Final · Treasury $4B AI fraud-prevention announcement (Oct 2024) Final · Treasury AI cybersecurity risks report (Mar 2024) Final
NY DFSDFS AI Cybersecurity Industry Letter (Oct 2024) In force
NISTNIST IR 8596 (Cyber AI Profile) Proposed · NIST AI 100-2e2025 (Adversarial ML) Final
EU AI ActDraft Commission guidelines on high-risk classification Proposed · EBA factsheet on the AI Act Final · Regulation (EU) 2024/1689 In force
ECBMontagner speech: 'Encouraging innovation, managing risks' (Feb 2026) Final · Supervision Newsletter: AI use cases for credit scoring and fraud detection (Nov 2025) Final · SSM supervisory priorities 2026–28 In force
EBAEBA report: Rising application of AI in EU banking and payments (Sep 2025) Final · EBA Report on Big Data and Advanced Analytics (EBA/REP/2020/01) Final
UK (BoE / PRA / FCA)HM Treasury Financial Services AI Adoption Plan (Jul 2026) Final · 2024 BoE/FCA AI survey Final
FSBFSB AI financial stability report (Nov 2024) Final · FSB 2017 AI/ML report Final
Basel CommitteeBCBS Digitalisation of finance report (May 2024) Final
DateEventDocument
Jul 24, 2026FinCEN alert on AI-assisted student-aid fraudFIN-2026-Alert004 (Federal Student Aid Fraud)
Jul 7, 2026ECB Dear-CEO letter on AI-enabled cyber threatsECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301)
May 7, 2026OCC: AI transforming the cyber and fraud threat landscapeOCC Semiannual Risk Perspective, Spring 2026
Apr 10, 2026FinCEN proposal credits 'effective use of AI' in AML programmes2026 AML/CFT Program Proposed Rule
Nov 20, 2025ECB workshops on AI for credit scoring and fraudSupervision Newsletter: AI use cases for credit scoring and fraud detection (Nov 2025)
Nov 13, 2024FinCEN deepfake media alertFIN-2024-Alert004 (Deepfake Media)
Oct 17, 2024Treasury: $1 billion recovered by machine-learning check-fraud detectionTreasury $4B AI fraud-prevention announcement (Oct 2024)
Oct 16, 2024DFS maps AI-enabled social engineering to Part 500DFS AI Cybersecurity Industry Letter (Oct 2024)
Jul 12, 2024EU AI Act exempts fraud detection from the high-risk credit categoryRegulation (EU) 2024/1689
May 22, 2024FDIC Risk Review: deepfakes defeat authenticationFDIC 2024 Risk Review
Mar 27, 2024Treasury names the 'fraud data divide'Treasury AI cybersecurity risks report (Mar 2024)
Jan 25, 2024CFTC warns customers about AI-branded trading scamsCFTC AI Scams Customer Advisory
Dec 3, 2018Agencies encourage AI in BSA/AML monitoring2018 Joint Statement on BSA/AML Innovation

Which of the 100 largest US banks use AI against fraud?

50 of the 100 bank pages on this site record an AI fraud, scam or payment-defence use case. Each links to the bank's page, where the claim is sourced.

BankWhat the record showsStatus
JPMorganFraud and AML analytics: Machine-learning monitoring across roughly $10 trillion of daily payment flows, per the bank's own operating description.In production
Wells FargoPayments fraud defence: AI on payment flows of more than $1 trillion a day; guidance to corporate clients on generative-AI fraud.In production
U.S. BankTreasury fraud defence: Anomaly detection, behavioural intelligence and network analytics on payments.In production
PNCIn-house fraud-blocking models: One of the named targets for the bank's own language models.Announced
TruistFraud detection: ML for defined patterns plus generative AI for undefined threats.In production
SchwabMachine-learning fraud detection: Long-running ML models across the business.In production
TDFraud defence and claims: AI in fraud defence and insurance-claims fraud detection; $150 million claims-cost target.In production
Fifth ThirdScam and impersonation defence: Expanded scam investigations; AI named by the fraud director as accelerating the threat.In production
HuntingtonAI-enabled fraud defence: Guidance and controls against AI-crafted BEC and impersonation.In production
First CitizensFraud defence for business clients: Controls against AI-enabled fraud and check fraud.In production
CitizensPayment-fraud defence: Head of fraud on AI deepfakes, BEC and bank impersonation.In production
AmexEmbedded fraud controls in B2B payments: Authentication and fraud controls in buyer–supplier flows.In production
KeyBankAI-deepfake fraud defence and client education: Guidance on AI-generated voice and video used in business email compromise.In production
Northern TrustAI in tokenisation security: Executives point to AI's role in detecting fraudulent behaviour around digital assets.Announced
HSBCAI-redesigned fraud detection and credit applications: Among 50 processes under end-to-end redesign.Rolling out
RegionsDeepfake and AI-scam education: Client guidance on AI-generated impersonation.In production
PinnacleAI-enabled fraud awareness for treasury clients: Guidance that fraudsters use AI too, with human review kept in payment workflows.In production
SantanderDeepfake-scam education and AI fraud models: Purpose-built fake AI ads in the UK; consumer education in the US.In production
Western AllianceTriangle of Fraud Protection (Digital Disbursements): Real-time screening and AI fraud scoring for class-action settlement payments.In production
ZionsAI in targeted fraud-detection workflows: Named by management as an early targeted use.In production
Old NationalDispute and fraud-claim resolution (Quavo): Vendor-provided agentic-AI disputes technology; award for highest client satisfaction.In production
UMBClient fraud-prevention education: Romance-scam and fraud guides for personal and business clients.In production
SouthStateAI-fraud and synthetic-identity education: Customer guidance on AI-enabled scams.In production
CIBCAI in fraud detection and credit monitoring: Cited at the annual meeting as faster and more effective risk work.In production
ValleyAI-powered fraud capabilities: Reached production with partners ahead of similar-sized banks.In production
BOK FinancialAI-enabled fraud awareness and controls: Client guidance on generative-AI phishing, deepfakes and ACH/wire social engineering.In production
Barclays USBehavioural biometrics (BioCatch): Distinguishes customers from fraudsters and automated bots.In production
AssociatedAI-enabled fraud education and controls: Webinars and guides on social engineering, deepfakes and BEC.In production
Atlantic UnionAI fraud education for customers: Guides on generative-AI scams and AI-generated phishing.In production
CommerceAI-scam awareness and investigations: Corporate investigations guidance on AI-enabled impersonation.In production
BankUnitedAI-fraud awareness programme: Continuous client guidance on AI-enabled scams and AI-based fraud prevention.In production
FNBOAI-scam and deepfake awareness: CISO-authored guidance for consumers and businesses.In production
Banc of CaliforniaGenerative-AI fraud guidance: Client-facing guide to AI-driven scams and synthetic identity.In production
United BankCustomer fraud-awareness content: Fraudulent-website and card-control guidance.In production
United CommunityAI fraud-prevention tools: Credited with helping customers avoid potentially millions of dollars in losses.In production
ArvestCustomer fraud education on AI-enabled scams: Deepfakes, phantom-hacker schemes, push-payment fraud, data quality.In production
AmerisCustomer education on AI-generated fraud: Deepfake voices and AI-enabled phishing.In production
WaFd BankCustomer education on deepfake scams: Voice cloning and AI impersonation guidance.In production
WesBancoClient education on AI-generated fraud: Deepfake and account-takeover guidance for businesses.In production
First HawaiianDeepfake and scam awareness for customers: Deepfake protection at work and home; malware and job-scam warnings.In production
Bank of HawaiiScam education for seniors: Top-ten scams guidance.In production
First Financial BankCommercial fraud education including AI deepfakes: Annual checklist and commercial fraud hub for business clients.In production
TowneBankCustomer education on AI scams: Voice cloning and deepfake awareness.In production
Mechanics BankCustomer fraud education: Impostor scams, tax-season fraud and senior fraud prevention.In production
Seacoast BankAgentic AI dispute management (Quavo QFD): Intake to resolution automation with AI fraud detection trained on millions of cases.In production
First MerchantsCustomer education on text scams: Recognising smishing and impersonation.In production
Central BankCustomer education on AI-enhanced scams: Voice cloning and impersonation guidance.In production
Merchants Bank of IndianaWire-fraud customer education: Guidance on verifying payment instructions.In production
Busey BankCustomer education on AI fraud and deepfakes: Guidance for consumers and businesses.In production
Enterprise Bank & TrustAnnual fraud-protection guidance: Payments and fraud controls for business clients.In production

Is AI fraud detection regulated differently from other bank AI?

It is treated more leniently. The EU AI Act excludes systems used solely to detect financial fraud from its high-risk credit-scoring category, US agencies have encouraged AI in BSA/AML monitoring since 2018 and FinCEN's 2026 proposal counts effective use of AI in a bank's favour. What still applies: model-risk validation in proportion to materiality, adverse-action duties when a fraud score declines a customer, and data governance over the training data.

What are regulators warning banks about?

Deepfake identity documents, voices and video that defeat onboarding and authentication (FinCEN, FDIC, DFS), AI that lowers the cost and raises the speed of cyberattacks (OCC, ECB, DFS), synthetic identities in benefit fraud (FinCEN), and AI-branded investment scams aimed at customers (CFTC).

How many of the largest US banks run AI against fraud?

The bank pages on this site record an AI fraud or scam-defence use case at half of the 100 largest US banks, most of them described as in production; the table below lists each with its source.

Where does the fraud data divide bite?

Treasury's 2024 report found smaller institutions lack the data to train their own anti-fraud models, which pushes them to vendor models and consortium data. Third-party risk guidance (SR 23-4) then applies to the vendor relationship, and the bank remains responsible for validating what it buys.

Every new fraud alert and every bank's fraud move, the morning after.

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning