Fraud is where AI cuts both ways for a bank, and where regulators have been most specific. On the threat side, FinCEN, the FDIC, New York's DFS, the OCC and the ECB have all put in writing that generative AI now produces deepfake documents, voices and video that defeat identity checks and lowers the cost of attacks. On the defence side, the rules mostly encourage AI: the EU AI Act exempts fraud detection from its high-risk credit category, US agencies have encouraged AI in monitoring since 2018, and Treasury credits machine learning with $1 billion of its own fraud recoveries in a year. 50 of the 100 largest US banks profiled on this site record an AI fraud or scam-defence use case, 47 of them in production. What still binds: model validation in proportion to materiality, adverse-action duties when a fraud score declines a customer, and governance of the data the models learn from.
How are banks using AI in fraud detection?
AI in fraud detection at a bank means machine-learning models that score transactions, logins, applications and payments in real time, flag the anomalous ones and route them to a block, a step-up check or an investigator, and increasingly generative tools that help investigators work alerts. The bank records on this site show the range: machine-learning monitoring of payment flows at JPMorgan Chase and Wells Fargo, anomaly detection with behavioural and network analytics at U.S. Bancorp, generative AI for undefined threats at Truist, behavioural biometrics at Barclays US, agentic dispute handling at Old National and Seacoast, and customer education on deepfake and voice-clone scams almost everywhere. It is the AI use case regulators are most comfortable with: the EU AI Act carves it out of high-risk credit scoring and FinCEN's 2026 proposal counts effective use of AI in a bank's favour.
The largest with a recorded fraud use case: JPMorgan · Wells Fargo · U.S. Bank · PNC · Truist · Schwab · TD · Fifth Third. All 50 banks, with what each has disclosed ↓ Related: how fraud models are validated and AI chatbots in banking.
How is AI changing fraud against banks?
Regulators describe the same shift from three angles. Generative AI produces deepfake identity documents, voices and video good enough to defeat onboarding and authentication, which FinCEN, the FDIC and New York's DFS have all put in writing. AI lowers the cost and raises the speed of attacks, which the OCC, the ECB and DFS say changes the cyber threat landscape rather than any one scheme. And AI itself is used as bait, with trading bots and guaranteed-return schemes that the CFTC has warned customers about since January 2024.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| FinCEN Alert FIN-2024-Alert004 (deepfake media) | FinCEN | Deepfake IDs, images, video and audio used to defeat identity verification; red flags, phishing-resistant MFA, live verification, SAR key term FIN-2024-DEEPFAKEFRAUD. | In force from Nov 13, 2024 |
| FinCEN Alert FIN-2026-Alert004 (federal student aid) | FinCEN | AI-generated synthetic identities and chatbots that keep 'ghost students' enrolled; SAR key term FIN-2026-FSAFRAUD. | In force from Jul 24, 2026 |
| FDIC 2024 Risk Review | FDIC | Generative AI used to circumvent identity- and authentication-based controls through deepfakes, voice cloning and forged documents. | Published May 22, 2024 |
| DFS AI cybersecurity letter | NY DFS | AI-enabled social engineering and AI-enhanced attacks must appear in Part 500 risk assessments, training and MFA design. | In force from Oct 16, 2024 |
| OCC Semiannual Risk Perspective, Spring 2026 | OCC | AI 'significantly transforming' the threat landscape: lower barriers to entry, more speed, scale and sophistication in attacks and fraud. | Published May 7, 2026 |
| ECB 'Dear CEO' letter SSM-2026-0301 | ECB | AI models that find vulnerabilities and generate exploits at unprecedented speed; action plans due to supervisors. | Plans due Oct 31, 2026 |
| CFTC AI scams customer advisory | CFTC | AI-branded trading bots, signal services and crypto schemes promising guaranteed returns. | In force from Jan 25, 2024 |
What rules govern a bank's own use of AI to detect fraud?
Fraud detection is the AI use case regulators are most comfortable with, and the rules mostly encourage it. The EU AI Act exempts systems used solely to detect financial fraud from its high-risk credit-scoring category; FinCEN's 2018 innovation statement and its 2026 AML programme proposal reward 'effective use of artificial intelligence' in monitoring; and US model-risk guidance treats a fraud model as a model, validated in proportion to its materiality. The constraints come from elsewhere: a fraud model that blocks or declines a customer can trigger adverse-action and UDAAP questions, and the data it learns from sits under BCBS 239 and privacy law.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| EU AI Act, Annex III 5(b) carve-out | EU AI Act | AI used solely to detect financial fraud is excluded from the high-risk credit-scoring category. | In force |
| 2018 Joint Statement on BSA/AML innovation | FinCEN | Agencies encourage innovative approaches, including AI, to meet BSA/AML obligations; pilots will not be penalised for themselves. | In force |
| 2026 AML/CFT Program Proposed Rule | FinCEN | 'Effective use of artificial intelligence, federated learning, or other advanced monitoring tools' counted in favour of an institution. | Proposed; comments closed Jun 9, 2026 |
| SR 26-2 / OCC 2026-13 | Federal Reserve | Fraud models that are 'complex quantitative methods' are models: validation, monitoring and outcomes analysis scaled to materiality. | In force from Apr 17, 2026 |
| ECOA / Regulation B adverse action | CFPB | A fraud-driven decline of a credit application is still an adverse action needing specific reasons. | In force |
| ECB Supervision Newsletter on credit scoring and fraud | ECB | Decision trees dominate, neural networks used mainly for fraud, no self-learning after deployment; gaps on explainability and data standards. | Published Nov 20, 2025 |
| EBA report on AI adoption | EBA | AML/CFT and fraud detection among the dominant AI uses at EU banks; fraud alerts the most common consumer-facing generative-AI use. | Published Sep 25, 2025 |
Does AI fraud detection work at scale?
The best public number is Treasury's: machine learning that expedites identification of Treasury check fraud accounted for $1 billion of the $4 billion in fraud and improper payments prevented or recovered in fiscal 2024, across about 1.4 billion payments a year. The same Treasury found a 'fraud data divide' that leaves smaller banks without enough data to train comparable models, which is why data sharing and vendor models matter more to community banks than to the largest.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Treasury $4B fraud-prevention announcement | U.S. Treasury | $1 billion of FY2024 recoveries attributed to machine-learning check-fraud detection; $2.5 billion from prioritising high-risk transactions. | Published Oct 17, 2024 |
| Treasury AI cybersecurity risks report | U.S. Treasury | A 'fraud data divide' between large and small institutions; proposals for data sharing and vendor-AI 'nutrition labels'. | Published Mar 27, 2024 |
| Treasury AI in Financial Services report | U.S. Treasury | Sector-wide findings on AI use, including fraud detection, from the 2024 request for information. | Published Dec 19, 2024 |
Which fraud-related documents has each authority published?
| Date | Event | Document |
|---|---|---|
| Jul 24, 2026 | FinCEN alert on AI-assisted student-aid fraud | FIN-2026-Alert004 (Federal Student Aid Fraud) |
| Jul 7, 2026 | ECB Dear-CEO letter on AI-enabled cyber threats | ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) |
| May 7, 2026 | OCC: AI transforming the cyber and fraud threat landscape | OCC Semiannual Risk Perspective, Spring 2026 |
| Apr 10, 2026 | FinCEN proposal credits 'effective use of AI' in AML programmes | 2026 AML/CFT Program Proposed Rule |
| Nov 20, 2025 | ECB workshops on AI for credit scoring and fraud | Supervision Newsletter: AI use cases for credit scoring and fraud detection (Nov 2025) |
| Nov 13, 2024 | FinCEN deepfake media alert | FIN-2024-Alert004 (Deepfake Media) |
| Oct 17, 2024 | Treasury: $1 billion recovered by machine-learning check-fraud detection | Treasury $4B AI fraud-prevention announcement (Oct 2024) |
| Oct 16, 2024 | DFS maps AI-enabled social engineering to Part 500 | DFS AI Cybersecurity Industry Letter (Oct 2024) |
| Jul 12, 2024 | EU AI Act exempts fraud detection from the high-risk credit category | Regulation (EU) 2024/1689 |
| May 22, 2024 | FDIC Risk Review: deepfakes defeat authentication | FDIC 2024 Risk Review |
| Mar 27, 2024 | Treasury names the 'fraud data divide' | Treasury AI cybersecurity risks report (Mar 2024) |
| Jan 25, 2024 | CFTC warns customers about AI-branded trading scams | CFTC AI Scams Customer Advisory |
| Dec 3, 2018 | Agencies encourage AI in BSA/AML monitoring | 2018 Joint Statement on BSA/AML Innovation |
Which of the 100 largest US banks use AI against fraud?
50 of the 100 bank pages on this site record an AI fraud, scam or payment-defence use case. Each links to the bank's page, where the claim is sourced.
| Bank | What the record shows | Status |
|---|---|---|
| JPMorgan | Fraud and AML analytics: Machine-learning monitoring across roughly $10 trillion of daily payment flows, per the bank's own operating description. | In production |
| Wells Fargo | Payments fraud defence: AI on payment flows of more than $1 trillion a day; guidance to corporate clients on generative-AI fraud. | In production |
| U.S. Bank | Treasury fraud defence: Anomaly detection, behavioural intelligence and network analytics on payments. | In production |
| PNC | In-house fraud-blocking models: One of the named targets for the bank's own language models. | Announced |
| Truist | Fraud detection: ML for defined patterns plus generative AI for undefined threats. | In production |
| Schwab | Machine-learning fraud detection: Long-running ML models across the business. | In production |
| TD | Fraud defence and claims: AI in fraud defence and insurance-claims fraud detection; $150 million claims-cost target. | In production |
| Fifth Third | Scam and impersonation defence: Expanded scam investigations; AI named by the fraud director as accelerating the threat. | In production |
| Huntington | AI-enabled fraud defence: Guidance and controls against AI-crafted BEC and impersonation. | In production |
| First Citizens | Fraud defence for business clients: Controls against AI-enabled fraud and check fraud. | In production |
| Citizens | Payment-fraud defence: Head of fraud on AI deepfakes, BEC and bank impersonation. | In production |
| Amex | Embedded fraud controls in B2B payments: Authentication and fraud controls in buyer–supplier flows. | In production |
| KeyBank | AI-deepfake fraud defence and client education: Guidance on AI-generated voice and video used in business email compromise. | In production |
| Northern Trust | AI in tokenisation security: Executives point to AI's role in detecting fraudulent behaviour around digital assets. | Announced |
| HSBC | AI-redesigned fraud detection and credit applications: Among 50 processes under end-to-end redesign. | Rolling out |
| Regions | Deepfake and AI-scam education: Client guidance on AI-generated impersonation. | In production |
| Pinnacle | AI-enabled fraud awareness for treasury clients: Guidance that fraudsters use AI too, with human review kept in payment workflows. | In production |
| Santander | Deepfake-scam education and AI fraud models: Purpose-built fake AI ads in the UK; consumer education in the US. | In production |
| Western Alliance | Triangle of Fraud Protection (Digital Disbursements): Real-time screening and AI fraud scoring for class-action settlement payments. | In production |
| Zions | AI in targeted fraud-detection workflows: Named by management as an early targeted use. | In production |
| Old National | Dispute and fraud-claim resolution (Quavo): Vendor-provided agentic-AI disputes technology; award for highest client satisfaction. | In production |
| UMB | Client fraud-prevention education: Romance-scam and fraud guides for personal and business clients. | In production |
| SouthState | AI-fraud and synthetic-identity education: Customer guidance on AI-enabled scams. | In production |
| CIBC | AI in fraud detection and credit monitoring: Cited at the annual meeting as faster and more effective risk work. | In production |
| Valley | AI-powered fraud capabilities: Reached production with partners ahead of similar-sized banks. | In production |
| BOK Financial | AI-enabled fraud awareness and controls: Client guidance on generative-AI phishing, deepfakes and ACH/wire social engineering. | In production |
| Barclays US | Behavioural biometrics (BioCatch): Distinguishes customers from fraudsters and automated bots. | In production |
| Associated | AI-enabled fraud education and controls: Webinars and guides on social engineering, deepfakes and BEC. | In production |
| Atlantic Union | AI fraud education for customers: Guides on generative-AI scams and AI-generated phishing. | In production |
| Commerce | AI-scam awareness and investigations: Corporate investigations guidance on AI-enabled impersonation. | In production |
| BankUnited | AI-fraud awareness programme: Continuous client guidance on AI-enabled scams and AI-based fraud prevention. | In production |
| FNBO | AI-scam and deepfake awareness: CISO-authored guidance for consumers and businesses. | In production |
| Banc of California | Generative-AI fraud guidance: Client-facing guide to AI-driven scams and synthetic identity. | In production |
| United Bank | Customer fraud-awareness content: Fraudulent-website and card-control guidance. | In production |
| United Community | AI fraud-prevention tools: Credited with helping customers avoid potentially millions of dollars in losses. | In production |
| Arvest | Customer fraud education on AI-enabled scams: Deepfakes, phantom-hacker schemes, push-payment fraud, data quality. | In production |
| Ameris | Customer education on AI-generated fraud: Deepfake voices and AI-enabled phishing. | In production |
| WaFd Bank | Customer education on deepfake scams: Voice cloning and AI impersonation guidance. | In production |
| WesBanco | Client education on AI-generated fraud: Deepfake and account-takeover guidance for businesses. | In production |
| First Hawaiian | Deepfake and scam awareness for customers: Deepfake protection at work and home; malware and job-scam warnings. | In production |
| Bank of Hawaii | Scam education for seniors: Top-ten scams guidance. | In production |
| First Financial Bank | Commercial fraud education including AI deepfakes: Annual checklist and commercial fraud hub for business clients. | In production |
| TowneBank | Customer education on AI scams: Voice cloning and deepfake awareness. | In production |
| Mechanics Bank | Customer fraud education: Impostor scams, tax-season fraud and senior fraud prevention. | In production |
| Seacoast Bank | Agentic AI dispute management (Quavo QFD): Intake to resolution automation with AI fraud detection trained on millions of cases. | In production |
| First Merchants | Customer education on text scams: Recognising smishing and impersonation. | In production |
| Central Bank | Customer education on AI-enhanced scams: Voice cloning and impersonation guidance. | In production |
| Merchants Bank of Indiana | Wire-fraud customer education: Guidance on verifying payment instructions. | In production |
| Busey Bank | Customer education on AI fraud and deepfakes: Guidance for consumers and businesses. | In production |
| Enterprise Bank & Trust | Annual fraud-protection guidance: Payments and fraud controls for business clients. | In production |
Is AI fraud detection regulated differently from other bank AI?
It is treated more leniently. The EU AI Act excludes systems used solely to detect financial fraud from its high-risk credit-scoring category, US agencies have encouraged AI in BSA/AML monitoring since 2018 and FinCEN's 2026 proposal counts effective use of AI in a bank's favour. What still applies: model-risk validation in proportion to materiality, adverse-action duties when a fraud score declines a customer, and data governance over the training data.
What are regulators warning banks about?
Deepfake identity documents, voices and video that defeat onboarding and authentication (FinCEN, FDIC, DFS), AI that lowers the cost and raises the speed of cyberattacks (OCC, ECB, DFS), synthetic identities in benefit fraud (FinCEN), and AI-branded investment scams aimed at customers (CFTC).
How many of the largest US banks run AI against fraud?
The bank pages on this site record an AI fraud or scam-defence use case at half of the 100 largest US banks, most of them described as in production; the table below lists each with its source.
Where does the fraud data divide bite?
Treasury's 2024 report found smaller institutions lack the data to train their own anti-fraud models, which pushes them to vendor models and consortium data. Third-party risk guidance (SR 23-4) then applies to the vendor relationship, and the bank remains responsible for validating what it buys.
Every new fraud alert and every bank's fraud move, the morning after.
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning