The very technology that enables the construction of better defenses is also being used to create faster, personalized, and scalable attacks. The competition is no longer just between attackers and security systems. Increasingly, it is taking place between AI systems attempting to deceive and AI systems attempting to detect that deception.
Attackers Are Automating, Too
The most significant evolution lies not merely in the creation of deepfakes or AI-generated emails, but in the ability to integrate artificial intelligence into various stages of a fraudulent operation.
In 2026, Google Threat Intelligence reported that malicious actors are using AI for vulnerability research, exploit development, infrastructure generation, reconnaissance, and the creation of social engineering campaigns. It also identified experiments involving malware capable of using AI during execution to dynamically alter its behavior. This changes the economics of an attack.
An operation that once required specialists, time, and multiple tools can now begin to automate parts of the process. AI can assist in researching a victim, crafting a convincing message, generating synthetic content, and adapting the strategy based on the victim's response.
During 2025, Google also observed the maturation of the underground market for AI-based tools. Advertised capabilities included functions for phishing, malware development, and vulnerability research.
The problem, therefore, is not simply that attacks are becoming "smarter." It is that they can be more efficient and reproducible.
From Generic Phishing to Personalization at Scale
AI is fundamentally changing social engineering. An attacker no longer necessarily needs to send thousands of identical messages in the hope that someone will take the bait. It can generate communications tailored to each victim's context, mimic writing styles, create synthetic voices, or produce images and videos capable of reinforcing a fake identity.
The FBI recorded over 22,000 complaints related to the use of artificial intelligence in 2025, with adjusted losses exceeding US$893 million. Documented methods include using generative AI to craft Business Email Compromise (BEC) emails, cloning voices to request fund transfers, and producing content used in various types of fraud.
This presents a new challenge for financial organizations. The content of an interaction can appear legitimate even when the identity behind it is not.
When AI Also Plays a Defensive Role
The answer is not to stop using AI. Precisely because attackers are adopting it, security teams need to use it to analyze the same environment at greater speed. This is where the second half of the equation comes in.
Models can analyze vast amounts of signals, detect anomalous behavior, identify connections between seemingly unrelated events, and help prioritize investigations. Google describes this dynamic as a "dual-use" scenario. While attackers use AI to accelerate their operations, the company employs systems like Big Sleep to identify vulnerabilities and CodeMender to help automatically fix them. This logic applies to fraud as well.
If an attacker can automate the creation of a synthetic identity, a fake interaction, or a social engineering campaign, the defender needs to automate the ability to evaluate those signals.
Speed Becomes Part of the Defense
The challenge lies not in detecting a signal, but in connecting the context. One of the main limitations of traditional approaches is analyzing each event in isolation.
- A credential might be valid.
- The device might be recognized.
- The location might appear plausible.
- The session might have successfully passed authentication.
And yet, the entire operation could still represent fraudulent behavior.
AI enables a shift toward a more contextual assessment. Instead of simply asking whether a specific signal is correct or incorrect, it can analyze how consistent the set of signals is with expected behavior. This is especially relevant when attacks combining various techniques emerge.
A fraud incident might begin with phishing, proceed to session hijacking, and employ social engineering and culminate in a seemingly legitimate transfer. No single event necessarily explains the full scope of the risk. The key lies in connecting the dots.
The New Battlefield
Deloitte notes that the use of AI in financial institutions continues to grow, with fraud detection use cases being among the most common. At the same time, it identifies governance challenges and the need to establish appropriate controls and boundaries around these models. This raises a strategic question for banks and fintechs.
What happens when the attacker's speed of adaptation outpaces the speed at which defenses are updated?
The answer cannot rely solely on adding another AI model. Teams need the ability to continuously monitor the environment, combine signals, reassess risk as the context shifts, and learn from new attack patterns. After all, the attacker's objective does not remain static either. The race will be ongoing.
The AI used by criminals will evolve. Defensive models will have to evolve as well. And the advantage will not necessarily go to whoever has "more AI," but to whoever can most quickly turn it into context, intelligence, and security decisions.
AI vs. AI: The Next Stage of Fraud Prevention
Artificial intelligence is changing the nature of digital fraud.
It is no longer just about detecting a malicious email, a fake identity, or an unusual transaction. It is about understanding increasingly dynamic operations, where multiple techniques can combine and adapt in real time.
In this scenario, defense strategies must evolve from models that react to known patterns toward systems capable of continuously interpreting signals, context, and behavior. The race between attackers and defenders has already begun. And in this new stage, the question won't be who uses artificial intelligence. It will be who can use it to adapt the fastest.
Stay Ahead of Fraud