The $40B AI Fraud Crisis: The Industry Fights Back
Deloitte projects AI-enabled fraud will reach $40 billion by 2027. Here is how the financial industry's landmark 20-point plan reshapes KYC compliance.

Three of the most influential organizations in financial services compliance released a joint policy document on April 1, 2026. It sounds less like a white paper and more like an emergency declaration. The American Bankers Association (ABA), the Better Identity Coalition, and the Financial Services Sector Coordinating Council (FSSCC) — joined by more than 130 experts from financial institutions, technology companies, and government agencies — devoted 18 months to a two-document set. That package maps the full scope of AI-enabled identity fraud and puts forward 20 specific policy actions to contain it.
A single incident did not set this off. The trigger was a trend line that had become impossible to deny.
Figures That Left No Room to Wait
Deloitte's Center for Financial Services framed the core forecast in blunt language: generative AI could drive fraud losses to $40 billion in the United States alone by 2027, against $12.3 billion in 2023. A 32% compound annual growth rate of that kind turns a risk-management problem into a systemic threat.
The channels feeding the surge look equally severe:
- Deepfake injection attacks increased 783% in the most recent reporting period
- Deepfake incidents in the fintech sector grew 700% in 2023 compared to 2022
- AI-generated facial imagery now routinely passes first-generation liveness detection systems
- Synthetic identity fraud has become the fastest-growing category of financial crime
Another report, issued on April 24, 2026, stretches the horizon. Global digital payments fraud losses are projected to more than double from $40 billion in 2024 to $100 billion by 2029, and AI is expanding the attack surface and the defensive toolkit at the same time.
None of these figures appeared from nowhere. KYC bypass attacks in recent months have already shown how far the barriers to a sophisticated identity-fraud attempt have fallen. Work that once demanded serious technical skill and expensive infrastructure now sells for less than $20 per attempt on a commercial darknet marketplace.
Inside the Joint Policy Package
Two documents make up the ABA/FSSCC/Better Identity Coalition publication. Financial institutions are the audience for the first, which reviews attack methodologies and the defensive technologies firms can put in place today. Policymakers are the audience for the second, which lists 20 specific actions the authors consider necessary to build the regulatory and infrastructure conditions for effective defense.
A shared thesis runs through both texts. Identity fraud driven by AI is not a cybersecurity problem that individual institutions can solve on their own. Coordinated action across government, regulators, and industry is required — and those actions have to move faster than the legislative calendar usually allows.
Four Recommendations With the Widest Reach
From the full list of 20 recommendations, the authors singled out four with the broadest cross-sector impact. Federal action in these areas, the working group judged, would unlock the largest defensive gains.
1. Accelerate NIST Liveness Detection Guidance
NIST is updating SP 800-63-4, its digital identity guidelines, to cover modern threats that include deepfakes and synthetic biometrics. One critical gap is still open: a standardized testing methodology for liveness detection technology.
Financial institutions, without a federal benchmark, are buying liveness products against inconsistent vendor claims and with no independent validation framework. Attackers, at the same time, are already reverse-engineering first-generation systems. Bank onboarding deepfake attacks have already documented how modern camera injection techniques defeat liveness checks that rest on simple motion detection or reflection analysis.
NIST is being pressed by the working group to speed publication of minimum performance standards — specifically testing protocols that measure resistance to 3D mask attacks, video injection, and AI face-swapping tools. The WEF's 2026 report "Unmasking Cybercrime" examined 17 face-swapping tools and 8 camera injection tools and arrived at the same finding: vendors cannot make credible comparative claims without standardized evaluation criteria.
2. Expand eCBSV Access
Participating financial institutions can use the Social Security Administration's Electronic Consent Based SSN Verification (eCBSV) service to check, in real time, whether a Social Security Number, name, and date of birth combination matches SSA records. That check hits the mechanics of synthetic identity fraud directly.
A typical synthetic identity pairs a real SSN — often belonging to a child, elderly person, or recent immigrant with a thin credit history — with fabricated name and address information. eCBSV breaks that pairing at the point of verification. Access, however, has been limited to depository institutions, shutting out many fintechs, crypto platforms, and non-bank lenders that operate under state licenses.
The paper calls for expanding eCBSV access across institution types and lowering adoption barriers. An existing federal tool, in this rare case, could cut fraud immediately if those access constraints were lifted.
3. State Infrastructure Grants Tied to NIST Standards
A Treasury-run grant program for state-level identity verification infrastructure improvements would be created by the Stop Identity Fraud and Identity Theft Act of 2026 (HR 7270). State driver's license databases, real-ID infrastructure, and identity document issuance systems are foundational inputs to financial institution KYC — and many of them remain technically outdated.
Those grants, the recommendation says, should be tied to NIST guideline compliance. States would then have a financial incentive to modernize infrastructure so that it yields verifiable identity data financial institutions can actually rely on.
4. Multi-Agency Task Force on AI Identity Threats
No single federal agency holds a comprehensive mandate to monitor, assess, and coordinate responses to AI-driven identity fraud across sectors. Pieces of the picture sit with the FBI, NIST, Treasury, the FTC, and banking regulators, yet they do not operate with shared threat intelligence or coordinated response protocols.
A cross-agency task force is what the paper proposes, with an explicit mandate to monitor AI-driven identity threats, share intelligence across financial sector participants, and accelerate coordinated standards — before the next generation of attack tools makes current defenses obsolete.
Passkeys and Authentication That Resists Phishing
The paper does not stop at the identity-proofing moment, when a person first proves who they are during account opening. Ongoing authentication is in scope as well. The direction is unambiguous: regulators should push financial institutions toward FIDO2 security keys and passkeys for internal systems and customer-facing applications alike.
That recommendation tracks the updated NIST SP 800-63B-4 framework, which now formally folds passkeys into authentication assurance levels. Synced passkeys qualify for AAL2 (Authentication Assurance Level 2); device-bound passkeys reach AAL3. SMS-based one-time passwords, still widely used across financial services, do not meet these levels and are called out as inadequate against AI-powered social engineering.
For compliance teams, the operational implication is straightforward. Institutions that wait for regulatory mandates before leaving SMS OTP will confront compressed timelines and higher implementation costs once those mandates land.
Steps Compliance Teams Can Take While Policy Catches Up
Legislators and regulators are the addressees of the 20-point plan. The practical question for compliance teams at financial institutions, crypto exchanges, and regulated fintechs is what to do while federal action is still forming. Several moves follow clearly from the evidence the paper lays out:
Audit liveness technology against current attack vectors. A documented gap exists if your biometric verification vendor cannot show testing against camera injection and 3D mask attacks. Agentic KYC platforms that keep detection models current close that gap structurally — static liveness models that are not updated against new attack tools go stale faster than procurement cycles can respond.
Implement layered identity signals. Document, biometric, or behavioral verification on its own is no longer enough. The WEF report and the ABA/FSSCC paper land on the same conclusion: effective defense depends on adaptive, multi-layered approaches that correlate signals instead of treating each one in isolation.
Accelerate eCBSV integration. US-regulated institutions should treat eCBSV adoption as a near-term priority, not a later roadmap item. Expanding access, as the policy paper recommends, may take time; firms already integrated will hold a compliance and fraud-reduction advantage.
Score synthetic identity risk continuously. Thin credit files, unusual application timing, and specific document inconsistencies — the fraud patterns typical of synthetic identities — can be spotted through behavioral and document analytics. Autonomous identity agents can watch those signals throughout the customer lifecycle rather than only at the onboarding checkpoint.
Assign a passkey migration timeline. If SMS OTP still sits in your authentication stack for high-value transactions or administrative access, set a deprecation date. The regulatory signal is already clear; the remaining question is whether your institution leads or reacts.
Why the Cost Structure Favors Attackers
An asymmetric cost problem sits at the root of the 20-point plan. The fraud 4.0 dynamic — AI-generated attacks met by AI-driven defenses — has produced a situation in which a convincing deepfake identity costs less than $20 to generate, while a manual compliance review runs to hundreds of dollars per case once analyst time, escalation, and rework are included.
Machine speed was never the design target for manual review pipelines. Fraudsters using AI tools can file hundreds of synthetic identity applications per day. No compliance team scales at that rate. New research from Mitek Systems and Datos Insights puts a number on the exposure: synthetic identity fraud is on track to exceed $3.1 billion in 2026 losses, growing at roughly 16 percent per year — a pace no manual review headcount can absorb.
That imbalance is the core case for autonomous AI agents in identity verification. They are not a substitute for human judgment in complex or edge cases. They are the first layer that works at machine speed and scale, triaging the fraud patterns human reviewers should never need to see.
A political and regulatory answer to a technological problem is what the industry's 20-point plan provides. Adaptive, continuous, AI-driven verification is the technological counterpart that compliance infrastructure still needs to sit alongside it.
How the Compliance Obligation Itself Is Changing
A wider implication sits inside the policy paper, beyond any single recommendation. Identity verification is framed explicitly as a continuous obligation, not a one-time onboarding event. That language tracks the EU's AMLR 2027, which requires risk-proportionate monitoring throughout the customer relationship, and the AMLA supervision framework already active in Europe.
Across jurisdictions, the regulatory path is converging on the same model. Identity verification is not a gate passed once. It is an ongoing process that must scale with risk. Firms that invest now in adaptive, autonomous verification infrastructure will be better placed for the fraud threats already in play and for the regulatory requirements still being written.
FAQ
What is the ABA/FSSCC/Better Identity Coalition joint policy paper?
It is a two-document set published on April 1, 2026 and developed over 18 months by more than 130 experts from financial institutions, technology companies, regulators, and government agencies. Attack methods and defensive tools for firms are covered in one document; 20 policy recommendations for policymakers addressing AI-driven identity fraud are laid out in the second.
What is the $40 billion fraud projection based on?
Generative AI-enabled fraud losses in the United States could reach $40 billion by 2027, according to Deloitte's Center for Financial Services, up from $12.3 billion in 2023 — a compound annual growth rate of 32%. Digital payments fraud will exceed $100 billion by 2029, according to a separate April 2026 global report.
What is NIST's role in liveness detection standards?
SP 800-63-4, NIST's digital identity guidelines, is being updated. The industry is pressing NIST to speed publication of minimum performance standards for liveness detection technology, so financial institutions can judge biometric vendors against independent benchmarks instead of unverified claims.
What is eCBSV and why does it matter for KYC?
Financial institutions can use the SSA's Electronic Consent Based SSN Verification service to check Social Security Number, name, and date of birth combinations against federal records in real time. That check hits synthetic identity fraud directly, since those schemes pair a real SSN with fabricated personal information. Expanding access to this service is one of the four priority recommendations in the joint policy paper.
What are passkeys and why are regulators recommending them?
Passkeys are FIDO2-based cryptographic credentials designed to resist phishing. NIST SP 800-63B-4 formally places passkeys inside AAL2 and AAL3 authentication assurance levels. Regulators, the ABA/FSSCC paper argues, should push financial institutions toward passkeys and FIDO2 security keys in place of SMS-based one-time passwords, which fall short against AI-powered social engineering.
How can autonomous AI agents help compliance teams respond to AI-driven fraud?
AI-generated identity fraud attacks run at machine speed and scale — hundreds of synthetic applications per day at a cost of under $20 each. Manual compliance review cannot match that throughput. Behavioral signals can be watched continuously by autonomous AI agents, which also score synthetic identity risk patterns and trigger enhanced due diligence workflows across the full customer lifecycle, closing the cost gap that makes AI fraud economically viable for attackers.
Related Articles

Synthetic Identity Fraud: The $3.1B Crisis Reshaping KYC
Synthetic identity fraud will cost $3.1B in 2026. New research reveals why static KYC fails against ghost identities—and how continuous AI monitoring closes the gap.

Voice Cloning Is Breaking KYC: The $1.8B Crisis
Financial institutions lost $1.8B to AI voice cloning in 2025. Here's why phone-based identity verification is now fundamentally compromised—and what must change.

Fraud Rings Now Recycle Identities Across KYC Systems
Shufti's September 2026 report exposes how organised fraud rings share devices, IP addresses, and forged identities to defeat KYC at scale.