Key takeaways
- Artificial intelligence is making credible deception cheaper, faster and easier to adapt.
- Static rules and point-in-time checks will not detect every attack.
- Defensive AI can connect identity, device, behavioural and transaction signals, but firms must use it lawfully and fairly.
- Fraud controls need to operate across the full customer and product lifecycle.
- Regulators will examine what firms have done to prevent fraud, how they have handled customer responses, governance and their approach to decision-making.
Fraud is not new. But it is changing.
AI allows criminal actors to produce convincing identities, documents, voices and conversations at speed. It can also help them test controls, observe the result and change their approach in real time.
Financial services firms face a difficult asymmetry. Fraudsters can use AI without considering whether their methods are lawful, fair or transparent. Regulated firms cannot.
Gilbert + Tobin hosted the Australian Finance Industry Association’s Fraud Uncovered: Beyond the Scam – Preventing Tomorrow’s Fraud Today summit at our Sydney office.
Antonia Garling moderated the opening panel, The Changing Face of Fraud, with Rachel Walker, Daniel MacPherson and Georgina Willcock. Melissa Fai and Simon Burns later presented Fighting AI with AI: Defending Against the Next Generation of Digital Crime.
Both sessions reached a common conclusion: firms need more adaptive fraud controls, but the technology used to defend customers creates legal and governance risks of its own.
AI changes the economics
AI has not simply made fraud more sophisticated. It has changed how quickly and cheaply credible deception can be produced.
One actor can generate many documents, identities and scripts, each with small variations. That makes repeated patterns harder to identify and allows criminal groups to test more approaches at a lower cost.
AI also increases speed. An attacker can test an application or transaction workflow, observe whether the institution approves or declines it and adjust the next attempt.
Voice, video and language can be tailored using public or compromised information. This supports highly personalised phishing, impersonation scams, business email compromise and fake customer service interactions.
Attackers can also move between channels, change transaction amounts and work around thresholds once a control starts detecting them.
This creates an arms race. Successful attacks produce more data about what works. That data improves the next attack. Defensive systems need to learn and respond at a comparable pace.
Lending gaps remain
The lending sector continues to face risks that AI can amplify.
Applicants can alter payslips, financial statements and bank records to inflate income or conceal expenses. Generative AI makes convincing documents easier to create and harder to identify.
Third-party distribution adds another layer of risk. Brokers, referrers and other intermediaries give lenders reach and customer choice, but they can reduce direct contact between the lender and customer.
This can make it difficult to identify whether false information came from the customer, an intermediary or both. It also increases the importance of obtaining reliable data directly from its source.
Fraud controls cannot stop at application and settlement.
Payment redirection scams often occur months after a facility is established. A fraudster who compromises an email account can redirect several payments before the institution detects the change.
Firms should assess fraud risk separately for each distribution channel and stage of the product lifecycle.
Defence needs context
Defensive AI is not one model that approves or declines a transaction. It is a set of tools that can help an institution detect, investigate and intervene earlier.
Melissa and Simon identified several applications:
- identity intelligence can connect  identity, device, document, location and network signals. The question is no  longer whether one credential appears genuine, but whether the entire  interaction makes sense
- behavioural analysis can identify account takeover, coercion or a departure from the customer’s usual activity. This may include changes in how a customer types, navigates or uses a device
- real-time scam detection can assess a  sequence of events. A suspicious call followed by a new device, new payee and  unusual transfer may justify an intervention even if each event appears normal in isolation
- investigation tools can connect transactions, accounts, devices and communications after an event. Adversarial testing can also help firms examine their controls from an  attacker’s perspective.
The shift is from credential verification to contextual authentication. Instead of asking only, ‘Who are you?’, the institution also asks, ‘Does this interaction make sense?’
The session explored how an AI voice bot could be placed in the path of a suspected scam call. The bot could keep the caller engaged while the institution studies the scammer’s scripts and tactics.
That information could improve warnings, controls and cross-sector intelligence sharing. It could also help disrupt a scam before the customer loses money.
But technical success does not settle the legal position. Depending on how the system operates, communications interception, surveillance and privacy laws may apply.
The law constrains defence
AI-based fraud controls can create serious consequences for customers. A system may block a payment, restrict account access, decline an application or identify a person as high risk.
Firms need to understand how the system reaches those outcomes. While AI tools may be part of a firm’s toolkit for combating scams, the firm cannot shift its legal responsibilities – it retains obligations under its licence and to customers, and can be liable if the system is misapplied.
Historical or incomplete data may produce biased results. A model may generate more false positives for particular demographic, cultural or socioeconomic groups. That can raise issues under financial services, consumer protection and anti-discrimination laws.
The risk increases when the model operates as a black box. If staff cannot explain why the system produced an alert, they may struggle to investigate the result, communicate with the customer or defend the decision.
Implementation is not the end of the process. Firms should test for model drift, monitor false positives and assess whether the control remains suitable as fraud patterns change.
Human review remains important where an intervention may materially affect the customer. AI should support judgement, not remove accountability.
Privacy is another constraint. Fraud tools may collect, infer or combine personal information, including device data and behavioural signals. The Office of the Australian Information Commissioner’s guidance confirms that the Privacy Act applies when AI collects, generates or infers personal information.
From 10 December 2026, additional privacy policy obligations apply where an organisation uses personal information in automated decision-making that may significantly affect an individual’s rights or interests. The policy will need to explain the types of information used and the types of decisions made or supported by the program.
Surveillance and workplace monitoring laws may also apply, particularly where an organisation uses a tool to identify insider fraud. Notice requirements can sit uneasily with covert monitoring, so firms should resolve that issue before deployment.
There is also a practical tension between transparency and control security. Customers need a meaningful explanation of decisions affecting them. Firms should not, however, reveal enough detail to let attackers work around the model.
Regulation is tightening
Regulators do not need to wait for AI-specific fraud laws before acting.
Existing financial services and credit  laws, responsible lending, privacy, dispute resolution and risk management obligations already apply. A new tool must operate within that framework.
The Scams Prevention Framework adds more direct obligations across designated banking, telecommunications and digital platform services. The framework is built around preventing, detecting, disrupting, responding to and reporting scams.
Designated organisations must be members of the Australian Financial Complaints Authority from 1 September 2026. AFCA will begin considering complaints under the framework about relevant matters occurring from 31 March 2027.
The framework does not prescribe one fraud detection technology. It does increase the pressure on firms to show that their controls and governance processes match the nature and speed of current threats.
Anti-money laundering and counter-terrorism financing (AML/CTF) controls also need to connect with fraud monitoring.
Reforms to AML/CTF obligations commenced for existing reporting entities on 31 March 2026. The Australian Transaction Reports and Analysis Centre expects those entities to maintain effective controls, manage relevant risks and make sustained progress when implementing reform-related changes.
Fraud detection, transaction monitoring and suspicious matter reporting should not operate as separate processes. A signal identified by one team may complete the picture for another.
Response is a control
Technology is only part of the regulatory picture.
In June 2026, the Federal Court ordered HSBC Australia to pay a $35 million penalty for failures relating to scam prevention, investigation and responding to customers.
The admitted failures included inadequate controls on an internal payment system, delays that meant investigations took an average of 144 days and inadequate systems for helping customers regain account access. The contraventions concerning inadequate scam controls were allocated a penalty of $10 million, whereas $25 million in penalties related to the contraventions concerning management of customer complaints and communications to customers about reactivating frozen accounts.
The case shows that regulators will examine not only how a firm is managing the risk of fraud occurring, but how it responds and handles customers if apparent fraud has occurred. Firms need to investigate promptly, give customers clear information and review restrictions on their accounts. They also need to apply the relevant payment, complaints and remediation rules consistently.
The case shows that governance records matter and clear record-keeping will be important for a firm in establishing that it sought to manage fraud (in a changing and challenging environment) seriously and proportionately. A firm should be able to show:
- when management became aware of a fraud trend
- how it assessed the risk
- what control changes it considered
- why it selected or rejected a response
- how it monitored implementation.
A fraud incident may also engage AML/CTF, privacy, financial services breach reporting, cyber security and law enforcement processes. Voluntary reporting may also be appropriate, because intelligence sharing and education is a key component of effective fraud response management.
Incident plans should identify who can stop a payment, preserve evidence, contact the customer, assess reporting obligations and approve remediation. Teams should test those plans before a real event occurs.
What firms should do now
To respond effectively, financial services firms should:
- map fraud risks across each customer type, product and service,  distribution channel and stage of the customer lifecycle
- test controls against realistic scenarios, including AI-generated  documents, deepfakes, synthetic identities, mule activity and payment  redirection. Control testing should cover fraud identification as well as  appropriateness and timeliness of response
- assess AI tools for data quality, bias, false positives,  explainability, security and model drift
- retain human review for decisions that can materially affect a  customer
- connect fraud, cyber, AML/CTF, payments, hardship, breach and  complaints data
- confirm that alerts support real-time intervention and response,  rather than post-event investigation alone
- document management decisions, control limitations and remediation
- update incident response plans to cover each potential reporting and  customer response pathway.
Fraud is becoming more adaptive. The response must be equally adaptive, but not indiscriminate.
Firms need systems that can move quickly, people who can challenge their outputs and records that explain why the institution acted.
No single organisation sees the full chain. Effective prevention will also depend on faster information sharing and coordinated action across lenders, payment providers, telecommunications companies, digital platforms, regulators and law enforcement.