By Walt Williams
Bank customers want to know their money is safe and they expect easy access to their money. Banks have long sought to balance those two competing interests, but the rise of widely available and cheap deepfake and artificial intelligence technologies is straining the systems they have in place to achieve that equilibrium. And even as new threats emerge, consumers remain wary of the added security measures that banks put place to prevent fraud and cyber attempts if customers report something amiss.
“A lot of times they end up not disputing transactions because they don’t want to lose access to their card or their account shut off,” says Heather Schaefer, CRCM, CERP, VP and chief risk officer at First Financial Bank in Indiana. “They don’t want to be hassled, even if it is to protect them from themselves or from an AI situation.”
In recent years, the banking, technology and government sectors have been collaborating to find ways to strengthen security even as new technologies lower the barriers to creating convincing false identities. A mix of government action, technology adoption by financial institutions and consumer education will be needed to smooth the friction between security and customer access.
“When talking about customer friction, there are so many steps that bankers on the front lines with customers are dealing with every day,” says Schaefer, who moderated a panel on the subject at the ABA Risk and Compliance Conference in May.
Fraudster strategies
In 2024, several organizations — ABA, the Better Identity Coalition and Financial Services Sector Coordinating Council, and the Financial and Banking Information Infrastructure Committee — brought together more than 60 executives from the private, public and nonprofit sectors in a year-long effort to address risks with AI and identity and authentication. That working group found that bad actors were targeting authentication systems in three ways, says John Carlson, the association’s SVP for cybersecurity regulation and resilience.
The first tactic is deepfake-driven social engineering and impersonation, which includes using technology to mimic other people’s voices when calling a bank’s call center, or using AI to create realistic phishing emails. The second tactic is synthetic identity creation, such as using AI to impersonate other people over real-time video. The third is using AI agents as attack surrogates by leveraging the technology to launch account takeovers and automated fraud campaigns.
AI is also being leveraged against customers to bypass bank security measures. “A fraudster is presenting themselves as their child or grandchild or someone they know, because they’ve leveraged audio or video from a social media feed that they then use to create a deepfake,” Carlson says. “So the trust has been crossed over, meaning they believe they are dealing with the person they know. And then the fraudster claims that the grandchild has been arrested at a police station and they need to have money wired or sent in some way, shape or form, oftentimes through crypto.”
Mitigation and education
The working group ultimately produced a series of papers with policy recommendations for tackling the problem, along with mitigation strategies for financial institutions. Some of those strategies include using image-analysis tools to detect photo editing, ensuring that call centers have multiple risk-based technologies in place, implementing additional processes when transferring funds and using phishing-resistant authentication, such as passkeys.
Still, heightened security can translate into additional roadblocks for customers trying to access their accounts. The working group concluded that customer education will be a vital component in any defense strategy. It recommended that government agencies collaborate with the financial services sector to develop educational campaigns that teach best practices for avoiding AI-enabled scams.
As far as the financial institutions themselves, the working group coauthored two reports with ABA, including one with recommendations on what a consumer education campaign should look like. Any institution’s campaign should avoid “information overload” by focusing on its clients’ primary communication channels, digital banking behaviors and specific fraud risk exposure, according to the report. That means an institution focused on small business growth might prioritize education about AI-enhanced phishing campaigns targeting invoice or payroll systems. An institution aiming at consumer awareness may educate customers on deepfake “grandparent” scams.
“You want to have all those layered controls behind the scenes that are effective in detecting and identifying when someone is being impersonated or using a synthetic identity,” Carlson says. “But I think you also need a conversation with the customer to say, ‘Hey, we’re in a changing risk environment. We are doing more at our bank to protect you and protect the institution, and we’re going to be requiring more, which will sometimes be visible to you and sometimes will not be visible.’”
“Maybe there’s a way to merge the customer education with the value proposition of why you’re needing to step up your authentication, or to step up your controls and to drive home the message that we’re here as a bank to protect you as our customer, because we are seeing this rising tide of AI-generated fraud,” he adds.









