UK fraud losses hit £1.17bn in 2024. With AI fuelling attacks, this piece explores how banks can harness AI to defend payments and restore trust.
Payment fraud in the UK has reached unprecedented levels. In 2024 alone, £1.17 billion was stolen through authorised and unauthorised methods, with more than 3.1 million confirmed cases of unauthorised fraud – a 14% year-on-year rise. Remote purchase fraud, where stolen card details are used online, surged 22% and is now the most common attack vector.
At the same time, fraudsters have also adopted AI as a tool for their malicious activities. From deepfake voice calls to synthetic identities and hyper-personalised phishing, AI has supercharged fraud. More than 50% of fraud attempts now use AI techniques. Yet the technology is also becoming the most vigorous defence: nine in ten UK banks already deploy AI in their fraud detection strategies.
The message is clear: only AI can fight AI. And critically, AI systems need assurance, governance and regulatory alignment to deliver results without introducing new risks.
The following actions highlight how banks, regulators, and partners can harness AI effectively to combat fraud while maintaining trustworthy, compliant, and resilient defences.
Strengthen behavioural analytics with “segment-of-one” profiling
Traditional fraud detection relies on rules and thresholds, such as blocking large transactions and flagging unusual geographies. These blunt tools are easily gamed.
AI now enables hyper-granular monitoring of each person’s unique behaviour, known as segment-of-one profiling. This encompasses subtle patterns, such as mouse movements, typing cadence, mobile touch pressure, and normal transaction rhythms. Even with correct credentials, deviations in behaviour reveal attacks.
To stay ahead, banks must invest in behavioural biometrics that monitor hundreds of real-time data points and continually train models on evolving attack patterns—particularly for mobile-first fraud, which rose 11% after iOS updates enabled remote-access scams.
Deploy real-time AI decisioning for transactions
Fraud occurs in milliseconds; stopping it requires the same speed. Mastercard and others are expanding AI-powered, real-time insights to UK banks, enabling transaction checks before funds are transferred from accounts.
These systems assess hundreds of factors simultaneously—device integrity, network anomalies, location patterns—and return a fraud score in under 300 milliseconds.
For effectiveness, these engines must remain explainable to meet FCA accountability requirements, while integrating tightly into payment rails to minimise false positives and negatives without compromising the customer experience.
Embed AI into open banking fraud prevention
Open banking has spurred innovation—but also new attack vectors. With 59% of UK banks citing it as a rising fraud risk, AI must play a central role.
Replacing insecure screen scraping with AI-enhanced API monitoring that detects anomalies in real-time will be crucial. So will intelligence sharing across participants. By flagging compromised accounts or mule behaviour before transactions spread, banks can protect open banking without slowing growth.
Harness collaborative AI threat intelligence
Fraud is borderless: 75% of UK e-commerce fraud links to overseas merchants. The next step is AI-powered mining of shared datasets for cross-institution patterns — such as mule recruitment or deepfake campaigns—that would otherwise remain hidden. Participation in collaborative AI platforms will turn collective knowledge into stronger collective defence.
Invest in mobile-first AI defences
As banking shifts to mobile, criminals exploit remote-access tools and malware to bypass device security. Remote access fraud has contributed to the overall growth in mobile first fraud and is expected to continue rising.
AI models need training on mobile-specific behaviours such as swipe dynamics, tilt, and habitual app switching. They must also recognise signs of remote-control activity, like identical device fingerprints accessing multiple accounts. By adapting biometrics to mobile devices, banks can close one of the fastest-growing channels of fraud.
Prepare for quantum-enhanced fraud and defence
The UK government’s £162 million investment in quantum technology signals both risk and opportunity. Quantum computing could undermine current cryptography, enabling criminals to break encryption. But it also promises transformative fraud detection through faster pattern recognition.
Banks should begin migrating to quantum-resistant cryptography now, while also exploring quantum-ready AI that could one day significantly enhance fraud pattern recognition.
Align AI fraud prevention with regulation
The UK is a global pioneer in fraud regulation, introducing mandatory reimbursement for authorised push payment (APP) fraud in 2024. This has already led to 86% of eligible losses being returned to victims. But compliance demands AI models that are both accurate and explainable—regulators must understand why a transaction was blocked or reimbursed.
Building algorithmic accountability frameworks that document decision logic, alongside regular audits for FCA and PSR compliance, will be critical to sustaining public trust and preventing discriminatory outcomes.
Tackle synthetic identities and deepfakes with AI
Fraudsters are increasingly deploying AI to fabricate entirely new identities, complete with convincing voice, image, and video evidence. These bypass traditional ID checks and even fool biometrics.
To counter this, banks must deploy multi-layered verification that combines biometric checks with behavioural analysis, device reputation, and cross-platform correlation. AI models must also be trained to detect deepfake artefacts, from unnatural facial micro-expressions to irregular voice patterns that go unnoticed by humans.
Create fraud orchestration platforms
The long-term vision for UK banks should be integrated fraud orchestration platforms. These systems unify transaction monitoring, behavioural biometrics, open banking APIs, reimbursement workflows and regulatory reporting into a single AI-driven ecosystem.
Moving from siloed detection tools to orchestration provides banks with visibility across all interactions, automates compliance reporting, reduces costs, and enhances transparency.
The fraud war is no longer about reacting to losses; it is about preventing attacks through AI-driven intelligence. UK banks that invest now in behavioural analytics, real-time monitoring, open banking security and collaborative threat sharing will protect customers, reduce compliance costs, and secure competitive advantage.
AI is both the fraudster’s weapon and the bank’s shield. The institutions that learn to wield it most effectively will define the future of safe payments in the UK.
Disclaimer: This content has been contributed by a member of The Payments Association and represents the views of the author alone. It does not constitute The Payments Association’s research, advice, or official position.



















