At the Fraud Leaders Summit in London last month, I stood in front of a room of fraud leaders and asked the question: if attackers are pivoting daily, why is your control stack still updated quarterly? The session looked at the rise of generative AI and how it has fundamentally changed the economics of fraud: how AI is being used by fraudsters, how good we are at stopping it, and which controls have the greatest impact on fraud prevention outcomes
Criminals can now launch attacks at a scale, speed and level of sophistication that was previously impossible. As a result, fraud losses continue to rise despite growing fraud prevention investment.
In fact, 70% of banks report increasing fraud losses, despite most banks spending more every year on fraud prevention [a].
We can also see the increase in the industry fraud statistics: UK fraud losses increased by 4% and case volume increased by 11% [1]. In EU the total value of fraud increased by 20% from 2023 to 2024 [2].
Fraud is driven by GenAI
The increased availability and sophistication of generative AI models are helping fraudsters both increase the scale, efficiency and effectiveness in their attacks.
Previously fraudsters faced a trade-off between personalized messages that were effective but time-consuming to create, or automated attacks at scale using generic content that achieved lower success rates.
That is no longer the case, by using AI fraudsters can deliver personalized messages at scale. Today, 82.6 % of all fraudulent messages are generated with help of AI [3].
And these AI generated personalized messages are even more effective than a personalized message from a human. AI models now generate messages that are 24% more persuasive than a message from a human fraudster.

In 2023, the AI models had only 69% of the effectiveness of a human-crafted message [4].
In 2024, it increased to between 90% and 100% effectiveness of a human-crafted message [4] [5].
In 2025, it was 124% effectiveness of a human-crafted message. [4]
There is no longer a trade-off, the fraudsters have both the scale and the effectiveness.
And sending messages are only part of the fraudsters use of AI. They use them across the entire attack chain [6]: image generation, text generation, chatbots, voice cloning, video generation, and deepfakes.

Fraudsters have automated and scaled their operation, as well as increased the effectiveness of every interaction. This increases the challenge on banks to prevent, detect and intervene.
Fraud detection rates
So how good are banks currently in detecting fraud? As I have written before, some of the core KPIs for measuring fraud detection performance are [7]:
- Account Detection Rate (ADR),
- Transaction Detection Rate (TDR),
- Value Detection Rate (VDR)
Gartner® has in its latest research studied the spread of the TDR performance among banks [8]:

In summary, 31% of the banks have high detection rates: above 80% TDR. Another 34% of the banks have between 60% and 80% TDR, which is still solid performance.
However, the remaining 35% of banks are below 60% TDR. Those banks are struggling to identify fraudulent transactions, or as it is phrased in the Gartner® report: “One in three banks are not successful in pre-emptive fraud detection.” [8]
We know how to improve it
Fortunately, we know how to improve the prevention and detection performance. Research by Finextra and NICE Actimize the top three highly effective fraud controls, in addition to transaction monitoring, for European banks are [9]:
1. Human intervention (fraud specialist in contact centre)
2. Behaviour biometrics
3. Strong user authentication (MFA, biometrics, eID, step-up auth)
So how many banks have adopted these fraud controls?
Strong User Authentication is nearly universal, more than 95% of banks are using it [b], driven in part by regulatory requirements.
Human intervention is also commonplace, particularly among traditional financial institutions. Even digital-first banks and fintechs are increasingly introducing specialist fraud teams and customer outreach to combat authorised push payment scams and social engineering attacks.
However, behaviour biometrics is a major gap, only 52% use behaviour biometrics [b], despite it being the second most effective fraud control.

AI for fraud operations
While human intervention remains one of the most effective fraud controls, it is also one of the most resource intensive. Fraud specialists spend significant time reviewing alerts, investigating cases, contacting customers and documenting outcomes. As fraud attack volumes increase, scaling these operations becomes increasingly expensive.
Therefore, 31% of European banks have deployed GenAI for fraud operations, including activities such as agent assist, case summarization, alert triage [9].
One example is Lloyds Banking Group, which is a customer of Callsign [10], that has a program for AI agents for fraud operations. It is part of a £100 million of planned AI value. “The agentic AI system helps fraud teams by deploying multiple AI agents in real time, allowing colleagues to assist customers more quickly” [11].
Using AI to improve efficiency of fraud operations will free up time to handle more alerts and enable capturing more fraud.
AI for dynamic interventions
A big part of human intervention, is speaking to the user on the phone and break the spell of the fraudster that the user is under, helping the user recognise suspicious activity before money leaves their account.
However, it is expensive: the average talk time on the phone for one UK bank is 8 minutes and 20 seconds [12]. Considering typical cost-per-minute for call centres which is $2.11 for a median organisation [c], the cost for human intervention time for a fraud alert is $17.61. This also varies significantly depending on fraud type, where complex romance or investment scams can require hours on the phone with the user.
The real game changer to be able to scale this human intervention by automating it.
This is where Dynamic Intervention comes in [13]. By using AI to ask the user a series of questions, the dynamic intervention performs the same activity as a human intervention, asking contextual questions designed to assess risk and encourage critical thinking before payment completion. In many cases, this enables customers to identify that the recipient is fraudulent and voluntarily cancel the transaction before any loss occurs.
The result is a more scalable, more consistent and more cost-effective approach to fraud intervention. [13]
Behaviour biometrics
Behaviour biometrics is the most underutilized, yet highly effective fraud control. Only 52% of the banks are using behaviour biometrics, despite it being the second most effective fraud control.
Behaviour biometrics is using details about the user’s interaction with their device to identity who they are and asses the risk of fraud:
• Typing patterns
• Touchscreen behavior
• Device handling
• Navigation behaviour
• Signs of hesitation
• Indicators of external coaching or manipulation
These behavioural signals can reveal when a user is acting differently, potentially indicating that they are being manipulated by a scammer or that an attacker has gained access.
Banks deploying behavioural biometrics have achieved improvements of at least 40% in fraud detection rates compared with transaction monitoring alone [14].
Behavior biometrics really shine in combination with dynamic interventions, where the user’s behavior while answering the questions also provide further clues to if the user is being scammed [13].
Conclusion
As fraudsters continue to industrialise their operations using AI, banks must respond with equally sophisticated and scalable defenses. This includes deploying the highly effective fraud controls:
• Human interventions and dynamic interventions
• Behaviour biometrics
• Strong user authentication (MFA, biometrics, eID, step-up auth)
Callsign uniquely delivers all three capabilities through a single platform, enabling banks to strengthen fraud prevention while maintaining a seamless customer experience.
Notes & References
[a] Gartner® notes that “despite 53% of institutions increasing their fraud prevention budgets by 5% or more, 70% of banks continue to see rising fraud losses” (Sharma, Major Fraud Trends That Banking CIOs Must Counteract (Part 1), 2026)
[b] Gartner® notes that “Fifty-two percent of banks report using behavioural biometrics” and “95% of banks use MFA, with one-time passwords (OTPs) sent via SMS as the most commonly cited method by Gartner clients.” (Sharma, Reduce Fraud Losses With Machine Learning and Layered Detection (Part 3), March 2026)
[c] Gartner® notes that “Among individual assisted service channels, cost per contact varies little; the median organization reported a cost per phone contact of $12.24” and “Median Average Talk Time is 347.5 seconds” (Foster, October 2025)
Åvist, P. (2026, January). AI-Powered Phishing Outperforms Elite Red Teams in 2025. Retrieved from Hoxhunt Blog: https://hoxhunt.com/blog/ai-po...
Callsign. (2019, July 11). Callsign partners with Lloyds Banking Group for digital identification and authentication. Retrieved from https://www.callsign.com/news/...
Callsign. (2024). Case Study of Behaviour Biometrics Improvement.
Callsign. (2025). Case Study: Dynamic Interventions.
Eliasson, A. (2024, August). How the choice of KPI affects fraud prevention performance. Retrieved from Callsign Homepage: https://www.callsign.com/knowl...
European Banking Authority and European Central Bank. (2025). 2025 Report on payment fraud, EBA/REP/2025/40. Brussels.
Federal Bureau of Investigation. (December 2024). Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. Public Service Announcement,(I-120324-PSA).
Finextra and NICE Actimize. (June 2026). The European Fraud Insights Report 2026, Survey report. Finextra Research.
Firstsource. (n.d.). Challenger bank reduces fraud response call times by 55%. Retrieved June 2026, from https://www.firstsource.com/in...
Foster, O. (October 2025). Service and Support Benchmarks: Assisted Service Channel Productivity and Costs. Gartner.
Heiding, F., Lermen, S., Kao, A., Schneier, B., & Vishwanath, A. (November 2024). Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects. arXiv.
KnowBe4. (March 2025). The ransomware resurgence, AI-powered polymorphic phishing campaigns, and the hackers applying for the jobs at your organization. Phishing Threat Trends Report, 5(Know4Be), 3.