The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Finance/ProSight Banking Strategies
ProSight Banking Strategies artwork

Fighting Smarter Fraud: Learning to Navigate an AI-Driven Threat Landscape

ProSight Banking Strategies · 2026-06-25 · 31 min

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber12 / 20
Specificity & Evidence6 / 20
Conversational Craft9 / 20

Bobby Paul brings three decades of fraud experience from roles at Citi, Dell Financial Services, and various consulting positions to discuss how artificial intelligence is fundamentally transforming fraud operations and defenses. The conversation reveals that fraudsters have historically moved faster than institutions, a gap that AI is widening - they can adopt tools without regulatory constraints while banks must remain accurate, explainable, and compliant. However, financial institutions maintain advantages in data quality, fraud intelligence, and behavioral analytics. Paul highlights three critical AI-enabled threats: deepfake video and voice impersonation driving account takeovers and business email compromise; synthetic identity fraud scaling across industries with AI-generated supporting documentation; and highly personalized phishing and vishing attacks using demographic data for social engineering. Beyond individual fraudsters, organized fraud operations now function like legitimate businesses with commercial office spaces, dozens of employees, and standardized operating models - some state-sponsored. Paul emphasizes that effective fraud programs require layered approaches combining behavioral analytics, anomaly detection, supervised and unsupervised machine learning, entity resolution, and graph analytics, rather than single solutions. He discusses balancing friction with customer experience, the role of both real-time AI decisioning and post-transaction analytics with human review, and the importance of understanding organizational fraud appetite within acceptable loss thresholds.

Key takeaways

  • →AI has lowered the barrier to entry for fraud by making sophisticated attacks executable by less-skilled actors at massive scale, with fraud increasingly operating as organized business campaigns targeting thousands simultaneously rather than individual incidents.
  • →The three most critical AI-enabled fraud threats are deepfakes (video/voice impersonation), synthetic identity fraud with AI-generated documentation, and highly personalized social engineering that exploits demographic data to build false trust.
  • →Effective fraud defense requires multi-layered approaches combining behavioral analytics, machine learning, entity resolution, link analysis, and graph network analytics rather than single solutions, with both pre-transaction prevention and post-transaction detection capabilities.
  • →Deepfake detection technology continues to be circumvented as fraudsters improve their tools, making layered defenses and human review essential even for sophisticated fraud threats, though no single solution will ever catch 100% of fraud.
  • →Fraud programs must balance operational friction against customer experience and organizational risk appetite, using AI to reduce false positives and making security measures transparent to customers as protection rather than inconvenience.

Guests

Bobby Paul

Topics in this episode

Behavioral analyticsAccount takeover attacksEntity ResolutionDeepfake technologyAnomaly detectionBusiness email compromiseSynthetic identity fraudVishing and phishing attacksGraph and network analyticsLink analysis

Questions this episode answers

What are the three most dangerous types of AI-enabled fraud for financial institutions right now?

Deepfakes for video and voice impersonation driving account takeovers and business email compromise; synthetic identity fraud supported by AI-generated documentation; and highly personalized phishing and vishing attacks using social engineering with demographic targeting that appear to come from real people and trusted institutions.

How are fraudsters using AI to operate at scale?

Fraudsters are automating reconnaissance, content creation, and testing to run fraud campaigns that target thousands or tens of thousands of individuals simultaneously through organized operations with their own operating models, using available open-source tools, commercial AI platforms, and open APIs rather than traditional fraud rings.

Is deepfake detection technology currently effective against fraud?

While vendors have created AI-powered solutions to detect deepfakes, fraudsters continue to improve and overcome detection methods that previously worked like liveness checks and hand movements; layered defenses combined with human review remain essential because no single solution catches 100% of sophisticated deepfake fraud.

What AI models and approaches are most effective for detecting fraud?

No single model is most effective; mature fraud programs leverage multiple approaches including behavioral analytics, anomaly detection, entity resolution, link analysis, supervised and unsupervised machine learning, and particularly graph and network analytics to find hidden relationships between identities, devices, accounts, and transactions.

How should banks balance fraud prevention with customer experience?

Banks should deploy friction strategically based on fraud risk appetite and organizational tolerance for losses, using AI to reduce false positives and making security measures transparent to customers as protective measures rather than inconveniences, recognizing that over-friction can drive away legitimate customers.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode contains a handful of genuinely useful observations - fraud campaigns vs. rings, the democratisation of sophisticated attacks, and the physical infrastructure of fraud operations - but these are dispersed among long stretches of general framing and repetition of known ideas like 'layered approach' and 'fraudsters only need to be right once.'

We now see fraud campaigns. Right. We used to refer to them as fraud rings.
AI has enabled the fraudsters to automate their own reconnaissance, their content creation, their testing.

Originality

8 / 20

Most of the framing - arms race metaphor, layered defence, garbage in garbage out, human oversight remaining essential - are well-worn industry takes; the observation that fraud rings operate from commercial buildings with their own desks is a concrete detail that lifts the score slightly above baseline.

They're just not in a boiler room though. They actually have commercial building access. Oh, they have places of business.
The future of AI and risk is accountable augmentation

Guest Caliber

12 / 20

Bobby Paul has genuine 30-year practitioner credentials across Citi, Dell Financial Services, and leadership of global fraud departments including fintech and BaaS, but he is currently in a consulting role at Huron rather than actively running an in-institution fraud operation at scale, which slightly limits the authority of his front-line claims.

I started my career at uh, Citi. I moved on to Dell Financial Services. I have been in consulting and I've worked at various other institutions, leading global fraud departments
managing programs across not only general banking, but fintech services as well as banking as a service

Specificity & Evidence

6 / 20

The episode is almost entirely free of concrete evidence: no named institutions, no dollar-loss figures, no attack-volume statistics, no vendor names, and no cited research; the closest thing to a specific data point is the anecdotal evolution of liveness-check bypass techniques.

I actually wrote a perspective paper recently on that, specifically around governance.
We have some great vendors in the industry who are using AI, uh, of course, and are very good at detecting it.

Conversational Craft

9 / 20

The host makes a reasonable effort to dig deeper - raising autonomous AI agents, the risk of over-reliance on automation, and false positives - but never meaningfully challenges a claim, pushes for hard numbers, or introduces productive disagreement, keeping the conversation pleasant but low-friction.

Is there a chance it works so well that it creates vulnerabilities? Maybe there is a loss in know how.
Is that almost as though fraud is becoming industrialized?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B65%
  • Speaker A35%

Most-used words

fraud62institutions20fraudsters18financial16human16real11deep10risk10technology10operations9sophisticated9tools8customers8continue8level8rings8

Episode notes

As fraudsters harness AI to automate and personalize attacks, financial institutions face a rapidly evolving threat landscape. This episode of the ProSight Banking Strategies podcast explores how banks can respond with layered defenses, smarter analytics, and disciplined governance.

Full transcript

31 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: This is the prosight Banking Strategies podcast. We're here to inform you on the top trends, challenges and opportunities in banking today. Prosight is a leading non lobbying connector of people and information with deep expertise in risk fraud compliance and retail and commercial banking. Our purpose is to empower financial services leaders to strengthen and advance our industry through training and insights as well as tools and resources like this podcast. Hello and welcome to this prosight Banking Strategies podcast. I'm, um, Frank Devlin, Senior Editor at prosight. For financial institutions and their customers, the fight against fraud has entered a new and rapidly evolving phase one defined by artificial intelligence. Financial institutions are investing heavily in real time decisioning and defenses. But fraudsters aren't standing still. They're leveraging the same technologies to scale attacks, mimic human behavior and and exploit vulnerabilities faster than ever before. Is this an arms race? And if so, who's actually winning? From deep fake driven scams and synthetic identities to fully automated fraud operations, the threat landscape is becoming more sophisticated, more accessible and more difficult to detect. At the same time, banks are walking a tightrope, strengthening defenses without creating friction for legitimate customers and embracing AI while managing the risks it introduces. Today we're joined by Bobby Paul, Managing Director for Fraud at Huron, who will let us in on what's happening on the front lines. We'll explore how fraudsters are using AI to supercharge social engineering and how financial institutions can respond with smarter, more adaptive defenses. We'll also look ahead. What does fraud look like in the next three to five years if trends continue? Welcome Bobby. Before we get started, can you tell us just a little bit about your background in fraud mitigation?

Speaker B: Certainly. It's great to be here with you today Frank, and looking forward to our conversation.

Speaker A: Same here.

Speaker B: I have been in the industry for about 30 years and have worked in many different areas, industries and across the services within financial institution. I started my career at uh, Citi. I moved on to Dell Financial Services. I have been in consulting and I've worked at various other institutions, leading global fraud departments and managing programs across not only general banking, but fintech services as well as banking as a service. It's a passion of mine and again, I'm happy to be here with you.

Speaker A: Well, we're really happy and lucky to have you, Bobby. So I thought maybe we could start with this sort of headline question. In this arms race between fraudsters and financial institutions that are employing AI, who's

Speaker B: ahead right now in the environment today? I don't necessarily say either is ahead. I would say that the environment is an acceleration phase for both of them. Fraudsters have historically benefited from the agility of AI more than large institutions. And AI is continued to amplify the advantage. Criminals, they adopt the new tools and test the tactics quickly. They scale successfully without governance or regulatory interference, if you will. Operational constraints that the financial institutions face certainly create challenges for them. The financial institutions still have a slight advantage because we maintain access to the data, good data. You hear the, the old term garbage in, garbage out. We know how to make sure that our data is good. We have the fraud intelligence, the behavioral analytics and our controls. The challenge is that institutions, we have to be accurate, explainable and compliant. Why the fraudsters, they only need occasional success. We have to be right every day with the financial institutions. So I think the race is, it's a heated one. We pull ahead, they pull ahead. We do have advantages. But in the end I think that it's more about the speed of adaptation and how well we adapt to it and remain agile, just as the fraudsters do.

Speaker A: Really interesting and important point about how fraudsters, they don't have to be right every time. They can throw a hundred exploits against the wall and just not even really maybe know what they're doing. They're buying intel and that sort of thing and capabilities on the dark web maybe, and they just need to get be right once. So it's really just once daunting task. Yeah. So maybe this doesn't have to be AI specific, but as we're advancing and getting more technological, is there a certain surprising fraud attack you've seen recently or perhaps heard about at a conference or some kind of gathering?

Speaker B: I wouldn't say it is the attack itself. AI brings with it a, uh, level of sophistication. You don't have to have the sophistication and skills to use AI. So in general, the attacks that previously required significant skills are more executable and uh, repeatable at scale by less sophisticated actors. So the surprise that this brings to us is, is we could foresee this coming, right. The usability of AI and any new technology, not just AI, it brings forth an entire new population and community of bad actors into play. So we are fighting the fight of old, but we are fighting at an ever increasing scale.

Speaker A: Yes. So the attack surface is much larger. Do you mean just the fact that agents can be deployed, non human agents or actually they're more physical human people trying to get in on the act of fraud as well?

Speaker B: I would say it's the more human people because of what you mentioned. The AI generated communications, right? The communications can be transposed into multiple language at once. The deep fake technology. You don't have to be an expert anymore to create deep fakes. You don't have to be an expert anymore to create stolen identity and documentations that support those. So it's the human capital that is increasing and increasing that scalability with the AIs and the Agentix help. Unfortunately, the fraud community is growing.

Speaker A: It sounds like it's all bad. It sounds like deep fakes are bad. Synthetic identities are difficult. Phishing. Are any of these more concerning examples of technology enabled fraud? Is there a way to delineate them or are they just all a challenge?

Speaker B: Yes. So I believe there are three that really stand out. The first is around the deep fakes, the video, uh, and voice impersonation. Because these two, they really accelerate targeted account takeover, business email compromise, executive impersonation. And those are the ones that they don't take a long tail of a fraud event to create a tremendous amount of loss financially. It only takes one. You have a business email compromise that's successful. You have an executive impersonation that's successful. The loss to the institution is significant in that one, that one hit. I'd say the second one is around synthetic identity. Synthetic identity continues to cross industries within the world, not just financial institutions. We see uh, you know, just the cross reference into other industries. But the support of AI generated documentation and information is making that more difficult to combat. And unless you have a mature program, unless you have the budget to invest in that technology, the processes, the people to actually combat it, the smaller institutions suffer from that greatly. And then of course, AI also allows us to be more real with each other. I uh, put that real in quotations because it helps engineer at a highly personalized level. The phishing attacks, right, the vishing attacks. Things that we used to be able to spot easily are not so easily spottable now. And they seem like we're talking to real people, we're talking to real businesses. So the social engineering is creating a new level of trust when it shouldn't be trusted.

Speaker A: I know in a very basic level we're not seeing the sort of obvious spelling mistakes and that sort of thing. If AI is helping people kind of polish up uh, their exploits, but what else is making things seem more real? Could that the written word itself is better the way they're doing and it's more real? Or do you mean it has to involve some aspect of voice or visual?

Speaker B: It is, the writing is a large part of it. So Even if the voice isn't involved, AI enables fraudsters to use demographic information. So the social engineering that AI is able to do is what really gets the community, the consumers, over the line of this seems real. They know me, right? This is my bank. It knows me, it knows what I've done, it knows where I've been and it speaks to me in my language. So the social engineering part of it, I think is really driving the amount of effort we've put into educating consumers. And the market as a whole is being tested because of the ability of AI to use the social engineering, personalizing the information. And they're getting past that comfort level. We have created a community of trust but verify. And now AI is making it so that our customers believe they have verified.

Speaker A: Yeah, so it's disarming people where like their antenna are not going up. They're like, oh, this is so and so. And I, you know, they're not even questioning it. Another thing that you mentioned I wanted to get to was like you were talking about it's easier to do this at scale. And so I wanted to ask you about is it almost as though fraud is becoming industrialized? How would you classify what's happening there? Where you can maybe launch many more exploits than you could? How do you defend against that?

Speaker B: So I, I do think that we are increasingly seeing fraud operate more like a business than individual crime incidents. AI has enabled the fraudsters to automate their own reconnaissance, their content creation, their testing. We now see fraud campaigns. Right. We used to refer to them as fraud rings. Well, there are fraud rings, but now there's actually fraud campaigns being executed. And the result is a shift from those individual fraud attempts to the highly scalable fraud operations that don't just target, you know, one to 10, 20 at a time, even with bots, hundreds at a time. We now see them targeting thousands and tens of thousands of individuals simultaneously.

Speaker A: When you say fraud campaigns, I'm almost picturing like sort of like a boiler room or something like that where there's a bunch of like minded fraudsters and they've got like charts up and they're tracking their progress or. But how sophisticated do some of these exploits get? How much are we talking about rings of 10, 20, 30 people in like a crime ring? And is that a thing? Is that happening?

Speaker B: It is a thing. We also see state funded fraud rings, fraud operations. We're moving slowly from the fraud rings to a standard operating model for them, um, if you will. They are using their own models, they're leveraging public tools it's common. They're able to use available models, available open source tools, commercial AI platforms, open APIs. It's become much more of a business for them and scalable. So these rings are becoming larger, they're becoming sponsored. It is a business. And you know, you reference that, uh, like a boiler room. Yeah, you're not far off in that. They're just not in a boiler room though. They actually have commercial building access. Oh, they have places of business.

Speaker A: I thought you were going to say that we're all doing it virtual, but now you're saying it's even like more set up than I was thinking they do.

Speaker B: So you have virtual fraud, but you truly do have operations and physical operations where they have dozens of people and they have their own desk.

Speaker A: But it just shows what banks and their customers are up against. It's not just like a couple of hours someone's going to take a chance and get through on a fraud. It's a very sophisticated structure.

Speaker B: It is very well defined structure. Like I said, they have their own operating models.

Speaker A: Now is that taken into account the fact that things are so put together and we're talking about less sophisticated attempts, but now there are still sophisticated organizations. Is that something that's on the mind of someone like you and someone like a, uh, fraud official at a bank they have to sort of account for, weigh in the fact that they're up against a nation state or a big crime ring. Does that make the attack surface seem any different or you just have to do your job and do your best?

Speaker B: I think you need to be aware, you need to understand the level of attacks that could come your way. We just touched on the operating model of fraud rings, fraud operations, AI. Though current technology has, you know, as we mentioned before, it's also lowered that entry level, that barrier to get into it. So AI has been a force multiplier not only for these operations of frauds, but also those with the less technical expertise, those without the language skills, et cetera, they are there too. So you do have to be aware, but you still, to your point, you still have to do your job. And it's from the spectrum of being attacked from individual fraudsters that appear to be sophisticated because of our tools that we have available, but also the fraud rings, the fraud operations and many of the processes, the solutions that we use and will continue to be used to thwart both ends of the spectrum. You go in every day, you do your job, you look for those emerging trends, use the technology. We have to fight the bad technology. If you will being aware. But yes, you still have to do your job. And it's from both ends of the spectrum. You can't really focus on just one or the other one will overtake.

Speaker A: I wanted to move on and talk about more ways that financial institutions can fight back. But I wanted to dig down on one more thing. You mentioned the spectrum and so here I was asking questions about nation states and big organizations. The other side of that spectrum is like maybe an AI agent that maybe just someone sets free and just does what it can to see how it can manipulate and get through defenses. Is that happening already? And can uh, you share any information and then is it like a spy versus spy and then a bank would they set up their own agents and they would try to find and capture these. It just seems so futuristic. But I feel like we're here or we're almost here.

Speaker B: So I like the word futuristic because I do believe we're still in the early stages. We don't know the full extent of capabilities nor preventive capabilities. The direction is very clear though to your point. We are heading to more and more automated portions of the fraud life cycle. You know I mentioned that targeted research and that identity aggregation before, being able to generate that content automatically. I don't believe that we see fully autonomous fraud operations today. But are they getting there? Uh, are they using the portions of the technology that automates things and processes more quickly and removes some of that reliance on human capability? Definitely. I think in the industry and institutions we should anticipate the increased use of AI enabled agents that will perform more of those multi steps simultaneously. So removing some of that human intervention on their part. And the implications will be a uh, continued increase in velocity, the scale and the attack persistence going back to for multiple reasons the financial institutions have to be right every day. The fraudsters only have to be right once so it doesn't cost them to try and fail if you will. So they will continue to exploit that and find ways to automate more the process of the fraud life cycle and attack.

Speaker A: But right now, today, so forget like the future M a, um, year or two, what AI, uh, models, types of AI are most effective in detecting fraud. Maybe even something that has been used 5, 10 years. Pre generative AI.

Speaker B: I like that you say pre generative definitely. There is no singular method in my opinion. I believe that the most effective framework fraud programs we continue to leverage multiple approaches rather than any one single model. Some of these solutions, tools, models, they include behavioral analytics, obviously the anomaly detection, entity resolution, link analysis, going back to some old school that's become new school, the supervised machine learning, the unsupervised pattern detection along that is used within AI, obviously. And I would say that a particularly powerful solution is graph and network analytics. Uh, and that's because fraud rarely occurs in one place in isolation. And the ability to be able to find those hidden relationships between identities, devices, accounts, transactions, I think that continues to be one of the significant advantages when you're using that.

Speaker A: I just was thinking with AI, I just had a thought about deep fake voice and video scams and I was wondering where that stands right now and detecting them. I know that maybe a year or so ago there were certain telltale things that would happen. You could ask someone who might be using a fake voice or video to move a certain way and then things would pixelate and you oh, this is a fake. Are fraudsters getting better at that? What's the sort of the state of the art now and the state of prevention for deep fakes?

Speaker B: So unfortunately they are getting better. It used to be to your point, yes. And aliveness. We would ask you to blink or we would ask you to turn your head left and then right. AI has enabled defrosters to overcome that. More recent ones include inserting something into the picture I recently just saw. They call it the finger of the hand. Right. AI was very poor at moving objects. So we started to ask to move your hand with your face. Right. And now we find that AI has enabled fraudsters to even overcome the moving hand in front of your face. So yes, they are getting better. I do believe that the solutions that are out there, we have some great vendors in the industry who are using AI, uh, of course, and are very good at detecting it. We have some disruptors out there that are creating solutions to disrupt it and saying that. That's why I go back to what we just talked about, the multilayer. Because even as something as sophisticated as using solutions to identify a deep fake image, photo, video, voice, still won't capture 100%. There is a cost of doing business. We won't ever stop all the fraudsters, and we know that. But having the right approach of uh, a layered fraud program, having the solutions that can mature your program and understanding your risk and when to deploy them and using it wisely. I would never recommend deploying everything everywhere. It's very expensive. And then, um, the fraudsters know exactly how to get around you. So I go back to that layered approach, using it wisely and understanding that you won't capture 100% but a mature Program should capture much of it.

Speaker A: There's the term risk appetite. I don't know if there's a term fraud appetite where your organization decides within a certain basis points, you know, range. We're not going to spend millions of dollars to prevent a couple hundred thousand dollars in fraud. So is it that sort of decision that's made yet?

Speaker B: Uh, okay, it is. Fraud losses fall within that risk appetite. And it's that appetite is usually defined because we recognize it's not just technology. We recognize we are going to have losses. How much loss can you absorb? How much is reasonable? But also how much effort do you put into protecting your business and your consumers, your customers and being able to have those layers of controls that include the authentication, the technology, the procedures and the human review. The human review still becomes very important when you're up against the more sophisticated, the deep fake enabled fraud.

Speaker A: So where does it stand right now do you think? And I imagine it will change. There's a role, like you're saying, for humans to review a transaction or a relationship, but then there's also real time decisioning that whether you want to call AI or automated, certain things just sort of happen in the background and that's why a credit card purchase might get flagged, et cetera, et cetera. How is AI going to change that? How might AI already be changing that sort of backroom decision making and fraud is a concern.

Speaker B: AI plays a part in both real time and then post transaction, post loss, uh, are critical. And AI is essential in both in my opinion because we are using AI in our models, in our tools and our solutions for preventing the fraud. Meaning we're trying to mitigate that loss before the funds leave the institution, before the account is taken over and requests are made. But we will have those times where we miss it and uh, it gets through that post transaction or opportunity. And the analytics around that is still valuable because it helps us identify those emerging threats. Whether it's a fraud attack, a trend or a way to prevent it. It helps us improve our models. It also helps us uncover the organized fraud networks because we can do that link analysis, we begin to understand was this a one off? Do we have a larger problem and is it just our institution? Detecting the activity is not always apparent at that time of authorization. And you can't insert friction into every transaction. So the strongest programs will use I think both the preventative pre capability as well as the detective capabilities afterward. With AI and with the human intervention.

Speaker A: Yeah, so there's that almost age old balance between friction to slow up fraud and prevent fraud. But then you also have the customer experience on the other end. You're talking about sort of fraud appetite and allowing knowing a certain amount of fraud will get through. But in the big picture, it's better because you don't want to spend more than you're saving, but there might also be like opportunity costs on the other side. So not only are you maybe if you overprotect, if that's a word, but maybe spend more than you need to spend or devote to fraud prevention. You're also maybe losing some customers because they just don't like being held up and everything's so fast and real time payments. Now I've heard some people say that perhaps AI will reduce false positives, will make it easier to reduce friction without compromising your fraud defenses. What do you see happening there?

Speaker B: They should reduce the false positives. The AI is to make our models better. So false positives, sometimes that term gets a bad rep. Also, consumers also expect us to be protecting them in the world we live in. I mentioned the education we've done across industry for so long. Consumers know that fraud is out there. They expect financial institutions to protect their money, their identities, their very livelihood at times. So not all interaction is bad. Fraud transaction reviews, fraud interactions, whether it's AI initiated and it's just a text that comes up on my side, or it is a human, an actual analyst calling it should be near transparent. They should know that they're being protected. When we do introduce that friction, it should be apparent, if not obvious, that we are doing so for the benefit of protecting them, their funds. And it becomes a brand, a loyalty, an expectation factor that businesses need to consider. So false positives are a metric that we're always going to identify. But I do think we need to uh, understand also that every interaction is an opportunity to convey our dedication to protecting our customers also.

Speaker A: Yeah, that's a great way to look at it. And assuming AI does make that smoother and as you're saying it should is far as like making the friction less painful, et cetera. So is there a chance it works so well that it creates vulnerabilities? Maybe there is a loss in know how. I know a lot of people are worried about like if more is relied on from AI, that maybe the folks coming up now they won't have the same learnings and are they going to be able to lead or could it create blind spots like, okay, we're automating so much and we think we have it covered, but maybe you're not looking in the right spaces anymore because you're so reliant on AI. Is that too theoretical or is that something you've thought about or considered that

Speaker B: is not too theoretical? That's a lot to unpack and I have considered it. So absolutely. AI does introduce and create its own risk. Those include things like model drift, bias, explainability, which is a huge one for regulators, data quality issues, and as you said, the over reliance on automation. One of my biggest concerns with the automation complacency is that organizations, we tend to start trusting model outputs if we don't have sufficient challenge processes, oversight and governance. And that is why the human accountability remains critical within the industry. Financial institutions need to be able to answer the questions of where am I using AI? What is the data I'm inputting? Who has access to change that model? Who has access to challenge that model? What attributes can be introduced? Do I even know what attributes are being introduced? And what does that life cycle of change management and monitoring include? Many institutions can't answer those questions. Many institutions haven't thought about. How do I put this within my risk assessment? How has it become part of my risk assessment? Integrate it not as an afterthought. So governance is a huge portion of that. And I actually wrote a perspective paper recently on that, specifically around governance. Because the way of the future is going to include AI. Mature programs, applications that are successful within those programs will have a strong governance framework. Those who don't will not have success with it. As far as the human capital, there's been a lot of focus on the automation and efficiency that AI brings, which is great. It's good for the business, it's good for our customers. But we haven't given enough attention, I think, to the risk of eliminating too much of that human expertise. And everybody can see it, it's in the news, it's on LinkedIn, we're talking about it over coffee. The mature organizations, though, my view, my observation is that they're not eliminating human expertise. They may be reallocating, some of it, putting it to better use. But experienced investigators, the analysts, the risk professionals, will continue to remain essential for validating the outputs of the AI, identifying the trends and challenging the model assumptions. And when you get down to it, high impact decisions that we have to answer to, closing an account, denying funds, firing somebody, anything like that, those high impact decisions, I do not foresee a time where human oversight and final decisions will be taken away. I believe that organizations should carefully balance the efficiency objective with that operational resilience and understand that the long term implications and limitations of AI, we're still discovering all of the good and all of the bad. So I go back to. AI can be a very powerful force multiplier, but it's not a replacement for accountable decision making and domain expertise.

Speaker A: So you just told us in your perspective what you think fraud mitigation functions might look like in future years. We're getting towards the end of this interview now. I was wondering next to last question, what do the fraud exploits look like in three to five years, do you think? If the current AI, uh, trends continue,

Speaker B: I think they're going to keep being more personalized. I'm very attuned to that. The fact that they are getting so good at mimicking true communication that they're going to be personalized because of the ability to take in more data, to take in demographic data, to adapt to it and be scalable. So we're going to see increased attacks, they are going to be personal, they're going to generate more identities, more synthetic Personas I think are going to hit the industry than ever before. The automation of that social engineering and the orchestration of those campaigns that I mentioned I think are going to increase. And I think that, that eventually we've seen that blur of lines between cybercrime, identity fraud, aml, financial crime, social engineering and the tools have made a lot of advancements that have blurred our ability to separate them. And I think that that continues and we start to see very large impacts to institutions that miss them. On the flip side of that though, our defensive technologies also will include these advancements. We'll still become more intelligent, we'll be more proactive. As long as we continue to combine the analytics, the governance, the investigators, and we remain as agile as the fraudsters are, we still beat them and edge them out in the end.

Speaker A: Yeah, that's a, that's a nice way to end it, but it doesn't sound like you're saying there's a silver bullet and it's get a lot easier. You're saying it's going to be hard work. If we do it well, we'll stay a bit ahead. There's no magical solution coming to this fraud challenge.

Speaker B: There is no magical solution. There are only dedicated fraud fighters out there. And I think that we do take it in the end.

Speaker A: We covered an awful lot. I really appreciate your time, but was there maybe one issue we did not discuss that you think it would be important for our audience to hear or if there's anything maybe that you'd like, really like to emphasize that we did talk about before we let you go.

Speaker B: I would say that there's no longer a question of whether AI should be used. Occasionally hear that now, but it's so much less. It's really not a question anymore. It is where we use it. It is how we use it. When should humans be engaged and how the decisions remain governed. Governance is going to be a huge aspect so that we do it right and that we can continue to gain the benefits of the new solutions opportunities that we have to fight fraud at a higher level and become just as aggressive as fraudsters are against us, we are against them. The future of AI and risk is accountable augmentation and ensuring that we deploy it appropriately governed within well defined, documented frameworks that we can challenge ourselves and we don't become complacent.

Speaker A: Thanks so much. That's a really compelling idea to end on, so I really appreciate that. So thank Bobby for sharing your perspectives with us today and the Proslave Banking Strategies podcast to our listeners. Thanks for spending your valuable time with us. If you liked it, please spread the word. I'm, uh, Frank Devlin.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Bilt's Director of Identity, Ryan: Fraud is a Tax on EveryoneRisk and Reason · on Synthetic identity fraud88 / 100
  • 21 in 21: Patrick Ball on Using Bitcoin and AI to Defend Human Rights21 in 21 · on Entity Resolution87 / 100
  • Secure AI Starts with EducationBuilding Unbreakable Brands · on Business email compromise86 / 100
  • ACH Rule Changes for 2026: What Treasury Needs to KnowThe Treasury Update Podcast · on Business email compromise85 / 100
  • Security Data Pipelines: How to Cut SIEM Costs and Noise with Dina KamalCyber Sentries: AI Insight to Cloud Security · on Entity Resolution85 / 100
  • The Evolution of Human RiskSimplifying Cyber · on Entity Resolution83 / 100

More from ProSight Banking Strategies

All episodes →
  • Thinking Outside the Checkbox: Optimizing Compliance for a Complex Environment
  • More Teammate Than Technology: How Agentic AI Will Transform Banking
  • The Expansion of State-Level Regulation - and What It Means for Compliance
  • Gen X: The Quiet Force Behind Banking Opportunities
  • Failure Analysis: How Banks Can Turn Adversity Into Advantage
Explore the best B2B Finance podcasts →
All ProSight Banking Strategies episodes →