The New Fraud Economy: AI Accelerates While Defenses Lag
Fraud is becoming more automated, more believable, and more scalable than the systems built to stop it. We spoke to six experts about how payments infrastructure can keep up.
Is today’s payments infrastructure simply too fragmented to defend effectively against modern fraud?
Kyle Caldwell, VP, Head of Fraud Prevention at The Clearing House: Fraud prevention is a shared responsibility and is not something that a single organization can solve on its own.
Payments infrastructure is not fragmented in the sense that institutions are completely disconnected. Most banks ultimately connect through shared payment networks and clearing systems. However, fraud detection can still be challenging because activity spans multiple payment rails and channels.
Appropriate data sharing and collaboration across institutions and networks are critical to identifying and stopping fraud effectively. As the payments landscape grows with new products and players, there is a greater opportunity for collaboration to build a connected and resilient ecosystem.
Serge Kuznetsov, CPO & Co-founder of INXY: The problem lies in the high fragmentation of the market. There are too many different players and solutions in the market, yet there is a lack of uniform standardization procedures for AML, risk, and KYT. As a result, one payment company may deem funds to be clean, while another may deem them insufficiently clean, which creates problems not only for the companies themselves but also for the user experience.
At the same time, such standardization is very difficult to implement technically, because everyone has different policies and different risk appetites.
Darren Beyer, Chief Product Officer and Co-Founder at Qolo: Where you’re seeing the lion’s share of fraud is still in card payments. The unfortunate thing is merchants and the networks haven’t made this any easier. The merchants care about fraud happening at the point of sale - but not just all fraud, only the fraud that impacts them.
Network rules and chargeback costs tend to favor merchants - especially in t low-dollar fraud schemes. This gives fraudsters even more of an edge. All three parts of the payments ecosystem need to be fighting fraud in parallel if we’re going to make a dent in this.
Where do companies most commonly underestimate the operational costs of a complex payments stack?
Randy Hayashi, Chief Operating Officer at Kurv: Companies often underestimate the hidden operational costs of a complex payments stack, like the hours spent monitoring multiple systems, manually reconciling transactions, managing disputes, and maintaining integrations. For SMBs, these burdens can steal time and resources, leaving less room to focus on business growth, customer experience, or managing cash flow effectively.
Adding processors or fraud layers introduces new edge cases, like timing differences, partial approvals, reversals, chargeback workflows, tokenization mismatches, dispute evidence requirements, and inconsistent data. That translates into more headcount, slower change cycles, and a higher frequency of incidents. Context-switching is the quiet killer, because when no one has an end-to-end view, you waste time coordinating across vendors and internal teams only to resolve a single incident or merchant escalation.
What types of organizations are most exposed right now, large banks with legacy systems, fintech startups growing quickly, or smaller institutions without large security budgets?
Faisal Nisar, VP of Product Management at Mitek: Exposure is real across all three, but the pressures driving it are different. Large banks carry complex, layered infrastructure built over decades. Large banks have invested significantly in fraud controls, but the complexity of infrastructure built over decades means identity workflows can be fragmented across systems, and attackers are skilled at finding where those fragments don’t connect. Account opening and recovery are where those gaps tend to surface.
Fast-growing fintechs face a different pressure. Speed to market and reducing friction are legitimate priorities, but they can leave verification and recovery flows under-tested at exactly the moment growth brings the most scrutiny from attackers. Smaller institutions often have fewer resources to layer and update their controls, which can create a longer gap between the threat evolving and the response catching up.
What cuts across all three is the same underlying exposure: identity being treated as a checkpoint rather than a continuous signal. Attackers understand that. They look for the point in the customer journey where that assumption holds, and that’s where they focus.
What foundational changes should payments companies make now if they want to successfully integrate AI into their platforms over the next few years?
Nicolas Cabrera, Chief Product Officer at Tala: AI is only as powerful as the data and feedback loops behind it, so payments companies need to rethink how data flows through their tech stacks. Investing in better data collection and building infrastructure that allows models to continuously learn and improve from real-time signals is critical for success.
Darren Beyer, Qolo: Payments are no different from any other industry. If you’re not using AI to do your coding and software development, you’re just going to fall behind. Everybody else will be doing what you can do with a much smaller workforce, and that gives them AI-centric companies an inherent advantage.
Serge Kuznetsov, INXY: The first area is AI-powered anti-fraud, meaning systems capable of identifying unusual behavioral patterns, suspicious transactions, and atypical addresses in big data. The second is improving the consumer experience with AI: remembering user behavior patterns and typical addresses, and enhancing the convenience of crypto processing, which currently remains insufficiently intuitive. The third is the development of agent infrastructure and agentic payments, including agent-to-agent, agent-to-business, business-to-agent, and agent-to-consumer scenarios, because this is precisely the future of crypto payments.
How is AI fundamentally changing the economics of fraud attacks in payments?
Kyle Caldwell, The Clearing House: AI is improving the scalability and quality of social engineering. Fraudsters can quickly generate convincing emails, messages, and fake documents that lack the spelling and grammatical errors that historically helped institutions and customers identify fraud.
AI is also helping automate attacks that mimic legitimate user behavior online. Automated scripts and bots can replicate patterns of normal banking activity, which can allow attackers to bypass simpler behavioral controls.
Darren Beyer, Qolo: The issue is that financial institutions and the people in legacy fintech supporting them are not quick to take up AI, but fraudsters are. And so their lead is growing because AI enables them to be exponentially more productive. When you have one side quickly growing its capabilities and the other being slow on the uptake, it creates a widening gap.
Does AI make attacks cheaper, faster, or both? And how does that affect the scale criminals can operate at?
Faisal Nisar, Mitek: The combination of cost and speed is what fundamentally changes the threat model. Historically, the effort required to run a convincing fraud campaign acted as a natural constraint. Technical expertise, time, and infrastructure were genuine barriers. Generative AI has removed all three simultaneously. A tactic can be built in minutes, tested across channels, and refined faster than most defenses can respond.
What this unlocks isn’t just more attacks. It’s a fundamentally different operating model for fraud. What once required an organized group with specialist skills can now be executed by a small team running multiple sustained campaigns at once, each one localized and personalized. The economics have shifted permanently. The organizations that understand this aren’t just asking how to stop more attacks. They’re asking how to reduce the window between a new tactic emerging and their controls catching up.
What other urgent infrastructure issue is nobody talking about?
Nicolas Cabrera, Tala: If you’ve built a modern tech stack, you’re sitting on an asset many fintech and payments platforms desperately need. Productizing the infrastructure layer can be a significant source for partnership growth. This strategy has fueled our evolution at Tala to extend our reach in emerging markets, utilizing our infrastructure through embedded credit-as-a-service and tokenized lending with institutional partners.
Randy Hayashi, Kurv: What nobody talks about enough is control versus automation. While companies race to add in AI layers, few invest in infrastructure that safely governs those systems in production. Risks like model drift, shadow rules, and silent vendor changes become systemic without centralized observability and automated rollback.
Data normalization is another hidden risk, because AI is only as good as the consistency of the event stream feeding it. Inconsistent data across fragmented systems can degrade model performance and increase false positives.
Kyle Caldwell, The Clearing House: Institutional knowledge: Many legacy payment systems rely on undocumented workarounds, custom integrations, or internal tools maintained by only a few individuals. When those employees retire or leave, rebuilding that expertise can require significant time and cost. Organizations should actively manage knowledge transfer and succession planning for critical payment infrastructure.
Randy Hayashi, Chief Operating Officer at Kurv
Nicolas Cabrera, Chief Product Officer at Tala
Kyle Caldwell, VP, Head of Fraud Prevention at The Clearing House
Darren Beyer, Chief Product Officer and Co-Founder at Qolo
Serge Kuznetsov, CPO & Co-founder of INXY
Faisal Nisar, VP of Product Management at Mitek








