Experian's 2026 U.S. Identity & Fraud Report describes fraud that no longer looks like a forged check or a stolen card number. Criminals now generate the emails, the websites, the supporting documents, the voice on the phone and the customer support interaction itself, and each piece is convincing enough on its own to persuade someone to send money or hand over account access. The activity described here was documented by Help Net Security.
The awareness numbers show how widely this has spread. Around 60% of consumers have heard of scams using AI-generated images or videos, 53% know about AI-generated phishing messages, and 47% are aware of deepfake voice impersonation. Nearly half say they feel more like a target for fraud than they did a year ago.
What changed is the economics. Producing a believable forged document or a cloned voice used to take skill and time, which limited how many attempts a fraudster could run. Those constraints are gone, and your reviewers are now evaluating artifacts that look correct to both a human eye and an automated check.
The pressure lands hardest at specific moments in your customer lifecycle:
- Account opening, where you have to separate real applicants from stolen credentials, synthetic identities and manipulated documents
- Account recovery, where a caller with a cloned voice is asking you to restore access
- High-value payment authorization, where the fraudulent transaction is the last step in a longer chain of deception
Businesses rank AI-generated phishing as a leading concern, alongside document forgery, automated bot attacks and synthetic identities.
Eighty percent of U.S. businesses already use machine learning or generative AI in fraud management, according to Experian's 2026 report.
Both sides of the transaction are now using the same technology. For your firm, that means the visual and audio evidence your staff have relied on to confirm who they are dealing with carries less weight than it did, and identity itself becomes the thing you have to prove.
Business and Compliance Risk: Account Takeovers, Regulatory Exposure, and Customer Trust
Account opening is where most of this risk converts into money. Experian's report puts verification at the onboarding stage as the point where companies have to separate real applicants from stolen credentials, synthetic identities and manipulated documents. Every one that clears your checks becomes a funded account, a credit line or a payment channel that sits on your books looking legitimate.
The direct loss is the part your finance team already tracks: fraudulent payments, chargebacks, written-off balances and the cost of making customers whole. The less visible cost is investigation. Each disputed transaction or contested account change pulls staff into manual review, document re-examination and customer contact, and that workload grows with every scam that looks plausible enough to survive a first pass.
For regulated firms, a synthetic identity that passes onboarding is also a KYC and AML problem. It becomes a customer of record in your systems, and unwinding it later means re-verifying accounts, filing corrections and explaining to examiners how the control failed. Remediation of that kind runs on a supervisory timeline rather than yours, and it consumes compliance capacity you had budgeted for other work.
Non-financial sectors carry a version of the same exposure. Retailers, healthcare providers, telecoms and any business with a customer support line face document forgery, automated bot attacks and AI-generated phishing aimed at account recovery. The report names AI-generated phishing as a leading business concern alongside those three, which places your help desk and password reset process squarely inside the fraud surface.
Your fraud controls also carry a revenue cost on the other side. Experian frames fraud losses as one measure among several, sitting next to false declines, abandonment, conversion and customer satisfaction. When your rules tighten after an incident, legitimate customers get blocked, carts get abandoned and applications go unfinished, and those losses rarely appear in the same report as the fraud numbers.
Trust is the slower cost. Only 23% of consumers feel they have complete control over how their personal data is used online, while 56% want that level of control. When someone discovers their voice, documents or account were spoofed to transact with your business, that gap between what they expect and what they experienced lands on your relationship, and 84% of consumers say they will accept extra verification when it prevents fraud.
Traditional risk models understate all of this because they score events in isolation. A fraudulent payment or account change is often the last step in a longer chain of deception that began with a message, a fake website or a support call your systems never saw. Scoring the final transaction tells you nothing about the six preceding touchpoints that made it look normal.
Two shifts widen that blind spot further:
- 27% of consumer-reported account openings were for AI chatbot accounts, up from 16% in 2025, changing what a normal signup pattern looks like.
- 31% of consumers have used AI tools for shopping and booking, with 23% open to it, so some of your traffic is already software acting for a person.
- Fraudsters can impersonate legitimate agents, compromise authorized ones or exploit weak permissions granted to them.
When an agent transacts on a customer's behalf, you need to establish the customer, the agent, the relationship between them and the permissions granted. Models tuned to human session behavior will flag that traffic as anomalous or wave it through, and both outcomes cost you. Experian describes Know Your Agent as an emerging control area for exactly this reason.
Attack Chain: From AI Model Access to Credential Harvesting to Account Compromise
The chain starts with generative tooling that no longer requires specialist skill. Experian's report frames AI as making digital scams both easier to create and harder to identify, which changes the economics at the front of the attack rather than the back. A single operator can now produce the email, the supporting website, the identity document and the voice on the verification call from the same workflow.
What follows is a repeatable sequence rather than a one-off forgery:
- Model access. The actor obtains generative image, text and voice capability and tunes it toward a target institution's document formats and support scripts.
- Identity sourcing. Real personal data from breaches and stolen credentials supplies the anchor details that make an application resolve against third-party data sources.
- Artifact generation. Manipulated documents, synthetic identity records, generated images and cloned voices are produced to match whatever evidence the onboarding flow requests.
- Submission. The package is presented at account opening, access recovery or a high-value transaction, the three moments Experian identifies as warranting elevated checks.
- Monetization. Account access is used to move funds, change payment details or stand up an entity that looks like an ordinary customer.
Document forgery, automated bot attacks and synthetic identities sit alongside AI-generated phishing as the leading business concerns in the report. The bot component matters because it converts the sequence above into volume. Once one submission pattern clears a verification flow, the same pattern gets replayed across thousands of applications with rotated identity details.
The fraudulent payment is rarely the intrusion. Experian describes it as the final step in a longer chain of deception, which means the transaction your fraud engine flags may be several weeks downstream of the moment the identity was first accepted. That gap is what makes post-transaction investigation expensive and reconstruction slow.
Deepfake voice impersonation extends the chain into the contact center, where an operator can defeat knowledge-based checks by sounding like the account holder. Customer support interactions themselves are among the things criminals now imitate convincingly, so the manipulation can run in either direction, toward your agent or toward your customer. Businesses counter this by combining multiple identity and authentication signals, including behavioral biometrics, rather than resting on any single proof.
AI agents open a distinct branch of the same problem. Thirty-one percent of consumers have used AI tools for shopping and booking, and 23% would consider it, while consumer-reported account openings for AI chatbot accounts reached 27%, up from 16% in 2025. Each of those agent accounts is a new credential set and a new set of granted permissions.
Experian identifies three specific abuse paths here: fraudsters impersonating legitimate agents, compromising authorized ones, and exploiting weak permissions. That forces a four-part verification question at transaction time, covering the customer, the agent, the relationship between them and the scope of what the agent was actually authorized to do. Know Your Agent is the emerging authentication and fraud-control capability being built to answer it.
Eighty percent of U.S. businesses already run machine learning or generative AI in fraud management, and the same technology is in use on the offensive side for phishing, forged documents, automated attacks and deepfakes. Both sides are drawing on comparable capability, and the difference comes down to data quality, model monitoring and where human review sits in the decision.
Detection and Response: Immediate Actions to Identify and Contain AI-Driven Fraud
Start with liveness detection on every identity submission flow you run. If a customer can pass verification by uploading a static image or a pre-recorded clip, the check confirms that a file exists rather than that a person is present. Passive biometric capture at the point of submission raises the cost of a generated document or face considerably, and it does so without adding steps the customer has to think about.
Inside the first few days, work through these four checks:
- Compare document metadata against submission context. Creation timestamps that postdate the claimed issue date, or image properties inconsistent with a phone camera capture, are worth routing to manual review.
- Correlate recently opened accounts on shared signals. Repeated IP ranges, device fingerprints, phone numbers or email patterns across supposedly unrelated identities indicate one operator running many applications.
- Re-examine payment and transfer behavior on accounts opened in the last quarter. Funding followed quickly by outbound movement is the pattern most likely to convert a bad approval into a written-off balance.
- Confirm which of your customer support workflows can authorize an account change on voice alone, and add a second channel to those that can.
Adding verification is not the friction risk teams often assume. Experian's report found 84% of consumers say they will accept additional checks when those checks help prevent fraud, which gives you room to step up authentication at account recovery and high-value transactions while leaving familiar-device activity alone.
Over the following weeks, layer detection rather than replacing what you have. Eighty percent of U.S. businesses already apply machine learning or generative AI in fraud management, and the useful applications are narrow and specific: scoring document authenticity, identifying manipulated media, and cutting the manual review queue down to cases that genuinely need a human. Pair that with multi-modal verification, so a single forged artifact never carries an approval on its own.
Authentication anomalies are where synthetic activity usually surfaces first. In environments Capstone manages, Adlumin ITDR monitors authentication behavior and flags login patterns, credential reuse and account-change sequences that do not match the established user, which shortens the gap between a fraudulent access event and your response to it.
Write the investigation playbook before you need it. A suspected synthetic identity case has different evidence requirements than a stolen-card dispute, and your analysts should know in advance which records to preserve, who signs off on freezing an account, and what gets reported externally.
For the longer horizon, three commitments matter. Move toward cryptographic identity attestation so verification depends on a signed claim instead of a rendered image. Build intelligence collection on new generative fraud tooling into your existing threat feeds, because detection signatures age quickly against models that update monthly. Share indicators with peer institutions, since the same operator rarely targets one brand.
Plan now for AI agents transacting on customers' behalf. Know Your Agent is the emerging control category for that work, and Experian describes businesses as only beginning to explore it.
Key Insight: Thirty-one percent of consumers have already used AI for shopping and booking, and 23% would consider it, which means your verification logic will soon need to establish the customer, the agent, the relationship between them and the permissions granted.
Track fraud losses alongside false declines, abandonment and conversion. Those four numbers together tell you whether a control is working or simply turning away good customers.
Regulatory and Compliance Expectations: What Examiners Are Watching
Customer identification obligations were written as a risk-based standard, and that is the part examiners are pressing on. The rule asks for reasonable measures given the risk you face, so when the risk shifts to generated documents and synthetic applicants, the measures that were reasonable two years ago stop clearing the bar on their own.
If your program still evidences compliance by showing that a document image was captured and the data matched a bureau record, expect that to be challenged. Bank examiners from the OCC, FDIC and the Federal Reserve, along with the SEC for registrants and the FCA for UK-regulated firms, review the documented rationale behind your controls, not just the fact that controls exist. The question in the exam room is whether your risk assessment names current fraud typologies and whether your control set actually addresses them.
Synthetic identities complicate your reporting obligations in a way that shows up later in a look-back. When the applicant never existed, your suspicious activity filing, your account records and your customer file all reference a person who cannot be located, and reconstructing which accounts belong to the same fabricated identity is slow work that examiners will expect you to have done.
Model governance is the second area drawing attention. Experian reports that 80% of U.S. businesses already use machine learning or generative AI in fraud management, which means most fraud decisions in scope of an exam are now model-driven. Once a model declines an application or freezes an account, it falls inside model risk management, and you should be prepared to produce validation records, performance monitoring over time, and evidence that a human reviews contested outcomes. Experian's own framing points the same direction: reliable data, model monitoring and human review are what keep the decisions defensible.
Declines carry their own regulatory weight. Adverse action and fair treatment expectations apply to fraud models the same way they apply to credit models, so a system that quietly suppresses applications from certain populations creates exposure separate from any fraud loss. Measuring false declines alongside fraud losses is as much a compliance record as a customer experience metric.
Privacy regulators are watching the inputs. Behavioral and physical biometrics carry consent, notice and retention obligations under state biometric privacy laws, and the underlying consumer sentiment is not comfortable. Only 23% of consumers feel they have complete control over how their personal data is used online, while 56% want that level of control. Collecting more identity signals without a documented retention and deletion position widens the gap your regulator will ask about.
AI agents create a category no rulebook has caught up with yet. Experian reports that 27% of consumer-reported account openings were for AI chatbot accounts, up from 16% in 2025, and 31% of consumers have used AI for shopping or booking. When an agent transacts on a customer's behalf, you will be asked who authorized it, what permissions were granted, and how you recorded that relationship. Know Your Agent is being discussed as an emerging control, which means you will be judged against the practices you wrote down rather than a published standard.
The consequences follow the usual path. Supervisory findings escalate to consent orders, civil money penalties, mandated look-back reviews of prior onboarding, and growth restrictions until remediation completes, with the remediation cost carried by you.
Limitations of Current Defenses and Emerging Countermeasures
Static document checking was built for a fraud model where the forgery had to be physically produced. Optical character recognition confirms that the fields on an uploaded ID are legible and internally consistent, and a bureau match confirms the data exists somewhere. A generated document satisfies both tests because it was constructed from the same field layout and populated with data drawn from a real record.
The same gap appears in the other verification modalities that businesses have relied on. Simple video liveness checks confirm motion, and voice-based speaker verification confirms that an audio sample matches a stored template. Experian's report notes that criminals can now imitate voices and customer support interactions well enough to persuade people to hand over account access, which means a template match no longer establishes that a human owner is on the call.
Four categories of countermeasure are being developed against this, and each addresses a different part of the problem.
- Adversarial detection. Models trained to recognize the artifacts left by generative tooling in images, documents and audio, rather than checking whether the content is internally plausible.
- Behavioral biometrics. Keystroke rhythm, cursor movement and device interaction patterns, which describe how a session is conducted instead of what was submitted at the start of it. Experian found that behavioral biometrics make 83% of consumers feel secure, the highest-ranked measure in the survey.
- Cryptographic and passwordless credentials. Proofs bound to a device or key rather than to a reproducible image or recording. Passwordless login, banking app authentication and physical biometrics also rank highly with consumers.
- Continuous authentication. Risk assessment that runs after onboarding, using multiple identity and authentication signals across the account lifetime.
The practical value of the behavioral and continuous approaches is that they are expensive to forge at scale. A generated document is a single artifact. A session that has to reproduce a specific user's typing cadence, device fingerprint and navigation habits across repeated logins is a much harder target, and the cost of faking it rises with every additional signal in the assessment.
Detection improvements do not settle the matter. Experian reports that 80% of U.S. businesses already use machine learning or generative AI in fraud management, while the same technology supports phishing, forged documents, automated bot attacks and deepfakes on the other side. Each detection model that gets published or inferred becomes a training target, and generation techniques adjust toward whatever the current detector misses. Your fraud controls therefore have a shelf life measured in model generations, not in years.
That dynamic is why Experian frames oversight as part of the control itself: reliable data, model monitoring and human review to keep decisions accurate as the inputs shift. A detection model that is not re-evaluated against current generated samples degrades quietly, approving applications it would have caught when it was deployed.
A newer gap is opening around automated buyers. Consumer-reported account openings for AI chatbot accounts reached 27%, up from 16% in 2025, and 31% of consumers have used AI for shopping or booking. When an agent transacts for a customer, verification has to cover four things: the customer, the agent, the relationship between them and the permissions granted. Fraudsters can impersonate a legitimate agent, compromise an authorized one or exploit permissions that were scoped too broadly. Know Your Agent is the emerging capability being built to address it.
No single check in this list holds on its own. Each one raises the cost of a specific attack technique, and the assessment holds together because the signals are layered and adjusted according to the risk of the request.
Immediate Priority: Audit Your Identity Verification Pipeline and Layer AI Detection Now
Eighty percent of U.S. businesses already use machine learning or generative AI in fraud management, according to Experian's 2026 report. The open question for your organization is which parts of your verification pipeline still run on checks designed for a world where a forgery had to be physically produced.
Answering that starts with an inventory rather than a purchase. Map every point where a person, a document or an application proves identity to you, and record what each one actually tests. Account opening, credential recovery and high-value transaction approval are the places where a generated identity converts into a funded relationship, so those deserve your attention before lower-risk flows do.
Your customers are not the obstacle here. Seventy-one percent say accurate online recognition matters to them, and 84% say they will accept additional verification when it helps prevent fraud. Behavioral biometrics make 83% feel secure. If you have been holding back on stronger checks at sensitive moments because of conversion concerns, the consumer data does not support that hesitation.
There is a second inventory forming behind the first. Thirty-one percent of consumers have used AI tools for shopping and booking, and 27% of consumer-reported account openings were for AI chatbot accounts, up from 16% in 2025. When an agent acts on a customer's behalf, you have four things to establish: the customer, the agent, the relationship between them and the permissions granted. Experian describes this as Know Your Agent, an emerging capability rather than a settled practice.
Fraud losses, false declines, abandonment and customer satisfaction all belong in the same measurement set. Reviewing them together tells you what your current verification design is costing you.