- Technology
Banks face the twin-edged sword of generative AI
- More and more, banks employ the latest artificial intelligence tools to fight fraud, but so do the bad actors.
Edmund Lawler
Share
Generative AI, the latest and most celebrated type of artificial intelligence that produces human-sounding text or images, would seem to be a godsend for fraud fighters at banks. “Advancements in AI help us authenticate our customers,” says Ash Khan, head of enterprise fraud management for Montreal-based BMO Financial Group.
“If we can authenticate our customers better, we can prevent things like account takeovers,” Khan says. “It helps us make decisions quickly as long as we have enough computing power, and we have access to all of the data—or what I call con – textual signals.”
Those signals help determine if the person interacting with the bank online, over the phone or in the interactive voice response system is a BMO customer or a possible fraudster. “AI makes us more efficient and effective, and it also improves the customer experience,” Khan explains. “The quicker we can address potential fraudulent transactions, the better we can get at reducing our false positive rates and improving our true detection rates. The quicker we do that, the better the outcome for the customer.”
But generative AI also has a dark side.
“From a generative AI perspective, there are potential nefarious uses of this technology,” says Khan, pointing to a product sold on the dark web known as FraudGPT.
Similar to ChatGPT, the aptly named evil chatbot deploys machine-learning algorithms to create malicious content like convincing phishing emails or phony landing pages. FraudGPT has become a favorite tool of cybercriminals who are beginning to master generative AI. “They don’t need to understand complex IT systems or programming languages to create malware, to write malicious code or to create fraudulent websites,” Khan says.
“Previously, you could tell a scam message from a real one because it had simple mistakes like typos and grammatical errors. You don’t see that anymore. Now you see messages that appear to have come from your bank.” With access to malicious AI tools, fraudsters can determine the kind of language that will resonate with a customer, whether it is a romance scam or a cryptocurrency scheme, he says.
Mary Ann Miller, who’s led the fight against cybercrime and other fraud for several banks and technology firms, has seen every financial scam imaginable over the course of her 30-year career. She brings that wary perspective to her role as a member of the U.S. Federal Reserve’s Scams Definition and Classification Work Group.
“We are in an environment of increased fraud risk,” says Miller, who is also the fraud and cybercrime executive advisor and vice president of client experience for PROVE, a leading identity verification and authentication platform. “Fraud is beginning to negatively affect the revenues at some banks. “I have even seen banks pause and turn off their digital onboarding processes because of the rate of fraud in their application processes,” she says.
“We are starting to see that fraud is having a material impact.” AI and generative AI can be useful tools in a bank’s battle against fraud. “AI can go through an automated process and help diagnose the type of fraud. Then, the investigation gets routed to the right team in the bank. They can properly classify the type of fraud that victimized the customer.” The fraud diagnostic process is critical, Miller says. “Customers often don’t know how they suffered a loss. They just know they have money missing from their account. But how did it happen?” The loss could be the result of an account takeover or some form of credit card scam, she adds.
Unfortunately, fraudsters are tapping AI and generative AI to launch attacks against banks. “I often refer to it as machine versus machine,” Miller says, referring to how fraudsters have become adept at using machine-learning algorithms to drive their assaults. “The bad actors are already using generative AI for voice cloning or romance scams, or using different forms of AI to duplicate people’s faces.” Adds Miller: “With the maturation of AI comes all its advantages. But with that comes all the responsibilities of AI.”
Banks, which must balance security and privacy against providing a frictionless customer experience, are in a tough spot. “But if you really look for innovation, you don’t have to trade off customer experience for security. You can have both,” Miller says. “You just have to invest and think wisely about customer experience design and make sure you have the right process and controls in place to enable the type of experience the customer expects.”
Security is a paramount concern of customers, according to a survey of 1,000 consumers in September for BAI Outlook Banking Outlook: 2024 Trends. When asked to list the top ways banks and credit unions can help them manage their money more effectively, consumers cited “provide better fraud and identity theft protection” as their number-one priority. The second leading priority was to “provide faster payments and quicker money transfers.”
In a survey of 102 financial services organizations for the same BAI report, more than half (58%) said they are using AI to address fraud or plan to within the next year.
As BMO’s Ash Khan says: “We are going to see lots of great uses of generative AI that will improve our lives and help us improve the customer experience. But at the same time, the fraudsters are going to be looking for opportunities to use the same technologies for nefarious reasons. We need to make sure that we fully understand the technology and that we stay abreast of changes when that happens.”
Edmund Lawler is a contributing writer for BAI.
A version of this article appeared in the January BAI Executive Report “Safeguarding Against Fraud.” Read more on fraud-prevention best practices there.
Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.