Generative AI is rapidly changing the fraud landscape, enabling criminals to create highly convincing synthetic identities, cloned voices, fake documents and realistic digital interactions at scale. As live deepfake technology becomes more accessible, scams are set to become even harder to detect.
Yet the same technology presents a significant opportunity for banks. Institutions that act now can use AI to strengthen fraud detection, improve customer protection and respond faster to emerging threats. With agentic AI still in its early stages, banks have a narrow but valuable window to build capabilities that could provide a lasting defensive advantage.
The stakes are particularly high in Africa, where mobile-first banking and digital payments are accelerating financial inclusion at scale. As digital ecosystems grow, so too does the opportunity for criminals to use AI-powered scams to target consumers and financial institutions alike.
Recent data suggests the nature of fraud across Africa is becoming increasingly sophisticated. According to TransUnion’s H1 2026 Update: Top Fraud Trends report, while suspected digital fraud rates declined in 2025, criminal activity has become more organised and targeted, with greater exploitation of digital identities. In Kenya, median consumer fraud losses reached $839, while South Africa recorded unusually high suspected fraud rates in login attempts.
Looking ahead, the biggest threat may come from agentic systems capable of running scams and fraud end to end without human intervention, increasing both the scale and effectiveness of digital deception. At that point, BCG estimates the cost of running scams and fraud could fall by 90% or more, enabling adversaries to launch a much larger volume of attacks, test a broader range of tactics, and more rapidly adapt against new defences.
“What makes agentic systems so concerning is that they could automate the entire fraud value chain. As the cost of running scams and fraud falls dramatically, cybercriminals will be able to scale their operations like never before. As a result, we could see successful scam and fraud activity more than double, with profound emotional and financial costs to those who are targeted,” says Othman Omary, Managing Director and Partner and Africa FI node Head.
For banks, this signals the arrival of a more persistent, ‘always-on’ threat environment that requires a different defence model.
Omary adds: “The good news is that AI is also a powerful tool for preventing, detecting, and responding rapidly to scams and fraud. Banks can take action now to build adaptive, AI-enabled defences, redesign operating models for scale, strengthen ecosystem coordination, and prepare for surge events.”
How agentic AI could industrialise financial crimes
Financial scams and fraud are already a major problem today, with scams alone costing consumers and businesses around $442 billion annually, according to the Global Anti-Scam Alliance. The range of fraud and scam types is wide, with the cost to victims extending well beyond their bank account.
Financial scams, which involve customers being deceived into voluntarily authorising payments themselves, and fraud, in which deception is used to gain access to the victim’s financial accounts, encompass a broad range of criminal activity.
As adversaries become more adept at exploiting digital identities, the impact is no longer confined to consumer losses, creating mounting risks for banks and the stability of the broader financial ecosystem.
While liability frameworks vary across African markets, banks increasingly face meaningful operational costs, including disputes, complaints, credit-reporting issues, debt collection activity, and wider customer-servicing costs. That is why increased scam volumes could lead not only to higher losses and greater regulatory pressure, but also to a broader erosion of customer trust and confidence in the financial system.
And the most disruptive shift still lies ahead – the rise of agentic AI capable of automating scams from start to finish.
Agentic capabilities have improved tenfold per year since 2024. If this trend continues, in the next one to two years models will have the capability to run day- or week-long scams. At that point, the ability of a model to perform multiple tasks along the end-to-end spectrum means that single individuals and small teams could generate sophisticated scams. This would democratise access to capabilities needed to run scams and fraud and potentially draw in thousands of new scammers.
Frontier models usually have built-in sophisticated safeguards to prevent misuse by criminals, however open-source models typically catch up with leading capabilities within six to 12 months. Scammers will likely get access to agentic models that can carry out end-to-end scams within the next couple years, which gives banks a relatively narrow window to get ready.
How banks can meet the rising scam and fraud threat
While the threat is growing, leading financial institutions are already demonstrating that proactive action can materially strengthen resilience. BCG has worked with a range of financial institutions in the region to enhance fraud-management capabilities by combining advanced analytics, behavioural monitoring and AI-enabled intervention tools. These organisations improved their ability to identify high-risk activity earlier, reduced the burden on fraud operations teams and accelerated response times to emerging threats.
“The most effective time to act is before operational pressure starts to build. Banks that invest now in strengthening their fraud prevention capabilities will be far better positioned than those forced to respond reactively. That means developing models that not only detect suspicious activity, but can also intervene in real time, freeze transactions, when necessary, help customers remove themselves from high-risk situations quickly, and preserve trust when fraud incidents occur,” says Hakim Hamane, Managing Director and Head of BCG Platinion.
Banks can take five actions to prepare:
- Increase threat monitoring: As agentic AI developments change the threat landscape at a faster pace, banks need to increase their threat monitoring so they can track new trends and developments in a much more granular way. This allows banks to rapidly adapt defences as the threat changes. This includes among others, gathering richer behavioural and transactional data to train and continuously retrain detection and anomaly models; tracking capabilities of open-source, uncensored AI models; building adversarial agents to red-team a bank’s own detection models; and creating fake customers as scam targets to extract scammer information.
- Leverage the head start afforded by frontier models: Banks should use the lead that frontier models have over open-source models to continuously improve scam and fraud prevention. Key steps they can take include building a strong internal AI team with early access to the latest models and developing rapid approval pathways to get new capabilities into production quickly.
- Build a responsive, scalable operating model: Banks will need an operating model that can effectively scale up to deal with volume spikes and respond within hours, not weeks. This includes steps like dynamically increasing controls on high-risk payments; real-time analysis of calls to detect new potential scam and fraud patterns and use those to update detection engines; and automating or agentifying intervention, investigation, and recovery steps so they become scalable.
- Strengthen collaboration: As fraud and scam networks become more connected and more adaptive, financial institutions will need to work more closely with payment providers, platforms, telcos, social media companies, regulators, and law enforcement to identify and disrupt activity earlier.
- Design ‘fire breaks’: Banks should prepare for periods when fraud and scam activity spikes and normal operating processes come under strain. In those moments, temporary measures may be needed to preserve control while the bank responds. For example, developing surge playbooks with clear thresholds and escalation paths and identifying customer journeys where temporary friction would have the greatest impact.
“The transition to agentic scams and fraud is unlikely to be gradual – it could happen faster than many institutions expect. As attacks become more persistent, adaptive and highly personalised, traditional defence models will come under increasing pressure. Banks that move now to redesign how they prevent, detect and respond to this threat will be better positioned to protect customers, preserve trust and limit losses. Those that delay risk falling behind an adversary that is learning faster than they are,” concludes Hamane.





