AI fraud is forcing enterprises to prove every critical communication

Verifying critical communications against AI fraud

AI-generated fraud is becoming harder to distinguish from legitimate business activity. Whether it takes the form of invoice fraud, executive impersonation or manipulated corporate communications, enterprises can no longer focus solely on identifying fake material after it appears. They also need to ensure that genuine information can be verified before decisions are made.

This is now a business problem as much as a security one. DigiCert’s latest AI Trust Outlook research found that 78% of organisations had experienced AI-related incidents or identified AI-related vulnerabilities, while only half had established formal AI governance programmes. New EU AI Act transparency rules, which began applying on 2 August 2026, also require the marking and labelling of certain AI-generated and manipulated content.

AI-generated fraud changes the economics

Fraud illustrates the problem because criminals no longer need to compromise a system to cause serious damage; often, they only need to convince someone that a request or communication is genuine. A realistic message from a senior executive can trigger an urgent payment, while a convincing change to supplier details can redirect funds before anyone realises that something is wrong.

INTERPOL’s 2026 Global Financial Fraud Threat Assessment warns that AI-enhanced fraud is now estimated to be 4.5 times more profitable than traditional fraud methods, reflecting how AI is helping criminal networks scale financial crime rather than simply making existing scams more convincing.

Additional verification can stop some attacks, but it comes at a cost. Payments are delayed, routine requests are escalated and communications teams spend time establishing whether apparently legitimate material can be relied upon. Across a large enterprise, these interruptions create operational drag and erode some of the productivity gains organisations expect AI to deliver.

Detection alone won't solve the problem

Most organisations are still treating this as a detection problem, which is understandable but the wrong place to start. Better detection, employee training and threat intelligence remain necessary, but they cannot reasonably be expected to investigate every suspicious email, document, image or recording as the volume and quality of synthetic material increase.

The challenge is to make genuine information immediately recognisable, rather than expecting employees, customers and partners to become experts in identifying convincing fakes.

"The organisations that gain the greatest value from AI won't be those that become best at spotting every fake. They'll be the ones that make genuine information easier to recognise, reducing fraud, removing friction and allowing people to make decisions with confidence."

Enterprises should begin by identifying the communications and decisions where authenticity matters most. Executive announcements, payment instructions, changes to supplier accounts, customer communications and regulatory disclosures are obvious priorities because a successful deception can lead directly to financial loss, legal exposure or reputational damage.

These interactions should be designed so recipients have an independent way to establish where information originated and whether it has been changed. That reduces reliance on appearance, familiarity or human instinct at the point when somebody must decide whether to act.

Making genuine information easier to recognise

No single technology will solve the problem. Governance must establish which information requires additional assurance, who owns the process and how exceptions are handled. Stronger operating procedures can reduce opportunities for fraud, while employee awareness remains an important line of defence.

Content provenance, cryptographic verification and emerging industry standards can then provide evidence of origin and integrity. Each addresses a different part of the problem, and none is a silver bullet. Cryptography may demonstrate that a communication came from a recognised source and has not been altered, but it cannot decide which communications should be protected or what an employee should do when verification fails.

For CISOs, the practical starting point is therefore not another wholesale technology deployment. It is working with finance, legal, procurement, communications and other business functions to identify where uncertainty creates the greatest financial or operational exposure. Appropriate controls can then be built into the workflows where fraud would cause the most harm.

The business case is straightforward. Making important communications easier to verify can reduce fraud, shorten approval times and cut the number of routine requests that require manual checking. It can also support compliance with emerging regulation and allow organisations to increase their use of AI without surrounding every interaction with additional delays.

AI will continue to make fraudulent material cheaper and more convincing. The organisations that gain the greatest value from AI won’t be those that become best at spotting every fake. They’ll be the ones that make genuine information easier to recognise, reducing fraud, removing friction and allowing people to make decisions with confidence.

Richard Hall

Richard Hall is AVP at DigiCert, working with the global Solutions Engineering (SE) team as technical counterpart with GTM sales and Product. Richard is a Digital Trust advocate, presenting at conferences and events. 

Author

Scroll to Top

SUBSCRIBE

SUBSCRIBE