By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: FingerprintPublished October 13, 2025

TL;DR: AI-powered attacks now account for 41% of attacks targeting organisations, and Fingerprint’s survey of more than 300 leaders in SaaS, fintech, payment platforms, and banking shows average annual losses of $414,000, with more than a third reporting losses above $1 million. Privacy-first tools and regulations are also making legitimate users harder to distinguish from fraudsters, so fraud teams need stronger device intelligence and faster risk-based decisioning.


At a glance

What this is: Fingerprint’s survey says AI-powered fraud is already driving measurable losses, heavier manual triage, and weaker user verification as privacy tools reshape detection conditions.

Why it matters: For IAM and identity verification teams, this matters because fraud controls, privacy constraints, and trust decisions now have to work together instead of being treated as separate problems.

By the numbers:

👉 Read Fingerprint's full State of AI Fraud & Privacy Report


Context

AI-powered fraud is not just a detection problem, it is a trust-governance problem. When attackers use generative tools to scale social engineering, automate account abuse, or adapt faster than static rules, traditional fraud models lose signal quality and analysts inherit more manual review.

In parallel, privacy-first browsers, VPNs, and consent-driven controls reduce the certainty available to fraud and identity teams. That creates a hard boundary for identity verification: organisations must distinguish legitimate privacy-preserving behaviour from malicious disguise without over-collecting data or increasing customer friction.

The article’s starting point is typical for a sector survey: it reflects a pattern now visible across digital businesses rather than an isolated vertical issue.


Key questions

Q: How should fraud teams adapt controls when AI-powered attacks scale faster than review capacity?

A: They should move from static rule sets to layered risk decisions that combine device intelligence, behaviour, and transaction context. The goal is not to block every anomalous event, but to classify risk quickly enough that analysts focus on the highest-value cases while automated controls handle the rest.

Q: Why do privacy-first technologies make fraud prevention harder?

A: Because they reduce the continuity signals fraud teams use to recognise returning devices, sessions, and users. That weakens passive detection and can make legitimate privacy-preserving behaviour look similar to disguise, so teams need clearer governance for how those signals are interpreted.

Q: What do teams get wrong about device intelligence in fraud prevention?

A: They often treat it as a standalone detector instead of an enrichment layer. Device intelligence is most useful when it helps confirm or weaken confidence in other signals such as velocity, geography, and account history. On its own, it rarely proves fraud; in combination, it improves decision quality.

Q: Who is accountable when privacy controls reduce fraud detection accuracy?

A: Accountability should sit with the teams that own both identity risk and customer experience, because the trade-off is operational as well as technical. Security, fraud, privacy, and product stakeholders need a shared policy for what evidence is required before blocking, challenging, or passing a user.


Technical breakdown

AI-powered fraud detection failure modes

AI changes fraud by compressing the attacker’s cost of experimentation. Instead of manually varying messages, devices, or account-creation attempts, attackers can generate many plausible variants that defeat simple heuristics and pattern-based rules. That pushes fraud programmes away from static indicators and toward adaptive scoring, behavioural context, and cross-signal correlation. In practice, the challenge is not just catching a single suspicious event, but distinguishing legitimate variation from machine-generated deception at scale.

Practical implication: teams need scoring models that combine device, session, and behavioural signals rather than relying on one high-confidence indicator.

Privacy-first technologies and identity signal loss

Privacy-first browsers, VPNs, and anti-tracking features reduce the reliability of device persistence and fingerprinting signals. That does not make all privacy-preserving activity suspicious, but it does make attribution harder for fraud teams that depend on continuity across visits, sessions, and accounts. The governance issue is not whether privacy is good or bad, but whether fraud controls can still make defensible decisions when the strongest passive signals are intentionally weakened.

Practical implication: reassess which device and browser signals are essential, and document how each signal is used in fraud decisions.

Manual triage as a control bottleneck

When AI-driven attacks increase false positives or generate new patterns that rule sets cannot classify, investigation shifts into human review. That can be useful for edge cases, but it becomes a bottleneck when volume rises faster than analyst capacity. The operational risk is slower containment, inconsistent decisions, and investigator fatigue. In identity terms, the programme starts to depend on humans as the fallback control when automation should have been the first line of defence.

Practical implication: measure how much of your fraud queue is truly exception handling versus recurring signal failure.


Threat narrative

Attacker objective: The attacker aims to increase successful account abuse, payment fraud, or identity deception while staying below detection thresholds.

  1. Entry begins with AI-generated or AI-assisted fraud attempts that mimic normal users across sign-up, login, or transaction flows.
  2. Escalation occurs when privacy tools and weak device continuity reduce detection confidence, allowing attackers to iterate faster than analysts can review.
  3. Impact is measurable loss, higher manual workload, and reduced ability to distinguish legitimate users from fraudsters at scale.

NHI Mgmt Group analysis

AI-powered fraud is now an identity-verification problem, not only a fraud-scoring problem. The article shows that attackers are using AI to increase scale, adaptiveness, and plausibility, which weakens controls that depend on static patterns or one-time verification. For identity teams, the important shift is that trust now has to be continuously re-evaluated across the user journey, not just at onboarding.

Privacy-first technologies create a verification trust gap. When browsers, VPNs, and consent choices suppress tracking, fraud teams lose continuity signals that once anchored risk decisions. That does not mean privacy-preserving behaviour is suspicious, but it does mean verification programmes need explicit governance for how they use device intelligence, session context, and fallback checks. The practitioner conclusion is that privacy and fraud prevention must be designed together, not traded off informally.

Operational strain is becoming a control failure mode. The article’s manual-review burden shows that modern fraud programmes can saturate their own analysts when automation cannot keep pace with adversarial variation. The deeper governance issue is not just detection quality, but whether the programme can sustain decision speed under AI-amplified attack volume. Teams should treat analyst backlog as a security risk indicator, not only an efficiency metric.

Device intelligence is a control layer, but it should be governed as identity context, not certainty. Persistent device and browser identification can add useful signal before login or account creation, especially when cookies are cleared or privacy settings change. Yet the value comes from risk context, not deterministic identity. The right model is layered assurance, where device intelligence supports fraud decisions without being treated as a standalone proof of legitimacy.

What this signals

Verification programmes will increasingly be judged on signal quality rather than signal volume. When privacy controls reduce tracking continuity, fraud teams need governance over which signals are trustworthy enough to trigger step-up actions or blocks. That pushes identity verification closer to policy design, with clearer rules for when device intelligence can inform a decision and when it should only contribute supporting context.

Manual review is becoming a leading indicator of fraud model drift. If AI-driven abuse is pushing analysts into repetitive triage, the programme is no longer scaling with the threat. Leaders should watch queue depth, false-positive clusters, and repeated edge-case handling as signs that controls need re-tuning rather than more human effort.

The NHI angle emerges when AI systems participate in fraud decisions at runtime. As organisations use AI to triage, score, or challenge users, those systems become part of the identity control plane and need explicit governance around access to data, decision rights, and auditability.


For practitioners

  • Rebalance fraud signals for privacy-constrained environments Review which device, session, and behavioural signals still remain reliable when users adopt privacy-first browsers or VPNs. Build risk models that tolerate signal loss without automatically elevating every privacy-preserving session to high risk.
  • Separate onboarding trust from ongoing trust Use different controls for account creation, login, and transaction approval so AI-generated abuse cannot rely on one verification decision to carry the whole lifecycle. Add step-up checks only where the risk pattern justifies them.
  • Track analyst backlog as a security metric Measure manual queue growth, median investigation time, and repeat-case volume as indicators that fraud controls are failing to classify new attack patterns. If review queues grow faster than the attack surface, the control model needs redesign rather than more staffing.
  • Document how device intelligence influences decisions Define where persistent device identification can inform fraud scoring, where it must not be treated as proof of identity, and what evidence is required before blocking a user. This improves explainability and supports compliance review.

Key takeaways

  • AI-powered fraud is now a governance issue because it degrades the quality of identity signals that fraud teams rely on.
  • The combination of privacy-first tools and adaptive attacks is increasing manual triage, response time, and decision uncertainty.
  • Fraud and identity teams need layered verification policies that preserve privacy while still enabling defensible risk decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST AI RMF set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BThe article centres on identity verification and fraud resistance in digital onboarding.
NIST CSF 2.0PR.AA-01Fraud programmes need access and identity assurance controls across the user journey.
GDPRArt.5Privacy-first technologies and identity data processing directly raise GDPR data-minimisation concerns.
NIST AI RMFMANAGEAI-assisted fraud decisioning requires ongoing governance of model and human-in-the-loop risk.

Review fraud data collection against Art.5 and limit identity signals to what the decision truly requires.


Key terms

  • Device Intelligence: Device intelligence is the practice of interpreting signals from a device to assess whether a session or transaction is likely legitimate. It goes beyond fingerprinting by combining device context with behavioural, identity, and payment evidence to support a risk decision.
  • Privacy-First Technology: Privacy-first technology reduces the amount of identifying information exposed during normal online activity. This includes browsers, VPNs, and tracking restrictions that protect user privacy, but also reduce the continuity signals fraud teams often use to detect abuse or connect sessions to a known device.
  • Identity verification: Identity verification is the process of confirming that a user, workload, or agent is the entity it claims to be before access is granted. In AI-heavy environments, that verification must include the requester, the system acting on its behalf, and the sensitivity of the action.

What's in the full report

Fingerprint's full report covers the operational detail this post intentionally leaves for the source:

  • Sector-by-sector survey breakdowns for B2B SaaS, fintech, payment platforms, and banking.
  • The report's wider data set on AI-powered fraud losses and investigation burden.
  • Practical discussion of device intelligence as a fraud signal before login or account creation.
  • The article's full framing on how privacy regulations are reshaping detection and user verification.

👉 Fingerprint's full report includes the sector breakdowns and operational detail behind these fraud trends.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It gives practitioners a structured way to connect identity controls to broader security and risk programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org