TL;DR: Agentic AI is making fraud run at software scale, with Incode citing 66 cross-checked AI-fraud cases, reported losses approaching 900 million dollars, and a 20.4 billion dollar US loss total in 2025. The core issue is that fraud is no longer constrained by human labor, so identity verification becomes the last reliable checkpoint.
NHIMG editorial — based on content published by Incode: How AI agents are fueling a record surge in fraud losses
By the numbers:
- Incode's incident database tracks 66 independently sourced, cross-checked AI-fraud cases in the US.
- 900 million dollars., ss those catalogued cases approach 900 million dollars.
- Global scam losses are growing at nearly 20% annually, according to Nasdaq Verafin.
Questions worth separating out
Q: How should identity teams handle agentic fraud in customer support and recovery flows?
A: Identity teams should treat support and recovery as high-risk verification points, not routine service interactions.
Q: Why does agentic AI complicate fraud compliance work?
A: Because compliance no longer reviews only model outputs.
Q: What do security teams get wrong about deepfake-enabled fraud?
A: They often treat deepfakes as a novelty problem instead of a verification economics problem.
Practitioner guidance
- Strengthen step-up verification for high-risk actions Require stronger identity proof before account recovery, payment change, beneficiary change, or support escalation.
- Add synthetic-interaction detection to trust workflows Instrument support, onboarding, and transaction flows for signs of deepfake audio, scripted language reuse, velocity anomalies, and repeated failed challenge attempts.
- Rebuild risk scoring around runtime context Combine device reputation, behavioural patterns, session history, and identity evidence when deciding whether to approve sensitive actions.
What's in the full report
Incode's full article covers the operational detail this post intentionally leaves for the source:
- The report’s 66-case incident database and how the vendor classified each fraud pattern by agentic capability.
- The 1-to-5 scoring model used to judge which fraud categories an AI agent can already run end to end.
- The projection model behind the 155.3 billion dollar and 380.1 billion dollar loss scenarios.
- The specific examples and methodology behind the documented fraud cases and loss estimates.
👉 Read Incode's analysis of how agentic AI is scaling fraud losses →
Agentic fraud is scaling fast. What should identity teams change?
Explore further
Agentic fraud is now an identity governance problem, not only a fraud problem. The article shows that AI agents can conduct outreach, adapt, and escalate without a human at every step. That shifts the control boundary from static fraud rules to identity verification, authorization, and trust validation across the whole customer journey. Fraud teams, IAM teams, and verification teams now share the same failure surface.
A question worth separating out:
Q: Who is accountable when account takeover and synthetic identity fraud occur?
A: Accountability usually sits across fraud, IAM, security, and product teams because the failure spans onboarding, session trust, and action-level controls. In practice, the owner should be the team that can change the decision point where abuse becomes possible. Shared risk does not mean shared inaction.
👉 Read our full editorial: Agentic AI is accelerating fraud into a software-scale threat