Security teams should combine stronger identity proofing, device and behavior signals, and step-up checks at high-risk moments. AI-driven scams often look legitimate at the surface, so controls need to focus on anomalies across onboarding, payment activity, and account recovery. The goal is to raise friction only where risk is material, while preserving a usable experience for genuine customers.
Why This Matters for Security Teams
AI-powered scams change the fraud problem from “is this account real?” to “is this interaction believable enough to pass normal controls?” That shift matters because attackers can generate convincing messages, impersonation flows, and account takeover attempts at scale, then tune them in real time based on what gets through. Security teams that rely too heavily on static rules, one-time verification, or isolated device checks will miss the broader pattern.
Fraud controls now need to work across identity proofing, session risk, payment risk, and recovery risk, with decisions made at the moment of action. Guidance from NIST AI Risk Management Framework aligns with this risk-based approach, while Ultimate Guide to NHIs — Why NHI Security Matters Now shows how identity abuse becomes harder to detect when trust is granted too early. In practice, many security teams encounter fraud only after synthetic identities or AI-assisted impostors have already been accepted into production systems.
How It Works in Practice
The most effective adaptation is to move from point-in-time verification to layered, risk-aware decisioning. That means combining identity proofing, device intelligence, behavioral signals, velocity checks, and transaction context so the system can distinguish a normal customer from a machine-assisted impersonator. Current guidance suggests using step-up controls only at high-risk moments, such as onboarding, password reset, payout changes, beneficiary updates, and large transfers.
For teams managing more advanced environments, the pattern is similar to workload trust in NHI security: issue more trust only when evidence supports it, and revoke it quickly when the session changes. A practical control stack often includes:
- Identity proofing with stronger evidence for new accounts or high-value actions.
- Device binding and session continuity checks to spot automation reuse.
- Behavioral analytics that look for abnormal typing cadence, navigation paths, or decision timing.
- Velocity and graph-based controls to detect many-to-one fraud patterns across accounts.
- Step-up authentication only when risk crosses a defined threshold.
This also means policy must be evaluated at runtime, not frozen in a static rulebook. Controls such as NIST SP 800-53 Rev 5 Security and Privacy Controls support this kind of risk-based enforcement, but they need implementation discipline: clear thresholds, alert tuning, and human review paths for edge cases. Fraud teams should also watch for related abuse patterns seen in Microsoft Midnight Blizzard breach, where identity compromise and trust abuse compound quickly. These controls tend to break down when legacy banking or call-centre workflows require broad manual exceptions because attackers can route around the strongest digital checks through the weakest human process.
Common Variations and Edge Cases
Tighter fraud controls often increase customer friction and operational review load, requiring organisations to balance protection against conversion, support cost, and false positives. That tradeoff becomes more visible for high-volume consumer services, cross-border payments, and shared-device environments, where legitimate users can look anomalous for reasons unrelated to fraud.
There is no universal standard for this yet, but current guidance suggests tailoring controls by risk tier rather than applying the same friction everywhere. For example, a low-risk login may only need passive scoring, while a payout change may justify step-up verification plus manual review. Teams should also expect AI-assisted scams to evolve faster than static fraud rules, which is why model refresh cycles, adversarial testing, and signal monitoring matter as much as the control itself. NHIMG research on the State of Secrets in AppSec shows how quickly attackers exploit exposed trust material once they find it, and the same speed applies when fraud actors discover weak thresholds or reusable recovery paths. AI-driven fraud is hardest to stop in environments where account recovery, customer service, and payment approval are split across separate systems with inconsistent identity assurance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, CSA MAESTRO and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A01 | AI scams exploit autonomous generation and impersonation at scale. |
| CSA MAESTRO | TRUST | Fraud controls need runtime trust decisions for dynamic AI-driven abuse. |
| NIST AI RMF | Risk-based governance fits evolving AI-enabled fraud patterns. | |
| NIST CSF 2.0 | PR.AA-03 | Adaptive identity verification supports stronger access assurance. |
| OWASP Non-Human Identity Top 10 | NHI-05 | Automated abuse often reuses credentials and recovery paths like compromised NHI patterns. |
Treat AI-generated fraud as adversarial agent behavior and test controls against adaptive abuse paths.
Related resources from NHI Mgmt Group
- How should fraud teams adapt controls when AI-powered attacks scale faster than review capacity?
- How should security teams stop agentic AI fraud without blocking real users?
- How should security teams reduce AI-powered fraud in SaaS applications?
- How should security teams protect browser-side fraud controls against AI analysis?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org