Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why does AI-enabled fraud increase the pressure on…
Identity Beyond IAM

Why does AI-enabled fraud increase the pressure on merchants to invest in AI-based defenses?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Identity Beyond IAM

AI-enabled fraud raises the speed, scale, and quality of attacks, which makes manual review and static rules easier to evade. Merchants need AI-based defenses because they can process more signals, adapt faster, and reduce false positives while still blocking suspicious activity. The practical goal is better decisioning, not AI for its own sake.

Why AI Raises the Fraud Bar for Merchants

AI changes fraud from a mostly labor-intensive problem into one that can be executed at higher volume, with better targeting and less obvious patterns. That shifts the merchant’s challenge from spotting a few suspicious attempts to separating legitimate customers from attacks that continuously adapt. The result is a stronger business case for defenses that can learn from new behavior rather than rely only on fixed thresholds.

The practical pressure comes from the economics of abuse. If attackers can generate believable text, synthetic profiles, coordinated purchase attempts, or tuned payment abuse faster than a human team can review them, manual review becomes too slow and too expensive. AI-based defenses are attractive because they can compare more signals at once and keep up with changing attack patterns without requiring the same level of analyst intervention.

Where Manual Review and Static Rules Start to Fail

Static rules work best when fraud follows repeatable patterns, but AI-enabled fraud deliberately erodes that predictability. Attackers can vary device traits, message content, timing, transaction size, and account behavior just enough to stay under hard-coded thresholds. They can also probe a merchant’s controls repeatedly, learning which patterns trigger friction and which ones pass.

Manual review has a different weakness: it scales poorly when the false-positive queue is large. As attack quality improves, review teams spend more time on borderline cases and less time on high-signal exceptions. That creates two pressures at once, slower customer decisions and weaker fraud coverage, which is why merchants start looking for systems that can rank risk continuously instead of applying a fixed yes or no rule.

Risk and Threat Considerations

AI-enabled fraud increases exposure because it improves both volume and disguise. Merchants face more automated testing, more convincing social engineering, and more transactions that look normal in isolation but become suspicious only when signals are combined across sessions, devices, and histories.

Failure mechanism: Attackers exploit brittle rules, noisy review workflows, and weak signal fusion by varying each attempt just enough to avoid threshold-based detection while preserving fraud effectiveness at scale.

Impact: Merchants absorb more losses, more review cost, and more customer friction, and they may also approve fraud that would have been caught by a system able to adapt faster than static controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1 — Identity Management, Authentication and Access ControlFraud defenses depend on verifying customers and sessions before allowing high-risk actions.
DE.AE-3 — Anomalies and Events are AnalyzedAI fraud pressure comes from needing to spot unusual behavior across many signals quickly.
RS.MA-1 — Incident Management Plan Is ExecutedFraud events require coordinated response when suspicious activity escapes prevention.
Recommendation — Strengthen identity and access checks for suspicious transactions and account activity. Analyze anomalous payment and account patterns in near real time. Trigger fraud response playbooks when abusive behavior exceeds tolerance thresholds.
CIS Controls v86.3 — Access Control ManagementFraud frequently exploits weak account controls and over-permissive customer access paths.
8.2 — Audit Log ManagementAdaptive fraud detection relies on detailed event data for model and rule tuning.
Recommendation — Restrict high-risk actions with tighter access control and step-up verification. Retain and review transaction and session logs for suspicious behavior patterns.
OWASP Agentic AI Top 10A1 — Prompt Injection and Instruction HijackingAI-generated fraud can use persuasive text and manipulated interactions to steer decisions.
Recommendation — Harden AI-mediated decision flows against manipulated inputs and deceptive prompts.

Practitioner Guidance

What to prioritise: Focus on detection quality, decision latency, and review capacity together. AI-based fraud controls are only useful when they improve real approval decisions, not when they simply move the bottleneck from fraud scoring to exception handling.

What to verify: Validate that any model or scoring layer is using multiple independent signals, not just pattern matching on one channel. A system that only learns surface features will be brittle if attackers change wording, timing, or transaction structure.

Common mistake: Treating AI as a replacement for policy. Good fraud programs still need business rules, human escalation paths, and measurable thresholds for when automation should defer or override a decision.

Practitioner takeaway: The right comparison is not human review versus AI, but rigid decisioning versus adaptive decisioning under attacker pressure, and merchants should invest where the greatest reduction in fraud loss and false positives is demonstrable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org