Fraud is a Permanent Condition of Humanity

Every major fraud wave in recorded economic history has followed the same pattern: economic stress creates pressure, new infrastructure creates opportunity and a novel tool lowers the barrier to entry. The railroad bond scams of the 19th century exploited westward expansion fever and telegraph-enabled information asymmetry. Post-2008 mortgage fraud grew from a housing market engineered to reward origination volume over credit quality. COVID-era PPP theft exploited pandemic urgency and a digital application process with minimal identity controls. The current AI-enabled fraud wave follows the same structure. The tool has changed. The pattern has not.

The business community often frames fraud as a solvable technology problem — an incident to investigate and patch. The deeper, more uncomfortable truth is that fraud is a structural constant of market economies and human psychology. The Association of Certified Fraud Examiners has measured organizational fraud losses every two years since 1996. Across 13 editions and more than 20,000 investigated cases, the figure has barely changed: approximately 5% of revenue every year, in every region. Fraud did not disappear after Sarbanes-Oxley. It adapted. Fraud did not disappear after chip-and-PIN. It migrated to card-not-present channels. Fraud did not disappear after two-factor authentication. It migrated to SIM swapping and social engineering targeting call centers. Every control that closes one avenue opens the economics for another.

That framing matters because it determines how institutions allocate resources. Leaders who treat fraud as an anomaly build reactive defenses and measure success by what they catch. Leaders who treat fraud as a permanent operating condition — the way they treat currency risk, supply chain disruption or inflation — make fundamentally different decisions about architecture, budgets and organizational design.

What AI Actually Changed

The dominant narrative — AI is making fraud worse — is imprecise. AI made fraudsters more sophisticated. A $20-a-month subscription can generate synthetic identities at scale, produce grammatically fluent phishing messages in any language, clone a voice from minutes of publicly available audio and forge identity documents that pass automated verification. The skill barrier that once limited sophisticated fraud to organized criminal networks has been eliminated. When the barrier to entry drops that far, fraud stops being an incident and becomes an infrastructure-level risk.

Economic pressures further compound the shift in technology. Mass layoffs in the technology sector, wage stagnation in developed economies and the absence of viable income alternatives in developing markets are pushing more people toward fraudulent activity — not as a career choice, but as a rational economic calculation. Organized fraud groups, meanwhile, are highly mutable. They exploit whatever attack vector is currently profitable and switch when that avenue dries up, the way legitimate capital flows to the best available return. The fraud economy mirrors the real economy in its responsiveness to incentives. It just operates without a compliance department.

The financial industry detects approximately 2% of global financial crime flows, despite increasing compliance spending by up to 10% a year. The FBI’s Internet Crime Complaint Center logged $16.6 billion in reported losses in 2024, a 33% increase from the prior year. The Financial Action Task Force’s (FATF) December 2025 Horizon Scan found that even unsophisticated actors can now defeat KYC processes, biometric verification and liveness checks using commercially available deepfake tools. These are not separate problems. They are the same condition viewed from different angles.

A Strategic Reframe

Companies that price fraud correctly into their operating models share several characteristics. They measure what they prevent, not only what they catch. They track false-positive rates as a revenue metric, not an operational statistic — because a legitimate customer declined by overzealous controls is revenue destroyed, not risk avoided. They build fraud and anti-money laundering (AML) functions into a single view rather than operating them as separate teams with separate systems, closing the organizational seam that attackers have learned to exploit. And they invest in context-rich, first-party data — the behavioral, device and identity signals generated by their own customer interactions — because that data is the one asset an attacker cannot fabricate at scale.

The most consequential decision is architectural. An institution that begins its fraud analysis at the point of transaction is already downstream of where the most effective interventions occur. Device fingerprinting, IP analysis, email and phone enrichment and behavioral signals captured at the first customer touchpoint — before the identity document is submitted, before the transaction is initiated — provide the foundation for a defense that operates earlier, faster and with fewer false positives than one built on rules and retrospective investigation.

The Choice

Five years from now, the companies that priced fraud as a permanent condition will have built compounding advantages: lower loss rates, better customer experience, stronger regulatory relationships and institutional knowledge that survives leadership transitions. The companies that waited to solve it will still be cycling through crisis-investment-complacency loops, funding each new wave of fraud with emergency budgets after the damage is done.

The 5%-of-revenue baseline is not the cost of doing business. It is the cost of doing business without the design discipline the work demands. The materials to build a better defense exist. The question is whether the institutions that need them will commit to the operating assumption that the threat is permanent — and design accordingly.

Fraud will not be solved. As long as systems retain value and humans find ways to exploit them, new vectors will emerge to replace those that are closed off. Technology will advance; so will the adversaries who learn to weaponize it. What separates resilient organizations from vulnerable ones is not the absence of fraud, but the refusal to treat its presence as a surprise.

Take the First Step Toward Transformative Fraud Prevention