Australia’s banks have spent the past decade building layers of digital defences, from biometric logins to real-time transaction monitoring. A fresh industry analysis argues that the same wave of artificial intelligence now propping up those defences is arming the criminals attacking them, and that the country’s control frameworks are not keeping up.
The warning comes in a report from Asian Banking & Finance, which finds that generative AI is lowering the cost and lifting the sophistication of financial crime while many institutions still lean on controls designed for a slower, more human style of fraud. The central concern is not a single new attack, but the speed at which AI compresses the work that once made large-scale fraud difficult.
Why AI changes the fraud equation
For years, the friction protecting bank customers was partly practical. Convincing scam messages took effort to write, especially in fluent local idiom. Fake documents took skill to forge. Impersonating a real voice on a phone call was largely the stuff of films. Generative tools have quietly erased much of that friction. Text models now draft flawless, personalised lures at scale, image and document generators produce convincing identity paperwork, and voice cloning can mimic a family member or a bank officer from a few seconds of audio.
The result is a shift from artisanal fraud to industrial fraud. Criminal groups can spin up thousands of tailored approaches, test which ones work, and iterate in hours rather than weeks. Synthetic identities, stitched together from a mix of real and fabricated details, are becoming harder for onboarding checks to catch because the AI-generated components look authentic. The analysis argues that this is where the control gaps bite hardest: fraud systems tuned to flag obvious anomalies can miss activity that has been deliberately shaped to look ordinary.
There is a second-order problem, too. As banks deploy their own AI models to spot suspicious behaviour, they inherit new blind spots. Models trained on yesterday’s fraud patterns can be slow to recognise a novel scam, and attackers who understand how detection works can probe for the thresholds that let a transaction slide through. Governance of these systems, including how they are tested, monitored and explained, often trails their deployment.
Two ways to read the threat
One school of thought treats this as an arms race the banks are equipped to win. On this view, financial institutions have the data, the budgets and the regulatory pressure to deploy AI defences that outpace the attackers, and the technology that helps criminals also helps investigators triage alerts, link accounts and freeze funds faster. Proponents point out that Australia’s major banks already run sophisticated machine-learning fraud engines and have been early adopters of shared intelligence between institutions.
The more cautious reading, and the one the analysis leans toward, is that defence is structurally harder than attack. A bank has to protect millions of customers across every channel, every hour, while a fraudster only needs one method to work once. Control frameworks, audit cycles and model-risk approvals move at the pace of regulated institutions, whereas criminal tooling moves at the pace of open-source releases. That asymmetry is the gap. It is less about any single missing control and more about the lag between how quickly the threat evolves and how quickly a large, governed organisation can respond.
What it means for Australia
The Australian stakes are unusually high because scams have already become a national policy problem, not just a banking one. Australians have lost billions of dollars to scams in recent years, and while combined efforts by banks, telcos and the National Anti-Scam Centre have pushed reported losses down from their peak, the totals remain painful. AI threatens to reverse hard-won progress by making the next generation of scams cheaper to run and harder to spot.
Policy has been moving to catch up. The Scams Prevention Framework, legislated in early 2025, places enforceable obligations on banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams, with the prospect of penalties for those that fall short. Banks have also rolled out a confirmation-of-payee capability so customers can check that an account name matches before sending money, a direct response to the kind of impersonation AI makes easier. Regulators including APRA, through its operational-risk standard CPS 230, and ASIC have been sharpening expectations around how institutions manage technology and third-party risk. The control gaps flagged in this analysis are precisely the ground these rules are trying to cover.
For Australian financial-services leaders, the practical challenge is that compliance and capability are not the same thing. Meeting a framework’s obligations on paper does little if a fraud model has not been retrained against the latest synthetic-identity techniques, or if a call centre can still be talked into resetting access by a cloned voice. The institutions that fare best are likely to be those that treat AI-enabled fraud as a moving target requiring continuous testing, red-teaming and cross-industry data sharing, rather than a box to be ticked once a year.
There is a customer-trust dimension that matters for a heavily banked, digitally mature market like Australia. Confidence in tapping a card, approving a payment or answering a call from a bank underpins the whole system. Each high-profile AI scam that succeeds chips away at that confidence and pushes more of the clean-up cost, and the reputational damage, onto the institutions. That gives banks a commercial reason, not just a regulatory one, to close the gaps quickly.
What’s next
Expect the pressure to intensify on several fronts. Regulators will keep testing whether banks’ fraud controls are genuinely keeping pace, and the Scams Prevention Framework will start to show its teeth as obligations are enforced. Banks are likely to accelerate spending on AI-based detection, behavioural biometrics and identity verification that can resist synthetic documents, while leaning harder on shared threat intelligence so a scam pattern caught at one institution can be blocked across the sector.
The harder question is governance: how institutions prove their own AI systems are safe, fair and effective when the fraud they face is itself AI-generated. That is the gap this analysis is really pointing at, and it is one Australia’s banks, regulators and customers will be grappling with well beyond the next reporting cycle.
Sources: Asian Banking & Finance.



















































