The rule-based fraud detection system that banks have relied on for decades was designed for a fixed threat model: a known catalog of attack patterns matched against transaction data, with static thresholds that trigger review or block. That model assumes fraudsters are not learning. Artificial intelligence has broken that assumption, and the defenses that will hold are not more sophisticated rules. They are different architecture.

The Attack Surface Has Changed

Banks are now contending with fraudsters who deploy the same AI tools available to their security teams. The tactics have evolved beyond automated credential stuffing and synthetic identity fraud. Deepfakes are now capable of defeating voice biometric and facial recognition systems that were validated as secure a few years ago. Multi-vector attacks, which combine social engineering with technical exploitation in coordinated sequences, allow attackers to enrich each attempt with contextual data gathered from earlier reconnaissance.

Richard Bailey, CIO of Entersekt, a fraud mitigation platform, described the shift directly: “Fraud actors now have the ability to apply AI to their attacks.” The consequence, he argued, is that static defensive systems are structurally incapable of keeping pace. “If AI is using deepfakes, for example, then voice biometrics and facial biometrics doesn’t work anymore.” The antidote is not a better biometric; it is a system that adapts as attack patterns evolve.

Advertisement

FinTech Your brand belongs here. Reach the decision-makers who read FinTech every day. Premium placements across the site and newsletter. Advertise with us

Infrastructure-Level Defense

The framing Bailey uses for the solution is precise: AI needs to move from “a feature of the product layered on top” to core operational infrastructure that influences authentication decisions and reacts to new attack patterns in real time. Most first-generation AI deployments in fraud detection were additive, placed alongside existing rule-based systems rather than replacing the architectural logic underneath them. That additive model has proven insufficient as attack sophistication increases.

Starling Bank’s June 2026 launch of its AI-powered scam detection tool, which it describes as the first of its kind in the UK, illustrates what infrastructure-level fraud defense looks like in practice. The feature is built into Starling Assistant, the bank’s in-app conversational AI launched in March 2026. When a customer initiates a transaction that matches early-stage indicators of a romance scam, investment fraud, or deepfake phishing attempt, the assistant engages the customer in a structured question-and-answer sequence, asking about the relationship, whether the counterparty can fund the transfer themselves, and how long the relationship has been established.

The system is powered by Google’s Gemini models running on Google Cloud infrastructure, which enables contextual analysis of uploaded images and text in combination with Starling’s proprietary risk assessment layer. The design reflects the architecture shift Bailey describes: the AI is not a flag thrown by a rule. It is embedded in the customer interaction itself, capable of recognizing the conversational patterns that precede a confirmed fraud event.

The Two Factors That Matter More Than the Model

Bailey identified two factors that separate effective AI fraud defense from less effective implementations, both of which are harder to replicate than the AI model itself. The first is explainability and governance compliance: a fraud detection decision that cannot be explained to a regulator or audited for bias is an operational liability, regardless of its technical accuracy. The second is access to high-quality, managed customer data. The effectiveness of any AI fraud detection system is bounded by the quality and completeness of the behavioral data it trains on.

Both factors favor institutions that have invested in their data infrastructure over years. Newer entrants and smaller community banks may have access to the same AI models as larger institutions, but the absence of a deep, clean behavioral dataset limits how well those models can calibrate to their specific customer base and fraud patterns.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What This Means for the Financial Technology Leader

For financial technology leaders, the shift from rule-based to infrastructure-level AI fraud defense requires a different kind of vendor evaluation. The relevant questions are not just whether a vendor’s detection rate is high on a benchmark dataset, but whether the system was trained on data that resembles your institution’s customer base, whether the AI decisions can be explained to compliance and legal teams, and whether the architecture allows the model to be retrained as attack patterns evolve.

The explainability requirement is particularly acute for institutions subject to consumer protection regulation. A decision to block a transaction, decline a loan, or flag an account based on AI inference must be defensible under the same standards that apply to human decisions. As regulators turn their attention to AI-generated adverse actions, the institutions with documented, auditable AI decision logic will be better positioned than those with black-box systems delivering opaque outputs.

The competitive signal from the sector is clear: fraud defense is becoming a product differentiator, not just a compliance cost. Starling’s investment in a customer-facing AI scam detection assistant reflects a deliberate positioning choice. As AI-native fraud tools become available across the market, institutions that deploy them visibly and explain them clearly to customers will earn a measurable trust advantage. The infrastructure layer in payments and financial services is increasingly where competitive differentiation is won or lost, and fraud defense is no exception.

Source: Starling Bank