Jon Glass
Partner, Financial Crimes Advisory

A finance employee joins a video call with his chief financial officer and colleagues, approves tens of millions of dollars in wire transfers on their instruction and later learns that every face on the call except his was a deepfake. What once required nation-state resources now takes little more than a subscription. Scale it down: A community bank opens a remote deposit account with an artificial intelligence-generated selfie and license that pass the vendor’s liveness check. Funded by an automated clearing house (ACH) transaction, it is drained through mule accounts within 72 hours. The $40,000 loss surfaces months later, when the real person whose identity was faked disputes an account they never opened. The controls worked exactly as built, for a world in which a legitimate-looking ID and a live selfie meant a real person was on the other end. That assumption no longer holds.

The Asymmetry Boards Are up Against
AI has handed fraudsters enterprise-grade capability at street-level prices, while defenders run on tighter budgets and far less data. The Federal Bureau of Investigation’s 2025 Internet Crime Report logged $20.9 billion in losses, up 26% in a year, with AI-enabled crime newly broken out at $893 million. A bank under $10 billion carries the same regulatory expectations as the largest banks with a fraction of the means. No community institution will outspend this threat; the path runs through governance and shared capability, not a bigger check.

What Actually Changed
AI forges ID documents and injects synthetic video into the selfie step — the least-defended vector — since most liveness tools catch a photo held to a camera instead of a virtual feed. Synthetic identities pair a real Social Security number with a fabricated name, so the identity checks out even though the person does not exist. Cloned voices defeat call-center authentication and wire callbacks.

The Blind Spot Inside Your Own Numbers
The most important risk hides inside your own reporting. When a synthetic identity busts out, the loss looks like a borrower who stopped paying. It gets coded as a credit loss, folded into charge-offs and the current expected credit loss (CECL) reserve and never reaches the fraud tally. The board then reviews what looks like a credit-quality problem when it is a fraud problem, and forward-looking reserve models rest on a contaminated number. On the deposit side, the same losses scatter across fraud, credit risk and Bank Secrecy Act (BSA) reporting with no single owner. This is an important governance issue because if no one can say who aggregates synthetic-identity losses across both sides of the balance sheet, then that silence is the finding.

You Cannot Buy Your Way to Parity
The buy-a-platform instinct is exactly where directors should press. Reliable AI detection needs more transactions and confirmed fraud than any bank under $10 billion generates alone, pointing to the one promising path here: pooled, cross-institution data. A vendor’s value is the network behind it, so favor vendors that contribute to consortia, not just draw from them. In June 2026, the Financial Crimes Enforcement Network confirmed the Section 314(b) safe harbor covers suspected fraud, widening the lane for peer sharing. The honest objections are model risk and false positives. A black-box model a small bank cannot validate is a gap examiners probe, and when peers all run the same platform, a criminal who beats it, beats everyone. The board’s job is not to pick the model but to insist management can answer for it, including the false-negative rate vendors rarely volunteer.

What the Board Should Do
Ask for a single annual fraud report that ties losses to specific attack vectors, separates fraud from credit loss and shows how the institution shares data and uses the 314(b) safe harbor. “Handled across several departments” is not an answer; fragmentation is what the criminals count on.

Five Questions Every Director Should Ask:
1 Can management show fraud losses by attack vector, not just one aggregate number?
2 Are fraud losses bleeding into our credit-loss and CECL figures instead of being tracked separately?
3 Do our fraud and BSA/AML teams share data and work cases together or operate in silos?
4 Are we using the expanded 314(b) fraud safe harbor, and does vendor selection favor consortium participation?
5 If someone tested our onboarding controls today with a deepfake or a cloned voice, what would get through?

 

WRITTEN BY

Jon Glass

Partner, Financial Crimes Advisory

Jon Glass is a Partner in the Financial Crimes Advisory practice at SolomonEdwards and a nationally recognized advisor on anti-money laundering (AML), sanctions, fraud risk management, artificial intelligence (AI) governance, and financial crime transformation. For more than 25 years, he has helped financial institutions strengthen compliance programs, modernize operations, respond to regulatory scrutiny, and manage emerging financial crime risks.