Paul Vigna, an editor at American Banker, opens his latest column with a story of being scammed: people impersonating literary agents approached him in the manner of the old advance-fee fraud, and the episode made the point that no amount of professional skepticism is a defense against fraud that arrives through channels you trust. His larger claim, the one in the headline, is that whatever your level of worry about AI deepfakes, it is not high enough.
The survey data he assembles supports at least the first half of the claim. A survey by Coveron, a scam-protection firm, found almost half of Americans say they have been victims of online fraud and nearly 80 percent have faced an attempted scam. Pew Research found 73 percent of Americans have either been victimized or seen an attempt. Fraud is not an edge case anymore; it is a background condition of having a phone. The question Vigna poses is whether the banking industry's fear has caught up with the fraud, and his answer contains a finding that deserves more attention than it will get: the banks that use AI the most are the most alarmed by what it can do.
Experience is what produces the fear
American Banker's executive survey asked banks to rate AI-enabled fraud as a threat. Among banks that do not use AI or are only exploring it, about 55 percent rated operations or third-party risk from AI as a high threat. Among banks furthest along in AI deployment, the figure rose to 83 percent. The pattern is the reverse of what the usual story about technology adoption predicts. The usual story says exposure breeds comfort: the people who know a technology fear it least, because fear is what ignorance feels like. Here the data run the other way. The institutions that know the technology best are the ones that consider it most dangerous, and the gap between the two groups is nearly thirty points.
The reason is not hard to find. A bank that has deployed AI knows what the tool can do, because it has watched it work. The same systems that power a bank's fraud detection, its chatbots, its document processing, are the systems an attacker uses against it, and the difference between the two uses is mostly a question of whose data and whose intent. Sophistication in this market means having seen the model's capabilities from the inside, and the inside view is not reassuring. The banks still experimenting have not yet had the experience that produces the alarm; the banks that have, are.
The attacker's supply chain is open
The cases Vigna collects show why the inside view is the accurate one. In the Netherlands, a man opened 46 bank accounts by blending his own features with stolen passport photos, defeating facial-recognition verification on every one, and was ordered to repay about 6,000 euros alongside a 30-month sentence. A fraud ring in Hong Kong used similar techniques to open 30 accounts. The tools that make these attacks possible are not hidden on darknet markets. KYC-bypass kits are sold openly online, priced like ordinary software, and marketed to people who never meet their buyers.
That is the asymmetry that the industry's alarm is really about. The bank's defensive arsenal is built and maintained under procurement rules, vendor diligence, regulatory review, and audit. The attacker's arsenal is a product with a price tag and a user manual. When the defender's verification technology improves, the attacker buys the update. The Netherlands case is not a story about an especially skilled criminal; it is a story about what happens when a verification system designed against one generation of fraud meets a tool that was built specifically to defeat it, sold to anyone with a few hundred euros.
The defense is a policy memo
Against this, the regulatory response so far is thin, and the industry knows it. FinCEN has issued alerts about deepfake-enabled identity fraud, which is to say it has described the problem. Julia Jakimenko, chief executive of the forensics firm Cyberette, argues the new European anti-deepfake rules contain loopholes that the fraud ecosystem has already mapped, and that in the United States there is no concrete method for stopping these attacks, leaving banks and vendors to defend themselves. Among the AI-deep banks in the survey, more than 80 percent expect the pace of new laws and federal regulations to pick up over the next three to five years. The expectation is not evidence of confidence. It is an admission that the current tool kit is not enough, wrapped in a hope that someone else will supply the next one.
The gap between the two sides' tooling is worth stating in plain terms. The attacker needs one technique that works once against each verification channel, and the ecosystem supplies a catalog. The bank needs every channel to hold against every technique, forever, and its defense updates on the regulatory calendar. The phrase that keeps appearing in coverage of this problem, that banks are on their own, is an odd one for an industry with a federal council dedicated to its safety. But it is accurate about the current state: the alert has been issued, and the method has not.
Deepfakes broke the premise the KYC system rests on
The Netherlands case deserves one more look, because of what it says about the verification system rather than the criminal. The premise of modern know-your-customer screening is that a face plus a document proves a person. A live face on camera is matched to a photo on a passport, and the pairing is the identity. Deepfakes do not forge either half. The document in the Dutch case was real, and so was the face, in the sense that a real person sat in front of the camera. What was false was the pairing: the face belonged to one man, the document to another, and the machine concluded they were the same.
That is a new category of failure for a verification system, and it matters because it cannot be patched with better document checks. The document was fine. The liveness check was fine. The system asked whether the person at the camera matched the document in the database, and the tool answered that question on the attacker's behalf, convincingly, 46 times. Defenses built for the old problem, forged documents and impersonation in person, do not touch the new one, because the new attack does not counterfeit the inputs. It interpolates between them.
The candidate remedies are all escalations in an arms race the defenders are losing on cost. Stronger liveness detection can probe for signs of synthesis, but the synthesis improves on the same schedule. Behavioral analysis and device intelligence add signal but raise false positives that fall on legitimate customers. Consortium sharing of known attack patterns helps the banks that participate and does nothing for the ones that lag, which is the point of the survey gap. The uncomfortable conclusion is that identity verification is moving from a check performed once at onboarding to a risk priced continuously, and the banks furthest along in AI are the only ones staffed to make that transition. The rest are still buying better document scanners.
The question that will convert fear into action is who pays
There is one lever that has not yet been pulled, and it is the one that matters most for whether the industry's alarm turns into investment. Today the losses from deepfake-enabled account opening and identity fraud land mostly on banks, and through them on the customers whose accounts are drained, under terms set by regulation and litigation. Vigna has covered the consumer advocates working to push more of that liability onto banks themselves, and the direction of that pressure is the interesting part. If verification failures become the bank's loss by default, the economics of the arms race flip: the cost of better detection stops being an optional budget line and becomes the cheaper alternative to paying claims.
That is not a prediction about any pending rule. It is a description of how defenses against fraud have always spread. Card networks built their fraud apparatuses on the same mechanism: whoever absorbs the loss invests in the defense, and the defense becomes an industry standard rather than a competitive choice. The deepfake era has no equivalent yet. The FinCEN alerts describe the threat; the European rules have loopholes; the banks are on their own, which means each bank is currently free to decide how much fear it can afford. An industry where the most sophisticated firms rate the threat at 83 percent and the least sophisticated at 55 percent is an industry that has not yet agreed on who absorbs the loss. The moment it does, the gap closes, and the fear becomes a line item.
The banks that fear it most are the ones best positioned
None of this means the alarm is misplaced, and none of it means the banks furthest along in AI are in the most danger. The finding probably runs the other way. The 83 percent who call AI fraud a high threat are not more exposed; they are more aware. A bank that has not yet integrated AI into its operations is flying blind in a storm it cannot see, and its 55 percent figure is a measure of ignorance rather than safety. The deep-AI banks have the monitoring, the fraud teams, and the experience to see attacks coming; that is precisely why they rate the threat higher. Fear, here, is a form of information.
The question the survey cannot answer is whether fear will convert into defense fast enough. The attackers' advantage is a product ecosystem; the defenders' is awareness and budget, and the two are not symmetric. The man in the Netherlands beat facial recognition 46 times with a tool anyone can buy. The next version of that tool is already for sale, and the banks that understand this best are not the ones who will be surprised.
Primary sources
- Paul Vigna's American Banker column of August 20, 2026, for the Coveron survey finding, the Pew Research figure, the American Banker executive survey showing 83 percent of AI-deep banks against 55 percent of non-adopting banks rating AI fraud a high threat, and the Netherlands and Hong Kong account-opening cases.
- Julia Jakimenko's assessment of European anti-deepfake rules and FinCEN's alerts on deepfake-enabled identity fraud, and the survey finding that more than 80 percent of AI-deep banks expect faster regulation over the next three to five years.