Leadership1 distinct publisher3 min readPublished
Experian's respondents are funding fraud controls ahead of their own loss experience, so the question facing a finance team this quarter is less whether AI-enabled attacks land than which budget carries the answer.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
The seventeen points between the loss share and the budget share are where the decision sits. Experian puts fraud losses higher at a minimum of 60% of its 200 respondents and larger fraud-management budgets at 77% [1][2], which means that on the survey's own floor at least 17 points of the sample, about 34 companies, are funding a response they have not yet recorded a loss against [13]. The floor matters: the loss figure is published as "at least 60%", so if the real share is higher, that guaranteed gap narrows [15]. Money is moving before the damage is fully measured either way.
A skeptic would say 200 respondents reporting a direction of travel is not a budget case, and on the narrow question that is correct. The figures in the report are shares of respondents, not amounts [1][2], so they cannot tell a finance function how much to move or what return to expect. What they do tell it is that roughly three quarters of the surveyed peer set has already made the call [2], which changes the internal burden from proving the threat to explaining the exception.
The reason this reads as an operating cost rather than a security one is in the adoption number. Eighty percent of respondents already run machine learning or generative AI inside their fraud-management environments, for suspicious-activity detection and identity verification [4], which is spend sitting in the workflow that approves payments and onboards customers. Cody Tyler of EXOS argues that AI has not created new scam categories but supercharged existing ones [5], and that exposure tracks access to money and sensitive systems rather than seniority [6]. If he is right, the marginal dollar hardens accounts payable and the front desk rather than the perimeter.
The cheapest control described in the Forbes account also carries the most awkward invoice. Victor Smushkevich of CallSetter AI says a three-second voicemail greeting is enough to clone an executive's voice [8], and that the defence is a mandatory callback to a verified number on every financial request made by phone, with no exceptions [9]. That is close to free to buy and expensive to run, because every urgent payment now takes a second call, and the delay is absorbed by treasury and payables rather than by the function whose budget holds the tooling. Noe Ramos of Agiloft says several companies have lost hundreds of millions to a single phone call [7]; that is one practitioner's assertion in the same article, and it is the loss figure a callback rule gets priced against.
The case for buying procedure over awareness is that awareness depreciates. Olga Polishchuk of ZeroFox says the artifacts staff are taught to look for, lip-sync errors and plastic skin among them, are being patched in real time [10], and Scott Edwards of BOK Financial says fraudsters moved off older tactics as recognition of those tactics spread [11]. Stanislav Kazanov of Innowise describes the text-side version, with a target's LinkedIn profile fed into a model to reproduce a colleague's writing manner [12]. A callback does not depend on spotting the fake, which is why it survives the next model release. What the record does not settle is how long the unscripted follow-up question keeps working, since the only evidence offered is that synthetic voices still stumble on them [9], and that is a question for the decade rather than the quarter.
Ranked by verification strength, evidence, and original report placement.
At least 60% of 200 companies surveyed by Experian report fraud losses "somewhat or significantly higher" than previous years.
77% of the Experian survey respondents are responding with larger fraud management budgets.
Respondents named AI-generated phishing attacks as their leading AI-related fraud concern (53%), followed by AI-assisted first-party fraud (51%), document forgery (45%), automated bot attacks (40%) and deepfake voice scams (37%).
80% of respondents report using machine learning or generative AI within fraud management environments to help identify suspicious activity, improve identity verification and enhance fraud detection capabilities.
Tyler said the common thread through AI scams "is less about who you are and more about what you have access to or how easily you can be convinced," with employees who have access to money or sensitive systems and organisations with limited cybersecurity resources more at risk of being targeted.
Smushkevich said every financial request over the phone should get a mandatory callback to a verified number with no exceptions, and that AI-generated voices still stumble on unscripted follow-up questions.
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
Experian's 2026 fraud numbers move the work from catching events to proving people1 distinct publisher
security
Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one2 distinct publishers
invest
Socure adds agentic fraud investigation at a valuation 16% above its 2021 round3 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One survey, unpublished methodology
Every quantity in this story comes from a single Experian survey that Forbes describes but never characterises — no sample frame, no fielding window, and a loss share stated as 'at least 60%' rather than a number. Around it sit eight practitioner quotes, which are testimony rather than measurement, and the largest figure in the piece attaches to no identifiable incident.
Near-universal on paper
If the survey is taken at face value, AI in fraud operations is already the norm rather than a pilot: four in five respondents say ML or generative AI is in their detection and identity stack, and three in four are adding budget. What keeps this from scoring higher is that both figures are firms describing themselves, with no deployment scale, spend level or outcome to anchor them.
Anecdote outruns the arithmetic
The memorable lines are the least supported ones — three seconds of voicemail to clone a chief executive, hundreds of millions gone in one call — while the checkable material is more modest and, in one place, cuts the other way: deepfake voice scams rank last among respondents' concerns at 37%, behind ordinary phishing. Forbes also leaves its own strongest finding unstated, that spending has decoupled from recorded losses in at least 17 points of the sample.
Sellers describing their own market
Experian conducted the survey and sells fraud management services into the budgets it reports growing. The quoted voices are a CISO at a security firm, an AI operations VP at a contract software vendor, the founder of an AI voice-calling company asserting how little audio a clone needs, an investigations VP at a threat intelligence vendor, and the CEO of an endpoint control company. That is not disqualifying, but every party describing the threat also profits from the response, and Forbes discloses none of it.
Solid on the numbers as quoted
We can be confident about what was said and about the subtraction that follows from it; the 77% and the 60% floor are quoted plainly and the gap is arithmetic. Confidence stops there. With one publisher, an undescribed survey and no corroboration for the loss anecdotes, the underlying picture of how much AI-enabled fraud is actually landing stays out of reach.