Race Against The Machine? – The Good, the Bad, and the Ugly of AI Compliance in 2026
- Dipo Akin-Deko

- Aug 6
- 4 min read
Updated: Aug 7

AI can review 10,000 transaction data before I've finished my morning coffee. That is the good news and part of what companies aim for with the increased usage and adoption of AI. The bad? It can also help a fraudster write 10,000 convincing phishing emails with perfect grammar just as efficiently. According to the FBI’s 2025 Internet Crime Report, losses from Business Email Compromise (BEC) in 2025 alone amounted to a staggering $3.04 billion making it the second most rampant internet crime.
With the playing field evened for everyone, it really is a race between defensive AI vs offensive AI. Therefore, the need for strategic and timely intervention to disarm an attack from an opponent is now.
Mastery of Deception - Deepfakes
Here is the ugly truth of where we are in 2026. AI has multiplied the Lokis of the world by allowing anyone with a bad intention to master the art of deception.
Traditionally, banks required thumbprint and/or physical presence to open a bank account. To keep up with the growing demands of the booming digital banking industry, AI truly became an exciting addition (or in some cases, substitute) to the traditional onboarding process. However, the emergence of deepfakes forces organizations to press the brakes and reassess their AI driven processes.
In March 2026, A 34-year old man used stolen identity documents that were collected through a fake tenancy listing to open 46 fraudulent bank accounts at Netherlands’ ABM AMRO Bank. He used deepfake technology to create images resembling the stolen IDs and managed to bypass the bank’s face recognition software, which automates the comparison between an applicant’s photo ID and selfie (a very popular measure in many payments platforms. The scheme came to light when an officer flagged an anomaly which launched an investigation.
This is an interesting case for compliance as it highlights one of the defining paradoxes of recent times: AI being leveraged to undermine the very AI driven controls designed to enhance security and efficiency.
AI-Powered Social Engineering
Perhaps 10 years back, someone who has worked in a company for 20 years could say “I know my manager’s voice” with certainty. In today’s world, we have technology that questions our instincts.
Fraudsters are now weaponizing AI by automating social engineering attacks by leveraging human emotions and trust.
The 2024 Arup Scam in Hong Kong is a landmark case that serves as a stark reminder that lowering scepticism and vigilance can cost you a fortune. An employee in Arup was manipulated into wiring USD $25 million to fraudster. The employee first received a phishing email from the company’s CFO and was later invited to a video conference call where familiar colleagues were present authorizing the transactions, except they were digital replicas. The images, audio were all AI-generated deepfakes.
With the collapse of trust as a control mechanism, it truly drives home the point that no actions should be conducted based on “The CFO asked, and therefore I executed” but rather “What does our Zero Trust Policy say?”
Staying Ahead of the Race
Many current deepfake laws such as the TAKE IT DOWN Act provides protection against non-consensual (authentic and computer generated) intimate imagery on online platforms, which is definitely a step forward in the right direction. However, corporations will still very much need to rely on existing fraud, cybercrime, intellectual property laws against the adversarial use of AI.
In reality, operational controls are stronger defence than legal protections as they prevent the damage in the first place.
For all high-risk checkpoint approvals, there must be a combination of one or two of the following:
Multi-party approval
Verifiable credentials such as digital signature backed by the CFO’s email, time stamp, and company stamp.
Authenticated systems and audit logs indicating who logged into the system, who approved it and when, and whether a passkey was used.
Cryptographic device, which is the use of passkeys stored on company issued devices to approve transactions.
Find the Weakness Before Criminals Do and Stay Prepared
Penetration testing is not just a yearly procedure for ISO compliance. We should be genuinely curious about how strong our defences are.
Periodic strain tests should include simulations designed to test whether the deepfake can bypass human judgment and manipulate workflows. This exercise is to assess the baseline on how the team would respond to these simulations and how we should reinvent training.
Leverage AI Against AI but With Human Intervention
FATF’s Horizon Scan recommends deployment of advanced ID verification tools, including advanced “liveness checks” and combining traditional investigative methods with advanced technologies such as AI powered forensic tools, deepfake detection, and blockchain analytics to combat AI enabled deepfakes. But AI alone is not sufficient. As recommended by the EU AI Act, human intervention is still key in detecting anomalies. AI should support, rather than replace, human verification integrity and anti-corruption functions.
TLDR
AI is neither a compliance tool nor a fraud tool. A modern approach to compliance and governance will be not to discourage the adoption of AI as it is inevitable. Rather, it should reinforce the need for responsible implementation, constant vigilance and healthy scepticism.
A quick compliance pulse check will be to ask the following questions:
Is my organization trained to handle AI driven attacks?
Is my team trained to catch AI driven fraud?
What are the loopholes in my new AI enabled verification process; does it break during a strain test?
Does my organization have sufficient cyber insurance policy with extended coverage on AI enabled crimes?
Stay safe!
Dipo Akin-Deko, Head of Legal, and Lavannya Manickam, Senior Manager for Legal and Compliance, both of BowerGroupAsia
