🎓 CoursesInnovationAdvanced⏱ 60 min

AI and fraud prevention. 6 chapters and a final quiz.

How artificial intelligence became the core of payment fraud detection. The raw material (features and weak signals), how models evolved (rules, gradient boosting, graphs), real-time scoring at authorization, and the trade-off between fraud losses and false declines. Then the chargeback feedback loop, the generative AI counterattack by fraudsters (deepfakes, AI-assisted fraud), the tooling landscape, and the governance of an automated decision model (explainability, GDPR, the AI Act).

Chapter 1. The cost of fraud and the limits of rules.

Payment fraud covers transactions the account holder did not authorize, as well as those they authorized because they were manipulated. Two reports give a sense of scale, one global and one European. According to the Nilson Report (2024), global card fraud losses reached $33.83 billion in 2023, and the firm projects cumulative losses of more than $400 billion over the next decade. In Europe, the joint ECB/EBA report on payment fraud (August 2024) puts total fraud at €4.3 billion in 2022 across all payment instruments. Broken down by acceptance channel, fraud is clearly concentrated. Card fraud is overwhelmingly card-not-present (remote payments), which accounts for nearly 79% of card fraud by value in the EEA.

🔑
Why AI, and not just rules?
A rules engine (“if amount > €3,000 and country ≠ country of issue, then block”) is readable, auditable, and instant. But its logic is static, generic, and easy to get around. A fraudster who finds a threshold by trial and error then keeps their transactions just below it. Meanwhile, a rule written for a fraud pattern already observed declines legitimate cardholders whose habits have changed. AI addresses these limits in three ways: it learns combinations of signals, adapts to new patterns, and scores a probability instead of making a binary call.
$33.83B
global card fraud losses in 2023
Nilson Report, 2024
€4.3B
total payment fraud in the EEA in 2022 (all instruments)
ECB/EBA, Report on Payment Fraud, August 2024
≈ 79 %
card-not-present share of card fraud value (EEA)
ECB/EBA, 2024
< 0,05 %
target fraud rate on SCA/3DS-authenticated transactions, far below the rate on unauthenticated ones
ECB/EBA, 2024

Strong authentication moved fraud elsewhere; it didn't eliminate it

In Europe, PSD2 and strong customer authentication (SCA), rolled out through 3-D Secure, sharply reduced fraud on authenticated transactions. Other markets rely on different authentication mechanisms. Fraud moved to flows outside the scope of SCA. These include cross-border transactions with an acquirer outside the EEA, merchant-initiated transactions (MITs), and transactions exempted under transaction risk analysis (TRA). Two other routes bypass authentication without having to defeat it. Social engineering leads cardholders to authenticate a payment they believe is legitimate, and account takeover puts the account holder's authentication factors in the fraudster's hands. SCA did not solve the problem. A single checkpoint at the start of the customer journey no longer covers these cases. Detection must therefore score every transaction continuously: before, during, and after authorization.

  • Rule: fixed, explicit logic and a binary decision, easy to get around once the threshold is known
  • Statistical/ML model: learns correlations across thousands of transactions and produces a continuous risk score
  • In practice, you combine both: rules handle known patterns and regulatory requirements (sanctions lists, limits), while the model handles nuanced and novel cases
🎯 Quick question
Why is a rules engine alone no longer enough to fight payment fraud?