Home / Insights / AI risk, safety and trust
AI Did Not Create Scams. It Industrialized Them
A finance employee wired $25 million in 2024.
He thought he was on a video call with his CFO.
He was talking to deepfakes.
This is not a cybersecurity failure.
This is an operational failure.
The constraint is gone
Fraud used to have limits.
A human had to write the message. Record the voice. Run the operation.
That friction-capped scale.
AI removed it.
Now deception is:
- cheap
- fast
- good enough
Not perfect. Convincing.
That is all it needs.
The economics flipped
Scams used to be volume.
Bad grammar. Obvious signals. Easy to filter.
Now:
Cost of execution: near zero Quality of deception: high enough Scale: unlimited
That breaks every legacy defense model.
Your filters were built for noise.
This is precision.
The target moved
This is not hacking systems.
It is hacking perception.
Attackers don’t break infrastructure. They study it.
They scrape LinkedIn. Map org charts. Reconstruct decision flows.
Then they simulate trust.
A message that sounds right. A voice that feels familiar. A request that fits the moment.
The system is secure. The decision is not.
The exposure is internal
Companies still defend infrastructure.
Firewalls. Identity. Endpoints.
All necessary. All incomplete.
Because the attack surface moved to:
- humans
- workflows
- approvals
AI does not need to break your system.
It needs you to use it.
Approve the payment. Trigger the process. Grant the access.
That is where the loss happens.
Speed became the vulnerability
Everything was optimized for speed.
Instant approvals. Seamless workflows. Automated execution.
That removed friction.
Friction was protection.
Now:
AI creates urgency. Context. Pressure.
Humans respond.
This will not be solved by awareness
Training people to “be careful” does not scale against systems designed to deceive at the machine level.
This is not a people problem.
This is a system design problem.
What needs to change
Trust cannot be implicit anymore.
It has to be engineered.
That means:
- verification at the action level, not the identity level
- multi-step validation for critical decisions
- AI detecting AI
- controlled execution environments
- clear ownership of automated workflows
If AI can act inside your operations, it must be governed like an operator.
Not treated like a tool.
The bottom line
Deloitte projects fraud driven by generative AI could reach $40 billion in the US by 2027.
That number assumes companies keep their current model.
Most will.
The winners will not be the ones who use AI faster.
They will be the ones who control how AI acts inside their systems.
Because in this environment:
The biggest risk is not that AI makes mistakes.
It is that AI makes lies look operational.
If AI is already touching your workflows, approvals, or customer interactions, you are already exposed.
The question is simple:
Do you know where trust is enforced in your operations or are you assuming it exists?
First published in the OG Approved newsletter on 24/03/2026. Read it on Substack or subscribe to get the next one.


