Home / Insights / AI risk, safety and trust

AI risk, safety and trust

AI Did Not Create Scams. It Industrialized Them

Olivier GomezOlivier Gomez (OG), 3 min read

A finance employee wired $25 million in 2024.

He thought he was on a video call with his CFO.

He was talking to deepfakes.

This is not a cybersecurity failure.

This is an operational failure.


The constraint is gone

Fraud used to have limits.

A human had to write the message. Record the voice. Run the operation.

That friction-capped scale.

AI removed it.

Now deception is:

  • cheap
  • fast
  • good enough

Not perfect. Convincing.

That is all it needs.


The economics flipped

Scams used to be volume.

Bad grammar. Obvious signals. Easy to filter.

Now:

Cost of execution: near zero Quality of deception: high enough Scale: unlimited

That breaks every legacy defense model.

Your filters were built for noise.

This is precision.


The target moved

This is not hacking systems.

It is hacking perception.

Attackers don’t break infrastructure. They study it.

They scrape LinkedIn. Map org charts. Reconstruct decision flows.

Then they simulate trust.

A message that sounds right. A voice that feels familiar. A request that fits the moment.

The system is secure. The decision is not.


The exposure is internal

Companies still defend infrastructure.

Firewalls. Identity. Endpoints.

All necessary. All incomplete.

Because the attack surface moved to:

  • humans
  • workflows
  • approvals

AI does not need to break your system.

It needs you to use it.

Approve the payment. Trigger the process. Grant the access.

That is where the loss happens.


Speed became the vulnerability

Everything was optimized for speed.

Instant approvals. Seamless workflows. Automated execution.

That removed friction.

Friction was protection.

Now:

AI creates urgency. Context. Pressure.

Humans respond.


This will not be solved by awareness

Training people to “be careful” does not scale against systems designed to deceive at the machine level.

This is not a people problem.

This is a system design problem.


What needs to change

Trust cannot be implicit anymore.

It has to be engineered.

That means:

  • verification at the action level, not the identity level
  • multi-step validation for critical decisions
  • AI detecting AI
  • controlled execution environments
  • clear ownership of automated workflows

If AI can act inside your operations, it must be governed like an operator.

Not treated like a tool.


The bottom line

Deloitte projects fraud driven by generative AI could reach $40 billion in the US by 2027.

That number assumes companies keep their current model.

Most will.

The winners will not be the ones who use AI faster.

They will be the ones who control how AI acts inside their systems.

Because in this environment:

The biggest risk is not that AI makes mistakes.

It is that AI makes lies look operational.


If AI is already touching your workflows, approvals, or customer interactions, you are already exposed.

The question is simple:

Do you know where trust is enforced in your operations or are you assuming it exists?

First published in the OG Approved newsletter on 24/03/2026. Read it on Substack or subscribe to get the next one.