Artificial Intelligence (AI) is transforming how financial institutions tackle fraud, and this shift goes beyond suspicious transaction identification systems. Due to the increasing speed of transactions, banks need to make decisions in much shorter time intervals, deciding whether to block a transaction, analyze it more deeply, or let it proceed.
In Brazil, Pix serves as a prominent example of this change. Carlos Cruz, Head of Data Strategy and Artificial Intelligence at IBM in Latin America, informed Olhar Digital that banks were accustomed to using protection technologies against attacks that did not occur in real time. The new payment system drastically shortened this reaction window, now requiring an integration of data, AI, automation, and transactional monitoring.
A study conducted by the IBM Institute for Business Value (IBV) reinforces this scenario. It revealed that 61% of surveyed executives consider fraud risk detection as the application of AI with the greatest potential for generating business value. This was followed by cybersecurity (52%), and KYC (Know Your Customer) and AML (Anti-Money Laundering), both mentioned by 45%.
This survey was conducted in collaboration with Oxford Economics and involved 100 bank executives responsible for risk, compliance, and validation, located in the United States, United Kingdom, Australia, India, Singapore, and Germany. Participants were equally distributed across the roles of Chief Risk Officer (CRO), Chief Compliance Officer (CCO), and Chief Validation Officer (CVO), and the research took place in May 2025.
The main current challenge lies in converting risk identification into an immediate response from the bank. Previously, AI systems and other tools could only issue alerts after a transaction occurred, allowing for subsequent investigations and actions. However, with instant transactions, this methodology loses some of its effectiveness.
Cruz clarifies that Pix has reduced the time lag between a fraud and the transfer of money, forcing banks to assess risk in a much shorter period. In this context, the institution must balance the ability to detect fraud with the risk of preventing legitimate transactions. The executive points out that this marks a change from the historical use of technology by banks, questioning: 'How do I regulate my alert threshold so that I catch the criminal without affecting the real customer's use of resources?' He emphasizes that in the past, AI was used as a reactive tool, generating alerts after the fact.
Currently, according to Cruz, banks use a combination of data strategies, artificial intelligence, intelligent automation, and continuous monitoring. These technologies can track both customer behavior over time and the path of a transaction before its completion.
The IBM research indicates that fraud detection is seen by executives as the area with the greatest potential for AI, but technological implementation also requires robust mechanisms to validate models and manage risks. Sixty-one percent point to validation as crucial for investments in personnel and skills, while 46% agree on the need for risk control.
To quickly determine if a transaction is suspicious or valid, the bank needs a comprehensive view of who is making the payment. Cruz identifies this as a central challenge for institutions: consolidating the necessary information to form a coherent picture of the so-called client entity. He details that by knowing who the client is to the bank, it becomes easier to discern what might be fraud or misuse of the payment channel or instrument.
The situation becomes complicated when financial data is scattered across various entities and services. Cruz mentions the advancement of Open Finance as an aggravating factor, since information about the same client can be linked to multiple organizations, making it difficult to obtain a complete view of the financial profile.
The study also highlights KYC and AML as the processes most difficult to be transformed by AI: 43% of executives consider them the most challenging, surpassing fraud detection (36%), cybersecurity, credit and pricing, and compliance reporting, all at 33%. Simultaneously, 45% of respondents expect AI to generate a significant transformation in these KYC and AML processes.
For Cruz, a data strategy focused on customer knowledge enables the monitoring of payment methods and the identification of behavioral deviations. The idea is to integrate this information with risk models and investigative technologies, creating a sequence that goes from problem identification to action taking.
The strategy for combating financial crimes does not require the use of a single AI model in all phases. Cruz explains that different technologies can be applied according to the function they are meant to perform. For example, in a real-time authorization phase, resources closer to statistics and deterministic models are used to evaluate patterns and authorize or not the operation. In investigation activities, other types of models are employed.
The distinction, according to the executive, lies in the predictability level of each technology and the function it fulfills in the anti-fraud strategy. In the case of generative AI, which is not deterministic, its responses are less predictable, leading banks to seek a greater understanding of how these technologies operate at each stage of the financial crime fighting process, to know where to best use them in protection and where they are most suitable for investigation.
Cruz adds that generative AI can be valuable in investigations, while deterministic models are better suited for decisions about the nature of a fraud. Furthermore, generative AI tools can be exploited by criminals to refine their attacks, citing the use of these technologies to create deepfakes, voice simulations, and synthetic identities, even during client onboarding.
Control mechanisms are also priorities highlighted by the research. Sixty-three percent of executives consider stress testing simulations as the main risk and compliance priority for scaling AI within the company, while 48% highlight real-time risk controls. The survey also reveals a disparity between the importance given to monitoring and its practical application: only 25% of interviewed professionals state that they consistently apply real-time monitoring in high-risk AI use cases.
In addition to technology, there is a demand for professionals who can combine knowledge of financial fraud, data, technology, legislation, and operations. Cruz observes that this profile is scarce due to the requirement of mastering distinct areas. He describes the situation as an asymmetric race, where criminals seem to always be ahead due to the low cost of certain technologies, while banks struggle to find people capable of managing the composite tripod of technology, data, and the legal and operational aspects.
Cruz concludes that 'from the detection part to you taking action, this conveyor belt has to work in an integrated way.'

