Banks need to actively test how artificial intelligence (AI) can be used in fraud before criminals exploit weaknesses. While there is optimism about AI's potential to improve financial services—making processes faster, detecting suspicious activity earlier, and helping manage fraud at scale—criminals are also using AI to enhance their own tactics. Unlike financial institutions, which face strict regulations and compliance requirements, fraudsters can experiment freely, fail, and try again. This creates a growing gap between how quickly AI-enabled fraud evolves and how fast banks can adapt their defenses. Many current identity verification methods rely on the assumption that a human is pretending to be someone else. This has led to controls like video liveness checks, voice callbacks, and one-time document verification. These steps add layers of security, making it harder for fraudsters to pass as real. However, generative AI is changing the game. It can create convincing voices, synthetic faces, and even fake identity documents. What used to require specialized skills and effort is now becoming cheaper and easier to produce, making traditional verification methods less reliable. This doesn't mean these controls are obsolete, but it does highlight the need for financial institutions to rethink their assumptions. For example, a liveness check is only useful if it can reliably detect synthetic media, which is constantly evolving. This means the effectiveness of these checks is always shifting and must be continuously tested and updated. Synthetic identity fraud is particularly concerning. Unlike traditional identity theft, where a real person is the victim, synthetic identities are entirely fabricated. Fraudsters can mix real data with invented details to create a seemingly legitimate person. AI can help generate the necessary documentation and digital footprint to make this identity appear credible. Because there is no real person behind it, there's no one to raise the alarm. This makes synthetic identity fraud difficult to detect early, as the fraudster can behave normally, build a financial history, and establish trust before committing fraud. This challenge should be approached similarly to how the industry once dealt with account takeover. Today, there are well-established systems, shared intelligence, and behavioral indicators to detect account takeovers. However, synthetic identity fraud is still in its early stages, and AI could accelerate the problem before the industry is ready to address it. The solution isn't simply to buy another AI-powered fraud product. Instead, banks need to use AI offensively by testing their own systems. Just as security teams have used red teams to test network vulnerabilities, identity and onboarding processes should be similarly tested. This includes checking whether AI-generated voices can pass voice callbacks, synthetic faces can beat liveness checks, and fabricated documents can survive onboarding. Each test should provide lessons that improve security. Relying on one-time verification is no longer sufficient. If a person's identity can be convincingly fabricated at the moment of onboarding, that moment alone is less reassuring. Instead, financial institutions should focus on behavior over time. How an account is used, how a customer interacts with services, and whether activity is consistent with known patterns can provide more reliable signals. These behaviors are harder to fake with a single deepfake or forged document. While regulatory bodies like the Financial Conduct Authority (FCA) play a crucial role, regulations alone won't solve this problem. AI is evolving too quickly for today's rules to anticipate all future fraud techniques. This means financial institutions must take more responsibility. Trust and accountability should be built into AI systems from the start. Firms should test how their systems can be deceived or misused. They need clear leadership when automated decisions go wrong, rather than letting responsibility disappear behind "the algorithm." They must also understand and explain why important decisions are made. This should not become just a compliance exercise. Institutions that treat AI governance as paperwork may meet today's requirements but remain vulnerable to tomorrow's fraud. Those that continuously test their assumptions, challenge their own controls, and build accountability into the technology will be far better prepared.