Good habits by consumers can help prevent scams, but U.S. regulations have not kept pace with the rapid development of technology. The FBI’s Internet Crime Complaint Center started tracking complaints involving artificial intelligence (AI) in its 2025 annual report, revealing that Americans reported over 22,000 such cases, with losses totaling around $893 million. Investment fraud accounted for $632 million of that, and individuals over the age of 60 suffered $352 million in losses. According to Deloitte, the actual impact of AI-driven fraud is expected to be much larger, potentially pushing U.S. fraud losses to $40 billion by 2027, up from $12.3 billion in 2023. AI has dramatically changed the cost and effectiveness of scams. For example, creating a cloned voice now requires only a few seconds of audio and inexpensive tools. In one study, people could identify an AI-generated voice only about 60% of the time. Video deepfakes are also becoming more realistic. In 2024, a finance employee at the architecture firm Arup was tricked into sending about $25 million to fraudsters after a video call that used deepfake technology to mimic the chief financial officer and colleagues. Phishing attacks have also evolved, with AI-generated messages that are fluent and personalized using data collected from social media. These messages often include deepfake videos of well-known business figures promoting fake investment opportunities. Cyber insurance company Resilience found that more than 85% of its claims in the first half of 2026 were due to attacks targeting individuals rather than systems. These scams often play on fear and urgency, such as a panicked grandchild or an urgent request from a boss. Stress can narrow a person’s focus and lead them to make quick, emotional decisions instead of thoughtful ones. Fraudsters often use authority figures, like a CFO or a government official, to gain trust, as people are more likely to comply with such figures. AI-enabled theft doesn’t always require direct interaction with the victim. Stolen personal information can be sold for a few dollars on the dark web, and criminals use AI to automate attacks on bank and financial systems, testing credentials and looking for weaknesses faster than any human team. In late 2023, the AI company Anthropic helped stop an espionage campaign where an AI agent performed most of the intrusion work against multiple targets, including financial institutions. Once inside a customer account, fraudsters can take control quickly. Instant payment platforms like Zelle, designed for fast transactions, can be exploited to move money within minutes, making recovery nearly impossible. Banks often use procedures rather than constant vigilance to protect their wire transfer systems. Households can adopt similar strategies. If you receive a suspicious call, hang up and call a number you already know, such as your bank’s fraud hotline. Avoid using numbers provided by the caller. Set up a family code word for emergencies and treat any request for money without that word as fake. Require two people in your household to approve large transfers, and consider waiting 24 hours before making a big payment. This helps counteract the scammer’s use of urgency. Protect your financial accounts by enabling two-factor authentication and never sharing verification codes. These codes act as a second lock on your account. Enable transaction alerts from your bank to detect suspicious activity quickly, and consider a credit freeze to prevent thieves from opening new accounts with stolen data. For older family members, who are particularly vulnerable, it’s important to discuss these steps and ask their bank or brokerage about adding a trusted contact. This can help alert the institution if something goes wrong. If money has already been transferred, contact your bank immediately and ask about recovery options. Then report the scam to the Federal Trade Commission. Federal law is supposed to protect consumers from unauthorized electronic transfers, and regulators have stated that a payment initiated by a fraudster is considered unauthorized even if the victim was tricked into sharing their credentials. However, many victims of instant-payment fraud recover little, as banks often classify such losses as "authorized." The Consumer Financial Protection Bureau sued Zelle’s operator and three major U.S. banks in late 2024 over their handling of fraud claims, but dropped the case in early 2025. New York’s attorney general has since filed a lawsuit, which is moving forward. Zelle’s operator denies the allegations and plans to appeal. In contrast, the U.K. has implemented rules requiring banks to reimburse most scam victims up to £85,000, with the cost shared between the sending and receiving institutions. Since these rules took effect, 88% of eligible scam losses have been returned to victims. An independent evaluation also found that scam losses decreased by about a fifth in the first year of the policy.