AI-native fraud eliminates the anomalies investigators rely on, replicating legitimate behavior so convincingly that fraudulent transactions bypass all controls. This exposes an auditability gap, requiring examiners to treat underlying behavioral and system-level data as primary evidence. To respond, fraud examination must shift from retrospective, precedent-based methods to proactive validation.
In traditional fraud cases, investigators expect to see at least one control layer signaling risk in a suspicious financial transaction, whether it’s unusual login behavior or transaction patterns. Fraud examiners can prepare a reconstruction of how fraud likely occurred by piecing together various kinds of documentary evidence and investigating anomalies. But fraud driven by artificial intelligence (AI) operates differently, as it’s designed to conform to expected patterns rather than deviate from them. Reconstruction alone isn’t enough since there isn’t a deviation to identify and reconstruct.
This dynamic is evident in all-green interaction fraud in which an automated system replicates the presence of a human customer. In our previous Fraud Magazine column, we described a sequence of activities associated with an online banking transaction we dubbed the “the perfect session” that consisted of an entirely “green” online interaction, indicating a transfer performed by a human. But the customer never logged in.
In all-green interaction schemes, behavioral monitoring doesn’t trigger an alert because interaction patterns, such as timing, phrasing and workflow, are consistent with historical norms. Transaction monitoring systems observe nothing more than a routine, properly authorized transaction, initiated in a way that conforms to authentication standards and behavior patterns. The evolution from AI-forged documents to AI-forged human presence renders existing investigative methods insufficient. Fraud examiners must adopt new validation frameworks capable of identifying authenticity beyond observable artifacts.

Precedent-driven validation and the auditability gap
The Association of Certified Fraud Examiners’ (ACFE) Code of Professional Standards requires conclusions to be supported by “relevant, reliable and sufficient” evidence. This type of evidence has traditionally been understood to be documentary, observable or externally verifiable artifacts. A precedent-driven model prioritizes what can be seen, reproduced or confirmed.
AI-enabled fraud challenges that assumption. The issue isn’t explainability but whether the signals we observe qualify as evidence. Increasingly, meaningful indicators are nondocumentary, appearing in interaction timing, event sequencing and device-level telemetry rather than in records or confirmations. As a result, current standards can constrain detection by favoring familiar evidence over emerging signals.
This creates an auditability gap. Auditability is the capability of a system to maintain a complete, accurate, tamper-resistant record of all activities, including data changes and user access, ensuring transparency, accountability and compliance while remaining accessible to authorized users. In all-green interaction fraud, monitoring systems produce clean outputs because adversarial inputs satisfy the system assumptions. Clean outputs don’t guarantee authentic inputs.
Closing this gap requires treating primary data such as Human Interface Device (HID) telemetry (data from mice, keyboards and touchscreens), event-to-action latency (time between a system event and user response) and input cadence (variability in typing rhythm) as evidence. Telemetry gives organizations real-time insight into system and network activity, helping them monitor performance, detect anomalies quickly, strengthen security and minimize disruptions. Signals not yet reflected in case law or enforcement are often dismissed as speculation, delaying recognition of real risk. Post-event validation bias determines when risk is acknowledged; precedent-based validation explains why it’s recognized too late.
Retrospective methods and evolving threats
Recognizing that seemingly “perfect” user sessions may signal fraud is an important step for fraud examiners in this AI-driven environment. Understanding where and how these attacks are executed allows fraud examiners to develop new detection approaches and indicators for all-green interaction fraud. This shift becomes clearer when examining how these attacks are executed. Arkose Labs explains that agentic AI attacks operate at the interaction layer rather than the network layer. These attacks target processes such as account registration, login and takeover, API calls, and payment flows. The agent behaves like a legitimate user, but the difference lies in its behavior during interactions, detectable only if organizations have the tools to observe them. Many platforms lack this visibility, creating an opportunity for fraud to succeed.
This challenge can also be understood through the lens of control failure, defined as “the speed at which a control breaks down or becomes ineffective.” Control failure analysis can identify how rapidly failure leads to an unwanted event or maximum impact. Some failures have minimal effect, others can be catastrophic, and the controls designed to prevent them would be considered “genuinely critical.” Critical control failure leads directly to impact with little opportunity for intervention.
The rapid increase in AI-enabled fraud underscores the urgency of this issue. LexisNexis’ 2026 cybercrime report indicates that malicious bots’ ability to impersonate people is accurate enough to bypass advanced behavioral fraud detection systems. Employing advanced tools, cyber criminals’ malicious bot activity surged by 59%, and agentic traffic increased 450% between January and December 2025. By creating a new category of digital interaction, these agents represent a long-term challenge for fraud detection.
Radware Cybersecurity’s 2025 threat alert warned that AI bot impersonations were more likely to target the financial services, e-commerce, ticketing and travel, and healthcare industries. As agentic AI reached an inflection point in 2025, evidence of its capabilities became more pronounced. Anthropic uncovered and disrupted a highly advanced AI-driven cyber espionage campaign in which tools like Claude Code autonomously executed up to 90% of attack operations. The attack prompted the company to strengthen detection systems and develop proactive defenses against large-scale autonomous cyber threats.

Rethinking detection and validation
Current fraud detection frameworks rely on assumptions rooted in human behavior, but those assumptions no longer hold in an AI-driven environment. One key gap lies in the measurable difference between human and machine interaction. Humans require perception and processing time, typically taking at least 200 milliseconds to respond to a prompt. Automated systems can act in less than 10 milliseconds, entirely avoiding interacting with the visual interface. By bypassing the rendering layer and engaging directly with underlying page elements, modern automation operates at speeds and through pathways inaccessible to human users. These differences create detectable signals, but most systems aren’t designed to treat them as evidence.
At the same time, AI-driven fraud is reshaping what systems recognize as “normal.” When synthetic behavior is accepted as legitimate, it becomes embedded in training data and control calibration, gradually redefining the baseline itself, a phenomenon known as baseline drift. AI-generated identities and behavior profiles can now maintain internal consistency across timing, device and interaction patterns, allowing them to blend seamlessly into expected activity. Repeated acceptance of these synthetic patterns results in establishment of a false norm, increasing the likelihood that future fraudulent activity will go undetected.
This shift undermines traditional validation methods, which depend on stable reference points and retrospective analysis. Techniques such as reconstruction, analytics and interviews remain valuable, but they become less reliable when the baseline for comparison is already compromised. In this environment, the absence of anomalies is no longer reassuring. Instead, a system that consistently reports “no issues” may indicate a deeper control failure.
To address this, fraud detection must switch to a proactive model that includes continuous audit simulation, adversarial testing, and the recognition of behavioral and system-level data, such as interaction timing, execution pathways and device telemetry, as legitimate forms of evidence. It also requires expanding documentation and risk assessment frameworks to account for what’s technically possible, not just what has historically been observed. As synthetic behavior continues to evolve, detection standards must evolve with it, shifting from human-centered assumptions to system-level verification.
The hazard of hindsight
All-green interaction fraud inherently alters the meaning of control effectiveness. When malicious activity can fully satisfy system expectations, “passing” controls no longer indicate security; they may indicate risk. The implication is clear: Fraud detection can no longer be limited to anomalies or surface-level validation. It must assess whether systems can be convincingly deceived while appearing to function correctly.
This shift introduces a critical timing risk. AI-driven fraud compresses the window between execution and detection. If recognition continues to depend on precedent, documentation or visible failure, organizations will consistently identify fraud only after losses accumulate. Retrospective validation isn’t a safeguard but a delay mechanism.
This calls for an intentional, immediate response from fraud examiners, who need to expand their definition of evidence to include system-level and behavioral signals, such as interaction timing, execution pathways and device telemetry. Controls must be tested through adversarial simulation, not just evaluated through historical performance. Most importantly, practitioners must interrogate what systems can’t explain, not just what they report.
Waiting for legal or regulatory recognition isn’t a neutral choice. It allows synthetic fraud to expand unchecked. The tools to detect these patterns already exist in measurable differences between human and machine interaction. The task now is to make them operational. Fraud examination is at a turning point. The question is no longer whether synthetic identity fraud can be detected but whether it will be detected in time.
Zachary Kelley is an associate professor of instruction in the Department of Information Systems and Analytics at Texas State University in San Marcos, Texas. Contact him at zachkelley@txstate.edu.
Carolyn Conn, Ph.D., CFE, CPA, is a clinical associate professor in the Department of Accounting at Texas State University in San Marcos, Texas. Contact her at cc31@txstate.edu.