.png)

Dr. Srinath Sridharan is a Corporate Advisor & Independent Director on Corporate Boards. He is the author of ‘Family and Dhanda’.

Anand Venkatanarayanan is a strategic security and digital policy researcher.
September 15, 2026 at 6:05 AM IST
The first rule in tackling fraud is to accept that there is no hierarchy in who is better. There is always a smarter human on the other side, unseen and unknown, with the tools, tricks and techniques to beat the system. The fraudster may be operating from a laptop, a phone or a network of compromised accounts, but the underlying advantage is the same. (S)He has a single-minded incentive to find a weakness and profit from it.
The institution on the other side has to protect millions of legitimate users while preserving convenience, complying with regulation, managing false positives and explaining every failure. The fraudster needs to succeed just once. The defender has to succeed every time.
This is why the reassurance that fraudsters are getting smarter but “we are also getting smarter” deserves a harder examination. UIDAI chairman Neelkanth Mishra recently, in his speech at a fintech conference, described fraud as a cat-and-mouse game, with fraudsters getting smarter and UIDAI getting smarter in response.
Yet there is a dangerous assumption of symmetry in that formulation. “My AI” being better than “your AI” is a bad starting point for thinking about fraud. Generative AI and agentic AI are putting increasingly powerful tools into the hands of both sides. The fraudster does not need better AI than the defender. He needs one weakness that the defender has not anticipated.
Technology has changed the economics of that search. A fraudster can generate personalised messages, clone voices, fabricate documents, study a target, test multiple approaches and automate the ones that work. He can fail repeatedly at relatively little cost and keep learning from each attempt.
The institution cannot behave that way. A bank that blocks a hundred genuine transactions while catching one fraudulent one has created another problem. A regulator cannot simply permit unlimited surveillance in the name of security. A payment system cannot introduce so much friction that its legitimate users lose confidence in it. The attacker is optimising for one successful breach. The defender is balancing security against the functioning of an entire society.
That is where the idea of a fraud stack becomes useful. Fraud rarely begins and ends with a fraudulent transaction. Personal information may be obtained from one source, used for social engineering somewhere else, combined with a compromised device or credential, routed through a mule account and dispersed through several payment rails before the trail becomes visible. A telecom operator may see one signal, a bank another, a payment platform a third and law enforcement the consequences much later. Each institution can therefore have a functioning control while the fraud succeeds across the connections between them.
The fraudster sees the ecosystem. The defender often sees the institution.
This matters particularly in India because our digital systems have become extraordinarily fast and deeply embedded in everyday life. UPI has made legitimate payments almost frictionless. It has also compressed the window in which a fraudulent transaction can be stopped. When money moves in seconds, detecting it after the event increasingly means reconstructing the crime after the proceeds have moved. Greater use of behavioural intelligence, mule-account detection and real-time information sharing is therefore essential, but the harder task is making intelligence travel across banks, payment companies, telecom operators, platforms and law enforcement with comparable speed.
The human being remains at the centre of this technology story. Fraudsters understand fear, greed, urgency, authority and trust. A cloned voice succeeds because someone believes the person speaking is genuine. An investment scam works because the victim wants the promise to be true. A compromised employee account works because another employee trusts the instruction. AI gives criminals greater reach and personalisation, but the vulnerability it exploits is often profoundly human. Our defences therefore need to understand behaviour as closely as they understand transaction patterns.
There is an old lesson from criminology that becomes more relevant in a digital economy: crime follows opportunity and incentive. The digital world has made both abundant. The fraudster can probe continuously, change tactics and abandon failures without waiting for a committee meeting. Institutions can become prisoners of procurement cycles, compliance processes, quarterly reviews and organisational boundaries. One side is continuously experimenting. The other can become trapped in the rhythm of administration. The issue, therefore, is not simply whether institutions possess sophisticated technology. It is whether they can learn faster than the criminal can adapt.
This should change the questions asked in boardrooms and regulatory offices. Instead of asking whether management has deployed an AI fraud-detection system, ask: if an intelligent and determined fraudster had six months to study our systems, where would he attack us? Which signals would he learn to evade? Which controls depend on assumptions that are no longer valid? Can a suspicious device, identity, phone number and transaction be connected to intelligence sitting somewhere else? And how quickly does intelligence from today’s fraud become protection against tomorrow’s fraud?
The arrival of agentic AI makes those questions more urgent. Once machines can communicate, make decisions or initiate transactions on behalf of humans, the attack surface extends from credentials and transactions to identity, intent and authorisation. A system may authenticate the right user and still execute an action the user never intended. That creates questions that conventional fraud controls were never designed to answer.
The implications extend beyond cybersecurity. Privacy and identity are becoming part of the fraud architecture itself. As more aspects of life become digitally represented, compromised personal information becomes more valuable. A country’s digital sovereignty therefore depends partly on whether it has the capability to secure the systems through which its citizens increasingly live and transact.
We should stop asking whether our AI is smarter than his. The harder question is whether our institutions are becoming harder to defeat.