By FRISS —
While insurers navigate budget cycles, data quality projects, and organizational change management, fraudsters are already deploying AI as a weapon. They are not waiting for governance frameworks, nor are they running pilots. They are running schemes, and the gap between the industry’s preparedness and the sophistication of what is being deployed against it is widening.
The shift from opportunistic to AI-powered fraud is an architectural change rather than a gradual evolution. The tools that fraudsters now have access to do not just make existing schemes faster or more scalable; they make entirely new schemes possible. These include synthetic identities that have never existed, deepfake evidence that is indistinguishable from reality, and autonomous agents that can execute complex fraud operations across multiple digital environments without human intervention at each step. Understanding what this threat actually looks like, not as a future scenario but as a present and accelerating reality, is essential context for the preparedness gap this section exposes.
How Fraudsters Will Weaponize AI
When asked how agentic AI could be weaponized, practitioners identified four primary vectors. Generating synthetic documents or IDs (76%) tops the list, representing a direct attack on the claims verification processes that most insurers still conduct manually or through rules-based checks designed before AI-generated forgeries were possible. Creating deepfake evidence (71%) follows, which includes images, audio, and video fabricated with sufficient fidelity to pass ordinary scrutiny. Automating large-scale application fraud (44%) and coordinating organized fraud networks (33%) complete the picture.
How could agentic AI be weaponized?
- 76% – Generating synthetic documents or IDs
- 71% – Creating deepfake evidence (images, audio, video)
- 44% – Automating large-scale application fraud
- 33% – Coordinating organized fraud networks
The combination of synthetic identities and deepfake evidence is particularly dangerous because these two capabilities attack the same vulnerability from different angles. Synthetic IDs fabricate identity at the point of entry, creating a policyholder who does not exist. Conversely, deepfake evidence fabricates proof at the point of claim, creating documentation of an incident that did not happen. An organized operation combining both can construct an end-to-end fraudulent claim with virtually no traditional evidence trail. A policy could be taken out by someone who never existed, for an incident that never happened, and documented with evidence that was generated rather than recorded.
The only reliable countermeasure is AI-powered detection, and the arithmetic of where the industry stands on that front is not comfortable. With only select organizations having fully deployed AI or ML for fraud detection, the asymmetry between attacker capability and defender readiness is stark.
The Deepfake Gap: Knowing the Threat and Failing to Act on It
The misalignment between the perceived threat and the operational response revealed in this study is one of the most consequential findings in the entire dataset. Fifty-eight percent of practitioners expect deepfakes to become the dominant fraud tool in the near term, yet only 20% treat document and media verification as a critical operational priority. While 40% consider it very important, “important” and “critical” are not the same operationally. An additional 31% consider it “somewhat important”; furthermore, 9% report that media verification is not used at all.
This gap is not born of ignorance; rather, it is born of under-resourcing and organizational inertia, which are the same forces that slow AI adoption more broadly. Practitioners know deepfakes are coming, and many know that media verification is the technical answer. However, knowing and prioritizing are different things. In an environment of budget pressure and competing demands, “very important” tasks routinely lose to “critical” ones. The problem is that this misclassification will become harder to correct as deepfake quality continues to improve and accessibility continues to broaden.
Every claims workflow, across every line of business and from first notice of loss to final settlement, needs to treat media and document authenticity checking as a default rather than an exception. The technology to do this at scale already exists. The window to deploy it before deepfakes become indistinguishable from legitimate evidence is open now, and it will not remain open indefinitely.
The Agentic AI Readiness Gap
The agentic AI preparedness data is the most stark and consequential in this entire study. More than three-quarters (78%) of respondents believe agentic AI is somewhat or very likely to influence insurance fraud within the next two years. That is a near-consensus view among frontline practitioners about a near-term threat. And yet only 2% feel very well prepared to defend against it.
The arithmetic is worth sitting with. The window before agentic AI fraud becomes mainstream is, by practitioners’ own estimation, approximately two years or less. 38% of respondents are currently at or below the ‘not very prepared’ threshold. Even ‘somewhat prepared’ is a precarious position against a threat that may not yet be fully understood in its implications.
Agentic AI is qualitatively different from earlier fraud technology. Earlier generations of fraud tools, even the sophisticated kind, require human direction at each step. A fraudster might use software to generate a fake document, but they still had to decide when and where to submit it. Agentic AI systems can autonomously plan, act, and adapt across multiple digital environments without human direction at each step. They can identify targets, fabricate supporting evidence, navigate submission processes, monitor responses, and adapt their approach based on what they learn without a human operator guiding each action. This is not a faster version of existing fraud. It is a different category of threat, and it demands a response that matches its scale.
Key Takeaway
The threat is not theoretical, and the timeline is not distant. Practitioners themselves estimate the agentic AI inflection point to be two years or less, yet only 2% feel very well prepared. The deepfake and synthetic identity capabilities that will power that threat are already in use today. Awareness without an operational response is not a defense. The window to build a defense is open, but it will not remain open indefinitely.
- Learn more about FRISS in the InsurTech Spotlight.
About FRISS
FRISS is 100% focused on automated fraud, risk and compliance solutions for P&C insurance companies worldwide. Their AI-powered solutions are available for Underwriting, Claims, and SIU, offering support for full end-to-end digital processing. With over 200 implementations across more than 40 countries, FRISS is seen as a trusted advisor, guaranteeing a safe digital transformation for all of their customers, and unique tailoring of solutions to fit their specific needs. Carriers can expect a seamless integration and products that provide a quick time to value (TTV). Now, with $65 Million from their Series B funding round in 2021, FRISS will be able to continue offering their customers state-of-the-art technology to guide carriers through an ever-changing fraud landscape. For more information, please visit FRISS.com.
Source: FRISS


