Schiffrin, A., Marwick, A. E., Sinha, N., Wangnoo, A., Williams, K., Huseynova, E., & Hatfield, A. (2026). Deepfake financial fraud: The global regulation of ai-driven scams. https://doi.org/10.69985/enbp3007
Summary
This policy brief examines the global rise of deepfake-enabled financial fraud and surveys the fragmented regulatory responses across jurisdictions. It maps the “scam ecosystem” — social media platforms, messaging apps, telecoms, banks, crypto exchanges, and money laundering networks — that collectively serve as enabling infrastructure for AI-driven fraud. Its central argument is that effective regulation must shift responsibility away from individual victims and toward the gatekeepers and intermediaries best positioned to prevent harm. Reviewing interventions in the UK, EU, Singapore, China, Taiwan, the US, and elsewhere, the authors identify cross-border coordination gaps and argue that liability-based regimes (including mandatory reimbursement) create stronger prevention incentives than voluntary or victim-focused approaches.
Key Contributions
- One of the first comparative, cross-jurisdictional surveys focused specifically on deepfake-enabled financial fraud regulation.
- Develops a “scam ecosystem” framework mapping enabling actors (platforms, telecoms, banks, launderers) to concrete regulatory intervention points.
- Distinguishes prevention-oriented regulation from liability regimes, arguing the latter is a stronger lever for changing platform behavior.
- Synthesizes scattered evidence on scam losses, victim reporting, and platform ad revenues into a policy-actionable picture.
- Offers concrete recommendations centered on gatekeeper accountability, real-identity ad verification, data-sharing frameworks, and cross-border coordination.
Methods
The brief is a comparative policy review spanning frameworks in the UK, EU, US, Singapore, China, Taiwan, Australia, Indonesia, and many other jurisdictions. It synthesizes investigative journalism (OCCRP, ICIJ, ProPublica, Reuters), industry and government reports (Deloitte, Resemble AI, F-Secure, UNODC, FBI, US State Department), and academic literature on platform governance, fraud detection, SIM-registration regimes, and AI regulation. Illustrative case studies — the Arup deepfake CEO scam, the Brad Pitt romance scam, the Indonesian Prabowo deepfake, and the Chen Zhi/Prince Holding Group indictment — anchor the analysis.
Findings
- Losses are large but underreported: Deloitte projects US generative-AI fraud losses rising from 40B (2025); only ~37% of scam victims across 12 countries report the crime, and just 27% of those go to police.
- Meta serves over 15 billion “high risk” ads per day (~$7B annually) and removes scam ads only when ~95% certain of fraud, while ad personalization steers vulnerable users toward more scam content.
- End-to-end encrypted messaging apps act as downstream infrastructure that evades moderation after initial contact on public platforms; transparency labels (EU AI Act, China’s deep synthesis rules) can be stripped and scams migrate to private channels.
- Mandatory SIM registration has not been shown to reliably reduce scam prevalence and may create new vulnerabilities.
- Emerging liability models — Singapore’s Shared Responsibility Framework and COSMIC, Taiwan’s federated-learning Eagle Eye alliance, and the UK’s mandatory APP fraud reimbursement — distribute responsibility and enable data sharing.
- Southeast Asian “scam compounds” integrate coerced labor with AI translation and voice cloning at industrial scale, while US Section 230 protections effectively export US liability rules globally and limit foreign enforcement reach.
Connections
This brief extends platform-governance scholarship on intermediary accountability and systemic-risk approaches (DSA/AI Act) into the domain of AI-enabled financial harm, complementing work on generative-AI abuse and platform responsibility such as Triedman2025-uy and Vincent_undated-re. Its concern with how platforms enable and profit from harmful synthetic content connects to broader debates on platform data access and governance represented across this register, though most listed papers address political disinformation rather than fraud specifically.
Podcast
A research-radio episode discusses this paper: 🎧 MP3 · Spotify · Apple Podcasts