The review was first launched on 27 January 2026, but the full Mills Review and feedback summary were published on 6 July.

For banks, payment providers and financial sector boards, one of the most important conclusions is not about AI innovation. It is about fraud, cyber risk and trust. The review states that AI will amplify fraud and cyber risks by 2030, making them faster, cheaper, more scalable and more persuasive. It also notes that these risks will not remain inside one organisation or one channel, but will cut across firms, platforms, telecoms, payment rails, identity systems, technology providers and jurisdictions.

This is especially relevant for payment fraud. Modern payment crime increasingly depends on convincing a person, system or institution that a transaction is legitimate. AI can strengthen that deception. It can make impersonation more credible, generate more realistic messages and scripts, support synthetic identity abuse, automate social engineering, and use stolen personal data in more targeted ways. The Mills Review says respondents specifically highlighted impersonation, synthetic identity abuse and automated social-engineering attacks as areas where AI is making fraud and scams quicker to spread and more persuasive.

The strategic issue is that payment fraud is moving from isolated incidents to a resilience challenge. Criminals no longer need to break every technical control if they can manipulate a customer, employee or automated workflow into approving the payment. In authorised push payment fraud, the user initiates the transfer. In account takeover, the attacker may appear to be the legitimate customer. In synthetic identity fraud, the fraudster may enter the financial system through apparently valid onboarding. AI increases the scale and credibility of each of these paths.

Capco’s US Payments Fraud Survey provides useful supporting evidence. Its survey of 1,000 US consumers found that 49% had experienced attempted payment fraud in the previous two years. The leading concerns were card and card data theft, identity theft, unauthorised purchases and account takeover. The same survey also reported consumer concern about the use of online personal data for impersonation and security-question compromise.

The European payment data shows why this matters beyond consumer inconvenience. The European Central Bank and European Banking Authority reported that fraud losses in the European Economic Area reached €4.2 billion in 2024. Credit transfers accounted for €2.2 billion and card payments for €1.329 billion. For credit transfers, payment service users bore around 85% of total fraud losses, mainly because they were tricked into initiating fraudulent transactions.

That point is central. AI-amplified payment fraud is not only a technical compromise problem. It is also a decision-integrity problem. The question is whether a bank, payment provider or customer can correctly judge identity, intent and authority before money moves.

Instant payments make this more urgent. Faster payment infrastructure reduces the time available to detect, challenge or stop suspicious transfers. The EU’s Instant Payments Regulation addresses part of this risk by requiring payment service providers to offer Verification of Payee. Under the regulation, payers must be able to check whether the payment account identifier and the intended payee name match before initiating a standard or instant credit transfer. The ECB explains that the service informs payers of discrepancies through results such as match, close match or no match.

Verification of Payee is an important control, but it is not a complete fraud strategy. It can reduce misdirected payments and some impersonation scenarios, but it does not solve the full problem of manipulated trust. If a victim has been convinced that the payee is legitimate, or if a synthetic identity has already passed onboarding, a name-check service may reduce risk but not eliminate it.

The Mills Review also points to a future where AI agents act on behalf of consumers and firms. In payments, this creates difficult questions about authorisation, delegation and liability. The review notes that existing payment frameworks assume human approval and are not fully aligned with pre-authorised, bounded and revocable mandates operating over time. It also asks who is responsible when an AI agent causes financial harm, because liability allocation will shape firm behaviour and consumer confidence.

This has direct implications for financial sector governance. Fraud, cybersecurity, identity assurance, payment operations, customer protection and financial crime compliance can no longer be managed as separate domains. AI-amplified payment fraud crosses all of them. A single incident may involve compromised credentials, synthetic identity, social engineering, payment execution, reimbursement, regulatory reporting and customer harm.

CyberKreuz believes financial institutions should treat AI-amplified payment fraud as a board-level resilience topic. The relevant question is no longer only whether fraud detection tools are in place. The stronger question is whether the organisation can recognise manipulated trust before funds leave, and whether it can explain how responsibility, escalation and redress work when AI tools or AI-driven fraud are involved.

The operational response should be layered. Payment providers need stronger identity assurance, continuous behavioural monitoring, risk-based transaction checks, better customer warning design, and internal escalation routes that connect fraud teams with cybersecurity and financial crime functions. They also need clear governance for their own defensive AI systems. The Mills Review warns that poorly governed AI can create false assurance or new blind spots, even while well governed AI can improve detection, triage and disruption.

The regulatory direction is becoming clearer. AI will be used by both financial institutions and criminals. Faster payments will increase the value of early detection. Synthetic identity and impersonation will test onboarding and authentication models. Consumer-facing AI agents will challenge traditional assumptions about approval and liability.

CyberKreuz recommends that banks and payment providers review payment fraud scenarios through a cyber resilience lens. This means testing how the organisation would respond to AI-assisted account takeover, synthetic identity onboarding, deepfake-enabled payment authorisation, manipulated customer transfers and agent-driven payment mistakes. It also means ensuring that Verification of Payee, strong authentication, customer education, fraud analytics and incident response are treated as one connected control environment, not as isolated compliance activities.

AI-amplified payment fraud is becoming a test of financial sector trust. Institutions that focus only on transaction speed and customer convenience may underestimate the risk. Institutions that combine secure payment design, explainable fraud controls, clear accountability and cross-sector intelligence will be better positioned as AI changes how payment decisions are influenced, authorised and executed.