AI-driven voice authentication tools must constantly be updated as fraudsters coordinate new workarounds and financial losses continue to grow, experts say.
AI-enabled scams including voice cloning, deepfake videos and fake identification documents accounted for nearly $893 million in reported losses in 2025, according to an FBI’s Internet Crime Complaint Center report published on April 6.
Voice authentication tools rely on machine learning to identify anomalies within voice samples, which signal if a voice was generated by AI.
But fraudsters can smooth out these anomalies to bypass the technology, Andre Kassis, a cybersecurity researcher at the University of Waterloo in Ontario, Canada, told FinAi News.
It is “a cat-and-mouse game,” Kassis said. “You have one side trying to outsmart the other.”
OpenAI chief executive Sam Altman, speaking at a Federal Reserve conference last month, warned of a “significant impending fraud crisis” in banking caused by voice deepfakes that bypass authentication checks.
“A thing that terrifies me is apparently there are still some financial institutions that will accept the voiceprint as authentication,” Altman said at the conference. “That is a crazy thing to still be doing. AI has fully defeated that.”
Just this week, on Aug. 5, financial services firms on Wall Street Point72 Asset Management, Two Sigma Investments and Citadel faced deepfake hackers using AI voice-cloning technology, Bloomberg reported.
Demanding watermarking
To combat losses and put pressure on bad actors, government forces are pushing LLM providers to place watermarks on audio created with AI.
Watermarking involves embedding hidden but traceable signals that show a voice was made by AI, Kassis said.
For example, the EU AI Act Article 50 that went into effect on Aug. 2 requires LLM providers to add watermarking to any AI-generated content including voice, video, text and images.
But that only works if fraudsters use watermarked LLMs, said Dominic Forrest, deepfake detection provider iProov’s chief technology officer. Scam artists often use open-source models or those available on the dark web.
As part of a joint research project, researchers from cybersecurity firms SentinelOne and Censys scanned internet-accessible open-source LLM deployments over 293 days, between March and December of 2025, and found widespread use of open-source models such as Meta’s Llama and Google’s Gemma for criminal purposes, as of a SentinelOne report from Jan. 2026.
Open-source models also are used by fraudsters to remove watermarks, according to a March 2025 study led by Yizhu Wen at Michigan State University.
Detecting deepfakes
While governments are beginning to regulate voice fraud attempts, fintechs continue adopting voice authentication technology.
In June, tech provider Eltropy teamed with fraud prevention companies Illuma, IDgo and Pindrop to provide their credit union customers with voice authentication technology, Saahil Kamath, head of AI at Eltropy, an agentic AI platform, told FinAi News.
Here’s how the three providers work together:
- Illuma provides passive voice security;
- Pindrop adds authentication intelligence across voice interactions; and
- IDgo offers device-based authentication.
Eltropy, whose clients include InTouch Credit Union and Spokane Teachers Credit Union, now says it can detect voice deepfakes with 99% accuracy, Kamath said.
PINs and security questions are no longer effective at banks, Kent Lugrand, chief executive at InTouch Credit Union told FinAi News.
“Today’s ‘fraud fight’ necessitates you use AI to combat AI,” Lugrand added.
iProov builds its own LLMs, which allows the company to black box their system and quickly adjust to new types of fraud, iProov’s Forrest told FinAi News.
Black boxing is when the internal verification system isn’t shown to users. This prevents fraudsters from knowing at what stage of approval they were rejected.
The 20 models iProov runs within its most robust product are updated multiple times a week, Forrest said.
However, black boxing data does not provide full security, the University of Waterloo’s Kassis said.
He said his own research bypassed commercial voice authentication security systems.
“This is a threat vector that I find very hard to mitigate against nowadays or even the future,” Kassis said.
Call retention takes priority
Financial service providers still use the tech in hopes of a smooth customer experience and better call retention, Kamath said.
“It makes [calls] really frictionless because the second you detect [a customer’s] voice, you can just unlock their account and then give all the details,” Kamath said. “But of course that also opens up some door to fraud.”
Before collaborating with Pindrop, Illuma and IDgo, Kamath’s team noticed that when call center agents asked customers to verify their member numbers or the last four digits of their credit cards, 30% to 40% abandoned the calls.
Eltropy wanted a more seamless verification system, he said.
The setup is simple: Banks collect a “voiceprint” from their customers, then record a snippet of their speech. Then that voiceprint is used to match the caller’s voice with the sample, eliminating the need for other forms of authentication, Kamath said.
Comprehensive approach
Kassis said companies shouldn’t wait until disaster strikes to focus on security.
“I don’t want to be very pessimistic … but for me I’m just an old-school guy. I just use my password and the stuff that I can trust and rely on,” he said, adding that passwords and two-factor authentication still remain the safest options.
Register here for the FinAi Lending Summit, set for Oct. 7-8 in Las Vegas. This inaugural event will include speakers from Fifth Third and Capital One as well as a fireside chat with Piermont Bank founder and Chief Executive Wendy Cai-Lee.





