AI in banking and payments now shapes how fraud gets flagged, how credit gets approved, and how fast a payment settles once you press send. None of that matters unless the systems behind it hold up under real regulatory pressure, including instant payment deadlines and the EU AI Act’s compliance dates arriving through 2027.

Fraud detection is one of the clearest proving grounds for that shift. Our piece on artificial intelligence in fraud detection covers the detection mechanics in more depth, including the anomaly models banks use to flag transactions before money moves.
AI-Driven Fraud Detection and Mitigation
Fraud prevention is where AI in banking and payments earns its budget fastest. According to the EY and IIF 15th Global Bank Risk Management Survey, published 24 February 2026 across 101 banks in 31 countries, 61% of chief risk officers report active AI deployment in fraud and financial crime detection. The same survey recorded digital fraud risk rising to 59%, up from 23% a year earlier, which explains the urgency behind that adoption number.
Attackers are not standing still either. Entrust’s 2026 Identity Fraud Report, released 18 November 2025, found that payments firms account for 82% of fraud attempts aimed at the authentication process, the highest share of any sector it tracked. Deepfakes made up one in five biometric fraud attempts in the same study, and injection attacks against verification systems rose 40% year over year. That is the threat picture AI in banking and payments has to keep pace with right now.
The EU AI Act draws a clear line between fraud detection and credit scoring. It lists creditworthiness scoring as high risk, then explicitly excludes “AI systems used for the purpose of detecting financial fraud” from that same high risk category. Fraud tools carry a lighter compliance load than credit scoring models, which sit inside Annex III as high risk, so not every system in the bank faces identical rules.
Credit Scoring and AI-Based Decisions
Credit scoring is the part of AI in banking and payments where the gap between adoption and results is largest. Deloitte’s 2026 banking and capital markets outlook, published 30 October 2025, cites Evident’s finding that only 4 out of 50 banks analyzed in 2025 reported realized return on investment from their AI use cases. That is not a reason to stop investing, but it is a reason to measure results before claiming success.
Data quality is the recurring obstacle behind that gap. More than 90% of bank data users told Deloitte the data they need is often unavailable or takes too long to retrieve, a self-reported figure worth treating as a starting point rather than a precise measurement.
The EY and IIF survey found a similar pattern from the risk management side, with 80% of chief risk officers naming data quality and availability as the primary barrier to AI adoption, and 72% saying AI use in the risk function is still at an early stage. That gap helps explain why credit models often under promise and over report.
Credit scoring also carries the heavier regulatory load. Under the EU AI Act, systems that evaluate a person’s creditworthiness sit inside Annex III as high risk, unlike fraud detection tools, which the Act excludes from that high risk category entirely.
The Digital Omnibus Regulation (EU) 2026/1744, in force from 27 July 2026, pushed the Annex III compliance deadline for that category to 2 December 2027, so banks running AI in banking and payments for credit decisions have a fixed date to work toward, not an open ended one.
Customer Service Chatbots Powered by Generative AI
Generative AI adoption inside banks is already measurable, not hypothetical, and it shows what AI in banking and payments looks like once a tool reaches scale. JPMorganChase’s internal LLM Suite went from zero to 200,000 onboarded users in eight months after its release to eligible employees in summer 2024, and the platform won American Banker’s 2025 Innovation of the Year grand prize in the generative AI category.
Customer facing chatbots sit inside a specific part of the EU AI Act. Article 50 covers AI systems that interact directly with natural persons, which includes the chatbots, AI agents, and avatars used across AI in banking and payments. Generative outputs from those systems must eventually carry effective, machine readable marks, though a grace period pushes that specific marking duty to 2 December 2026 for generative systems already on the market, not to the whole of Article 50.
That marking duty has stated exemptions worth knowing before the deadline. Nothing is required where the AI generated nature of content is obvious to a reasonably informed person, where the output is assistive editing that does not substantially change the original, where the communication is machine to machine, or for artistic and satirical content, which gets a lighter labelling duty instead. Chatbot deployments built on this technology should map against these exemptions now, not after enforcement begins.
Predictive Analytics for Revenue and Risk Optimization
Predictive analytics is where AI in banking and payments moves from defense into forecasting. Bank of America’s CashPro platform, used by more than 35,000 companies worldwide, approved a record 1.2 trillion dollars in payment value in the year to April 2026, an average of 38,000 dollars every second, while app sign ins grew 20% year over year over the same period.
That growth is feeding tools built to score outcomes, not just report them. CashPro Capital Markets Insights produces an AI driven Trade Evaluation Driver score for corporate treasury teams, turning transaction history into a single number a treasurer can act on. It is a working example of that shift: fewer dashboards, more direct recommendations.
None of this replaces judgment. A predictive score still needs a human owner who checks assumptions before a forecast becomes a decision, which keeps AI in banking and payments useful rather than authoritative.
Instant Payments, Verification of Payee, and Real-Time Settlement
Instant payments change what fraud detection has to do. Under Regulation (EU) 2024/886, euro area payment providers have had to receive instant credit transfers since 9 January 2025 and send them since 9 October 2025, with non-euro area member states following by 9 January 2027.
Once a payment clears in seconds and cannot be recalled, the settlement delay that fraud teams used to rely on for manual review disappears. That is why real time scoring inside AI in banking and payments has become a requirement rather than an upgrade.
The regulation’s other major piece is Verification of Payee, and it applies to both standard and instant credit transfers, not just instant ones. The European Commission describes the mechanism plainly: a payee’s name must match the provided IBAN in order for a payment to be processed, which helps prevent mistakes and scams.
The check must be offered free of charge, and the Commission notes that similar tools have already proven effective at reducing certain payment fraud in the Netherlands and the UK for several years.
There is one narrow exception. Article 5c(6) lets payment service providers offer non-consumer users an opt out from verification, but only when they submit multiple payment orders as a single batch, and those users can opt back in at any time. It is not a general exemption for businesses on ordinary transfers.
Article 5c(8) then sets the liability rule that matters most here: if the provider ran the check, warned the customer, and the customer proceeded anyway, liability for a misdirected payment sits with the customer, not the bank.
That combination, a payment that cannot be reversed and a name check that runs before it clears, is why this regulation matters more here than most other rules on this list.
Regulatory Compliance and the EU AI Act
The EU AI Act arrived in stages, and each one matters for a different part of AI in banking and payments. Prohibited practices and AI literacy obligations applied from 2 February 2025. Governance requirements and the general penalty regime followed on 2 August 2025. General applicability, the Article 50 transparency duty, and the Commission’s power to fine general purpose AI model providers under Article 101 all start on 2 August 2026.
Credit scoring got a later date than any of those. Annex III classifies creditworthiness scoring as high risk, but the Digital Omnibus Regulation (EU) 2026/1744, in force from 27 July 2026, pushed that specific obligation to 2 December 2027. Fraud detection AI stays outside Annex III entirely, under the exception written into point 5(b), so the two systems inside the same bank now sit on different compliance timelines for the teams building both.
Penalties back both regulations. AI Act fines run up to 15 million euros or 3% of a company’s total worldwide annual turnover, whichever framework applies to the breach.
The Instant Payments Regulation carries its own separate penalty duty, requiring member states to have set out effective, proportionate and dissuasive sanctions for verification and payee matching failures by 9 April 2025. Treat both timelines as fixed inputs when planning AI in banking and payments compliance work, not as dates to revisit later.
AI Tools for Liquidity and Cash Flow Management
Liquidity management is the other side of the same data problem. Bank of America describes its CashPro Forecasting tool as an AI driven data intelligence tool that automatically integrates account data and applies machine learning to analyze global cash positions, generate accurate forecasts, and deliver actionable insights.
That is a direct description from the bank, not a marketing paraphrase, and it is the clearest published example of AI in banking and payments applied to treasury forecasting rather than fraud or credit.
Adoption elsewhere in risk management is earlier stage. The EY and IIF survey found 41% of chief risk officers already use AI for cyber and operational risk monitoring, a category that overlaps with the operational visibility liquidity teams need. Matching that pace against your own forecasting tools is a reasonable next step before assuming AI in banking and payments has solved the cash visibility problem on its own.
Treasury teams evaluating either tool should ask for the same evidence: a dated source, a named institution, and a specific measured outcome. That standard is missing from most vendor marketing, which is exactly why Bank of America’s own numbers stand out.
Future Applications of Generative AI in Payments
The next step for generative AI in payments is agents that act, not chatbots that only answer. JPMorganChase describes its own direction as extending the same LLM Suite platform already running inside the bank, combining generative AI with workflows to create AI agents that can carry out a series of actions to complete a goal. That is the direction AI in banking and payments is heading: fewer single answers, more multi step tasks completed end to end.
Fraud tactics are evolving in parallel. Entrust’s 2026 Identity Fraud Report found digital forgeries made up 35% of document fraud in 2025, up from a 29% average between 2022 and 2024, even though physical counterfeits still account for a larger 47% share overall. The same report found fraud attempts peak between 2am and 4am UTC, when defenses in many regions are offline, a scheduling detail that argues for continuous AI in banking and payments monitoring rather than business hours review.
Banking technology will keep adding use cases in the next few years. Whichever one comes next, the same standard should apply: a dated result from a named institution, not a percentage with no source attached.
Fraud detection, credit scoring, and instant payment compliance are easier to plan when every claim behind them has a dated source. If you want help turning that evidence into a working roadmap, our AI services team can help you scope where the technology already pays for itself and where it still needs a human check.
You can also read more on AI email replies and lead nurturing for the customer facing side of this work, or browse our broader library of AI tools for business.
Where to Start
Pick one system, not all of them. If fraud tools already run in production, audit them against the EU AI Act’s fraud detection exclusion before assuming they stay exempt. If credit scoring is still on the roadmap, plan for the 2 December 2027 deadline now, while there is time to build the evidence trail regulators will ask for.
Amperly helps banks turn regulatory deadlines into a working plan, not a compliance scramble. If you want a second set of eyes on where your bank stands today, reach out to Amperly and we will help you map the next step.

