Generative AI has changed what insurance fraud costs to commit, and that is reshaping the risk every insurer carries. Convincing fakes that once took a skilled fraudster days can now be produced in minutes and at scale, shifting both the volume of fraud and the defences needed to stop it.
This piece looks at how AI insurance fraud works in practice, why traditional detection struggles against it, and what an effective, lifecycle-wide response looks like for compliance and claims teams.
Let's start with the numbers. Insurance fraud in Belgium is estimated at somewhere between 400 and 800 million euros a year, up to roughly a tenth of everything paid out in non-life claims. Yet in 2024 Assuralia and its members detected just 147.5 million of it, across 7,169 cases. Hold those two figures next to each other, because the distance between them is the real story. Most fraud is never caught. It is estimated, inferred, assumed. And the tools that generative AI has put in fraudsters' hands are designed to widen exactly that gap. This is AI insurance fraud in practice: not a new crime, but an old one made cheap, fast and convincing.
Until recently, fraud was hard to pull off, and that difficulty protected insurers just as much as their fraud checks did. To fake a claim convincingly, someone needed time, real skill, and the nerve to forge evidence good enough to fool an experienced claims handler. Most people could not manage it, or would not risk it. So the number of fake claims stayed low.
Generative AI erases that difficulty. Europol's 2025 Serious and Organised Crime Threat Assessment warns that AI is fundamentally reshaping organised crime, automating and expanding criminal operations and making them harder to detect, with online fraud increasingly AI-driven. Techniques that once required a specialist now require a prompt, which is what turns AI insurance fraud from a rare, artisanal act into a volume problem.
In general, we see four shifts. They surface at different points, from onboarding to the final payout:
The conclusion is simple. AI collapses the cost per attempt, so volume and quality rise at the same time. That combination is what makes AI insurance fraud so hard to contain.
Most insurance fraud detection in the market was built for human speed, human quality fraud. AI insurance fraud is neither. Rules based flags look for the patterns that careless fraudsters leave behind. Static document checks look for the artefacts of a rushed forgery. Synthetic documents and deepfakes are engineered to have neither.
Nor can we lean on human reviewers to close the gap. A 2024 meta analysis of 56 deepfake detection studies found that people average only around 55 percent accuracy, barely better than a coin toss. The evidence a claims handler is trained to trust, a clear photo, a matching document, a familiar voice, is precisely what the technology now counterfeits best.
Fraud signals sit in silos. Onboarding sees one thing, claims sees another, the anti-money-laundering team sees a third, and none of them sees the whole. A synthetic identity that would be obvious if its onboarding behaviour, claims history and payment patterns were read together passes cleanly when each is read alone. It is little wonder that Insurance Europe estimates that detected and undetected fraud together account for around a tenth of all claims expenditure in Europe.
If AI insurance fraud is a lifecycle problem, it cannot be solved with a lifecycle of disconnected checks. The fraud does not respect the boundary between onboarding and claims, so the defence cannot either.
That is the shift AI insurance fraud demands: away from isolated tools that each score a single step, and toward orchestrated insurance fraud analytics that connect identity, behaviour and transaction signals across the whole customer relationship. A deepfake might defeat one check. It is far harder to keep a fabricated identity consistent across every check, over time, while a single risk picture is being assembled from all of them.
For compliance teams rethinking their defences against AI insurance fraud, four principles separate the programmes that will hold up from those that will not:
None of this is happening in a vacuum. The direction of European regulation, from the AML package through to rising supervisory expectations, points toward exactly this posture: continuous, connected, lifecycle-wide monitoring rather than periodic, box-ticking checks. The pressure to modernise defences against AI insurance fraud and the pressure to meet regulatory expectations are, increasingly, the same pressure.
The gap between what is estimated and what is actually detected has always been uncomfortable. In an age where AI insurance fraud can be generated at scale and quality, it stops being an operational statistic and becomes a board-level risk. The insurers who close it will be the ones who stopped treating fraud as a series of checks and started treating it as a single, connected picture.
It is not a new category of claim. It is familiar fraud, staged incidents, inflated or invented losses and false identities, now carried out with generative AI. In practice that means AI-generated damage photos, deepfake video or cloned audio, fabricated supporting documents, and synthetic identities used to take out policies and later claim against them.
Because AI removes the flaws detection has always relied on. Rules-based flags and manual document checks were built to catch the artefacts of rushed, human forgery, and AI-generated evidence does not have them. Research shows people spot deepfakes only about as well as a coin toss, and the same fraud often spans onboarding, policy and claims, so each signal looks clean in isolation.
No single check is enough. The most reliable approach connects identity, behaviour and transaction signals across the full customer lifecycle rather than scoring each step on its own, so a fabricated identity that survives one check still fails against the wider picture.
Less than most teams expect, and in opposite directions. The AI Act deliberately leaves fraud detection alone: Recital 58 states that AI systems used for detecting fraud in the offering of financial services should not be considered high-risk, so the detection models themselves sit outside the Annex III regime. Life and health underwriting is the exception, because risk assessment and pricing for those lines is high-risk, and the Digital Omnibus in force since 27 July 2026 moved that compliance deadline from August 2026 to 2 December 2027. What does apply from 2 August 2026, untouched by the Omnibus, is Article 50: generative systems must mark their output as artificially generated in a machine-readable format, and deployers of deepfakes must disclose them. That helps less than it sounds, since the people fabricating claim evidence are precisely the ones who will not comply.
AMLR is where the obligation actually bites. It is reshaping customer due diligence toward continuous, connected monitoring rather than periodic, box-ticking checks, which is also what defending against AI-era fraud requires. The AI Act shapes how insurers may build detection. AMLR shapes whether that detection is good enough.
Often at the very beginning. Synthetic identities are built to pass KYC and onboarding, then held quietly before a claim is made, which is why identity checks at onboarding and monitoring later in the relationship cannot be treated as separate problems.
Harmoney orchestrates the whole counterparty lifecycle, from onboarding to continuous monitoring, in one auditable flow. Human-in-the-loop, audit-ready, always in control. Want to see how that works for your AML and risk assessment processes? Talk to us or explore the Harmoney platform, or stay in touch via our newsletter ⬇️.