The AI Threat:
Deepfakes, Synthetic IDs and Agentic Fraud

Chapter 3

While insurers navigate budget cycles, data quality projects, and organizational change management, fraudsters are already deploying AI as a weapon. They are not waiting for governance frameworks, nor are they running pilots. They are running schemes, and the gap between the industry's preparedness and the sophistication of what is being deployed against it is widening. 

The shift from opportunistic to AI-powered fraud is an architectural change rather than a gradual evolution. The tools that fraudsters now have access to do not just make existing schemes faster or more scalable; they make entirely new schemes possible. These include synthetic identities that have never existed, deepfake evidence that is indistinguishable from reality, and autonomous agents that can execute complex fraud operations across multiple digital environments without human intervention at each step. Understanding what this threat actually looks like, not as a future scenario but as a present and accelerating reality, is essential context for the preparedness gap this section exposes. 

How Fraudsters Will Weaponize AI 

71% of respondents identify auto insurance as their primary fraud challenge

When asked how agentic AI could be weaponized, practitioners identified four primary vectors. Generating synthetic documents or IDs (76%) tops the list, representing a direct attack on the claims verification processes that most insurers still conduct manually or through rules-based checks designed before AI-generated forgeries were possible. Creating deepfake evidence (71%) follows, which includes images, audio, and video fabricated with sufficient fidelity to pass ordinary scrutiny. Automating large-scale application fraud (44%) and coordinating organized fraud networks (33%) complete the picture. 

The combination of synthetic identities and deepfake evidence is particularly dangerous because these two capabilities attack the same vulnerability from different angles. Synthetic IDs fabricate identity at the point of entry, creating a policyholder who does not exist. Conversely, deepfake evidence fabricates proof at the point of claim, creating documentation of an incident that did not happen. An organized operation combining both can construct an end-to-end fraudulent claim with virtually no traditional evidence trail. A policy could be taken out by someone who never existed, for an incident that never happened, and documented with evidence that was generated rather than recorded. 

The only reliable countermeasure is AI-powered detection, and the arithmetic of where the industry stands on that front is not comfortable. With only select organizations having fully deployed AI or ML for fraud detection, the asymmetry between attacker capability and defender readiness is stark.  

76%

71%

44%

33%

Generating synthetic documents or IDs

Creating deepfake evidence (images, audio, video) 

Automating large-scale application fraud

Coordinating organized fraud networks

The Deepfake Gap: Knowing the Threat and Failing to Act on It 

71% of respondents identify auto insurance as their primary fraud challenge

The misalignment between the perceived threat and the operational response revealed in this study is one of the most consequential findings in the entire dataset. Fifty-eight percent of practitioners expect deepfakes to become the dominant fraud tool in the near term, yet only 20% treat document and media verification as a critical operational priority. While 40% consider it very important, "important" and "critical" are not the same operationally. Furthermore, 9% report that media verification is not used at all. 

This gap is not born of ignorance; rather, it is born of under-resourcing and organizational inertia, which are the same forces that slow AI adoption more broadly. Practitioners know deepfakes are coming, and many know that media verification is the technical answer. However, knowing and prioritizing are different things. In an environment of budget pressure and competing demands, "very important" tasks routinely lose to "critical" ones. The problem is that this misclassification will become harder to correct as deepfake quality continues to improve and accessibility continues to broaden. 

Every claims workflow, across every line of business and from first notice of loss to final settlement, needs to treat media and document authenticity checking as a default rather than an exception. The technology to do this at scale already exists. The window to deploy it before deepfakes become indistinguishable from legitimate evidence is open now, and it will not remain open indefinitely. 

20%

40%

31%

9%

Critical 

Very important 

Somewhat important 

Not used 

The Agentic AI Readiness Gap 

The agentic AI preparedness data is the most stark and consequential in this entire study. 78% of respondents believe agentic AI is somewhat or very likely to influence insurance fraud within the next two years. That is a near-consensus view among frontline practitioners about a near-term threat. And yet only 2% feel very well prepared to defend against it. 

The arithmetic is worth sitting with. The window before agentic AI fraud becomes mainstream is, by practitioners' own estimation, approximately two years or less. 38% of respondents are currently at or below the 'not very prepared' threshold. Even 'somewhat prepared' is a precarious position against a threat that may not yet be fully understood in its implications. 

Agentic AI is qualitatively different from earlier fraud technology. Earlier generations of fraud tools, even the sophisticated kind, require human direction at each step. A fraudster might use software to generate a fake document, but they still had to decide when and where to submit it. Agentic AI systems can autonomously plan, act, and adapt across multiple digital environments without human direction at each step. They can identify targets, fabricate supporting evidence, navigate submission processes, monitor responses, and adapt their approach based on what they learn without a human operator guiding each action. This is not a faster version of existing fraud. It is a different category of threat, and it demands a response that matches its scale. 

2%

29%

29%

31%

7%

Very well prepared

Somewhat prepared

Neutral

Not very prepared

Not prepared at all

Key Takeaway

The threat is not theoretical, and the timeline is not distant. Practitioners themselves estimate the agentic AI inflection point to be two years or less, yet only 2% feel very well prepared. The deepfake and synthetic identity capabilities that will power that threat are already in use today. Awareness without an operational response is not a defense. The window to build a defense is open, but it will not remain open indefinitely. 

Explore the Fraud Report as it unfolds.

New chapters will be released soon, each examining a key development shaping insurance fraud and risk. Explore the chapters available now:

Chapter 4: Collaboration
What the industry must do next