Search the blog
If you run a business bank account, take card payments or pay suppliers by bank transfer, AI is already handling your money. It decides in milliseconds whether a payment looks like you, whether a credit application is approved, and whether the person on the chat window gets a human. Three-quarters of UK financial firms told the Bank of England and the FCA in 2024 that they already use it (Bank of England and FCA, 2024).
Most of that is good news: fraud detection is where AI has the clearest track record. But the same survey found that nearly half of firms admit to only a partial understanding of the AI they run, and a third of it is bought in. This article sets out where AI actually sits in UK banking and payments, what rules apply, what the fraud numbers say, and what a small business should do.
Where AI is actually used today
The Bank of England and FCA survey, published on 21 November 2024, had 118 respondents across six financial-services sectors. 75% of firms already use AI, with a further 10% planning to within three years. The most common use cases were internal-process optimisation (41% of respondents), cybersecurity (37%) and fraud detection (33%). Firms ranked "AML and combating fraud" among the highest current benefits, and a further 36% expect to use AI for customer support, including chatbots, within three years (Bank of England and FCA, 2024).
The degree of automation matters more than the headline. 55% of AI use cases involve some automated decision-making, but only 2% are fully autonomous — a person is almost always in the loop, even if only to review a queue of flagged transactions. Foundation models, the general-purpose models behind chatbots, made up 17% of use cases (Bank of England and FCA, 2024).
| Use case | What the AI does | Evidence | Main risk |
|---|---|---|---|
| Fraud detection and transaction monitoring | Scores every payment in real time against your normal behaviour; holds or challenges outliers | 33% of firms use AI for fraud detection; £1.68 billion of unauthorised fraud prevented in 2025 | False positives blocking real payments; criminals using the same tools |
| Anti-money-laundering (AML) screening | Prioritises alerts so analysts see the risky ones first | "AML and combating fraud" among the top perceived benefits | Opaque and "hidden" models |
| Credit decisions | Scores applications using more data than a traditional scorecard | 55% of use cases have some automated decision-making; 2% fully autonomous | Bias and unexplainable refusals; Consumer Duty "good faith" test |
| Customer-service chatbots | First-line queries and triage | 36% of firms expect to use AI for customer support within three years | Wrong answers to vulnerable customers |
| Open banking and agentic payments | Apps initiate account-to-account payments on your behalf | 351 million open banking payments in 2025; 16.5 million user connections | Authorised payments are what criminals target (APP fraud £576.4 million in 2025) |
The rules that apply — there is no "AI Act" for UK banks
The UK has deliberately not created an AI regulator or an AI rulebook for finance. The government's white paper of 29 March 2023 set out five cross-sector principles — safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress — and asked existing regulators to apply them, arguing that a new AI regulator "would introduce complexity and confusion" (Department for Science, Innovation and Technology, 2023).
The FCA's AI Update of April 2024 mapped those principles onto rules that already exist. Its rules "do not usually mandate or prohibit specific technologies"; what is regulated is the outcome. The two levers that bite are the Consumer Duty and the Senior Managers and Certification Regime (SM&CR). Under Consumer Duty a firm must act in good faith and avoid foreseeable harm, and the FCA says plainly that AI which "embeds or amplifies bias" against some groups of customers may fail that test. Under SM&CR a named senior manager owns the decision to use a model, however it was built (FCA, 2024a). The FCA's current position is blunt: "We do not plan to introduce extra regulations for AI. Instead, we'll rely on existing frameworks" (FCA, 2024b).
In practice, when a bank's model refuses your loan, the bank cannot hide behind the model. Somebody is accountable.
Open banking: the plumbing that AI payments run on
Open banking is the regulated set of interfaces that lets a third-party app read your account or make a payment from it with your consent. It sits under "pay by bank" buttons, under accounting software that pulls your transactions automatically, and under agentic payments, where a software agent initiates payments on your behalf within limits you set.
Open Banking Limited reported 16.5 million user connections by December 2025, up 36% on the year, and 351 million payments in 2025, up 57%; the ecosystem handled 24.0 billion successful API calls (OBL, 2026). Every one of those payments passes through a bank's AI fraud model on the way out.
APP fraud reimbursement: what changed on 7 October 2024
Authorised push payment (APP) fraud is where you are tricked into sending money yourself — a fake supplier invoice, a call from "the bank's fraud team". Because you authorised it, banks historically treated it as your loss.
Since 7 October 2024 the Payment Systems Regulator has required banks to reimburse APP fraud victims, up to a cap of £85,000 and above a £100 excess. The PSR's dashboard, updated on 30 July 2026, shows that in the first 18 months consumers reported around 438,300 claims, 301,500 were in scope, and £316 million — 88% of the money lost — was paid back. In the first quarter of 2026 alone £72.6 million was reimbursed, the highest since the policy began; 82% of claims were closed within five business days (PSR, 2026).
That is a real change for the person who has been scammed. It is not a reduction in fraud.
What the fraud numbers say
UK Finance's 2025 report recorded £1.17 billion stolen in 2024. APP losses fell 2% to £450.7 million, with under 186,000 cases, the lowest since 2020; 70% of them began on online platforms (UK Finance, 2025).
The 2026 report, published on 15 June 2026, reversed the trend. Criminals stole £1.28 billion in 2025, up 4%. APP losses rose 19% to £576.4 million across 248,070 cases, £75.6 million of it from businesses. Unauthorised fraud losses fell 5% to £703.4 million even as cases rose 11% to 3.81 million, and the industry prevented £1.68 billion of unauthorised fraud — largely AI transaction monitoring doing its job. 66% of APP cases started online and 17% by phone, but the phone cases accounted for 28% of the money. UK Finance's summary: criminals are "exploiting advances like AI to industrialise operations" (UK Finance, 2026).
AI is winning on unauthorised fraud (a stolen card, a hijacked login) and losing on authorised fraud, where the weak point is a person being persuaded — increasingly by a cloned voice or convincing video — to press "send". No bank model can stop a payment the customer insists is genuine.
The risks, honestly
- Bias in credit decisions. A model trained on historical lending reproduces historical patterns. The FCA says this may breach Consumer Duty (FCA, 2024a), but spotting it is left to the firm.
- Explainability. 46% of firms have only a partial understanding of the AI they use; 34% claim complete understanding (Bank of England and FCA, 2024). A refusal nobody can explain is one you cannot contest.
- Concentration. A third of use cases are third-party implementations, and the top three providers account for 73% of reported cloud providers, 44% of model providers and 33% of data providers (Bank of England and FCA, 2024). If one has a bad day, many banks do.
- AI on the criminal side. Deepfake voice and video and industrialised scam operations are why APP losses rose 19% in a year when reimbursement was mandatory (UK Finance, 2026).
- Agentic payments. When software pays on your behalf, "did the customer authorise this?" becomes genuinely hard, and the reimbursement rules were not written with that in mind.
What a small business should do
- A convincing voice or video is not proof. Any request to change bank details, pay a new supplier or move money urgently is verified by calling back on a number you already hold. This habit costs nothing. Our phishing post covers the email side.
- Use Confirmation of Payee and read the result. If the name does not match, stop.
- Set limits. Daily payment limits, dual authorisation above a threshold and separate approval for new payees are available in most business banking.
- Know your position on reimbursement. The PSR rules have a cap and an excess, and eligibility depends on who you are and how you paid; ask your bank in writing whether your business is covered before you need to know.
- Treat agentic payments like a new employee with a company card. Small limits, named payees, weekly review, and an off switch.
- Keep the identity layer tight. Most authorised-fraud stories begin with a compromised mailbox. MFA everywhere and a properly configured Microsoft 365 or Google Workspace tenant are the groundwork; see our managed IT support page or get in touch.
AI has made your bank better at catching a stolen card. It has not made you any harder to fool, and the people trying now use the same tools. The controls that matter most are still the boring, human ones.
Sources
- Bank of England and FCA (2024) Artificial intelligence in UK financial services – 2024. London: Bank of England, 21 November. https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024 (accessed 25 August 2026).
- Department for Science, Innovation and Technology (2023) A pro-innovation approach to AI regulation (white paper). London: GOV.UK, 29 March. https://www.gov.uk/government/publications/ai-regulation-a-pro-innovation-approach/white-paper (accessed 25 August 2026).
- FCA (2024a) AI Update. London: Financial Conduct Authority, April. https://www.fca.org.uk/publication/corporate/ai-update.pdf (accessed 25 August 2026).
- FCA (2024b) AI and the FCA: our approach. London: Financial Conduct Authority. https://www.fca.org.uk/firms/innovation/ai-approach (accessed 25 August 2026).
- OBL (2026) Open Banking in 2025: now part of the UK's everyday financial life. Open Banking Limited, 29 January. https://www.openbanking.org.uk/insights/open-banking-in-2025-now-part-of-the-uks-everyday-financial-life/ (accessed 25 August 2026).
- PSR (2026) APP scams reimbursement dashboard. Payment Systems Regulator, updated 30 July. https://www.psr.org.uk/information-for-consumers/app-scams-reimbursement-dashboard/ (accessed 25 August 2026).
- UK Finance (2025) Fraud continues to pose a major threat with over £1 billion stolen in 2024 (press release, Annual Fraud Report 2025). London: UK Finance, 28 May. https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2025-press-release (accessed 25 August 2026).
- UK Finance (2026) Fraud remains a national security threat as criminals steal almost £1.3 billion (press release, Annual Fraud Report 2026). London: UK Finance, 15 June. https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2026-press-release (accessed 25 August 2026).