AI has not invented fraud — but it is making old scams faster, cheaper and more convincing. Criminals can now imitate a familiar voice, generate a realistic video of a public figure, create fake customer reviews, write polished messages and build convincing websites at scale.
The safest response is not to become an expert at spotting every deepfake. It is to use a repeatable process: recognise the pressure, verify the identity or claim through an independent route, and respond before more harm is done.
What counts as an AI-enabled scam?
An AI-enabled scam is a fraud attempt where artificial intelligence helps create, personalise or automate part of the deception. The underlying fraud may be familiar — investment fraud, impersonation, romance fraud, shopping fraud or phishing — but AI can make the content look and sound more believable.
- Voice cloning: fake audio that imitates a relative, colleague or trusted person.
- Deepfake video: synthetic or manipulated video used for fake endorsements, impersonation or emotional pressure.
- AI-generated messages: highly polished phishing, romance or support messages written at scale.
- Synthetic identities: fake faces, profiles and biographies used to build trust.
- Fake reviews and adverts: realistic testimonials, customer images or endorsements that may never have existed.
City of London Police says victim intelligence shows criminals are already using AI-generated video, cloned voices, manipulated images, fake websites and chatbots to make fraud attempts appear more authentic. Investment fraud is one of the areas where AI-generated endorsements are being reported. Read the police assessment.
The five warning signs to slow down for
1. Urgency
The message creates a reason you must act immediately: an emergency, a payment deadline, a security incident, a limited investment opportunity or a loved one in trouble.
2. A request for money, credentials or secrecy
Be cautious when someone asks for a bank transfer, gift cards, cryptocurrency, one-time passcodes, passwords, remote access to a device or asks you not to discuss the situation with anyone else.
3. Familiarity that feels unusually convincing
A caller may know names, workplaces, family details or recent events. Public social-media information and breached data can make impersonation much more persuasive. A familiar voice or face is no longer enough on its own to prove identity.
4. An unexpected change of channel or payment method
A supplier suddenly changes bank details. A family member messages from a new number. A supposed investment adviser moves you onto WhatsApp or Telegram. Treat changes in channel or payment instructions as a reason to verify independently.
5. Pressure not to verify
Legitimate organisations should tolerate reasonable verification. A fraudster benefits when you remain inside the conversation they control.
Voice cloning: what should families do?
Report Fraud warns that criminals use AI voice cloning to impersonate someone the victim knows and create an urgent reason to send money. Its guidance recommends agreeing a private safe phrase with close family or friends and, if suspicious, hanging up and calling back using a number you already know is genuine. See the official phone-fraud guidance.
A useful family rule is: voice is evidence of familiarity, not proof of identity. If a request involves money, passwords, sensitive information or an emergency, verify through a second channel.
Deepfake investment adverts and celebrity endorsements
AI-generated videos can make it appear that a well-known person is promoting an investment or product. UK fraud reporting has documented victims responding to apparently credible public-figure endorsements that were later linked to fraudulent investment platforms.
Do not use the advert itself as your route to verification. Search independently for the company, check the relevant regulator where applicable, and be suspicious of guaranteed returns, unusual payment methods and pressure to invest quickly.
How to verify before you trust
Community Smart Hub uses a simple verification principle: move outside the content you are being asked to trust.
- Stop. Do not act while under pressure.
- Check the source. Who sent this, and did you expect it?
- Use an independent route. Call the person or organisation using contact details you already know or find independently.
- Search for corroboration. Look for the same claim on official websites or trusted reporting.
- Check provenance where available. Content Credentials or other provenance signals can provide useful evidence about origin, but absence of a signal does not prove something is fake.
- Decide based on the whole evidence. No single AI detector should be treated as a truth machine.
For a deeper verification process, see Verify & Trust. To understand how provenance and multiple signals work together, read The Five-Layer Shield.
If you think you have already been scammed
- Contact your bank immediately if money or payment details are involved.
- Change compromised passwords and enable multi-factor authentication.
- Preserve screenshots, messages, usernames, phone numbers and transaction details.
- Stop further contact with the suspected fraudster.
- Use the appropriate official reporting route.
Community Smart Hub has collected the main UK routes on our Get Help page. You can also work through the immediate steps in Protect & Respond.
Why AI scam detection is not enough
The UK Government’s 2026–2029 Fraud Strategy identifies generative AI deepfakes impersonating trusted people and organisations as a growing threat. Government work on deepfake detection is therefore focused on evaluating detection capabilities against emerging real-world techniques rather than assuming one detector will solve the problem. Read the Fraud Strategy.
That is why Community Smart Hub teaches behaviour as well as technology. A detector may be useful evidence. It should not replace source checking, independent verification, provenance, account security and human judgement.
A simple family rule: STOP — VERIFY — RESPOND
STOP: Slow down when there is urgency, fear, secrecy or money involved.
VERIFY: Leave the message, call or advert and check through a separate trusted route.
RESPOND: Protect accounts, preserve evidence and report through official channels.
Frequently asked questions
Can I tell an AI scam just by looking or listening?
Not reliably. Synthetic media is improving quickly, and genuine media can also look unusual after compression or editing. Focus on the claim, source, context and independent verification rather than visual or audio clues alone.
Does a cloned voice mean the criminal hacked my relative’s phone?
Not necessarily. A voice sample may come from publicly available audio, social media or other recordings. Treat an unexpected request as unverified even when the voice sounds convincing.
What should I do if a family member calls asking urgently for money?
End the call and contact them using a number you already know. A private family safe phrase can add another verification step, but it should not be shared publicly.
Can an AI detector prove a video is fake?
No detector is universally reliable. Treat detection as one signal among several. Source, context, provenance and corroboration remain essential.
Continue learning: Scams & Deception · Verify & Trust · Protect & Respond · Get Help
Sources include Report Fraud / City of London Police and the UK Government Fraud Strategy 2026–2029. Guidance checked September 2026.




