Kenyan banks have a narrow window to strengthen their defences against a new generation of AI-powered scams that could make financial fraud faster, cheaper and harder to detect.
A new analysis by Boston Consulting Group (BCG) warns that agentic artificial intelligence could enable criminals to automate fraud schemes from start to finish, targeting customers through convincing fake identities, cloned voices, forged documents and highly realistic digital interactions.
The threat is especially significant in Kenya, where mobile money and digital banking have become central to daily transactions for millions of consumers and businesses.
According to TransUnion’s H1 2026 Update: Top Fraud Trends report, fraud across Africa is becoming more organised and increasingly focused on exploiting digital identities.
Although suspected digital fraud rates declined in 2025, TransUnion said criminal activity had become more targeted. In Kenya, the median consumer loss from fraud stood at Ksh108,482.
BCG Nairobi Partner Toivo Hensgens said agentic AI could allow criminals to automate the entire fraud value chain in one of Africa’s most digitally connected financial ecosystems.
“As the cost of running scams and fraud falls dramatically, cybercriminals will be able to launch highly personalised attacks at a scale and speed that has not been possible before,” Hensgens said.
“In a market where mobile money and digital banking are central to everyday life, this could lead to a significant increase in successful scams and fraud.”
Generative AI is already allowing fraudsters to produce convincing deepfakes, impersonate voices and create false documents at scale. The arrival of more capable agentic systems could take that further by allowing scams to run continuously with little or no human intervention.
BCG estimates that AI could reduce the cost of running scams and fraud by 90 per cent or more, allowing attackers to test more tactics, launch larger volumes of attacks and adapt quickly to new bank controls.
The consultancy added that agentic AI capabilities have improved rapidly since 2024 and could, within the next one to two years, be able to conduct scams lasting days or even weeks.
This could put sophisticated fraud tools within reach of individuals and small criminal groups, expanding the pool of potential scammers.
While leading AI models have safeguards designed to limit criminal misuse, BCG noted that open-source models often catch up with frontier capabilities within six to 12 months.
This means banks may have only a relatively short period to prepare for scams that are persistent, personalised and capable of adapting in real time.
Financial scams are already costly worldwide. The Global Anti-Scam Alliance estimates that scams cost consumers and businesses about $442 billion annually.
For banks, the impact extends beyond direct financial losses. Rising fraud cases can drive up customer complaints, disputes, recovery costs, regulatory pressure and reputational damage.
BCG Managing Director and Partner Henok Eyob said Kenya’s digital-finance leadership had created opportunities for inclusion but also increased the urgency of advanced fraud defences.
“Banks that invest now in strengthening their fraud prevention capabilities will be far better placed than those that wait and are forced to respond reactively,” Eyob said.
He said lenders should build systems that identify suspicious behaviour early, intervene in real time, stop high-risk transactions and protect customers against increasingly sophisticated scams.
BCG recommended five measures for banks preparing for the shift:
- Improve threat monitoring by collecting richer behavioural and transaction data, tracking emerging AI capabilities and testing internal fraud controls with adversarial AI tools.
- Use advanced AI models to strengthen scam and fraud-prevention systems before criminal groups gain access to similar capabilities.
- Build operations that can scale quickly during fraud spikes and respond within hours rather than weeks.
- Strengthen coordination with payment providers, telcos, social-media platforms, regulators and law-enforcement agencies.
- Establish “fire breaks”, including surge-response playbooks and temporary controls for high-risk customer journeys during major fraud attacks.
Hensgens said AI could also be used as a defensive tool, helping banks detect threats earlier and respond faster.
“The good news is that AI is also a powerful tool for preventing, detecting and responding rapidly to scams and fraud,” he said.
BCG argued that the transition to agentic fraud may not be gradual, urging Kenyan banks to act before attackers gain a significant advantage.
“Those that delay risk falling behind an adversary that is learning faster than they are,” Eyob said.











