Artificial intelligence is making it easier to do a lot of things. Committing crimes may be one of them.

As AI systems become more capable, the tools available to criminals are changing in ways that go beyond individual attacks becoming more convincing. The bigger shift is economic.

Tasks that once required time, money, and specialized expertise are becoming cheaper and faster to execute. The practical limitations that historically kept certain forms of crime from reaching very large numbers of victims are starting to disappear.

How AI is changing the scale and economics of criminal activity

Crime is getting cheaper. That is the simplest way to describe what AI is doing to the criminal threat landscape.

Phishing emails used to be written one at a time or blasted out in generic batches. Now they can be tailored to individual targets automatically. Deepfakes used to require production expertise. They do not anymore.

One in four data breaches recorded between March 2025 and February 2026 was AI-enabled, up 56% from the year before, CNBC noted. Fake identities used to take time and effort to build. Public data make them faster to construct.

None of these are new crimes. What is new is the cost of running them at scale.

Criminals used to face a hard choice. Run a lot of generic attacks or spend serious time on a carefully targeted one — not both. That choice is disappearing.

“AI doesn’t invent new crimes. It industrializes old ones. Work that used to need a skilled operator now runs at the cost of an API call, so one person can operate at the scale of a whole crew,” Leo Fan, CEO of Cysic, told TheStreet.

The crimes most transformed are the ones built on trust. Social engineering, identity fraud, and financial scams all depend on convincing people to do something they otherwise would not do. AI can make that process cheaper and more convincing at the same time.

The labor argument is equally significant. Criminal operations used to need people at every step: researching targets, writing messages, building fake websites, managing ongoing interactions.

More AI:

AI can now automate portions of that process. What once required a team can run with one person and a model.

“The barrier that protected most victims was never technical sophistication; it was labor, and that barrier is gone,” Michael Heinrich, CEO of 0G Labs, told TheStreet.

Three categories are changing fastest: impersonation fraud, including business email compromise and executive voice cloning, synthetic identity fraud involving people who never existed, and autonomous intrusion, where AI systems plan, adapt, and execute attacks without a human directing each step.

That last category represents the most significant inflection point.

Why defenders are losing ground to AI-enabled attacks

The shift in the economics of crime creates a structural problem for the people trying to stop it. Criminals need one successful attack. Security teams need to prevent all of them.

That asymmetry has always existed, but AI is widening it in ways that cannot simply be addressed by hiring more staff or increasing budgets.

Threat actors can now launch “automated, hyper-personalized campaigns against millions of individuals simultaneously” by scraping public data and using AI to tailor each interaction, Natalie Newson, senior blockchain investigator at CertiK, told TheStreet.

The emergence of crime-as-a-service models, powered by uncensored large language models, also allows less technically skilled actors to execute sophisticated attacks that would previously have required significant expertise.

Law enforcement faces particular difficulty because its tools were built for a different threat environment. AI-powered scams are evolving faster than regulatory and investigative frameworks were designed to handle, Fortune reported.

Traditional digital forensics relies on static artifacts. AI-generated material and deepfakes leave fewer obvious traces, making attribution harder. Jurisdictional boundaries and resource constraints compound the problem.

“Cybersecurity companies will have better luck keeping pace, but the odds are still in favour of attackers who only need to find one vulnerability, while defenders must find them all,” Newson added.

The speed problem is equally structural. AI systems can operate and adapt far faster than human investigators can review evidence and respond.

Security researchers have already documented cases in which AI agents took autonomous, unsanctioned actions during exercises before the organizations running them identified what was happening. The UK AI Security Institute published an incident report in August 2026 cataloging 19 such actions across evaluation runs of frontier AI models, according to CNN.

Heinrich added: “Attackers now operate at inference speed while investigations still run at human review speed. You cannot close a several-orders-of-magnitude speed difference by hiring.”

That creates a fundamental challenge for reactive approaches to security. Defenders primarily identifying threats after an attack has taken place may find that approach less effective as AI systems execute and adapt faster than human review times allow.

Synthetic content adds another layer. Deepfakes and AI-generated communications can be created and modified quickly. Detection systems focused on identifying fake individual pieces of content face a continuous arms race.

Artificial intelligence is making it easier to do a lot of things. Committing crimes may be one of them.

Dowell/Getty Images

How AI and fast digital settlement are compressing the window for investigators

The cryptocurrency industry illustrates how AI-enabled crime can become more urgent when combined with an asset class designed for fast, global settlement.

AI can personalize and automate social engineering to convince a victim to act. Those funds can then cross borders in seconds once that victim does.

Traditional financial fraud sometimes involves delays between deception, bank processing and withdrawal that give compliance systems time to identify suspicious activity. That window can disappear entirely when the transaction settles on a public blockchain in seconds rather than clearing through correspondent banking over days.

The FBI recorded $11.36 billion in digital fraud losses in 2025, up 22% year over year, Yahoo Finance reported. The AI-driven share of those losses is growing.

One significant change is who gets targeted and how. An attacker does not necessarily need to defeat a network’s underlying security. Increasingly sophisticated social engineering can instead persuade the victim to authorize the transaction themselves, using cloned voices, fake executives on synthetic livestreams, or AI-generated investment signals that appear legitimate.

As AI systems are increasingly given authority to execute financial transactions on behalf of users, a new category of risk emerges.

An instruction injected into an AI agent’s decision-making process can redirect funds without any visible sign of an attack. That is not a conventional scam. It is a category that most platforms have not yet developed policies to address.

Why verification may matter more than detection going forward

The dominant approach to defending against fraud has been detection: identifying content, behavior, or transactions as fraudulent after they occur. As AI makes fake content faster to produce and harder to distinguish from genuine material, some experts argue that the approach is insufficient on its own.

“The answer isn’t asking ‘Is this fake?’ It’s demanding that real things prove they’re real,” Fan added.

That reframing points toward verification, provenance, and auditable records as the more durable defense.

Rather than trying to determine whether a specific communication is fraudulent, the goal becomes establishing where it came from, what authorized it and whether the system that executed it can demonstrate what it was instructed to do.

For financial platforms and institutions, that points to infrastructure requirements that go beyond current practice.

Establishing verifiable identity for AI agents, creating auditable records of what those agents were authorized to do, and making that record available to investigators after the fact are all capabilities that most platforms have not yet built.

That transparency already provides one advantage that traditional finance does not: Transactions leave a permanent, auditable trail that investigators can trace even after funds move.

The harder problem is the AI layer operating above that record. If agents move money, communicate with users, and make decisions without leaving verifiable records of their instructions and authorizations, recovering from an attack becomes significantly more difficult, even when the underlying transactions are fully visible.

The gap that AI is opening in the security landscape is not simply that criminals have access to better tools.

It’s that the systems defenders rely on were built for a world where attacks required human operators at each step, not one where the criminal operation can plan, adapt, and execute faster than any human review process can respond.

Related: Goldman Sachs sends strong message on AI and jobs