AI AND THE FUTURE OF TREASURY

Building a smarter treasury defense against AI-enabled fraud

The same technology reshaping financial crime is arming treasury teams with tools that can help detect and prevent it

Treasury management is the new cybersecurity frontline

Fraud has moved from breaching systems to exploiting the moments money moves

Financial crime is now just as much a treasury challenge as it is a security one. As threats become more complex, organizations are confronting a new reality: the greatest risk is no longer confined to external breaches alone. It often emerges at the moment of payment initiation, when a legitimate user authorizes a transaction under false pretenses.

This dynamic is not new. For more than a decade, business email compromise (BEC) and impersonation-based fraud have been among the most damaging threats facing organizations, exploiting trust, urgency, and gaps in payment verification rather than technical system failures. What has changed is not the core tactics, but the tools used to execute them. Artificial intelligence (AI) is accelerating this shift.

In the wrong hands, AI enables more sophisticated impersonation and targeted fraud at the point of payment. In the right hands, it equips teams to identify threats earlier and respond with greater precision. In this environment, treasury management is no longer just about moving money; it serves as a critical gatekeeper for risk, governing payment decisions across every touchpoint before funds leave the organization.

AI-enabled deception is everywhere

Generative AI makes scams easier and harder to spot

Recent advances in generative AI and large language models (LLMs) have fundamentally evolved financial crime. What once took careful coordination and technical skill can now be produced with only a few data points and a simple prompt lowering the barrier to entry and allowing bad actors to scale schemes with a level of polish that makes it increasingly difficult to spot.

Attackers can rely on AI tools to produce fraudulent payment requests that closely match legitimate vendor emails and support them with spoofed phone calls that mirror a known contact. They can deploy the same technology to replicate an executive’s voice with enough accuracy to demand a wire transfer. Even the documents used to verify identity or payment changes can be easily falsified with AI, reinforcing the credibility of the request.

All these tactics are only getting easier to produce at scale, making fraudulent schemes appear increasingly realistic, ever-present and unavoidable. 

The bottom-line impact is staggering

AI-related incidents cost victims more than $893 million in 2025 alone.[1] BEC has become the leading avenue for corporate fraud. In controlled studies, AI-assisted phishing campaigns have shown success rates as high as 81%. Without AI, generic phishing emails typically see engagement rates closer to 19% to 28%.[3]

Modern attackers now count on employees to act on seemingly routine requests, initiating fraudulent transactions with valid credentials that are far harder for treasury teams to detect. Impersonation remains the dominant driver: most email-based fraud attempts involve criminals posing as third parties or vendors requesting changes to bank account or payment instructions, and a majority of organizations report imposters posing as senior executives to redirect funds.

Impersonation Drives Business Email Compromise

59%

of organizations received BEC emails from imposters posing as senior executives

79%

of organizations reported vendor-impersonation schemes tied to fraudulent invoices

80%

of fraud via email involved fraudsters impersonating third parties to request changes to account or payment details

AFP 2026 Payments Fraud and Control Survey Report [2]

Shifting to proactive intelligence from reactive monitoring

Existing security measures weren’t built for the AI world

Traditional detection methods fall short when AI-enabled fraud occurs through authenticated user activity. Rule-based controls were designed to block known threats like suspicious locations, unfamiliar devices and abnormal transaction sizes, not legitimate transactions initiated under false pretenses.

But the same technology arming attackers can arm defenders.

Rather than waiting for risk patterns to emerge, treasury teams can use generative AI to detect subtle behavioral anomalies and model potential fraud scenarios before they happen. The shift is from matching known signatures to recognizing what “normal” looks like, and surfacing the small deviations that rules were never written to see.

Spotting normal so you can catch the exception

These capabilities also extend to how organizations manage incoming communication. In controlled testing environments, AI-enabled LLMs have detected malicious intent in phishing emails with up to 75% accuracy, and can recommend actions such as verifying requests through official channels.3

More than a technology upgrade, the shift to proactive intelligence is a necessary evolution in how treasury teams approach risk. Risk mitigation needs to be dynamic, adaptive and forward-looking.

Once these capabilities are embedded within treasury operations rather than layered on top of them, systems can interpret signals consistently and at scale.

Making authentication harder to fake

Why biometrics, device-based methods and call verification matter

Like traditional detection methods, authentication is under new pressure in an AI-enabled world. Technology has made social engineering attacks more convincing, allowing hackers to mimic trusted contacts more believably. Several legacy authentication practices, such as passwords and knowledge-based authentication (KBA) methods like security questions, are inherently “phishable,” making them easier to exploit when credentials are shared or reused. 

As a result, many organizations are moving toward non-phishable methods, including biometrics and device-based authentication. At the same time, authentication now operates in both directions. 

Treasury must verify that requests to move funds are legitimate, especially when AI-generated voices and spoofed calls are imitating banks and vendors. PNC has worked to strengthen outbound call authentication by cryptographically signing calls through major carriers, helping block spoofed communications at the network level. Authentication now functions as an integrated, multi-signal validation process that helps combat AI-enabled fraud.

Payment Channels Used in Common Fraud Schemes[1]

Understanding how the following schemes typically unfold can help your organization better recognize risk and strengthen prevention efforts.

Investment
Fraud

Business
Email

Tech &
Customer Support

Government
Impersonation

 

View accessible version of these charts.

 

Prioritizing digital payments to help strengthen security

Why electronic payments outperform paper checks for AI-driven defense

As AI becomes more central to both fraud and fraud prevention, its effectiveness depends on the quality and structure of the data it receives. The same models used to detect risk are only as strong as the signals they can interpret. In treasury, those signals are generated through payments. However, not all payments are created equal, and some create blind spots scammers can exploit.

Structured data is key

Electronic payments provide enriched, standardized data fields through formats such as ISO 20022. Structured data allows systems to interpret key transaction details, such as beneficiary information and payment context, with far greater precision than legacy free-form inputs. It establishes patterns of normal transaction behavior, making it easier to identify anomalies before funds move.

“We get a lot of data intelligence from digital payment transactions,” explains Josh Del Valle, PNC’s Head of Enterprise Fraud. “Initiation is where the risk is, but once that happens, the flow to the beneficiary is controlled systematically.”

“Now, think about a paper check,” Del Valle continues. “After it’s issued, there’s time to alter the check and create copies before the beneficiary receives it, there’s so much risk in that process.”

Compared to electronic payments, paper checks introduce additional points of vulnerability. They offer limited visibility into the transaction and can be tampered with or redirected without immediate detection. AI can only protect what it can see, and paper checks hide too much. Treasury teams moving from paper to electronic payments cut the surface area for fraud and give banks more context to flag unusual activity.

Developing multi-faceted protection

Layered controls, escalation protocols and human judgment

“Fraud is always a game of multiple levels of controls,” says Del Valle. “Modern authentication is important, including biometrics, multifactor authentications, and methods that are not phishable. Segregation of duty, callbacks, real-time anomaly — that has to be layered into the process, too. When you pair that with proper fraud detection and mitigation services on the backend, you’re creating layers of protection. No one control or two controls will mitigate the risk.” 

Escalation as a built-in safeguard

The hardest fraud to catch is the kind that doesn’t trip a single alarm. The credentials are valid, the payment looks ordinary and the request feels urgent enough that no one slows down to question it. That's the moment a good defense has to interrupt.

Escalation protocols do that work. Before a large or unusual payment goes out, route it through a known internal contact on a trusted channel. If a vendor or bank calls with a payment change, hang up and call back through a verified number. These steps don't slow legitimate payments. They just add a beat of human verification at the moments that matter.


How the controls work together

Authentication, structured payment data and escalation all play different roles in the same defense. None of them work alone, but together they give treasury teams more chances to catch what a single control would miss. Fraud teams, treasury, banks and clients all share that responsibility, and the strongest defenses come from how well they stay aligned. At PNC, fraud prevention is embedded within treasury management to help strengthen both protection and client experience.


3 controls to prioritize

  1. Move to non-phishable authentication. Biometrics and device-based methods over passwords and security questions.
  2. Require a verification step for large or unusual payments. Route them through a known internal contact on a trusted channel before they go out.
  3. Make callback verification policy. When a vendor or bank calls with a payment change, staff verify through a number already on file, not one the caller provides.

Building a more secure future

How PNC treasury management helps build resilient payment operations

Many of today’s fraud risks go undetected by traditional systems. As financial crime becomes more socially engineered and AI-enabled, treasury strategy must evolve toward intelligent, layered defense. The PNC Treasury Management platform helps organizations support this shift, combining technology, governance, and practical safeguards to help clients build secure and resilient payment operations.

Payment Channels Used in Common Fraud Schemes

Chart 1: Investment Fraud

Cryptocurrency:

72%

Wire Transfer / ACH:

19%

Debit Card / Credit Card:

 3%

Peer-to-Peer Transfer:

 4%

Prepaid Card / Gift Card:

 2%

Chart 2: Business Email

Wire Transfer / ACH:

86%

Peer-to-Peer Transfer:

7%

Debit Card / Credit Card:

3%

Prepaid Card / Gift Card:

2%

Cryptocurrency:

2%

Chart 3: Tech & Customer Support

Cryptocurrency:

43%

Wire Transfer / ACH:

20%

Debit Card / Credit Card:

14%

Prepaid Card / Gift Card:

12%

Cash:

11%

Chart 4: Government Impersonation

Cryptocurrency:

40%

Wire Transfer / ACH:

21%

Prepaid Card / Gift Card:

15%

Peer-to-Peer Transfer:

14%

Debit Card / Credit Card:

10%