Agentic AI could cut the cost of running scams by 90 percent. Kenyan banks should treat that as an automation problem
The next fraud problem is not simply better phishing copy. Autonomous agents could make social engineering cheaper to run at enormous scale, forcing financial institutions to automate defence too.

Boston Consulting Group has a warning for financial institutions: the next step in AI-enabled fraud is not simply better fake messages.
It is automation.
BCG estimates that could reduce the operating cost of scams and fraud by 90 percent or more within the next two years, potentially contributing to a twofold or greater increase in successful activity.
The forecast is global.
The implications are particularly relevant in Kenya, where mobile money, messaging, digital lending and online banking can move money from conversation to transaction very quickly.
A scammer who once managed a small number of victims manually may eventually supervise automated systems handling many more interactions.
That changes the economics of crime.
Generative AI already made deception cheaper
Current generative AI can lower the cost of creating:
- Convincing messages
- Synthetic identities
- Fake documents
- Cloned voices
- Personalised social engineering
The criminal still needs to coordinate the operation.
Someone selects targets, responds to victims, changes the story when necessary and decides when to ask for money.
Agentic AI can automate more of that workflow.
An agent is designed to pursue a goal across multiple steps.
It can use tools, monitor outcomes and decide what to do next.
That is what makes the threat different.
Industrialisation is the useful mental model
Fraud has always been a business process.
Attackers need:
- Leads
- Scripts
- Communication
- Payment collection
- Account management
- Adaptation
Automation lowers labour cost.
If AI can perform more of these tasks simultaneously, criminal groups can test more approaches against more people.
Most attempts can fail while the operation remains profitable.
This is why a 90 percent cost reduction matters more than the fact that an can write a persuasive message.
Scale changes the defence problem.
Why Kenya is exposed
Kenya's digital-finance success creates enormous convenience.
It also compresses the distance between deception and money movement.
A victim can receive a message and transfer funds minutes later.
Social-engineering themes often exploit:
- Bank accounts
- Online jobs
- Investment schemes
- Deliveries
- Family emergencies
- Customer support
Agentic systems could personalise these narratives using information available online.
The goal for defenders is to recognise risk before the transaction becomes irreversible.
Banks cannot rely only on transaction monitoring
Traditional fraud systems look at money movement.
By the time an unusual payment appears, the psychological attack may already have succeeded.
Financial institutions need earlier risk signals.
These can include:
- Device changes
- Account behaviour
- New beneficiaries
- Unusual transaction amounts
- Transaction velocity
- Authentication anomalies
The bank does not need to read a customer's private WhatsApp conversation to improve defence.
It can identify risk around the financial action itself.
A first-time beneficiary plus unusual amount plus device anomaly may justify an additional confirmation step.
AI will fight AI
BCG's warning has a useful counterpoint.
The same technology can strengthen defence.
AI systems can:
- Detect suspicious patterns
- Prioritise alerts
- Recognise behavioural anomalies
- Support investigators
- Communicate contextual warnings
- Identify coordinated campaigns
Banks have an advantage because they see enormous volumes of legitimate transaction behaviour.
The challenge is operational speed.
A fraud model updated every six months is fighting attackers who can change tactics overnight.
Customer warnings need to become contextual
Banks and mobile-money providers often send generic warnings telling users never to share a PIN.
That remains useful.
It is not enough.
A modern warning can appear when risk is relevant.
For example, a bank might tell the user that the recipient is new and the payment is unusual, then ask whether the request was independently verified.
The system should not accuse the customer.
It should introduce friction at the moment friction has value.
Good security is sometimes the art of making one risky action slightly slower.
The danger of blocking legitimate users
Aggressive fraud controls can hurt real customers.
A small business making an unusual payment may be perfectly legitimate.
A family remittance can look statistically strange.
False positives can lock people out of essential money.
AI defence therefore needs:
- Human escalation
- Clear reasons
- Fast appeal
- Proportionate controls
The goal is not maximum blocking.
It is maximum reduction in fraud with minimum harm to legitimate activity.
Ecosystem coordination matters
A scam can cross several systems:
- Social platform
- Telecom network
- Bank or mobile-money account
- Recipient account
- Cash-out channel
No single participant sees the entire attack.
Kenya's response needs coordination among:
- Banks
- Telcos
- Fintechs
- Regulators
- Platforms
- Law enforcement
Privacy safeguards should remain intact.
Collaboration can focus on risk signals and patterns rather than unrestricted sharing of personal data.
The tecMAMBO take
The phrase "AI scam" can make the problem sound futuristic.
The core issue is painfully ordinary.
Automation makes labour cheaper.
When criminal labour becomes cheaper, attackers can target more people and experiment faster.
Kenya should prepare before autonomous scam operations become ordinary rather than waiting for a dramatic national incident.
The country already built one of the world's most sophisticated everyday digital-money environments.
Its fraud defences now need to become equally programmable.
Sources
Ask MAMBO
Have a plain-English question about this topic? Send it in and we may answer it in a future guide.
Ask a question

