AI Invoice Fraud 2026: Protect Your AP Team
For years, the advice for spotting fraudulent invoices was simple: look for typos, check the grammar, verify the email domain. That advice is now obsolete. Artificial intelligence has erased the competence barrier that once separated sophisticated fraudsters from amateurs, and AP teams are bearing the consequences.
The 2026 AFP Payments Fraud and Control Survey found that 76% of US organizations experienced attempted or actual payments fraud in 2025. Business email compromise — the category that encompasses most AI-assisted invoice fraud — hit 74% of respondents. The Journal of Accountancy called the current environment "the most dangerous threat landscape" for AP and AR functions in recent memory.
Understanding what has changed, and what controls still work, is now a core competency for anyone who approves payments.
What AI Has Changed About Invoice Fraud
The Competence Barrier Is Gone
Until recently, creating a convincing fraudulent invoice required skill. You needed to know how to use design software, understand how real invoices are formatted, and write persuasive business English. Most fraudsters lacked one or more of these capabilities, which limited the scale and quality of attacks.
Large language models have eliminated that barrier. A fraudster with a laptop can now generate a grammatically flawless, context-aware email impersonating a CFO, complete with accurate details about the company, its vendors, and recent transactions. They can produce a professional-looking invoice with the correct logo, address format, and payment terms. They can create a fake vendor website, a fake W-9, and fake articles of incorporation — all in minutes.
"What AI has done is dramatically lower the competence threshold," Jonathan Marks, a principal in BDO's Forensic Investigations practice, told the Journal of Accountancy. "Anyone with a laptop or an iPhone or an Android can run these scams now."
Complete Fake Vendor Identities
The most sophisticated attacks no longer involve a single fraudulent email. Fraudsters are now building complete ghost vendor identities: a professional website, a working phone number answered by a voice AI bot, a fake W-9 with a plausible EIN, and a history of email correspondence that appears legitimate.
When your AP team searches for the vendor online, they find a real-looking website. When they call the number on the invoice, they reach what sounds like a real person. The entire identity is synthetic, generated and maintained by AI.
This is why the traditional vendor verification steps — Google the company, call the number on the invoice — are no longer sufficient. The number on the invoice is the fraudster's number. The website is the fraudster's website.
AI-Assisted Internal Fraud
The threat is not only external. Forensic investigators report a rise in AI-assisted internal fraud, particularly expense fraud. Free-to-use tools can generate realistic receipts with any vendor name, amount, and date. Mainstream AI services can edit images to make them look weathered and photorealistic. The gatekeeping effect that once made document forgery difficult has been removed.
Internal fraudsters are also using AI to identify targets within their own organizations — scanning vendor lists for companies with multiple locations that might be impersonated, or identifying payment processes with weak controls.
The Statistics AP Teams Need to Know
The scale of the problem is documented in the 2026 data:
The gap between the 76% experiencing fraud and the 17% using AI defenses is the most important number in that list. Most organizations are fighting AI-assisted fraud with manual controls designed for a pre-AI world.
What Controls Still Work
The good news is that the most effective controls against AI-assisted fraud are not technological. They are procedural, and they work because they require out-of-band verification that AI cannot fake.
Independent Callback Verification
The single most effective control against BEC and vendor impersonation is an independent callback: before processing any payment instruction change — a new bank account number, a new remittance address, a new contact — call the vendor at a number stored in your vendor master file, not a number provided in the change request.
This control works because it requires the fraudster to have compromised your vendor master file, not just your email. It is low-cost, requires no technology, and directly addresses the false-pretenses scenarios that account for most AI-assisted fraud.
Dual Authorization on Payment Changes
No single employee should be able to change a vendor's payment details and also approve a payment to that vendor. This is segregation of duties applied to the specific risk of payment instruction fraud. When two people must independently verify a change before it takes effect, the social engineering attack must compromise two people simultaneously — a much harder task.
Vendor Master File Hygiene
A clean vendor master file is your first line of defense against ghost vendor schemes. Regularly audit your vendor list for: vendors with P.O. box addresses and no physical address on file, multiple vendors sharing the same bank account number, vendors added without a completed W-9 or EIN verification, and vendors with no payment activity in the past 12 months.
Each of these patterns is a potential indicator of a fraudulent vendor record. Catching them before a payment is made is far cheaper than recovering funds after.
Tighten the New Vendor Onboarding Process
AI makes it easier to create fake vendor identities, but it cannot fake a vendor that has been properly verified before being added to your system. A rigorous onboarding process — collecting a W-9, verifying the EIN against IRS records, confirming the business address through a source other than the vendor's own submission, and requiring management approval before the first payment — is the most durable defense against synthetic vendor identities.
Train Your Team on What Modern Fraud Looks Like
The old training — "look for typos, check the grammar" — is counterproductive now because it creates false confidence. Modern BEC emails are grammatically flawless and contextually accurate. Training should focus on the process controls: always verify payment instruction changes through an independent channel, never use contact information provided in the change request, and escalate any request that creates urgency or pressure to bypass normal procedures.
What AI Defenses Can Add
The 17% of organizations using AI to combat fraud report real benefits: faster detection of near-duplicate invoices, real-time flagging of unusual payment patterns, and better identification of deepfake documents. AI-powered AP automation can compare every invoice against your vendor master file, flag amounts that deviate from historical patterns, and identify invoices that share formatting characteristics with known fraudulent documents.
These tools are valuable, but they are not a replacement for procedural controls. AI fraud detection is a cat-and-mouse game — fraudsters adapt to detection patterns. The procedural controls described above work because they require human verification through channels that AI cannot compromise.
The Audit Trail as a Deterrent
One underappreciated benefit of strong internal controls is their deterrent effect on internal fraud. When employees know that every vendor addition, every payment instruction change, and every payment approval is logged and reviewable, the temptation to attempt fraud decreases. An immutable audit trail that records who did what and when is both a detection tool and a prevention tool.
The same trail is what external auditors, your bank, and law enforcement will ask for if fraud does occur. Building it now is both a fraud prevention investment and an insurance policy.
The Bottom Line
AI has made invoice fraud cheaper, faster, and more convincing. The 2026 AFP data makes clear that this is not a theoretical risk — it is happening to three-quarters of US organizations right now. The organizations that are weathering it best are not necessarily the ones with the most sophisticated technology. They are the ones with the most disciplined procedural controls: independent verification of payment instruction changes, segregation of duties on vendor setup and payment approval, and a vendor master file that is actively maintained and audited.
The technology helps. But the fundamentals of internal controls have never been more important — or more difficult to maintain without a systematic approach.
Ready to tighten your AP controls?
ApprovedAP gives you vendor compliance tracking, SoD violation detection, and payment controls in one place.
Get started free