What problem does it solve?
A fraud model that stops a card transaction cannot be certain the cardholder did not make it. When the customer did make it, the block interrupts a genuine purchase, often while they are still at the checkout, and they need an answer before they give up or pay another way. If confirmation depends on a person calling back, it can take longer than the customer stays at the checkout, and a call from an unknown number asking about their card looks much like the scams customers are warned about.
The confirmation step is therefore both a revenue problem (a genuine purchase that is declined is spend the issuer may not get back) and a security problem. Scammers send text messages that impersonate legitimate businesses (the reason Commonwealth Bank gives for moving some card verification into its app), spoof the bank's phone numbers (Westpac has put 94,000 of its numbers on a Do Not Originate list) and can clone a voice well enough to pass a voice identity check, as a journalist showed against Lloyds Bank's Voice ID in 2023. The job is to confirm quickly, in a channel the customer trusts, without creating a new route for scammers.
How does it work?
- Trigger from the scoring engine. A flagged authorization or a card placed on hold starts the agent, with the transaction details and the risk reason.
- Pick the trusted channel. The first choice is a push into the bank's app, where the customer is already authenticated. Commonwealth Bank now asks app users to verify certain online card transactions in the app instead of sending a code, because it can give clearer warnings there than in a text message. Then two way messaging, then an outbound call that is branded and verified (Westpac's SafeCall places calls through its app that show the reason for the call).
- Verify, never collect secrets. The agent confirms identity through the app or a strong factor, never asks for a passcode, PIN or full card number, and treats the voice on the line as untrusted.
- Ask one clear question. "Did you try to pay 84.90 EUR at this merchant at 14:02?" with the merchant's clear name and location.
- Act on the answer. Yes: lift the block, allow the retry and tune the rule for this customer. No: freeze the card, order a replacement and open the fraud claim. Unsure, or signs that someone is guiding the customer: route to a scam specialist.
- Handle silence. No response within the set time keeps the block in place and follows the bank's contact policy.
- Log and learn. Every alert, answer and action is recorded and fed back to the fraud team as labelled outcomes.
- Audience
- Customer facing
- Autonomy
- Supervised agent
- Adoption
- Emerging
- Channels
- Mobile app, SMS, Phone and voice, WhatsApp
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
| KPI | Median | Reported range | Data points | Claimed by |
|---|---|---|---|---|
| Fraud loss reduction | Too few to pool | 30% to 76% | 2 | 2 organization |
| False positive reduction | Too few to pool | 40% | 1 | 1 vendor |
Value drivers: Risk and loss reduction, Customer experience, Lower cost to serve, Revenue growth.
Indicative value
A card issuer with 1 million active cards
USD 194,000 to USD 2.1 million
Confirmation call cost avoided plus revenue from recovered genuine spend per year
How this is calculated
Formula: cards * alertsPerCard * (agentResolvedShare * costPerCall + genuineShare * recoveredShare * avgTransaction * marginRate). The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Active cards cards, cards | 1,000,000 | 1,000,000 | The reference issuer. |
| Fraud alerts needing customer confirmation per card per year alertsPerCard, alerts per card per year | 0.2 | 0.5 | Editorial assumption, replace with your own alert volume. |
| Share of alerts confirmed by the agent without a human call agentResolvedShare, fraction of alerts | 0.3 | 0.6 | Editorial assumption; depends on app adoption and on how many alerts need a specialist. |
| Cost of a human confirmation call costPerCall, USD per call | 3 | 6 | Editorial assumption, replace with your own fully loaded cost. |
| Share of alerts that are genuine customer transactions genuineShare, fraction of alerts | 0.7 | 0.9 | Editorial assumption, replace with your own alert outcomes. |
| Share of genuine blocked spend recovered by fast confirmation recoveredShare, fraction of genuine alerts | 0.2 | 0.4 | Editorial assumption. |
| Average value of a flagged genuine transaction avgTransaction, USD | 50 | 100 | Editorial assumption. |
| Issuer revenue as a share of spend marginRate, fraction of spend | 0.01 | 0.015 | Editorial assumption covering interchange and related income. |
What it leaves out: Leaves out fraud losses prevented by faster freezes, the lifetime value of customers who would otherwise switch cards after a false decline, messaging and telephony costs and the cost of the AI and integration.
Who already uses it?
5 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Capital One
United States · Banking · 2026
Eno is Capital One's virtual assistant. Capital One says it helps protect card accounts by looking out for charges that might surprise the customer, and sends insights when it spots free trials and recurring charges, through text, email and app alerts. Capital One does not publish outcome figures for Eno on this page.
No outcome disclosed.
Commonwealth Bank of Australia
Australia · Banking · 2025
Commonwealth Bank combines several AI controls against scams and fraud. Its fraud systems monitor more than 80 million signals a day and the CommBank app sends proactive warning alerts on payments that look risky; NameCheck and Confirmation of Payee check payee details on first time payments. From August 2025 customers are asked to verify certain online card transactions in the app, in real time, before they are authorised. In April 2026 the bank described an agentic system that spots emerging fraud patterns and proposes new detection rules, which the fraud analytics team reviews and approves before they go live. The bank reports a 76% fall in customer scam losses since their peak without attributing it to any single tool, and says its fraud detection technology played a role in cutting fraud losses by over 20% in the first half of FY26.
- Fraud loss reduction: 76%, second half of FY25 versus first half of FY23 (the peak)
"CommBank has seen a 76% drop in customer scam losses since peak (2H25 vs. 1H23)"
Claimed by: organization - Interactions handled: at least 40,000, per day on average, proactive warning alerts in the CommBank app
"Each day, CommBank processes more than 20 million payments on average and sends more than 40,000 proactive warning alerts on average to customers via the CommBank app."
Claimed by: organization - Fraud loss reduction: at least 20%, first half of FY26 versus first half of FY25
"The bank’s fraud detection technology has played a role in helping to reduce fraud losses by over 20% in the first half of the 2026 financial year compared to the first half of the 2025 financial year."
Claimed by: organization
Westpac
Australia · Banking · 2025
In May 2025 Westpac announced that it was piloting an AI call assistant with its specialist scam and fraud team. It transcribes live customer calls, flags indicators that the customer may be about to pay a scammer or is being coached in the background, and suggests questions for the banker. It sits alongside SaferPay (questions before high risk payments), SafeCall (verified calls through the app to resist spoofing), Westpac Verify (payee name mismatch warnings) and inbound payment detection. The bank reports early qualitative results only.
No outcome disclosed.
Revolut
United Kingdom · Banking · 2024
In February 2024 Revolut launched a machine learning feature, built by its financial crime team, that estimates whether a card payment is part of a scam. When the risk is high it declines the payment, blocks similar payments and sends the customer through an in app intervention flow that asks about the payment, checks whether someone is guiding them, shows scam stories and offers a chat with a fraud specialist.
- Fraud loss reduction: 30%, since launch, fraud losses from card scams where money was sent for investment opportunities
"Since the launch of the card scam detection feature, Revolut has observed a 30% reduction in the fraud losses resulting from card scams where money has been sent for investment opportunities."
Claimed by: organization
Macquarie Bank
Australia · Banking · 2025
Macquarie Bank uses Google Cloud AI for proactive fraud protection and digital self service. Google Cloud reports that the bank cut false positive alerts for client protection and that its help centre search sent more users to self service. The source does not say which channels carry the alerts.
- False positive reduction: 40%, not stated
"Macquarie Bank uses Google Cloud AI to enable efficient and proactive fraud protection and digital self-service capabilities — their Help Centre Search directed 38% more users towards self-service and they reduced false positive alerts for client protection by 40%."
Claimed by: vendor
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Real time alert feed with transaction and merchant details and the risk reason
- Verified contact channels and app enrolment per customer
- Contact policy per alert type (channels, timing, retries, quiet hours)
- Labelled outcomes of past alerts to measure false positives
Systems to integrate
- Fraud scoring engine and alert queue
- Card management platform (release, freeze, replace, rule tuning)
- App push and in app authentication
- Messaging and telephony with branded or verifiable calling
- Fraud claim and dispute case system
Complexity: Medium
The logic is simple; the timing is not. The agent must be triggered by the scoring engine in seconds, reach the customer in a trusted channel and change the card's status through the card platform before the customer gives up at the checkout.
- 1
Move confirmation into the app first
The app is authenticated and hard to spoof. Make an in app confirmation the default and keep other channels as fallbacks for customers without the app. Commonwealth Bank, for example, now asks app users to verify certain online card transactions in the app instead of sending a one time passcode.
- 2
Write the no secrets rule into everything
The agent never asks for a passcode, PIN or card number and tells the customer so in every message. This protects customers from scammers copying your alert.
- 3
Close the loop with the card platform
A yes must lift the block in seconds and a no must freeze and reissue. Test both paths end to end, including the retry at the merchant.
- 4
Connect to scam and dispute journeys
A customer who is unsure, or who describes being guided by someone, goes to a scam specialist; a confirmed fraud goes straight into the fraud claim with the details captured.
- 5
Measure false declines, not only fraud
Track genuine transactions recovered and customers lost after a decline, alongside fraud caught, so the fraud team tunes for both.
Guardrails
- No collection of passcodes, PINs, full card numbers or remote access in any channel
- Outbound calls are verifiable in the app or come from a registered, branded number
- Voice alone is never accepted as proof of identity
- Freeze and reissue actions only through the card platform's allow listed APIs
- Scam signals or uncertainty route to a human specialist
KPIs to instrument
- Median time from alert to customer answer, by channel
- Share of alerts resolved without a human call
- Genuine transactions recovered after confirmation
- Fraud losses on alerted transactions
- Complaints and satisfaction after a confirmation contact
Human in the loop
Fraud specialists handle uncertain answers, suspected scams, vulnerable customers and any case where the customer disputes the agent's action. The fraud team reviews alert outcomes weekly to tune rules, and approves any change to the contact policy or the actions the agent may take.
Common failure modes
- Your alert becomes the scammer's template
- Scammers copy the wording and ask for a code. Never request secrets, say so in every alert and prefer in app confirmation.
- Slow confirmation
- The answer arrives after the customer has left the checkout. Trigger in real time and prioritise the fastest trusted channel.
- Voice clone accepted as the customer
- A cloned voice passes a voice check. Confirm through the app or another strong factor, not the voice.
- Silence treated as consent
- No answer must never release a block. Keep it in place and follow the contact policy.
What are the risks and rules?
EU AI Act
Limited risk (transparency)
Confirming flagged transactions with cardholders is not listed in Annex III, and point 5(b) expressly excludes AI used to detect financial fraud from the creditworthiness category, so the system is not high risk. An agent that messages or calls customers must tell them they are dealing with AI under Article 50(1), and synthetic voice output must be marked as AI generated under Article 50(2).
Guidance
- Declaratory ruling on AI generated voices under the TCPA (FCC 24-17) (Federal Communications Commission, North America). Confirms that AI technologies that generate human voices count as an "artificial or prerecorded voice" under the TCPA, so US outbound AI voice calls fall under the TCPA's consent rules unless an exemption applies.
- TCPA Omnibus Declaratory Ruling and Order (FCC 15-72) (Federal Communications Commission, North America). Exempts from the TCPA's consent requirements, with conditions, certain calls and texts from financial institutions to mobile numbers about transactions that suggest a risk of fraud, provided they are free to the recipient and limited to three per event over three days.
- Annex III, high risk AI systems referred to in Article 6(2) (European Union, Europe). Point 5(b) excludes AI systems used for detecting financial fraud from the creditworthiness high risk category.
Controls to put in place
- AI disclosure in every automated message and call
- Documented contact policy per alert type with quiet hours and retry limits
- Audit log of every alert, answer, identity check and card action
- Regular tests of the alert channel against impersonation and spoofing
- Monitoring of false positive rates and outcomes for vulnerable customers
When it went wrong elsewhere
- How I Broke Into a Bank Account With an AI-Generated Voice. In February 2023 a Vice journalist used an AI generated copy of his own voice to pass Lloyds Bank's Voice ID check and reach his account, which is why voice alone should not verify a customer in a fraud confirmation call.
Frequently asked questions
- Should fraud confirmation use calls, SMS or the app?
- The app first, because the customer is already authenticated there and it is hard to spoof. Commonwealth Bank now asks app users to verify certain online card transactions in the app instead of sending a code, because it can give clearer warnings there. Keep messaging and calls as fallbacks for customers without the app.
- Can an AI agent unblock a card on its own?
- For a clear "yes, that was me" from an authenticated customer, releasing the block within set limits is a reasonable automated action. A freeze after a clear "no" can also be automated because it is reversible, while a reissue can go through human approval above a set threshold. Anything uncertain, or with signs of a scam, should go to a person.
- How do you stop scammers imitating the alert?
- Never ask for passcodes or card details, say so in every alert, and move confirmation into the app or to verifiable calls. Westpac, for example, places branded calls through its app that are verified by Optus and show the reason for the call, and has put 94,000 of its numbers on a Do Not Originate list so scammers cannot display them.
How to cite this page
Blits.ai AI Use Case Library, "AI agent for fraud alert confirmation with cardholders", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/fraud-alert-confirmation. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published