Skip to content

Nearly half of UK adults say it's harder to spot fakes online

National Trading Standards says 47% of UK adults find it harder to tell what's genuine online, as its new AI Scam Watchlist raises questions for banks' fraud warnings and monitoring.

By

Published
Ten identical telephone receivers fanned out around a single rotary phone on a bare desk, all lifted off their hooks.

National Trading Standards says that close to half of UK adults now find it harder to tell what is genuine online, as it published a new AI Scam Watchlist on 30 September 2026. The finding comes from a Censuswide poll of 2,000 nationally representative UK adults aged 18 and over, carried out between 18 and 22 September 2026, in which 47% said it was getting harder to tell what was genuine online.

That is a self-reported perception, not a test. The poll asked people how they felt about telling genuine material from fake online; it did not put a set of AI-generated offers in front of respondents and check how many they correctly identified. The distinction matters, because the same survey found that 62% of respondents were confident they could spot a scam created using AI — a different question, about confidence in their own judgement, rather than a contradiction of the 47% figure.

For UK banks and payment firms, the practical question is not how people rate their own scam-spotting ability. It is whether more convincing fakes are making customers more likely to authorise a payment they would once have questioned. National Trading Standards' Watchlist sets out the techniques driving that shift, and the implications for fraud warnings, transaction monitoring and customer support follow from existing regulatory expectations rather than from any new rule the Watchlist itself creates.

What the poll found

Alongside the headline 47% figure, National Trading Standards reported that 24% felt overwhelmed by increasingly sophisticated scams, 19% were avoiding some online activity because of scam concerns, and 79% were concerned that a friend or relative could become a victim. The release also ranked the five AI-enabled techniques respondents said concerned them most: fake websites first, then voice cloning, deepfake video, AI-generated images and digital humans, though it did not publish the percentage selecting each one.

The techniques on the Watchlist

National Trading Standards lists nine techniques it says are now part of the criminal toolkit: digital humans, deepfake video, AI-generated images, AI-generated messages, voice cloning, AI chatbots, poisoned AI search results, AI-generated websites and fake reviews. Several are extensions of long-standing tactics rather than genuinely new inventions. A cloned voice applies AI to the old trick of impersonating someone a victim trusts. A fabricated website or set of fake reviews does the job a dishonest shopfront or planted testimonial always did, but faster and more convincingly. A "digital human" or deepfake video goes further, generating footage of a person who may not exist, or putting fabricated words in the mouth of someone who does.

Old scams with a better disguise

National Trading Standards' central point is that AI is generally strengthening and scaling existing scams rather than creating wholly new categories of fraud. The Watchlist identifies ten established scam types it says AI is making more effective: shopping, investment, romance, travel and ticket, technical support, jobs, charity, family impersonation, rogue trader and recovery scams.

The mechanism in each case is similar. A chatbot can hold a sustained, plausible conversation about a fake investment opportunity. A cloned voice can make a call purporting to be from a distressed relative or a bank's fraud team sound authentic. A generated image or video can supply visual evidence a shopping or romance scam previously lacked. None of this changes the underlying deception, which remains a person being persuaded to hand over money or details. It changes how convincing that deception can be, and at what scale.

This matters for authorised push payment fraud — where a person is deceived into instructing a payment to a fraudster or for a fraudulent purpose, rather than having a payment made without their knowledge. If the supporting story, caller's voice, website or reviews are harder to fault, the resulting instruction can look legitimate to the bank even though it is not, which puts more weight on behavioural monitoring, beneficiary intelligence and payment-purpose context to catch what the customer-facing story no longer reveals.

Why generic warnings may not be enough

National Trading Standards has not announced any new obligation on banks. The implications for fraud controls are an inference from the threat it describes, set against expectations the Financial Conduct Authority (FCA) already applies to UK payment service providers.

The FCA's review of anti-fraud controls, first published in November 2023, says it expects firms to keep fraud risks and controls under review, help customers identify and report fraud, communicate clearly, and support victims — particularly those in vulnerable circumstances. These sit alongside the Consumer Duty, in force for open products and services since 31 July 2023.

A Financial Ombudsman Service decision applying the former voluntary Contingent Reimbursement Model Code set out criteria for an effective fraud warning: understandable, clear, impactful, timely and specific. That decision concerned one complaint rather than a binding rule, but the criteria illustrate a point that follows from more convincing AI-generated material — a generic warning shown at every payment is less likely to interrupt a customer who has just watched a deepfake video or spoken to a cloned voice than a warning timed to the moment of risk and specific to the payment's apparent purpose.

Separately, payment service providers operate under a technical standard — retained EU law within the UK framework, predating the Watchlist — requiring transaction-monitoring mechanisms that weigh factors including the transaction amount, known fraud scenarios and the customer's normal pattern of use. That standard does not give a bank visibility into the fabricated video or cloned voice that may have persuaded a customer to pay. Its systems generally observe the payment itself, along with account and device signals, rather than the conversation that led to it, which is why behavioural and beneficiary-based detection matters more as the customer-facing story loses its old tell-tale signs — poor spelling, implausible claims, a crude fake image.

Reimbursement if a payment goes wrong

Since 7 October 2024, victims of qualifying authorised push payment scams made by Faster Payments or CHAPS have generally been entitled to mandatory reimbursement, up to £85,000 per claim, subject to scope and exceptions. Firms may apply an optional excess of up to £100, but not to customers with characteristics of vulnerability.

FeatureDetail
Regime start date7 October 2024
Payment systems coveredFaster Payments and CHAPS
Maximum reimbursement£85,000 per claim
Optional excessUp to £100, not chargeable to vulnerable consumers

Coverage is not universal, and a reader who believes they have been scammed should check the official detail rather than assume reimbursement is automatic. Because both sending and receiving firms share liability, the Payment Systems Regulator (PSR) has said the regime gives both sides a financial incentive to prevent these scams — though it has also noted that information sharing between firms sometimes remains limited.

Early PSR data for the first three months of the regime showed 86% of reimbursable Faster Payments losses were returned to victims, totalling about £27m, with 84% of claims closed within five business days. The PSR was explicit that this early data could not be compared directly with earlier UK Finance figures, because definitions and methods differ.

For scale, UK Finance's member data recorded more than £1.1bn in fraud losses in 2024, including £144.4m from investment authorised push payment scams and £87.1m from purchase scams. Those figures cover UK Finance's member firms rather than the whole UK market, and none of them isolates how much involved AI-generated content; no source identified for this article quantifies the AI-enabled share of UK fraud losses.

Support for customers who are distressed or vulnerable

The FCA's expectations call for easy fraud reporting, clear communication and support that accounts for vulnerability, including exception processes where a firm's support is mainly digital; separate FCA guidance on the fair treatment of vulnerable customers covers how firms should handle complaints and support needs, including cases where a customer may be acting under fraud or coercion.

A customer who has just been deceived by a convincing cloned voice or fabricated video may be shaken or unwilling to accept that what they experienced was fake. Reaching a trained person quickly may matter more here than in a straightforward unauthorised-transaction dispute, though none of the sources reviewed measure whether current bank support models achieve this for AI-enabled scams specifically.

What is not yet known

No primary source quantifies how many UK fraud cases, or how much loss, specifically involved generative AI, deepfake content or voice cloning; the figures above describe scam categories, not the technology used. Readers can consult National Trading Standards' AI Scam Watchlist directly, the FCA's review of anti-fraud controls, and the PSR's guidance on reimbursement protections. Anyone who believes they have been scammed should use the official Report Fraud service and check their own provider's terms on reimbursement eligibility.

Sources

  1. AI Scam Watchlist (opens in a new tab)

    National Trading Standards · · Accessed

  2. Article 2 General authentication requirements (opens in a new tab)

    Financial Conduct Authority · Accessed

  3. Decision reference DRN-2605235 (opens in a new tab)

    Financial Ombudsman Service · Accessed

  4. FG21/1: Guidance for firms on the fair treatment of vulnerable customers (opens in a new tab)

    Financial Conduct Authority · · Accessed

  5. APP fraud reimbursement protections (opens in a new tab)

    Payment Systems Regulator · Accessed

All Fraud & Security coverage