Guidance Hub
AI-Enabled Financial Crime and Corporate Investigations
- Author
- Craig MacKenzie
- Role
- Partner and Solicitor Advocate
- Published
- 27 July 2026
- Reading time
- 13 minutes
Artificial intelligence has not created new dishonesty. It has changed the scale, speed and credibility with which dishonesty can be executed, and it has changed what an organisation must be able to prove about its own decisions when something goes wrong.
This page explains how an AI-related incident develops: from a suspicious payment or a fabricated video call, through the internal investigation, into regulatory exposure, corporate criminal liability and, for directors, senior managers and employees, potential personal exposure. It is written for the people who will have to make the first decisions.
How AI is changing the scale and credibility of fraud
Fraud has always depended on manufactured trust. What AI changes is the cost of manufacturing it. A convincing voice, a familiar face on a video call, a plausible email thread, supporting documents that survive a first inspection: each of these can now be produced quickly, cheaply and at scale.
The practical consequence is that the traditional signals organisations rely on, such as recognising a voice, seeing a face, or the apparent authority of a senior colleague, are no longer reliable evidence of identity or authority. The question for an organisation is no longer "did this look and sound genuine?" It is "did this instruction survive an independent verification process?"
External attacks against organisations
The most visible category is external: deepfake video calls and cloned voices used to procure payments, impersonation of executives and counterparties, synthetic documents supporting fictitious transactions, and AI-assisted phishing that adapts to its target. Publicly reported cases have involved employees transferring very large sums after joining video calls in which every other participant was fabricated, including a widely reported 2024 Hong Kong incident in which a finance employee authorised payments of around HK$200 million after a deepfake video conference (reported by The Guardian, February 2024).
An organisation attacked in this way is a victim. But victim status does not end the analysis. A significant loss will prompt questions from regulators, insurers, auditors and, in regulated sectors, supervisors, about the controls that allowed a manufactured instruction to move real money.
Internal use of AI to commit or facilitate fraud
The second category is less visible and legally more dangerous: people inside the organisation using AI to fabricate performance data, generate misleading customer communications, produce false supporting material for transactions, or manipulate the records a control framework relies on.
Here the organisation may not be the victim at all. If an employee or agent uses AI to commit fraud intended to benefit the organisation, or a person to whom the associated person was providing services on the organisation's behalf (inflated sales, misleading marketing that wins business, fabricated compliance records that keep revenue flowing), the organisation itself may face criminal exposure for failing to prevent it.
An organisation can be the victim of one AI-enabled fraud and potentially liable for another. Many real incidents contain elements of both.
AI error, negligence or dishonesty
Not every AI failure is a fraud. A model that produces wrong outputs, a system deployed carelessly, a communication generated without adequate review: these may be errors or negligence, with civil, regulatory or contractual consequences, without any crime.
The criminal law turns on human states of mind. The questions that matter are: who knew the output was false or misleading; who intended to gain, or to cause loss or risk of loss; who was dishonest by ordinary standards? The machine does not remove the need to prove human dishonesty. But equally, the involvement of a machine does not launder dishonest human conduct into an innocent system error. Establishing which side of that line an incident falls on is often the central issue in the early weeks.
Individual criminal liability
Individuals who use AI as an instrument of deception face the same offences as any other fraudster, principally under the Fraud Act 2006: fraud by false representation, by failing to disclose information, or by abuse of position. The legislation was drafted to cover representations made to systems and devices, not only to people, so the fact that a false representation was consumed by software rather than a human does not defeat the offence.
Directors, senior managers and employees can also acquire exposure from how they respond to an incident: from what is said in internal interviews, what is preserved or deleted, and what is asserted to regulators before the facts are established.
Corporate attribution through senior managers
Since 29 June 2026, under section 250 of the Crime and Policing Act 2026, an organisation can be criminally liable for offences committed by a senior manager acting within the actual or apparent scope of their authority. This attribution rule now applies to criminal offences generally, subject to the statutory conditions and territorial provisions; it replaced the narrower provision in the Economic Crime and Corporate Transparency Act 2023, which had applied only to economic crimes. "Senior manager" is a functional test: it looks at the person's real role in decision-making, not their job title. Liability depends upon proof of an individual offence and satisfaction of the statutory attribution conditions. There is no reasonable-procedures defence to attribution. It is a rule about whose conduct counts as the organisation's, and it operates separately from the failure-to-prevent-fraud offence.
Where decisions about deploying, overriding or ignoring AI systems are made by someone who satisfies the statutory senior-manager test and acts within the actual or apparent scope of their authority, section 250 may become directly relevant.
Failure to prevent fraud
For large organisations, the failure-to-prevent-fraud offence under section 199 of the Economic Crime and Corporate Transparency Act 2023 is now in force. In outline, a large organisation commits an offence where a person associated with it, whether an employee, agent, subsidiary undertaking or someone performing services on its behalf, commits a listed fraud offence intending to benefit, directly or indirectly, either the organisation itself (section 199(1)(a)) or a person to whom, or to whose subsidiary undertaking, the associated person was providing services on the organisation's behalf (section 199(1)(b)).
The two limbs matter, and so does the difference between committing fraud and suffering it. Fraud intended to benefit the organisation falls under the first limb. Fraud intended to benefit a client falls under the second. Where the alleged fraud was intended to benefit a client within section 199(1)(b), the organisation is not liable under that limb if it was itself, or was intended to be, a victim of the fraud. And an organisation that simply suffers loss through an external fraud, such as a manufactured payment instruction or a deepfake call, is not within the offence at all: the offence concerns fraud committed by the organisation's own associated persons, not fraud committed against it.
The offence does not require the board to have known anything. The analysis runs through a sequence of gateway questions: whether the organisation meets the size thresholds; whether the fraudster was an associated person acting in that capacity; whether a listed fraud offence was committed; whether the intended benefit satisfies the statutory test under the relevant limb; and whether the territorial requirements are met.
Losing money to an external fraud does not establish this offence. Committing fraud through your own people may.
The reasonable-procedures defence
It is a defence for the organisation to prove that it had such fraud-prevention procedures in place as it was reasonable in all the circumstances to expect, or that it was not reasonable to expect it to have any. This is a statutory defence which the organisation must prove on the balance of probabilities, and it is the court that ultimately determines whether the defence is made out on the evidence. Reasonableness is assessed in context. The existence of a policy document will not, by itself, establish that reasonable procedures were in place and operating in practice: written policies are relevant, but implementation, communication, monitoring and practical operation may all bear on the assessment. The Home Office guidance on the offence sets out principles organisations are expected to consider; it informs, but does not replace, the statutory test.
For AI-enabled risks, relevant questions are likely to include the following (this is practitioner analysis of how the statutory test and the guidance principles apply, not a settled prosecutorial checklist): did the fraud risk assessment consider AI-enabled methods; were payment and verification controls designed on the assumption that voices and faces can be fabricated; who owned the risk; and can the organisation evidence that its procedures operated in practice?
FCA and other regulatory exposure
Criminal liability is one lane. Regulatory exposure is another, and the two are frequently conflated. A regulated firm faces obligations and expectations about systems and controls, governance and senior-management accountability that operate regardless of whether any crime is ever charged, including the duty to deal with regulators in an open and co-operative way and to disclose appropriately anything of which the regulator would reasonably expect notice (Principle 11 and SUP 15). An AI failure that misleads customers, distorts decisions or breaks a control can engage supervisory scrutiny, information requirements, skilled-person reviews and enforcement and, under the accountability regime, questions directed at named senior managers.
Data-protection exposure runs in parallel where personal data is involved, including the accountability obligations and, where a reportable breach occurs, the notification framework in the ICO's personal data breach guidance. Using an external AI supplier does not transfer the organisation's own regulatory responsibilities. The supplier may have separate exposure, but outsourcing the tool does not outsource accountability.
The first response to a suspected incident
The first 24 hours are not about reaching an instant verdict. They are about controlling harm, preserving evidence and making defensible decisions.
That means: stopping further loss where possible; preserving systems, communications and AI-related records before they are overwritten; establishing a small, senior decision-making group; documenting what is decided and why; taking advice before conclusions are announced; and notifying accurately, whether banks, insurers, or where required regulators, without speculating beyond the established facts.
The most common early failures are predictable: informal interviews that contaminate later evidence, well-intentioned "tidying up" of systems that destroys exculpatory material, and confident early narratives that the facts later contradict.
Preserving evidence, including AI-specific evidence
AI incidents generate categories of evidence that traditional preservation instructions miss: prompts and outputs; system and access logs; model or tool configuration and versions; approval and escalation records; source or grounding material; relevant training or grounding data, where material to the incident and available; communications; audit trails; identity and authentication records; and evidence held by third-party providers. Not every category will be relevant in every incident, and some will not be within the organisation's possession or control; vendor-held material may need a prompt written preservation request. Some systems retain this material only briefly. Retention periods should be established immediately rather than assumed.
Preservation is not only about proving the fraud. It is also how an organisation, and any individual under suspicion, protects the material that may exonerate them. Deleting an AI output because it is embarrassing may destroy the very record that showed who knew what, and when.
Internal investigations and privilege
A properly structured internal investigation can establish facts, preserve the organisation's options and maximise the prospect that privilege will apply where its legal requirements are satisfied. Conducted badly, it creates documents that may later become disclosable and frame the organisation's conduct in the worst light, contaminates witness evidence, and closes off defences before anyone has understood the exposure.
Privilege in an internal investigation is not created simply by involving a lawyer or marking documents "privileged" or "confidential". Legal-advice privilege and litigation privilege are distinct, and the availability of each depends upon the purpose and circumstances in which particular communications and documents are created. For legal-advice privilege, identifying the organisation as the client does not end the analysis: it may also be necessary to identify the individuals authorised to obtain and receive legal advice on its behalf. Not every fact-finding communication will be privileged, and privilege, once established, may be lost or waived. This is why the structure of the investigation has to be considered at the outset, not retrofitted. The detailed position is covered in the dedicated internal-investigations guide.
Self-reporting, co-operation and DPAs
Whether, when and how to self-report, whether to the Serious Fraud Office, the FCA or elsewhere, is a strategic decision with permanent consequences. Prompt self-reporting and genuine co-operation can materially affect the route taken, including whether a deferred prosecution agreement under Schedule 17 to the Crime and Courts Act 2013 is considered. But a DPA is discretionary, requires judicial approval and is never an entitlement. Co-operation has a defined meaning in the SFO's published guidance. On privilege, the SFO states that an organisation will not be penalised merely for maintaining a valid privilege claim, although waiver over relevant material may be treated as a significant co-operative act. That decision requires careful, fact-specific advice.
A company's route to resolution and an individual's defence do not always point the same way. A DPA resolves the organisation's position, not any individual's: implicated individuals remain separately exposed to prosecution, and the process by which an organisation seeks a DPA (including the facts it provides and the positions it adopts) may have significant consequences for implicated individuals. Both need advice, and usually not from the same advisers.
Personal exposure for directors, senior managers and employees
Individuals are drawn into these investigations from several directions: as suspects, as senior managers whose conduct may be attributed to the company, as accountable managers under regulatory regimes, and as witnesses whose interviews may later be scrutinised in criminal proceedings.
The interests of the organisation and the individual can diverge quickly and quietly. An employee asked to attend an internal interview, a director named in a regulator's information request, a senior manager whose sign-off is in the audit trail: each should understand whose interests the organisation's advisers serve, and when independent advice is needed.
When independent specialist advice should be considered
Specialist advice should be considered earlier than many organisations expect, particularly where criminal, regulatory and individual interests may overlap: when a significant fraud is first suspected; as soon as there is a risk that potentially relevant material may be deleted, altered, reorganised or lost; before internal interviews are conducted; before a self-report is considered; and upon contact from the SFO, FCA or police. None of this alters the underlying position: potentially relevant material must not be deleted, concealed, falsified or altered, whether or not advice has yet been obtained.
When an internal concern may develop into a criminal or regulatory investigation, early advice can help an organisation or affected individual preserve evidence, identify conflicts and make defensible decisions before interviews are conducted, notifications are made or positions harden. Advice should be considered urgently where potentially relevant material may be deleted, altered, reorganised or lost, or where the interests of the organisation and an individual may no longer coincide.
Craig advises organisations and individuals at precisely this stage, combining serious criminal-case experience (defending in the most serious and complex cases, including murder, terrorism, organised crime and cross-border investigations) with early evidential analysis, strategic pre-charge defence and the management of parallel personal and corporate risk. This is Craig MacKenzie's personal professional website; legal services are provided through Forbes Solicitors, the regulated legal-services provider, and Craig does not accept instructions outside his role at Forbes Solicitors. All enquiries are directed to Craig at Forbes Solicitors and handled discreetly.
Sources and review
This page reflects the law of England and Wales and official guidance as at 26 July 2026. Principal sources:
- Economic Crime and Corporate Transparency Act 2023, s.199: the failure-to-prevent-fraud offence, its two benefit limbs, the victim exception and the reasonable-procedures defence.
- Home Office guidance on the failure-to-prevent-fraud offence (updated 10 October 2025), on reasonable fraud-prevention procedures.
- Crime and Policing Act 2026, s.250: attribution of senior-manager offences to the organisation.
- Fraud Act 2006: the underlying fraud offences, including representations made to systems and devices.
- FCA Handbook, SYSC, Principle 11 and SUP 15, on systems and controls, and notification obligations; Senior Managers and Certification Regime, on individual accountability.
- SFO Corporate Guidance (24 April 2025): self-reporting, co-operation and privilege.
- Crime and Courts Act 2013, Schedule 17: deferred prosecution agreements.
- ICO guidance on accountability and personal data breaches: data-protection obligations.
- The Guardian, 5 February 2024: the reported Hong Kong deepfake video-conference fraud.
Source research updated 26 July 2026; final legal review pending. The full verification register is maintained internally.
---
This page provides general strategic information about the law of England and Wales. It is not legal advice and does not create a solicitor–client relationship. The correct response in any individual case depends on the specific facts, the precise legal power exercised and the wider investigation. If you are affected by any matter described on this page, obtain specific legal advice without delay.
Discuss an emerging corporate fraud issue.
If your organisation is facing an actual or emerging AI-related fraud, investigation or regulatory issue, Craig MacKenzie can provide strategic advice through Forbes Solicitors at the point where the decisions matter most.
Speak to Craig at Forbes SolicitorsDo You Require Advice About Your Circumstances?
This material provides general information and is not a substitute for advice about a specific investigation or case.
Craig provides legal services exclusively through Forbes Solicitors. To make an initial enquiry, contact Craig at:
craig.mackenzie@forbessolicitors.co.uk
An enquiry does not constitute an instruction. Forbes Solicitors must confirm in writing that it has accepted the matter before any solicitor–client relationship arises.
Related Guidance
The First 24 Hours After Suspected Corporate Fraud
Guide 1: a strategic first-day guide to containment, evidence, privilege, reporting and ECCTA risk.
Failure to Prevent Fraud: A Strategic Guide for Organisations and Senior Leaders
Guide 2: corporate exposure under ECCTA, the reasonable procedures defence and the evidence boards should be able to produce.
Deepfake and Voice-Clone Fraud: Legal and Investigative Response
Guide 3: the law, immediate response, evidence and controls when synthetic media is used in suspected fraud.
Preserving Evidence in an AI-Enabled Fraud Investigation
Guide 4: preserving the complete generation trail, maintaining integrity and protecting exculpatory material.
Internal Investigations: Privilege, Interviews and Evidence Contamination
Guide 5: defining the client, protecting privilege, sequencing interviews and preventing evidence contamination.
Corporate Criminal Liability: Senior Managers, Associated Persons and Failure to Prevent Fraud
Guide 6: mapping senior-manager attribution, associated persons, intended benefit and the reasonable-procedures defence.
Self-Reporting, SFO Cooperation and Deferred Prosecution Agreements
Guide 7: deciding whether and when to self-report, genuine SFO cooperation, privilege and the route to a DPA.
When an AI Failure Is Not Fraud but Still Creates Regulatory Exposure
Guide 8: distinguishing fraud from data, consumer, equality, FCA, safety and professional exposure after an AI failure.
Fraud and Financial Crime
Craig's defence practice in serious fraud and financial crime investigations.
Business Crime
Advice for companies, directors and senior managers facing criminal exposure.
Crisis: My Business Is Under Investigation
Immediate steps when an investigation into the business has begun.