The AI advantage: Can governments finally get ahead of fraudsters?
By SAS
Ahead of a September webinar on fraud, waste and abuse, SAS's Keith Swanson makes the case for why the public sector's survival strategy is prevention and why detection alone is no longer enough.
-1786942901957.jpg)
Fraudsters around Asia-Pacific are already deploying AI, adding to the growing scale and complexity of fraud. Image: Canva
Fraudsters around Asia-Pacific are already deploying artificial intelligence (AI), be it testing new attack vectors, cloning identities, or moving stolen funds through mule accounts before public agencies can respond, adding to the growing scale and complexity of fraud.
Governments, meanwhile, are still working through how AI should be regulated, governed and deployed responsibly, which widens the gap between attack and response.
The result of this, says SAS' Director of Fraud and Security Intelligence for Asia Pacific-Japan, Keith Swanson, is an increasingly asymmetrical contest between governments and fraudsters.
That urgency is also driven by the rise of digital services and real-time payments, leaving governments with little time to intervene.
"The concept of pay and chase often doesn't work anymore when funds can be moved almost immediately after payment,” he notes.
With challenges mounting on multiple fronts, public sector fraud teams are grappling with rapidly growing workloads.
The question is no longer just whether to deploy data and AI in the fight against fraud, but whether governments can move fast enough before fraudsters act.
Swanson says that the agencies who are ahead of the contest share a common trait, which is that they started treating fraud as something to prevent than to solely detect.
The scam industry has found a new target
Across Asia, fraud has professionalised. According to Swanson, scam operations now run like enterprises, completed with contact centres, AI tooling, and sophisticated infrastructure.
As banks and financial institutions hardened their defences, these criminal syndicates went looking for softer targets which are increasingly governments, he adds.
The most vulnerable populations are often those with the greatest need for government engagement, which include elderly citizens and the digitally underserved.
"The segments that are most likely to be targeted may also have higher government needs or payments received – doubling down on the scammers' interest," he explains.
Account takeovers and synthetic identities, long familiar to the financial services' industry, are now prevalent in the government too, he adds.
AI is further expanding the fraudster's toolkit, enabling criminals to create convincing fake images to support fraudulent claims, clone voices to impersonate trusted individuals, and scale these attacks more rapidly.
The data paradox
While the government is not short on data, its problem is in using it to prevent frauds.
Many public agencies have spent years on enterprise-wide data initiatives, such as warehouses, lakes, fabrics, designed to bring information together and make it accessible.
But Swanson argues the focus has too often stopped at management, rather than pushing data into effective use to implement preventative measures.
"It is quite important that the focus moves beyond management and into utilisation — how it can help drive better and faster decisions," he says.
Where he has seen greater success is when individual departments are given the autonomy to access and act on data directly, without being beholden to longer enterprise transformation timelines.
Speed of access, speed of testing, and speed of action matter more, he emphasises.
Moving from detection to prevention
AI is already transforming how governments detect and prevent fraud, while enabling agencies to prioritise cases, streamline investigations and improve workforce productivity.
"Prevention really relies on being able to stop a payment from being made if it exceeds a risk tolerance or profile," he notes.
And doing so means verifying not just the eligibility data a citizen submits, but the citizen themselves, including their device, their behaviour, and their identity.
Applied or traditional AI has already delivered results here.
Machine learning models can flag a transaction as high risk because an unfamiliar device was used, or because the pattern of activity deviates from what is typical for that citizen, he shares.
Network graph analysis can also surface complex relationships between entities invisible to a human investigator working alone, while natural language processing can assess free-form text for patterns that indicate risk, he adds.
Generative AI is also extending these capabilities by acting as a co-pilot for investigators. It can summarise complex information, surface relevant insights and help staff navigate large volumes of data more efficiently.
However, governments remain cautious about adoption.
Particularly when sensitive citizen data is involved, agencies are looking to address issues such as data privacy, auditability, model bias and AI hallucinations before these technologies can be deployed at scale.
Looking ahead, agentic AI could automate parts of the investigation process, such as requesting additional information or initiating checks against trusted data sources, helping agencies manage growing fraud caseloads.
For now, however, many exceptions still require human review.
AI also have a role beyond prevention, as they can also help staff identify which cases need immediate attention, prioritise the most significant risks and resolve exceptions more quickly.
How governments can stay in the fight
Swan offers a threefold prescription for governments to stay at the forefront of preventing fraud.
1. Greater public-private collaboration
The intelligence on attack vectors, fraud typologies, and emerging threats should not sit in silos.
Sharing across the digital ecosystem, which is between public agencies and with private sector partners, is how good actors can match the agility of bad ones.
2. A genuine architectural pivot
"If an agency is focused on real-time delivery, then real-time blocking is needed as well," Swanson says.
Agencies that have committed to real-time service delivery must also commit to real-time blocking.
If a fraudulent application can be submitted and paid out in seconds, detection after the fact is not a strategy, he stresses.
3. Internal agility
This is about moving beyond traditional triage and remediation cycles toward governance frameworks that allow for rapid, proactive response.
In practice, this is about developing shared principles and practices, as well as instantiating internal processes that allow for rapid response or better proactive mitigation.
These actions are done within a defined testing and governance framework, he emphasised.
Also measuring what doesn't happen
How do you then measure success when success looks like nothing happening?
Prevention may shrink the traditional metrics, says Swanson.
"If you are good at deterring and preventing fraud, traditional metrics of fraud detected, amounts recovered, cases prosecuted may inherently decrease, and those declines could be mistaken for weaker performance," he warns.
Swanson argues that governments should shift the frame for measuring success towards outcomes such as the percentage of transactions verified in real time, the proportion resolved without human intervention, and whether social programmes are achieving their intended outcomes for citizens.
Beyond rethinking their technology and operating models, agencies also need a better way of keeping scores to get ahead of fraudsters.