It takes less than a minute for a mortgage customer to open an app, upload a photo of their license, and wait for a green checkmark. But it’s the single most contested moment in the entire life of that loan.
That's the tension lenders are living with today. The same technology that makes onboarding fast and convenient is the technology bad actors are learning to exploit. They use it to pose as genuine customers and get through the front door with loans they would otherwise never qualify for.
Often, this happens without anyone noticing until the damage is done. As AI takes on more of the work across the lending life cycle, security must travel with the customer from that first checkpoint on.
The shift to digital lending introduced new security challenges
Verifying a borrower used to mean a trip to the branch. An associate looked at a passport, compared a face to a photo, and made a judgment call. It was slow, but it was also hard to fake at scale.
With digital lending, that changed fast. Remote identity verification, biometric scans, and digital document checks became the norm. Customers stopped wanting to visit a branch at all. The problem was never really about criminals gaining access to someone's data. Fraudsters learned to use the same verification technology against itself, spoofing checks well enough to pass as someone with a stronger credit profile than their own.
The two biggest risks are injection attacks, which involve feeding manipulated images or video directly into verification systems, and deepfake attacks, which involve tricking the camera into believing it’s receiving a live capture.
Banks around the world have had to disclose significant fraud losses tied to this kind of impersonation publicly. Real estate fraud losses climbed to $275.1 million in 2025, a 59% increase over the prior year, driven largely by wire fraud tied to real estate closings, according to the FBI's 2025 Internet Crime Report.
The lesson here has less to do with digital verification itself and more with how security was treated once it was in place: checked typically at the start. For a long time, security was viewed as a technology component rather than a business one, until the losses made it impossible to ignore. Know-your-customer and anti-money-laundering practices need to run continuously because the risk doesn't end when the account opens. As fraud detection tools get smarter, fraudsters get smarter too, and that race doesn't pause after onboarding.
Where AI is already earning its place
What’s encouraging is that the same technology reshaping risk is also reshaping the response. Real-time threat detection tools can compare a submitted document against what it should look like and flag anomalies in real time. Anything suspicious routes to a person for the final call on scored, multi-signal responses while the application is still in progress.
Underwriting is another area where AI is proving its worth. Credit bureau data doesn't always tell the full story, and AI can add its own risk scoring on top of it, giving assessors a fuller picture before they make a call. Customer service is where the payoff shows up most clearly day-to-day. Once you strip away password resets, a familiar list drives most contact-center calls: borrowers asking how they can vary their loan, what's forecast for interest rates, or whether a discount is on the table. It's not unusual for a customer to spend 30 minutes or more on hold for exactly that kind of question, only to get a clear answer from an AI agent in a couple of minutes.
The real opportunity goes further than speed, though. Consider agents configured to offer a discount the moment they see a client headed down a path toward discharging, turning a retention risk into a retention win before the customer ever picks up the phone. A person still reviews the flagged document, still makes the final underwriting call, and still steps in when a situation is too complex for a bot to handle. That's by design.
Where AI’s promise is unrealized, yet
Not every part of the lending life cycle is ready for this. Real-time payment rails and loan disbursement remain firmly in human and regulatory hands, where getting it wrong risks reputational damage on top of financial cost.
Simply extending multi-factor authentication to cover these agents is no longer enough. The conversation is shifting from know your customer to know your agent. Regulators are exploring verifiable identities for financial bots tied to legal entities, along with authentication frameworks that confirm both an agent's identity and the authority a customer has delegated to it. All of this relies on clean, well-governed data underneath it and clear guardrails on how much latitude an agent has.
How Unisys helps lenders build this the right way
You don't have to solve this with a single tool or one conversation. What you need is a partner who understands your risk tolerance, data maturity, and regulatory environment, and can help you decide which risks are worth taking first.
That's what Unisys’ decades of experience in data, core banking access, and security make possible. It’s a clearer path to the value you're after, whether that's cutting fraud losses, speeding up service, or protecting the trust customers already place in you. By encouraging a genuine security-first, AI-first mindset from the top down, backed by real change management, you can keep building value.