Robert Newcombe explores the use of agentic AI in fraud, in Fraud Intelligence

Robert Newcombe June 23, 2025

Robert Newcombe discusses the increasingly prominent role of agentic AI in financial crime, and explores the challenges legislators, regulators and law enforcement face in keeping pace with the evolution of AI fraud.

A dishonest stockbroker behind a Stock Exchange fraud in 1814 might be surprised to know that his scheme would today be characterised as a “fake news, pump and dump”. A convincing rumour was spread around The City of London (and at every staging post between Dover and London) that Napoleon Bonaparte had been killed in a battle with Cossacks, at the height of the Napoleonic War. The value of Omnium and Consols increased dramatically (equivalent to today’s FTSE All Share index). A garlanded coach was seen processing through The City with supposed supporters of the French Bourbon dynasty at its side. The dodgy stockbroker had bought Omnium and Consols on margin, shortly before the rumours spread. His actions entangled his nephew, a brilliant, but sometimes unpragmatic frigate Captain and Member of Parliament who was heir to an Earldom, Captain Sir Thomas Cochrane RN aka Lord Cochrane. He had made his reputation by harassing French naval vessels and shore batteries, along with planning a daring fireship raid on the Basque Roads and had been nicknamed “The Sea Wolf” by Napoleon himself. It seems likely that the future Earl of Dundonald would have known nothing of the agreement to peddle fake rumours for financial gain. His investment was unleveraged, but it was sold at a modest profit.

After the rumours were confirmed as fake, the value of Omnium and Consols plummeted back to their previous level. The tracing began: following the money trail led back to the stockbroker, his noble nephew and others.

The trial before Lord Ellenborough LCJ was held in the Court of the King’s Bench in the Guildhall – he was a High Tory political opponent of Reform-aligned Cochrane. The defendants were convicted of conspiracy to defraud (R v De Berenger (1814) 3 M. & Sel. 67). The evidence was hotly contested with considerable time spent determining the colour of the coat that one conspirator was wearing on entering and exiting Cochrane’s London house.

Having been convicted by the jury along with the other defendants, Cochrane refused to pay the £1,000 fine (£67,800 in today’s money) and was incarcerated. He eventually used his physical prowess to climb out of his jail cell and walked into the House of Commons debating chamber! His friends and family raised the money to pay the fine and the cheque is still held in the museum of the Bank of England. His public degradation was complete when at midnight outside the Bath Chapel at Westminster Abbey, a proxy had his spurs hacked from the back of his boots – to symbolise the de-knighting of Lord Cochrane. The sentence of the pillory was never carried out.

Cochrane’s disgrace led to the end of his Royal Navy commission, but he was returned to Parliament with a landslide majority after a by-election and continued to serve as an MP. In 1817 he was recruited as Admiral of the Chilean Navy, gaining the trust of President Bernardo O’Higgins. Cochrane’s defeat of the Spanish forts at Valdivia in 1820 (with only one ship and 30 marines) was arguably the straw that broke the Spanish back and led to their retreat from Chile and surrender of it as a colony.

After similar adventures in Brazil and Greece Cochrane’s reputation was restored, he rejoined the Royal Navy, was re-installed into the Order of the Bath, knighted by Queen Victoria and ended his career as Admiral of the Red. He was buried with full honours in the nave of Westminster Abbey, aged 85.

The tale from over 200 years ago has common themes today. It was a conspiracy where misrepresentations which were untrue and misleading were spread for financial gain, thus prejudicing the rights of market participants.

Threats and opportunities for good and evil arise with Artificial Intelligence (AI).
Going back to 2011, the FBI in the United States were prime movers at using the justice system in taking down Trojan botnets (e.g. Coreflood). This malware was described in civil proceedings against criminal operators as “inherently criminal in nature”. Service of proceedings was to email addresses. Default judgements were entered after no notices of intention to defend proceedings were filed. The court order permitted the FBI to divert the product of the hacks into its own servers, away from the fraudsters’ command-and-control servers.

Education as to the dangers of unknown hyperlinks is crucial in combatting sophisticated fraudsters. A virus enters a computer network or individual device (perhaps by the user clicking an infected link) and then either the operator takes control of the system, or key-strokes are logged and transferred to command-and-control servers, allowing the hacker to see all operations on the system (including passwords, and other confidential material etc).

In May 2025 the same technique was used in the U.S. by the FBI and CISA (Cyber and Infrastructure Security Agency) to take-down the LummaC2 malware network by targeting 2,300 web domains and command-and-control servers. Whether AI was used by these agencies and the U.S. Department of Justice and Microsoft to identify any of the domains or servers is not known. The FBI linked LummaC2 to 1.7 million instances of stolen personal data.

The advent of AI increases the dangers of bot enabled misrepresentations via deepfakes, targeted at retail investors, as Martin Wolf, the Chief Economics Commentator at the Financial Times has discovered. He wrote an article published on 2nd May 2025 in the FT, having discovered that an avatar alter ego is pumping fake investment advertisements on Facebook and Instagram. 1,700 of them, reaching at least 970,000 users. He speaks about his shock at being an unwitting instrument of the scammers, but also the challenge of working with Big Tech to remove these deepfakes.

The victims are the unwary – believing the deepfake to be true and thus buying just as the fraudsters with guilty knowledge are selling.

Can AI be used to help law enforcement trace the transactions linked to the deepfakes – watching for market movements in the sequence “buy – pump market with deepfake – sell”? But how can one distinguish those innocent traders acting on market data (trading on anomalies in the market), and those with fraudulent insider knowledge? Observing and pattern-matching trades by regulators would seem to be the solution – but with Black Box (fully automated trading strategies) using algorithms for high-frequency trading, how would any connection be observable between the deepfake pump and the overlapping transaction?

Big Tech must have the wherewithal to develop and use AI technologies to spot, report and take down deepfakes of the Martin Wolf variety (and any other fake news that can move either an individual stock or the market as a whole). There will always be an adaptation race between fraudsters and the those whose duty it is to secure the integrity of the market and to keep our confidential material safe and secure.

At a simplistic level, a fraudster needs to know in advance that fake news is about to be proliferated in order to take advantage of it (like in frontrunning). This requires communication and networks of co-conspirators which can be penetrated.

Do law enforcement agencies then need to take a dual approach, relying on old-fashioned human intelligence – with informants, whistleblowers and even agents within trading floors? The role of the CHIS [covert human intelligence source], the circumstances of their gathering of information and any financial incentives are all factors to be considered when any prosecution is envisaged, with the usual range of issues arising. Is material disclosable to the defence team? Can a prosecution even commence without particular material which must be kept secret to protect a source? Could material evidence be argued out as unfair and so inadmissible, e.g. where an informant is incentivised to lie or exaggerate for financial reward?

But what happens when agentic AI is used by fraudsters whereby “it” solves complex problems and makes decisions autonomously without human oversight (with its own “agency”).

Could it become capable of proliferating deepfake news and trading algorithmically without human intervention? The human who sets up the system is no doubt guilty of fraud, by setting in motion the deepfakes – and collecting the proceeds of the crime. But the age-old issue is one of detection.

IBM describes agentic AI as having “the potential to revolutionize trading strategies by analysing market data and expediting executing trades. The extended reach of agentic AI is a significant benefit as agentic AI can be designed to search the web extensively. Agents are able to retrieve updates and obtain real-time information.”

Described as the next threat evolution, agentic AI may also be used in new, sophisticated ransomware attacks.

The tools that cybercriminals have are evolving in parallel with those of traders in the financial markets and law enforcement agencies.

Northumbria University has recently launched its Centre for the Responsible use of AI. Within the University’s School of Law is its PROBabLE Futures research programme (Probabilistic AI Systems in Law Enforcement Futures) which is a four-year, £3.4M Responsible AI UK funded Keystone Project leading Glasgow, Northampton, Leicester, Newcastle and Cambridge Universities.

“Our project, working alongside our law enforcement, third sector and commercial partners, is developing a framework to understand the implications of uncertainty and to build confidence in future Probabilistic AI in law enforcement, with the interests of justice and responsibility at its heart. Activities include mapping the AI ecosystem in law enforcement, including the use of large language models; developing guidance, checklist and frameworks to guide assessment of scientific and legal validity, and mock trials with AI outputs as evidence.”

The challenge for law enforcement and prosecutorial agencies together with financial regulators is that the evolution of criminal enterprises proceeds unhindered by ethical safeguards, constraints and considerations. But ensuring only the guilty are convicted is a paramount objective of our criminal justice system and so equality of arms demands fairness for defence teams, including the use of AI in trial preparation, if such tools are to be used by prosecution agencies.

Is existing legislation still relevant where agentic AI is used to assist in the perpetration of frauds? Rather like using a monkey to burgle a house, the mens rea of the human when combined with the actus reus is what matters in law.

But take the provision of section 6 of the Fraud Act 2006: “A person is guilty of an offence if he has in his possession or under his control any article for use in the course of or in connection with any fraud.” Is an agentic AI software programme/ app under the control of a person if it is acting with its own agency?

Perhaps, but maybe it’s time for the law to get ahead of the technology for once.

Fortunately for Lord Cochrane, he inherited an earldom, had his spurs restored and regained his place among the firmament of Victorian Britain as a hero and liberator of the oppressed.

The failure of the justice system which contributed to his disgrace ironically had a much larger impact on world events than could possibly have been imagined by Lord Ellenborough LCJ sitting in the Guildhall in 1814, given Cochrane’s subsequent buccaneering adventures.

Robert’s article was published in Fraud Intelligence, 20 June 2025.



Share this: