The scammers are going synthetic. In one lab, the machine beat the humans.

A four-university research team ran an uncomfortable experiment. Over seven days of text conversations, participants were courted either by trained human operators, recruits from the lead author’s university given six hours of coaching in the scammers’ playbook, or by an AI agent running that same playbook, with everything ending in a request to install an app of unknown provenance. The AI got 46 percent of its targets to comply. The humans got 18. The preprint, which Accounting Today covered this week, reports that participants also rated the machine higher on emotional connection and trust than the human operators.

Now the caveats, because this is one small study and we read it so you can weigh it. Twenty-two participants, digitally literate and mostly degree-holding, a compressed seven-day window against scams that normally unfold over months, a benign app standing in for a real financial ask, and a human baseline of coached recruits rather than seasoned criminals, a gap the authors flag themselves. One point in the study’s favor: it has since been accepted at the 2026 USENIX Security Symposium, a peer-reviewed venue. The researchers’ conclusion is carefully worded and still unsettling: romance-baiting “may be amenable to full-scale LLM automation, while existing defenses remain inadequate to prevent their expansion.”

If your reaction is that romance scams are not an accounting problem, look at what the mechanics actually are: build rapport by text, establish trust, then convert trust into an action. That is also the anatomy of business email compromise, the fake-vendor call, and the urgent wire request from the “CEO.” The FBI’s 2025 Internet Crime Report counted 24,768 BEC complaints with just over $3 billion in reported losses, notes that chat generators “can quickly create official-sounding emails mimicking a company’s CEO or other officials,” and tallied 22,364 complaints involving AI with losses above $893 million. The lab result and the field data point the same direction. Manipulation is becoming software, and software scales.

Here is what the study quietly breaks: every control that depends on a human sensing something off. Anti-fraud training teaches staff to spot the awkward phrasing, the odd hour, the pressure tactic. The subjects in this experiment trusted the machine more than the trained human operators, and the machine never gets tired, never breaks character, and can hold ten thousand conversations at the price of one. If coached recruits with a week and a playbook lose to the model, the case that a seasoned criminal outfit armed with the same model does better, not worse, writes itself. Betting your payment controls on someone’s gut feeling now means betting against an opponent specifically optimized to feel right.

The defense is not sharper instincts. It is process that does not care how convincing the conversation was. A callback to a known number, from your own records, before any change to vendor banking details. Dual authorization above a threshold, with no exception for urgency, because urgency is the tell. Treating every inbound channel, email, text, even voice, as unauthenticated by default. None of this is new advice; what is new is that the case for it no longer rests on the clumsy scammer. It rests on the competent one. There is a certain irony that regulators are now mandating machine-readable labels on AI content, as we covered Tuesday; labels help honest actors disclose, but nobody running this playbook will volunteer one.

The bottom line: the person on the other end of the chat may now be nobody at all, and more persuasive for it. Which is exactly why the boring machinery of accounting, the callback, the second signature, the segregation of duties, is having a moment. AI can do the work, including the con artist’s work. It cannot sign the work. Keep the signature, the authorization that moves actual money, behind a process no conversation can talk its way through, and the most charming bot in the world is just text on a screen.

Footnote

Footnote is an independent publication. It is not professional accounting, tax, or legal advice. The study described is a preprint since accepted at the 2026 USENIX Security Symposium, cited with the limitations its authors acknowledge; FBI figures are from the 2025 IC3 report. Details are current as of August 7, 2026.