July, 2026

The Consent Paradox in AI-Powered Payment Fraud Detection: Balancing Privacy and Security in India’s Digital Payments Ecosystem

The Consent Paradox in AI-Powered Payment Fraud Detection: Balancing Privacy and Security in India’s Digital Payments Ecosystem

India’s digital payments ecosystem has become one of the most transformative financial infrastructure developments globally. At the center of this transformation is the Unified Payments Interface (UPI), which has enabled instant, interoperable, and low-cost digital transactions at an unprecedented scale.

This scale, however, has also created a complex challenge. The same characteristics that make digital payments efficient - speed, convenience, and seamless connectivity - have also expanded the potential attack surface for fraud. Fraudsters have moved beyond traditional methods such as credential theft and unauthorized access towards sophisticated techniques including social engineering, account takeover, synthetic identities, and AI-enabled deepfake scams.

To counter these evolving threats, financial institutions and payment ecosystem participants are increasingly relying on Artificial Intelligence (AI) and Machine Learning (ML)-based fraud detection systems. These systems analyze behavioral patterns, transaction history, device information, network signals, and contextual indicators to identify suspicious activity in real time.

However, this creates a fundamental question: how can organisations use extensive behavioral data to protect individuals from fraud while respecting individuals’ privacy rights? This question has gained importance with India’s evolving data protection framework under the Digital Personal Data Protection Act, 2023 (DPDP Act), which places consent, purpose limitation, data minimization, and accountability at the center of personal data processing.

The challenge lies in balancing two equally important objectives - protecting individuals’ privacy and protecting individuals from financial harm. This blog explores how AI-based fraud detection works, why behavioral analytics has become central to payment security, and how India can develop a responsible approach towards AI-enabled fraud prevention.

Over the past decade, India has built and scaled a digital payments system that now touches nearly every transaction in the country, from street vendors to large institutions. The Unified Payments Interface (UPI) has enabled instant, interoperable, and accessible digital payments at an unprecedented scale, making it one of the most significant components of India’s digital public infrastructure. Over the years, UPI has evolved from a payment mechanism into a critical layer of India’s digital economy, enabling seamless transactions between individuals, businesses, and institutions. UPI completed ten years in April 2026, and the scale it has reached is striking. In the financial year 2025-26 it processed about 24,162 crore transactions worth around ₹314 lakh crore, a nearly 12,000-fold jump in volume over the decade (i). In March 2026 alone it set a monthly record of about 22.6 billion transactions, and on an average day it now handles close to 66 crore payments (ii). The International Monetary Fund has recognized it as the world's largest real-time payment system by volume, and it accounts for nearly 49% of all real-time payments made anywhere in the world. Behind every one of those payments there is a chain of players involved such as network operators, banks, payment apps and merchant platforms. Each captures a small piece of how an individual spends and transfers the money. The way this data is spread across many participants which helps make the system fast and reliable. However, at the same time, it also leaves it exposed to a risk of fraud on a large scale.

Two equally significant public interests now intersect within the digital payment ecosystem. The first is the protection of privacy and personal data under India’s Digital Personal Data Protection Act, 2023. The second is the prevention of financial fraud, which increasingly relies on AI-driven systems capable of analyzing behavioral patterns and detecting anomalies in real time. These systems learn from a large amount of data collected across many institutions over time, and they are expected to act instantly.

This blog examines the structural tension between them, identifies the consent convergence imperative and argues that it is resolved not by subordinating one interest to the other, but by designing governance precise enough to hold and protect both at the same time.

The Data Trail Behind Every Digital Payment

Source: Ministry of Finance, GOI

Every fast payment leaves a trail. For example:

Every digital payment creates a data trail. While a transaction may appear instantaneous to a user, multiple participants operate behind the scenes - including payment applications, banks, payment infrastructure providers, and merchant service providers.

During this process, different entities process information necessary to authenticate transactions, prevent fraud, manage risks, and ensure secure payment operations. It passes from the app to a sponsor bank, across the UPI switch operated by NPCI, to the beneficiary’s bank, and back in under a few seconds. Along the way, the device’s identifiers, the user’s location and network, the timing, the beneficiary’s history, and the amount relative to the payer’s usual pattern are all observed, logged or scored by one or more participants.

Use Case: The data journey of one transaction.

A salaried worker in Pune pays ₹180 to a roadside vendor at 8:40 in the morning. Her app records the phone and the session. Her bank logs the payment and keeps a tally of how often she pays. The UPI network notes where the money went and whether anything looks unusual. The vendor’s bank records the credit and ties it to a small-business account.

None of these entities sees the whole picture, yet together they hold a remarkably complete behavioral portrait of the user.

This fragmented data environment also raises an important design question: whether fraud detection requires centralized access to complete behavioral profiles, or whether equivalent security outcomes can be achieved through privacy-preserving approaches. Emerging PETs provide one possible pathway by enabling organisations to derive analytical insights while reducing direct exposure of personal data.

Autopay:

The trail is not limited to one-off payments. Once a user sets up a UPI AutoPay mandate for a ₹199 monthly streaming subscription, the permission is given once but acted on every month: each recurring debit, along with its timing and amount, is recorded by the payer’s bank, the merchant’s bank and the app. When a user makes a payment for a credit card bill, or swipes a card, the transaction passes through the merchant’s acquiring bank, the card network and the card issuer, each of which scores it for fraud against the cardholder’s usual spending. As with a single UPI payment, no one participant sees the whole picture, but together they capture the pattern of a person’s financial behavior in detail.

Understanding the Account Aggregator framework

There is another side to this story. When India wants financial data to move with the individual firmly in control, it has shown it can build exactly that. The Account Aggregator framework lets a person gather their financial information, such as bank accounts, investments and loans, and share it with a provider of their choice, like a lender or wealth manager, only with their clear, time-bound permission. Licensed Account Aggregators act as neutral intermediaries that move the data in encrypted form without reading or storing it, leaving the individual in control of what is shared, with whom, and for how long. Launched in September 2021 and built on the RBI’s groundwork from 2016, the framework has already enabled more than 2.2 billion financial accounts for consent-based sharing, with over 112 million users having linked their accounts, and it now serves as the data-exchange layer of India’s digital public infrastructure, alongside Aadhaar for identity and UPI for payments. The contrast is the heart of the matter: payments scatter data across many hands, yet the same system can also move data with the individuals’ permission front and center, which is exactly what makes fraud detection such a hard exception (iii).

The Account Aggregator framework demonstrates that data-driven innovation does not necessarily require unrestricted data access. A similar philosophy can inform AI-based fraud detection systems through privacy-preserving architecture, where insights can be generated without requiring unnecessary replication or disclosure of underlying personal datasets.

How fraud exploits speed

The very speed that makes the system useful also shrinks the time available to stop a fraud. Once an instant transfer goes through, getting the money back is hard, and often impossible. Fraudsters have learned to exploit exactly this, and four main types of attack now stand out.

The first is social engineering, also called authorized push payment (APP) fraud, where the victim is tricked into making the transfer themselves. Since everything checks out, the right password, the right authentication, the usual rule-based alarms stay silent. The second is account takeover, where someone gains control of a person's login or device. The third is synthetic identity fraud, where a fake identity is built up slowly until it can pass the usual checks. The fourth, and the most damaging to trust, is deepfake fraud, where a cloned voice or video is used to fool the human verification.

How Fraud Has Evolved in the Age of AI: Key Use Cases

1. The digital arrest scam

A retired individual receives a video call from a person claiming to be a law enforcement official. The caller falsely informs the individual that their identity has been linked to a criminal investigation and creates a sense of urgency and fear. Over an extended conversation, the victim is persuaded to transfer funds for ‘verification’ or ‘security purposes’.

From a fraud detection perspective, the transaction may appear legitimate. The customer has authorized the payment, and there may be no compromise of credentials or device.

The challenge for financial institutions is identifying behavioral indicators that suggest potential manipulation - such as an unusual transaction amount, a new beneficiary, an unexpected payment pattern, or activity that differs significantly from the individual’s historical behavior.

2. The cloned voice call

A bank employee receives a call from someone appearing to be an existing customer requesting an urgent transaction. The voice has been artificially generated using publicly available audio samples.

In such scenarios, voice-based authentication alone may not be sufficient. Fraud detection systems need to consider broader contextual indicators:

  • Does the request align with the customer’s usual transaction behaviors?
  • Is the transaction being initiated through a familiar channel?
  • Is the beneficiary consistent with previous activity?

This demonstrates why modern fraud prevention is increasingly moving beyond authentication-based controls towards behavioral and contextual analysis.

3. The patient’s fake identity

Fraudsters may gradually build synthetic identities by combining genuine and fabricated information to create profiles that appear legitimate during initial verification processes. Over time, such identities may develop transaction histories that resemble genuine customer behavior.

The limitation of point-in-time verification is that it may not identify risks that emerge over a longer period. Detecting synthetic identities often requires analyzing behavioral patterns over time and identifying inconsistencies across multiple data points.

AI-based systems can assist by identifying patterns that may not be visible through traditional rule-based verification mechanisms.

4. APP Fraud

APP fraud presents a unique challenge because the customer often actively authorizes the transaction. The payment may appear legitimate because authentication has been successfully completed and the transaction has been initiated through valid channels (iv).

Unlike traditional fraud scenarios involving stolen credentials or compromised devices, APP fraud often depends on manipulation and social engineering. Identifying such fraud requires understanding whether the transaction is consistent with the individual’s usual behavior or represents an unusual deviation.

As fraud techniques evolve, prevention is increasingly shifting from merely verifying credentials to analyzing behavioral and contextual signals. However, this also creates an important privacy question: how can organisations use behavioral insights responsibly while ensuring lawful, proportionate, and transparent processing of personal data?

Beyond Detection: The Changing Nature of Fraud Prevention

The evolution of digital fraud demonstrates a fundamental shift in the security landscape. Earlier fraud prevention approaches focused primarily on identifying unauthorized access - a stolen credential, a compromised device, or an unfamiliar login attempt. However, many emerging fraud scenarios involve authorized transactions initiated through legitimate channels.

This changes the role of fraud detection systems. The objective is no longer limited to answering ‘Was this transaction authenticated?’ but increasingly involves answering ‘Does this transaction make sense in the context of this user’s behavior?’

Privacy Enhancing Technologies: Enabling Responsible AI-Based Fraud Prevention

The central challenge in AI-driven fraud detection is not merely the availability of data, but the manner in which data is accessed, processed, shared, and retained. Traditional fraud analytics often depend on collecting large volumes of behavioral and transactional information, creating risks of excessive data concentration and secondary use.

Privacy Enhancing Technologies (PETs) provide a technical approach to addressing this challenge by enabling organisations to extract value from data while reducing unnecessary exposure of personal information.

Key PET approaches relevant to payment fraud detection include:

1. Federated Learning

Federated learning enables AI models to be trained across multiple institutions without requiring raw customer data to be transferred to a central repository. In a payment ecosystem involving multiple banks, payment applications, and infrastructure providers, this approach can allow institutions to collaboratively improve fraud detection models while keeping underlying transaction data within their respective environments.

2. Differential Privacy

Differential privacy introduces statistical protection that minimizes the possibility of identifying individuals from analytical datasets. This can support fraud research, model improvement, and ecosystem-level analysis while reducing risks associated with behavioral profiling.

3. Secure Multiparty Computation (SMPC)

Secure multiparty computation enables multiple entities to jointly analyze information while keeping their individual datasets confidential. In payment fraud detection, this could support collaborative identification of fraud patterns across institutions without requiring unrestricted sharing of customer-level information.

4. Privacy-Preserving Analytics and Data Minimization

Organisations can also adopt privacy-preserving analytics techniques that prioritize the use of only necessary data attributes, limit retention periods, and reduce dependence on detailed behavioral histories where less intrusive signals may achieve the same security objective.

PETs should not be viewed as a replacement for governance obligations under the DPDP Act, but as an operational mechanism to implement principles such as data minimization, purpose limitation, and privacy by design.

Conclusion

AI-driven fraud detection systems attempt to address this challenge by analyzing multiple signals, including transaction patterns, device information, beneficiary relationships, historical activity, and contextual indicators. The purpose is not to predict every transaction as fraudulent, but to identify unusual patterns that may require additional scrutiny or intervention.

However, this approach introduces a new dimension to the privacy discussion. Behavior-based fraud prevention requires analyzing patterns over time. Unlike a single transaction check, it depends on understanding relationships between multiple data points and identifying deviations from established behavior. This creates a delicate balance. The same data that helps protect individuals from financial harm can also reveal detailed insights into their financial behavior, habits, and interactions.

The question, therefore, is not whether AI should be used in fraud prevention. The more important questions are:

  • What categories of data are necessary and proportionate for effective fraud detection?
  • How can financial institutions ensure that behavioral analysis does not become excessive monitoring?
  • What level of transparency should individuals receive when AI systems assess their transactions for risk?
  • How can organizations maintain accountability when fraud decisions are influenced by automated systems?
  • What safeguards are required to ensure that privacy rights remain protected while preventing financial harm?

As digital payments continue to scale, trust will depend on the ability to build fraud prevention systems that are not only intelligent, but also transparent, accountable, and aligned with privacy principles. The future of digital payment security will not be defined merely by how much data systems can analyze, but by how responsibly that data is used.

This responsibility will increasingly depend on combining legal safeguards with technical innovation. PETs offer a pathway towards building AI fraud prevention systems that are not designed around maximum data collection, but around maximum-security outcomes with minimum privacy intrusion. The future of trusted digital payments will therefore depend on aligning governance, accountability, and privacy-preserving technology to ensure that security does not come at the cost of individual autonomy

Liza Vanjani is a Senior Associate with the Privacy and Policy Team at DSCI, working across Global tech policy, privacy and security, government engagement, cyber law, DPI, and digital payments regulation. She can be reached at: liza.vanjani@dsci.in or policy@dsci.in.

Author: Liza Vanjani