Reports tagged as involving artificial intelligence reached 956 in the 2025–26 financial year, a 395 per cent rise on the year before, and the losses attached to them climbed from £1.2 million to £9.6 million. The figures sit inside a City of London Police intelligence assessment on emerging fraud trends, released as the national reporting service completed its move from the Action Fraud name to Report Fraud.

Both numbers matter for what they leave out as much as for what they record. The assessment is the first full-year snapshot from the renamed service, and it lands in a week when the UK's wider arrangements for overseeing AI were being questioned in public.

What the assessment confirms

Three things are on the record. First the volume: 956 reports that analysts tagged as AI-related, against a substantially smaller base in FY24–25. Second the money: £9.6 million in reported losses, roughly eight times the prior-year figure. Third the mechanism, at least in outline — the assessment points to deepfake endorsement and voice cloning as the recurring techniques inside that caseload.

Deepfake endorsement fraud uses synthetic video or audio of a known figure — a broadcaster, a business leader, a public authority — to lend an investment or crypto pitch the appearance of authority it does not have. Voice cloning runs the other way: a short sample of someone's speech is enough to generate a convincing instruction to move money, whether the target is a bank's call centre, a relative or a finance team under time pressure.

What the 395 per cent does not mean is that AI-enabled fraud grew 395 per cent in a year. The change reflects two things moving at once: more incidents, and a service that has become better at identifying AI involvement in the reports it already receives. A rise measured from a low base produces large percentages, and 956 reports are a subset of the fraud volume the service handles, not a total.

Who holds the file

Fraud reporting in the UK runs through City of London Police, the national lead force for economic crime, which operates the reporting service and the National Fraud Intelligence Bureau that assesses what arrives. Reports are turned into intelligence packages and disseminated to forces across the country, but the bureau itself does not investigate individual cases — a division of labour that has long left victims unsure who is acting on what they submitted.

Further out, responsibility is crowded. Ofcom carries online safety duties under which fraud is a priority offence, the Financial Conduct Authority polices investment promotions and authorised firms, payments regulators and banks handle reimbursement questions, and the Home Office owns policy. Since the Department for Science, Innovation and Technology was wound up and the planned pre-release testing work for frontier models lapsed, no single department has been steering the AI-specific response.

The Ada Lovelace Institute published its own set of UK regulatory options on 25 September, weighing binding rules against the lighter-touch regime that has run since 2023. That argument is largely about model development, measuring and disclosure. Fraud sits downstream of it, and none of the options on the table settles who enforces against AI-assisted impersonation at the point a victim loses money.

What is still unknown

The published account does not yet break the 956 reports down by region, age, channel or loss per case, and it does not say whether AI-tagged means the offender used AI tooling, or the report was surfaced by an AI triage tool. Those are different measurements, and they point to different remedies.

Also open: how many of the £9.6 million in losses were recovered or reimbursed; whether any of the cases have produced a charging decision; and what share of the UK's total fraud bill this caseload represents. On the second question, the answer so far is silence, and the assessment makes no claim about prosecutions.

For readers treating the number as a warning rather than a statistic, the operational advice has not changed with the technology. Treat urgency as the tell, verify any payment instruction through a number or contact route you already held, and report what happened to Report Fraud even when the money is gone — the tagged caseload that produced this assessment is built from exactly those submissions. Whether next year's figure reflects more fraud or better detection will depend on which of the two moved first.