The AI fraud swarm is coming for your benefits

AP26260139104766_4aa97d.jpg


This week, the Australian prime minister revealed that an OpenAI agent had gained unauthorized access to a Medicare statistics portal run by Services Australia, the agency that administers the country’s health benefits. The agent wasn’t caught in the act. Nobody at Services Australia knew it was there. The country only found out because OpenAI disclosed it, three months after the fact.

Right now, most government systems can’t tell they’re talking to a machine at all. Not a good one, not a bad one. None. A benefits portal built to recognize a person filling out a form has no equivalent instinct for recognizing an agent doing the same thing at a thousand times the speed. It just sees a completed application.

A year ago, I publicly stated that the AI fraud crisis wasn’t coming. It was already here: deepfakes, synthetic identities, convincing documents produced at extraordinary speed. That problem hasn’t gone away. But something more dangerous is emerging behind it, and Washington is not ready.

Consider what an agent already does: finds the ticket, compares the fares, fills out the forms, and completes the purchase. The internet is shifting from a place where people use software to one where software acts on people’s behalf. Now point that capability at a Medicaid application, a SNAP enrollment, or a Social Security claim.

An agent that can do those things for an eligible citizen can do them for a criminal. And unlike a bot, an agent doesn’t follow a script. It pursues a goal. Get this application approved. Find what’s missing. Answer the follow-up. Correct the error. Try again. Keep going. Put that in the hands of an organized fraud ring, and it isn’t any better of a bot. It’s a workforce, one that never sleeps, never takes a vacation, and gets better at navigating the government’s defenses with every attempt, all while the system on the other end has no idea it isn’t talking to a person.

The exposure is documented. The U.S. federal government is losing an estimated $1 trillion a year to fraud, roughly $115 million every hour. The Government Accountability Office has flagged weak controls, fragmented data, and limited fraud-management capacity across exactly the state-administered programs an agent swarm would hit first.

The theft may not even be the worst of it. A swarm doesn’t need to steal a dollar to do damage; it only needs to consume capacity. Picture thousands of agents filing applications, uploading documents, and appealing rejections around the clock, invisible to a system that has no way to separate them from real applicants. An elderly person trying to fix a Social Security problem is suddenly competing with machines that can generate more interactions before lunch than a person could in a year. A mother legitimately applying for SNAP gets stuck behind a wave of automated filings no human fraud ring could have produced.

Here is the complication: the same technology is a genuine public good. Agents are already helping people complete benefit applications in days instead of weeks. That is worth protecting, not banning. The government has to be able to tell an agent working for an eligible American from one working for a criminal, and right now, it can’t even reliably tell that an agent is there at all.

That means Washington needs to answer a basic question immediately: Will AI agents be allowed to apply for government benefits on someone’s behalf, and under what rules, and how will an agency even know one has shown up? Almost no program has seriously grappled with either question. We need answers before criminals supply their own.

Enforcement alone won’t get us there. The White House Task Force to Eliminate Fraud, led by Vice President JD Vance with Scott Brady as executive director, deserves credit for elevating fraud as a national priority. But you cannot arrest an agent. If one criminal network can deploy a thousand agents at once, prosecuting fraudsters one at a time, after the money is gone, is arithmetic the government will eventually lose.

Prevention has to run at the speed of the attack. That means knowing who, or what, is on the other end of every application, the very thing Australia’s Medicare system couldn’t do until it was too late. The private sector is solving its version right now; Visa, Mastercard, and Ant International each already run an agent-identity protocol of their own, and they are now working to make them interoperate. Washington needs the equivalent: a digital passport for machines. A person authorizes an agent for a defined task. That agent carries a cryptographic credential stating who it is, who authorized it, what it may do, and for how long. The agency verifies it the instant the agent shows up, instead of finding out three months later that one already had.

AI IS ALREADY BREAKING OUT OF THE LAB. TRUMP’S RED PHONE WON’T STOP IT

That is a far sturdier proof than an uploaded photo of a driver’s license, now that a photo, a voice, or a signature can be manufactured convincingly and cheaply. When done well, it even improves privacy: instead of handing an agency every sensitive document a citizen has, the agent proves the one fact the transaction requires. The agency gets its proof. The citizen reveals less. The criminal’s problem gets much harder.

If we wait, agencies will discover this the way Australia just did: after the fact, from the company that built the agent, not from their own systems. The swarm is coming to a benefit program near you. We can keep swatting fraudsters one at a time, or we can build the screen door before the swarm arrives.

Haywood Talcove is the CEO of the Government Group at LexisNexis Risk Solutions, where he works with federal and state agencies on fraud prevention.

Continue reading...

[ H/T Washington Examiner ]

Comments

There are no comments to display
Back
Top