Threat of Adaptive AI Amidst Indonesia's Surge in Digital Payments
Financial institutions in Southeast Asia are entering a new era of risk management. Recent regional analyses reveal a significant shift as lenders begin delegating crucial decisions regarding credit, fraud detection, and compliance to autonomous artificial intelligence (AI) systems. However, this transition is accompanied by increasingly sophisticated threats from cybercriminals.
Attackers are reportedly using low-value trial transactions to train their evasion tactics. This method aims to test system responses and reduce the effectiveness of the traditional controls that financial institutions have long relied upon.
This phenomenon is particularly relevant to Indonesia. The expansion of real-time payment infrastructure, such as BI-FAST, and the massive adoption of QRIS have pushed digital transaction volumes to record highs. Based on projection data, Indonesia’s digital payment ecosystem is showing extremely rapid growth.
Dr Simon Liu, Chief Data and AI Officer at TrustDecision, highlighted that the use of AI by cybercriminals allows them to personalise communications and automate behavioural changes instantly. “The biggest shift is that fraud is now becoming faster, more adaptive, and more personalised,” he stated.
According to Liu, attackers can modify tactics with a speed that traditional rule-based systems cannot handle. These advanced threats often involve coordinated sequences of actions that build a victim’s profile slowly before executing an attack once a system vulnerability is identified.
Responding to this complexity, the Financial Services Authority (OJK) published a document titled “Indonesian Banking Artificial Intelligence Governance” on 29 April 2025. This regulation serves as a compass for financial institutions to adopt AI technology safely.
OJK emphasised the importance of comprehensive end-to-end governance throughout the entire AI lifecycle, as well as the use of more advanced fraud detection tools to close gaps between various banking systems and processes.
To combat evolving attack patterns, financial institutions in Indonesia are now looking towards an integrated approach. This strategy combines device intelligence, behavioural analysis, and network-level visibility into a single, unified decision-making framework.
By integrating fraud, credit, and compliance functions, banks are expected to detect coordinated threats more rapidly. This move aims not only to protect customer assets but also to meet the strict compliance standards set by regulators amidst an increasingly dynamic era of financial digitalisation.