Inscribe says AI is under 5% of document fraud. AppZen says 70.8%. Both are right.

One of them counted every fraudulent document a lending pipeline flagged. The other counted flagged fraudulent expense receipts. The gap between the two numbers is not a disagreement about the world.

Reference: PDF fraud signals — the field guide

Two companies that detect document fraud for a living published a figure this year for how much of the fraud they see is AI-generated. Inscribe said less than 5%. AppZen's figure is 70.8%. Both are dated, both come with a stated method, and both are correct.

Start with the sentence in the headline, because it is mine and not theirs, and it is already wrong in the specific way this whole post is about. Inscribe did not say AI is under 5% of document fraud. It said AI-generated documents were under 5% of the fraudulent documents its own network detected in lending in 2025. AppZen did not say 70.8% of expense fraud is AI. It reported that 70.8% of the fraudulent receipts its customers' expense reports had flagged were AI-generated. Put the denominators back and the contradiction disappears — along with, unfortunately, most of the headline.

I have no stake in which number is larger. I build a PDF fraud-signal engine and I sell neither an AI-detection model nor a lending platform, so the only thing the answer changes for me is what I tell people the threat actually looks like. What follows is the two measurements as published, why the distance between them is exactly what you should expect, and what happens to numbers like these on the way down the page.

What each company actually counted

Inscribe, 2026 State of Document Fraud Report, published 20 January 2026. The method is stated in the report and it is genuinely three-source: detection data from the Inscribe network “spanning millions of documents across banks, credit unions, fintechs, and lenders”, a survey of 90 fraud and risk leaders conducted in November and December 2025, and interviews with 15 practitioners. Within the fraudulent documents it detected, AI-generated documents were less than 5% — “the majority of document fraud is still template-based.”

AppZen, reported by PYMNTS on 26 June 2026. By mid-May 2026, 70.8% of flagged fraudulent expense receipts were AI-generated, from 1,471 AI-generated fake receipts submitted by 745 employees at 174 companies. In March 2025 the same figure was 0%.

InscribeAppZen
What is in the denominatorfraudulent documents flagged across its lending customersflagged fraudulent expense receipts
Document classesbank statements, pay stubs, tax forms, business filingsreceipts
Who submits themloan and account applicantsemployees claiming reimbursement
Period2025March 2025 to mid-May 2026
Sample disclosed“millions of documents”, plus n=90 survey and 15 interviews1,471 receipts, 745 employees, 174 companies
Published20 Jan 2026reported 26 Jun 2026
AI shareunder 5%70.8%

Nothing in those two columns describes the same population. They do not share a document class, a submitter, a review process or a year. The only thing they share is the phrase “document fraud”, which is doing an enormous amount of unpaid work.

A share is a ratio, and both sides of it move

A share can change because the numerator grew or because the denominator was small to begin with. These two numbers are a clean demonstration of the second case, in both directions.

Lending documents already had a forgery problem that worked. Inscribe's own measure of it: template-based fraud accounted for 1 in 5 flagged documents in 2025, up from 1 in 14 in 2024, and 91.2% of flagged documents carried edits to financial details. A forger arriving with a generative model in 2025 was not entering an empty category. It was competing with a method that already clears the control, in the hands of people who already know how to use it.

Where I have to stop short

The story usually told around that number — that pay-stub and bank-statement forgery has been industrialised by commercial operations for years — is one I went looking for a primary source on and could not find. No prosecution, no court record, no regulator's count of the generator sites; the sites operate openly, selling “templates” and “novelty” documents, and what enforcement exists appears to target borrowers rather than mills. Vendor commentary is the only source I found. The share is measured. The explanation for it is a hypothesis, and it is mine, not Inscribe's.

Expense receipts had almost no sophisticated forgery to displace. A receipt is small, unstructured, low-value and reviewed by a manager in a hurry. Before image models, faking one convincingly was either tedious or unnecessary — you kept a receipt from a personal dinner, or you edited a photograph badly and it worked anyway. AppZen's own series records the starting point: in March 2025, 0% of the fraudulent receipts it flagged were AI-generated. Then a general-purpose tool arrived that produces a plausible receipt for nothing, and it took very nearly the whole category, because there was no incumbent method to take it from.

That is the entire mechanism. Where a document class had no working forgery method, the first cheap one takes almost all of it. Where a document class already had one, the new arrival is one entrant among several. Under 5% and 70.8% are what those two situations look like when you divide.

A growth rate is not a share, and Inscribe published both

The same January report contains a second number: AI-generated document fraud, measured as monthly volume across Inscribe's network, rose roughly fivefold between April and December 2025. That figure and the under-5% share sit in one document and are both true, because they answer different questions. Fivefold is a statement about how fast a small base is growing. Under 5% is a statement about how small it still is.

Only one of the two ever travels. That asymmetry is most of the AI-fraud coverage of the last two years, and it is worth knowing how the rest of that genre is built. I went looking for the primaries behind “document fraud is up N%” and they converge on a handful of identity-verification vendors — Entrust, Sumsub, Smile ID — computing growth over their own verification traffic. That is their customers' onboarding funnels, not the economy, and the base is never published. One question dismantles all of them and it does not have an answer in print: up from what?

Which leaves a gap worth naming plainly, because it is the honest version of everything above: there is no dated prevalence baseline for AI-generated document forgery. Nobody has measured what share of submitted documents were AI-made, in any population, at any two points in time with the same method. What can be claimed is the measurement lag. Not the growth rate.

Both numbers count flags, and one company says so

Inscribe's word throughout its report is flagged. Roughly 6% of the documents processed on its network in 2025 were flagged as fraudulent — “roughly one in sixteen” — clustering between 4% and 7% across bank statements, pay stubs, tax forms and business filings. Flagged, not confirmed. It is a small piece of care and it is the reason theirs is the only vendor report I read this summer that I would quote at all.

It matters because every denominator in this market is the same kind of object: a vendor's own customer base — organisations that already bought fraud detection, self-selected toward the segments that have fraud in them. Two other companies publish a flag rate of their own. Snappt reported 6.4% of rental applications flagged fraudulent in 2024, from roughly five million documents on its own platform (via Multifamily Executive, 6 February 2025). Veryfi's blog puts a 7% fraud rate on a customer, in a case study that gives no sample size.

The convergence around 6–7% is genuinely interesting, and it is the closest thing this industry has to a prevalence figure. It is still not one. Not one of those three publishes how often it flags a document that was fine, so a 6% flag rate is compatible with a 3% true rate and a 6% true rate alike, and nothing published anywhere tells you which.

What happens to a number on the way down the page

By the time AppZen's figure reached me it had become “71% of expense fraud is AI-generated.” PYMNTS' own headline had already made the move — 70.8% of flagged fraudulent receipts became 71% of expense fraud — and the content sites downstream finished the job. One of them discloses, at the bottom, that it was produced by an “AI Editorial Desk”.

The edit is tiny and it changes everything: a share of the fraud somebody caught becomes a share of the fraud that exists. The first is a fact about a detection system. The second is a fact about the world, and no one has it.

Here is the same move with the arithmetic still visible. A figure you will find on fraud-vendor homepages, including one in my own market, is the “$130,000 average business email compromise incident.” The FBI's Internet Crime Complaint Center recorded 21,442 BEC complaints in 2024 with USD 2,770,151,146 in reported losses, restated in its 2025 Internet Crime Report alongside the 2025 figures. It publishes no average.

$ python3 -c 'print(round(2770151146 / 21442))'
129193
Somebody divided the two numbers IC3 does publish, rounded up to a friendlier figure, and everyone downstream copied the quotient. The complaints are voluntary and self-reported, so the base is not a count of incidents either.

The most-quoted statistic in the entire fraud industry is built the same way. “Organizations lose 5% of revenue to fraud each year”, and its $5.5-trillion global companion, come from the ACFE — who are completely transparent about it. The 5% is what surveyed Certified Fraud Examiners estimate; the trillions are that estimate projected against 2024 gross world product of $110.98 trillion. ACFE prefaces the section itself: “Calculating the global cost of fraud is an important, but incredibly difficult, task. The inherent elements of deception and concealment mean that the true prevalence and extent of fraud may never be fully measurable.” The laundering is entirely downstream — drop “CFEs estimate” and “projected”, and an opinion poll multiplied by a macroeconomic aggregate becomes a measured loss.

The test I run before quoting anything

A fraud statistic is probably laundered if any of these hold: it is a round number with no interval and no n; it is a global monetary total; you cannot find a publication date within two clicks; following the citation chain reaches another blog rather than a document; it conflates identity fraud with document fraud; it is a forecast presented as a current loss; or it comes from a company that sells the remedy and publishes no false-positive rate.

What is measured, by people with nothing to sell

Two things, and neither is a vendor's.

The detectors built for the previous era of document forgery score at or near chance on the new one. AIForge-Doc (arXiv, submitted 24 February 2026) assembled 4,061 forged document images from four public datasets across nine languages, manipulating numeric fields with current image models, and ran the standard detectors over them: DocTamper scored 0.563 AUC out of distribution against 0.98 in distribution, TruFor 0.751 against 0.96, and GPT-4o 0.509, which is chance. DocForge-Bench (2 March 2026) put 14 methods across 8 datasets and found a calibration failure running through all of them — high Pixel-AUC, near-zero Pixel-F1 — because the tampered region is only 0.27% to 4.17% of the pixels.

And per-case severity, in the category everybody is writing about, is going down. ACFE's Occupational Fraud 2026 puts the median loss from expense-reimbursement schemes at USD 36,000 across 306 cases; the 2024 edition put it at USD 50,000. Billing schemes: 90,000 against 100,000. Two different samples two years apart, not a panel, so that is suggestive rather than a trend — and it describes occupational fraud, an insider defrauding their own employer, which is not the same thing as an applicant sending a lender a forged statement. It is still 2,402 completed cases across 143 countries, and it points the opposite way to the marketing.

The number nobody in this market publishes

Every company in this market publishes something recall-flavoured: how much fraud it finds, how accurate it is, how fast the threat is growing. Several publish a headline accuracy figure with no definition, no base and no methodology attached, which is worse than publishing nothing. On 31 July 2026 I read the public pages of the nine companies in this market that publish detection claims at all — Resistant AI, Inscribe, Snappt, Ocrolus, Truv, Veryfi, DocuClipper, and the two structural-analysis vendors nearest to what I build. Not one publishes how often its system flags a document that was genuine.

That is the number a buyer pays for. A missed forgery costs you a loan. A false positive costs you a real customer, who was made to explain themselves, on a Tuesday, about a document that was fine — and you will never see the invoice for it. An industry that publishes only one side of that trade is publishing the easy half.

Mine are at /evidence, every figure carrying the engine version and the date it was measured at: false-positive rates on populations nobody curated, results reported per forgery operation rather than as one aggregate, and a null result published as a null result. The long version of how they were produced, including the four signal families I had to demote after measuring them, is in I measured my own false-positive rate on 1,728 documents nobody curated.

And the same discipline applied to my own side of the ledger: what I have is specificity. Every document in those populations was presumed genuine, so the measurement says how often the engine is wrong about innocent files and nothing at all about how often it is right about guilty ones. There is no public corpus of tampered PDFs to find out from — every benchmark in this space is pixel-level image forensics, and there is no structure-level equivalent, which also means no independent test can rank me against any company in this post in either direction. High precision, unknown recall. I am not going to put a number on the second one, and you should ask anyone who does what their denominator was.

Run it on a document of your own

The free checker takes a PDF and returns the signals with the raw evidence under each one — the revision chain, the producer strings, the bytes the finding was drawn from. No account, nothing stored, and no verdict: it reports what the file says about itself and leaves the conclusion to you.