Subscribe to get high-signal insights on how modern fintech is built.

ai & ml

When AI Can Fake the Receipt, Dispute Evidence Breaks

AI-generated fakes are already 70% of flagged expense fraud, and agent commerce is about to automate the resolution layer that assumes receipts are real.

By Alex Kugell ·

How do you prove a receipt is real?

For most of commercial history, you didn't have to. A receipt was a physical artifact, thermal paper from a register or a carbon copy from a credit card imprint. Fabricating one required effort that exceeded the value of most disputes. The economics of forgery protected the system.

That protection is gone. Generative AI can produce a receipt with the correct logo, formatting, tax calculation, itemization, timestamp, and transaction ID in under ten seconds. AppZen tracked over 3.5 million fake receipts generated on just the top four expense fraud websites in a six-month window. Google searches for "AI-generated receipts" rose 2,753% in a single year.

SensFrx reported that AI-generated receipts went from 0% of flagged fraud cases in March 2025 to 70.8% by mid-2026. No other category of document fraud has moved that fast.

AI-generated receipts as % of flagged expense fraud
0%20%40%60%80%Mar '25Mid '25Late '25Early '26Mid '26human detection accuracy (~55-62%)70.8%
SensFrx data

But the receipt problem runs deeper than expense fraud. Payment dispute systems, from credit card chargebacks to the agent commerce evidence protocols being designed right now, assume the receipt is authentic. When that assumption breaks, the dispute layer breaks with it.

The $893 million preview

The FBI included AI in its Internet Crime Complaint Center report for the first time in 2025. The numbers: 22,364 complaints, $893 million in losses. That's a floor, not a ceiling. IC3 only captures what victims report, and most receipt fraud never surfaces as a complaint to the FBI.

Signifyd's 2026 State of Fraud report shows the downstream pressure. Fraud in North America grew 33% year-over-year in the first four months of 2026. Account takeover is up 78%, card-testing attacks up 175%.

The category that matters most for dispute evidence is "item not as described," up 49%. Signifyd attributes the spike directly to AI-generated images of damaged goods submitted as dispute evidence. The fraudster fakes the entire evidence package: receipt, photo of the "damaged" item, shipping label.

In the UK, Cifas data shows AI-manipulated documents now account for more than 20% of falsified evidence in refund and chargeback disputes. Total UK fraud cases exceeded 444,000 last year. One in ten returns is estimated to be fraudulent.

Why detection is losing

A human auditor reviewing expense reports sees dozens per hour. A well-crafted AI receipt includes realistic wear and tear, coffee stains, faded text, correct vendor logos, proper tax math, even handwritten tips. AppZen's research showed fraudsters generating receipts with specific imperfections designed to look authentic.

Human detection accuracy for AI-generated documents hovers around 55-62%. Slightly better than random.

AI-powered detection systems do better, but they solve a different version of the problem. They cross-reference metadata, check vendor databases, flag mathematical inconsistencies, and look for digital fingerprints left by image generation models. AppZen claims to audit 100% of expenses with AI and catch fakes that manual review misses.

But that detection model requires access to vendor databases, transaction records, and behavioral baselines. A dispute resolver sitting between a buyer and a seller doesn't have that access. The resolver sees the evidence package. If the receipt looks valid, it looks valid.

Current dispute systems were designed for a world where fabricating evidence was hard. The entire flow, from the cardholder calling their bank to the merchant responding with documentation, assumes that the evidence submitted is either genuine or obviously fake. Synthetic evidence that passes visual inspection sits in a gap the system was never built to handle.

The agent commerce collision

Everything above describes fraud committed by humans against human-reviewed systems. Agent commerce makes it worse on both sides.

An agent committing refund fraud doesn't file claims one at a time. It parallelizes across hundreds of merchants simultaneously, generating fresh synthetic evidence for each claim. Where a human manages two or three fraudulent identities, an agent can generate and rotate them at the rate the model produces tokens.

The defense side is equally exposed. The whole point of agent commerce dispute evidence is mechanical resolution. The evidence triple proposed for agent disputes, a grant, a receipt, and a structured delta, is designed so a resolver can verify a dispute without human intervention.

That design assumes the receipt is a genuine artifact signed by the payment processor after a real transaction. The grant is a JWT the owner signed. The delta is computed from the two.

If the receipt is fabricated, the delta is meaningless. The resolver compares a real authorization against a fake action and reaches a fake conclusion.

Existing chargeback systems already have no reason code for agent errors. Synthetic evidence compounds the gap. A resolver processing fabricated receipts against real authorizations produces verdicts that look correct and are wrong.

Genuine receipt vs. synthetic evidence
Genuine Receipt
processor-signed artifact
Fabricated Receipt
AI-generated document
Grant
Valid
JWT signed by owner
✓
Valid
JWT signed by owner
✓
↓
↓
Receipt
Authentic
JWS from payment processor
✓
Synthetic
AI-generated, no processor sig
FAKE
↓
↓
Delta
Accurate
Computed from real data
✓
Poisoned
Computed from fabricated data
FAKE
↓
↓
Verdict
Correct
real evidence, valid mismatch
Wrong
fabricated input, false conclusion

What receipt provenance would require

The evidence triple needs a fourth property: attestation. A receipt must carry proof that the entity reporting it actually processed the transaction.

In ACK-Pay's grant-receipt model, the receipt is a JWS signed by the payment service. That signature proves the payment service issued the receipt. But it doesn't prove a transaction occurred. A compromised or malicious payment service could sign a receipt for a transaction that never happened.

Genuine provenance requires binding the receipt to the transaction at the infrastructure layer.

A processor attestation links the receipt to a settlement record. The payment processor signs the receipt with a key verifiable against its public certificate, and the signature covers a reference to the actual settlement, not just the claimed transaction details.

A timestamp anchor from a trusted third party proves the receipt was created at or after the transaction, not generated retroactively. RFC 3161 defines this for digital documents. Applying it to payment receipts is an extension, not an invention.

A content credential binds the receipt to its origin. C2PA, the Coalition for Content Provenance and Authenticity, defines an open standard for establishing where digital content came from. Adobe, Amazon, Google, Meta, Microsoft, and OpenAI sit on the steering committee. The standard was built for images and video, but its provenance model, a chain of signed assertions about how content was created and modified, applies directly to financial documents.

And a settlement reference closes the loop. The receipt carries a hash or identifier that a verifier can check against the processor's settlement ledger. Without this, a valid-looking signature on a receipt still doesn't prove money moved.

None of these exist in any machine payment protocol today. MPP's receipt is four fields with no provenance. x402's receipt deliberately omits the amount for privacy. ACK-Pay has a processor signature but no settlement binding, and none of the protocols carry content credentials or timestamp attestations.

What receipt provenance would require
Settlement Reference
Hash checked against the processor's settlement ledger
Settlement ledger
Content Credential
C2PA signed assertion chain proving document origin
C2PA provenance chain
Timestamp Anchor
RFC 3161 attestation proving creation time
Time-Stamping Authority
Processor Attestation
Signature covering the actual settlement reference
Processor public certificate
Receipt Artifactreceipt+jws
The payment receipt as it exists today — amount, merchant, timestamp, status
No machine payment protocol implements any of these layers today

The asymmetry that matters

The cost of producing synthetic evidence is approaching zero. A text prompt and a few seconds produce a document that passes visual inspection and basic structural validation.

The cost of verifying provenance is higher but bounded. A cryptographic signature check and a certificate chain validation are millisecond operations. The infrastructure to support them, processor attestation keys, time-stamping services, content credential chains, is the hard part.

But the asymmetry favors the defender over time, if the infrastructure gets built. Without it, automated dispute systems run on the assumption that evidence is real because it looks real. That assumption held when fabrication was expensive and collapses when fabrication is free.

The existing agent commerce protocols already have a receipt gap: receipts prove payment but not authorization. Synthetic evidence opens a second one. The receipt doesn't prove it's real, either.

Sources

Frequently Asked Questions

How common are AI-generated fake receipts in fraud cases?
AI-generated receipts went from 0% of flagged fraud cases in March 2025 to 70.8% by mid-2026, according to SensFrx data. Over 3.5 million fake receipts were created on the top four expense fraud websites in just six months.
Why do AI-generated fake receipts break the dispute evidence model?
Traditional dispute resolution relies on humans reviewing receipts and judging authenticity. Agent commerce automates that review. A mechanical resolver processing thousands of disputes per hour can't eyeball a receipt the way a bank analyst can. If the receipt is a valid-looking artifact, the resolver accepts it.
What would fix receipt authenticity in agent commerce disputes?
The evidence triple proposed for agent commerce disputes (grant, receipt, delta) needs a provenance layer. A receipt would need to carry a cryptographic attestation from the payment processor proving it was generated from an actual transaction, not fabricated after the fact.
How good is AI receipt detection right now?
Human detection accuracy for AI-generated documents hovers around 55-62%, barely better than a coin flip. AI-powered detection systems perform better but require cross-referencing metadata, payment processor records, and behavioral signals that most dispute workflows don't have access to.

Built by Trio, a fintech-native engineering partner helping teams build the next generation of financial technology and infrastructure.

Subscribe to Ledger Drift for high-signal insights into how modern fintech is built, from systems to code to teams.

Keep reading

analysisThe Ledger Company Wants to Be the BankModern Treasury processes $600 billion through partner banks. Now it's applying to be the bank underneath.
engineeringThe Ledger Is the ProductEvery fintech product is a UI on top of a ledger. Get it wrong and every layer above inherits the error.
engineeringGold Certificates, Usage Rights, and the Cooperative StackWhat if the floor price for art came from the gold in the certificate, not the artist's reputation?
View more ›