When AI Can Fake the Receipt, Dispute Evidence Breaks
AI-generated fakes are already 70% of flagged expense fraud, and agent commerce is about to automate the resolution layer that assumes receipts are real.
How do you prove a receipt is real?
For most of commercial history, you didn't have to. A receipt was a physical artifact, thermal paper from a register or a carbon copy from a credit card imprint. Fabricating one required effort that exceeded the value of most disputes. The economics of forgery protected the system.
That protection is gone. Generative AI can produce a receipt with the correct logo, formatting, tax calculation, itemization, timestamp, and transaction ID in under ten seconds. AppZen tracked over 3.5 million fake receipts generated on just the top four expense fraud websites in a six-month window. Google searches for "AI-generated receipts" rose 2,753% in a single year.
SensFrx reported that AI-generated receipts went from 0% of flagged fraud cases in March 2025 to 70.8% by mid-2026. No other category of document fraud has moved that fast.
But the receipt problem runs deeper than expense fraud. Payment dispute systems, from credit card chargebacks to the agent commerce evidence protocols being designed right now, assume the receipt is authentic. When that assumption breaks, the dispute layer breaks with it.
The $893 million preview
The FBI included AI in its Internet Crime Complaint Center report for the first time in 2025. The numbers: 22,364 complaints, $893 million in losses. That's a floor, not a ceiling. IC3 only captures what victims report, and most receipt fraud never surfaces as a complaint to the FBI.
Signifyd's 2026 State of Fraud report shows the downstream pressure. Fraud in North America grew 33% year-over-year in the first four months of 2026. Account takeover is up 78%, card-testing attacks up 175%.
The category that matters most for dispute evidence is "item not as described," up 49%. Signifyd attributes the spike directly to AI-generated images of damaged goods submitted as dispute evidence. The fraudster fakes the entire evidence package: receipt, photo of the "damaged" item, shipping label.
In the UK, Cifas data shows AI-manipulated documents now account for more than 20% of falsified evidence in refund and chargeback disputes. Total UK fraud cases exceeded 444,000 last year. One in ten returns is estimated to be fraudulent.
Why detection is losing
A human auditor reviewing expense reports sees dozens per hour. A well-crafted AI receipt includes realistic wear and tear, coffee stains, faded text, correct vendor logos, proper tax math, even handwritten tips. AppZen's research showed fraudsters generating receipts with specific imperfections designed to look authentic.
Human detection accuracy for AI-generated documents hovers around 55-62%. Slightly better than random.
AI-powered detection systems do better, but they solve a different version of the problem. They cross-reference metadata, check vendor databases, flag mathematical inconsistencies, and look for digital fingerprints left by image generation models. AppZen claims to audit 100% of expenses with AI and catch fakes that manual review misses.
But that detection model requires access to vendor databases, transaction records, and behavioral baselines. A dispute resolver sitting between a buyer and a seller doesn't have that access. The resolver sees the evidence package. If the receipt looks valid, it looks valid.
Current dispute systems were designed for a world where fabricating evidence was hard. The entire flow, from the cardholder calling their bank to the merchant responding with documentation, assumes that the evidence submitted is either genuine or obviously fake. Synthetic evidence that passes visual inspection sits in a gap the system was never built to handle.
The agent commerce collision
Everything above describes fraud committed by humans against human-reviewed systems. Agent commerce makes it worse on both sides.
An agent committing refund fraud doesn't file claims one at a time. It parallelizes across hundreds of merchants simultaneously, generating fresh synthetic evidence for each claim. Where a human manages two or three fraudulent identities, an agent can generate and rotate them at the rate the model produces tokens.
The defense side is equally exposed. The whole point of agent commerce dispute evidence is mechanical resolution. The evidence triple proposed for agent disputes, a grant, a receipt, and a structured delta, is designed so a resolver can verify a dispute without human intervention.
That design assumes the receipt is a genuine artifact signed by the payment processor after a real transaction. The grant is a JWT the owner signed. The delta is computed from the two.
If the receipt is fabricated, the delta is meaningless. The resolver compares a real authorization against a fake action and reaches a fake conclusion.
Existing chargeback systems already have no reason code for agent errors. Synthetic evidence compounds the gap. A resolver processing fabricated receipts against real authorizations produces verdicts that look correct and are wrong.
What receipt provenance would require
The evidence triple needs a fourth property: attestation. A receipt must carry proof that the entity reporting it actually processed the transaction.
In ACK-Pay's grant-receipt model, the receipt is a JWS signed by the payment service. That signature proves the payment service issued the receipt. But it doesn't prove a transaction occurred. A compromised or malicious payment service could sign a receipt for a transaction that never happened.
Genuine provenance requires binding the receipt to the transaction at the infrastructure layer.
A processor attestation links the receipt to a settlement record. The payment processor signs the receipt with a key verifiable against its public certificate, and the signature covers a reference to the actual settlement, not just the claimed transaction details.
A timestamp anchor from a trusted third party proves the receipt was created at or after the transaction, not generated retroactively. RFC 3161 defines this for digital documents. Applying it to payment receipts is an extension, not an invention.
A content credential binds the receipt to its origin. C2PA, the Coalition for Content Provenance and Authenticity, defines an open standard for establishing where digital content came from. Adobe, Amazon, Google, Meta, Microsoft, and OpenAI sit on the steering committee. The standard was built for images and video, but its provenance model, a chain of signed assertions about how content was created and modified, applies directly to financial documents.
And a settlement reference closes the loop. The receipt carries a hash or identifier that a verifier can check against the processor's settlement ledger. Without this, a valid-looking signature on a receipt still doesn't prove money moved.
None of these exist in any machine payment protocol today. MPP's receipt is four fields with no provenance. x402's receipt deliberately omits the amount for privacy. ACK-Pay has a processor signature but no settlement binding, and none of the protocols carry content credentials or timestamp attestations.
The asymmetry that matters
The cost of producing synthetic evidence is approaching zero. A text prompt and a few seconds produce a document that passes visual inspection and basic structural validation.
The cost of verifying provenance is higher but bounded. A cryptographic signature check and a certificate chain validation are millisecond operations. The infrastructure to support them, processor attestation keys, time-stamping services, content credential chains, is the hard part.
But the asymmetry favors the defender over time, if the infrastructure gets built. Without it, automated dispute systems run on the assumption that evidence is real because it looks real. That assumption held when fabrication was expensive and collapses when fabrication is free.
The existing agent commerce protocols already have a receipt gap: receipts prove payment but not authorization. Synthetic evidence opens a second one. The receipt doesn't prove it's real, either.
Sources
- FBI 2025 Internet Crime Report - First-ever AI section in IC3 annual report, documenting 22,364 AI-related complaints and $893 million in losses
- Signifyd 2026 State of Fraud Report - Fraud pressure data showing 33% YoY growth in North America, 49% increase in "item not as described" claims driven by AI-generated evidence
- AppZen: The Invisible Threat - Data on 3.5 million fake receipts created in six months, AI detection methodology for synthetic expense documents
- Dojo / Cifas AI Fake Receipt Data - UK data showing AI-manipulated documents account for 20%+ of falsified evidence in refund and chargeback disputes
- C2PA Content Provenance Standard - Open technical standard for digital content provenance and authenticity, backed by Adobe, Amazon, Google, Meta, Microsoft, and OpenAI
Frequently Asked Questions
Built by Trio, a fintech-native engineering partner helping teams build the next generation of financial technology and infrastructure.
Subscribe to Ledger Drift for high-signal insights into how modern fintech is built, from systems to code to teams.