Two stories about AI in South African banking landed within days of each other this month, and I don't think enough people have actually sat with how uncomfortable they look side by side.
Story one: Absa announced that it's cut small business account onboarding from about two days down to under 30 minutes. That's not a small improvement, that's a 99% reduction. They did it by chaining together biometric verification, automated CIPC company lookups, real-time credit bureau checks and instant KYC, all running through what they're calling straight-through processing. They also mentioned that debt review effectiveness jumped from 28% to 90%, and a financial analysis process that used to take two to five days now takes about four hours. Genuinely impressive stuff. More than 30,000 Absa staff use Microsoft Copilot every month, over 1,400 developers use AI coding tools. This is a bank that has clearly gone all in on AI as an efficiency engine, and if you're a small business owner who needs a bank account today because a client is paying you today, this is a real, tangible improvement to your life.
Story two, same week: a report on South African banking fraud found that only 7% of organisations feel more than moderately prepared to detect and prevent AI-powered fraud. Criminals are running AI agents that impersonate bank staff, complete with cloned voices, coaching victims in real time to approve fraudulent transactions or hand over their credentials. Standard Bank flagged this back in March. The projections aren't gentle either, deepfake social engineering and AI document forgery are both expected to grow by around 55% over the next two years.
Here's the thing I keep coming back to. These aren't two unrelated AI stories that happen to both involve South African banks. They're the exact same technology, applied by two different sets of actors, pointed in opposite directions. The biometric verification, the automated document checks, the instant KYC that Absa is using to onboard a legitimate small business owner in half an hour, is built on largely the same category of tooling that criminals are using to fake a voice convincingly enough to talk someone's grandmother into wiring money. Speed and automation don't have a moral direction built into them. They just remove friction, and friction was, whether we liked it or not, doing double duty this whole time. It slowed down real customers, sure, annoyingly so. But it was also slowing down fraudsters, forcing them through manual steps that took time and left traces.
What actually worries me isn't Absa's rollout, or even the existence of AI fraud tools on their own. It's the mismatch in speed between the two sides. Banks are getting faster at legitimate service because that's a clear, fundable, PR-friendly business goal with a straightforward ROI case you can put in a results presentation. Fraud defence doesn't have the same clean business case, it's a cost center, it's defensive, and the report flagged something I think is the real structural problem here: banks compete with each other on fraud prevention like it's a trade secret, while the criminals attacking them share tactics and stolen data freely across networks and borders. One side is optimizing in isolation. The other side is optimizing collectively. You don't need to be a security expert to guess who that dynamic favours over time.
I'm not saying don't build the fast onboarding, obviously build the fast onboarding, it's a genuinely good thing for the small business owners it helps. But if the industry's fraud defence keeps getting treated as a slower-moving, lower-priority cousin to the customer experience wins, we're going to keep reading paired stories like this one. Good news about how fast the banks got, and bad news about how fast everyone else got too.

