BioCatch does not check your password. It watches whether you are holding your phone at the angle you always hold it, whether your typing rhythm matches your last few hundred sessions, and whether the pause before you entered an account number was the pause of someone typing from memory or someone reading digits off a screen while a stranger talks them through it.
Visa is paying $2.4 billion in cash for that capability. The price is worth sitting with, because it tells you exactly what AI fraud detection for small business is about to become: extremely well funded, genuinely good, and aimed at a part of the transaction that is not yours.
The short version: Visa is acquiring behavioral biometrics firm BioCatch to stop account takeovers and scams before a payment happens. That protection lives inside your bank’s app and your customers’ bank apps. It does not cover the attack most likely to actually cost your business money, which is a convincing impersonation of someone your bookkeeper already trusts. That gap is closed with a written rule, not a product.
What did Visa actually buy?
Visa announced on August 3 that it will acquire BioCatch for $2.4 billion in cash from funds advised by Permira and other shareholders, with the deal expected to close by the end of Visa’s fiscal second quarter of 2027.
BioCatch sells behavioral intelligence. Its systems read thousands of signals from a digital banking session: keystroke timing, touch gestures, how a device is physically handled. From those, it separates a real customer from a fraudster operating an account, or from a real customer being coached through a transfer by a criminal on the phone. The company says it currently covers 1.8 billion devices and 760 million users across more than 350 banking clients in 21 countries, analyzing 19 billion sessions a month.
Visa’s rationale is blunt. Andrew Torre, who runs Visa’s value-added services business, put the global cost of account takeovers and scams at more than $1 trillion a year and said AI is enabling those attacks. A payment network does not spend $2.4 billion on a defensive capability because the threat is theoretical.
What does AI fraud detection for small business actually cover?
Almost certainly less than you assume, and this is the part worth being precise about.
Behavioral biometrics of this kind sits inside banking sessions. It protects the consumer logging into their bank, and it protects the bank from an account takeover. If you are a small business, you benefit from it in two indirect ways: your own business banking login gets harder to hijack, and fewer of your customers get drained by a scammer, which means fewer downstream disputes landing on you.
What it does not do is sit between your accounts payable inbox and a fraudulent invoice. It does not read the email your office manager received. It has no view into the phone call that confirmed the wire. The defense Visa just bought is upstream of the payment and inside the bank, and the attack that most often empties a small business account starts somewhere else entirely.
Why does a scam that never touches a card matter more?
The FBI’s 2025 Internet Crime Report logged 1,008,597 complaints and $20.9 billion in reported losses, a 26 percent jump year over year. Business email compromise alone accounted for $3.05 billion of that. For the first time in the center’s history, the report carried a dedicated section on artificial intelligence as a criminal tool: 22,364 complaints carried an AI descriptor, representing roughly $893 million in losses.
Inside that, one figure deserves your full attention. More than $30 million in business email compromise losses had a confirmed AI component, largely voice cloning used to place a follow-up call that confirms a wire instruction sent by email. The written request looks right because a model matched the executive’s tone and vocabulary. The phone call sounds right because the voice was cloned. The two artifacts corroborate each other, and the oldest verification habit in small business finance, “I’ll just call and check,” quietly stops working.
That $30 million is the confirmed floor, not the ceiling. Most victims never learn whether a model wrote the email that fooled them. We covered a related version of this asymmetry when an AI agent broke into three companies using weak passwords, and the pattern repeats: the attacker’s capability moved, the defender’s habits did not.
Does better fraud detection cost merchants anything?
Yes, and this is the trade nobody puts in the press release.
Every improvement in behavioral scoring makes the decision to decline a transaction more confident. Confident systems decline more. Some of those declines are wrong, and a wrongly declined order costs a merchant the sale, the customer, and often the customer’s next three purchases. The LexisNexis True Cost of Fraud study published in April 2025 found US retail and ecommerce merchants absorb $4.61 in total cost for every $1 lost directly to fraud, once chargeback fees, manual review labor, and operational drag are counted.
None of that is an argument against Visa’s purchase. Better upstream detection is straightforwardly good. It is an argument for knowing your own decline rate rather than assuming someone else is optimizing it for you. Your processor can produce that number. Most owners have never asked.
What should you do about it this month?
Nothing here requires software, and none of it requires replacing a person. It requires giving the people you already employ one rule that removes the judgment call from the moment they are least equipped to make it.
Write down a payment verification rule and put it where your bookkeeper can see it. The rule that survives voice cloning has one specific property: verification must travel over a channel the attacker did not choose, using a contact detail the attacker did not supply. A callback to the number in your own vendor records works. A callback to the number in the email signature does not, and that distinction is the entire defense.
Then set a dollar threshold above which any payment needs a second human, and treat any request to change a vendor’s bank details as a stop, always, regardless of who appears to be asking. Finally, turn on multi factor authentication for your business banking and the email account that receives your invoices, because that inbox is the actual target. Our AI cybersecurity playbook for small business owners covers what the tooling layer adds on top, and the AI Overviews support-number scam covers the version of this that targets your customers rather than your ledger.
Visa spent $2.4 billion to close its side of this gap. Yours closes with a laminated card next to the monitor, and it closes this week.
Frequently Asked Questions
Does the Visa BioCatch deal change anything for my business right now?
Not immediately. The transaction is not expected to close until the end of Visa’s fiscal second quarter of 2027, and even after that the technology operates inside banking sessions rather than in your point of sale or your accounting software. Treat it as a signal about where fraud is heading rather than a product you will buy or configure.
What is behavioral biometrics?
It is identity verification based on how you behave rather than what you know or carry. Instead of a password or a code, the system builds a profile from patterns like typing rhythm, mouse movement, touch pressure, and the physical angle at which you hold a device, then flags sessions where those patterns break. It is designed to catch a criminal who already has the correct password, and to catch a legitimate user who is being coached through a transaction under pressure.
Can AI fraud detection stop a fake invoice sent from a real vendor’s email account?
Generally no, and this is the most common blind spot. If a vendor’s mailbox is compromised, the invoice arrives from a legitimate address, with a real thread history and a plausible amount. Nothing in the payment network sees anything unusual, because from the bank’s perspective you authorized a payment to a new account on purpose. The control that catches this is procedural: a mandatory hold and an independent callback whenever bank details change.
Is a callback really enough protection against voice cloning?
A callback works only if you choose the number, not the sender. Cloned audio defeats the version where you dial the number printed in the suspicious email, because the criminal controls that line. It does not defeat the version where you dial the number stored in your own vendor file from before the request arrived. The protection is not the phone call itself, it is the fact that you selected the channel independently.
Here is what we are genuinely curious about: has your business already changed how it verifies a payment because of AI, or is the old habit still running on trust? Tell us what your rule is now.
