AI-generated receipts are now most of expense fraud

AppZen, an expense report auditing platform, published figures covering the 12 months ending 15 May 2026. In March 2025, zero percent of the fake receipts its system caught were generated by an AI model. By mid-May 2026 they were 70.8 percent. The crossover happened in April 2026, when model-generated fakes passed the older method of filling in a template.

The absolute numbers are small: 1,471 receipts, 745 employees, 174 companies, $148,143 claimed in total. The average suspect receipt was around $101 and the median was $32. That is exactly the range nobody checks twice.

Why the forgery crossed a threshold

A fake receipt used to take effort. A template, a font that matched, a logo at the right size, amounts that added up. Today one prompt to an image model returns a receipt with creases in the paper, a crooked crop, the shadow of a finger on the corner, and digits that sum correctly. The time it takes dropped from an hour to thirty seconds, and the cost dropped to zero.

The other side of the equation did not move. A manager approving an expense report looks at an image on screen for two seconds, checking for a plausible merchant, a plausible amount, and a date inside the month. All three show up in a generated receipt exactly as they do in a real one.

What has stopped working

Visual inspection does not work. An odd font, crooked alignment, smeared pixels were the tells of the template era, and they are gone.

File metadata does not work. EXIF strips out in one command, and photographing the screen with a phone produces a file with a clean device history.

Provider watermarks do not work on their own. Some models embed a mark, some do not, and a screenshot of an image removes some of them. The person checking cannot rely on a mark being present, because its absence proves nothing.

What does work

Matching against money movement. A receipt claims someone paid 240 shekels at a petrol station on 14 July. Either a matching charge exists on the card or in the bank account, or it does not. A model that generates an image does not generate a bank charge, and that is the one weakness a new generation of models will not close.

For a small business handling its own expenses or an employee's, that means three things: connect the business card feed to wherever expenses are stored, require every receipt to be attached to a transaction, and flag any expense with no matching transaction within two days. Cash spending stays the hole in the method, which is why it is worth capping by amount and approving separately.

The Israeli angle

In Israel the rule already favours the person checking. A tax-deductible expense needs a tax invoice carrying the supplier's business number, not a slip with an amount printed on it. A tax invoice has a real business behind it that reported the income, and that is a far harder document to conjure out of an image model without creating an offence on the other side of the transaction.

Anyone keeping payment receipts alone and hoping it holds up in an audit is leaning on the document type that just became easy to fake, and in the same breath on the document type that was never enough for a deduction. One action fixes both: ask for the tax invoice at the time of the purchase, not two months later.

If you employ people

One in three employees caught submitting a fake receipt did it more than once, and at one large employer the repeat rate reached 41 percent. A survey cited in the same reporting found 40 percent of US employees admitted using AI to generate or alter a receipt, 19 percent invented a purchase that never happened, and 15 percent inflated the amount of a real one.

A business with two employees does not need an automated audit system. It needs one written rule: an expense is reimbursed only when a matching card or bank charge exists. That rule is cheap to enforce, and it is the only one that does not expire every time a better image model ships.