There's a scene that repeats at practically every fintech conference in Brazil. An executive walks on stage, opens a slide titled "AI & Innovation" and lists: fraud detection, personalization, chatbots. The audience nods. The coffee goes cold. Nobody learns anything.
The problem isn't that these applications are irrelevant; they are, in fact, critical. The problem is that listing technologies isn't the same as understanding them, and the gap between "we have AI" and "AI transformed our operations" is a chasm most Brazilian institutions still haven't crossed.
This article isn't another list. It's an honest attempt to show where AI is really changing the game in the Brazilian payments market, with verified data, real architecture and the traps nobody mentions on stage.
1. The PIX paradox: the world's fastest system exposed how slow the models are
PIX closed 2025 with 79.8 billion transactions and R$35.36 trillion moved, growth of 33.6% over 2024, according to Brazil's Central Bank [1]. For scale: that's three times Brazil's 2024 GDP [2]. On December 5, 2025, the system set an all-time record: 313.3 million transactions in a single day, moving R$179.9 billion in 24 hours [3]. It has more than 170 million users, around 80% of the population [1].
No instant payment system on the planet operates at this scale and this speed.
But that speed created a problem few saw coming: existing fraud models weren't built for this pace.
In the pre-PIX world, a wire transfer (TED) took hours. A boleto, days. There was time for analysis, for manual review queues, for the analyst to grab a coffee and come back. PIX wiped out that luxury, literally. Settlement happens in up to 10 seconds. And within those 10 seconds, the system has to receive the transaction, enrich it with contextual data, run the risk model, make the decision and tell the user.
The latency budget for the scoring model? Somewhere between 50 and 200 milliseconds, depending on the architecture. That changes everything.
What this means in practice
A Gradient Boosting model with 400 features trained offline is useless if the feature store takes 300ms to assemble the input vector. A deep neural network is useless if inference time blows the SLA.
The institutions that actually solved this made hard architectural choices:
- Lighter models in production, heavier models in shadow mode. The light model decides in real time. The heavy one runs in parallel, doesn't block the transaction, but generates retroactive alerts and feeds retraining. That's pragmatism, not glamour.
- Feature stores with an in-memory hot layer. Having a feature store isn't enough; the most critical features (last transaction, device fingerprint and spending velocity over the last 2 hours) have to be precomputed and accessible in single-digit milliseconds. Setups like Redis with custom pipelines, or Feast with a DynamoDB backend, are common.
- Cascading decision architecture. Instead of a single monolithic model, the transaction passes through layers: fast deterministic rules first (blocklists and hard-coded limits), then a lightweight first-pass model, and only ambiguous transactions go to the full model. This cuts the volume of heavy inferences by up to 80%.
The lesson here is uncomfortable: the best AI in payments isn't the most sophisticated, it's the one that fits the latency budget.
2. R$29 billion in scams: the fraud AI doesn't catch
There's a lot of talk about fraud detection with machine learning. But the numbers tell another story.
A Datafolha survey from June 2025, in partnership with the Brazilian Public Security Forum, found that 24 million Brazilians fell victim to scams involving PIX or fake boletos, with accumulated losses of R$29 billion, an average of R$1,198 per victim [4]. Almost R$5 billion was lost specifically to PIX fraud [5]. And the share of victims jumped from 10% in 2024 to 14% in 2025 [4].
Across the financial system as a whole, the Unified Fraud Registry (Rufra) logged 12 million fraud indicators in 2025: fraud operating at "industrial scale", according to the Quod study [6]. Banks reported R$10.1 billion in fraud losses in 2024, up 17% over 2023, which led the Federal Police to call the phenomenon "digital banditry" (cangaço digital) [7].
There's one category of fraud where traditional models fail systematically: social engineering. The classic PIX scam works like this: the victim, under psychological pressure, makes the transfer voluntarily. From the system's point of view, everything is perfect: the device is the usual one, the biometrics match and the IP is the same as always. The model sees a legitimate transaction, because technically it is.
Where the real frontier is
The institutions making progress here work with subtle signals:
- Behavioral pattern shifts within a short window. The person has never sent a PIX above R$500 and suddenly sends three of R$4,900 in 20 minutes? The individual amount isn't anomalous. The pattern is.
- Relationship graph analysis. Has the destination account already received transfers from multiple accounts later reported as fraud? Graph neural networks applied to the transaction network can identify clusters of mule accounts before any single transaction looks suspicious.
- Device context signals. An abnormally long session before the transaction, an accelerometer showing the user is walking (possible in-person coercion). These signals require multimodal models that combine transaction data with device telemetry.
And what about MED (the Special Refund Mechanism), which was supposed to be the safety net? In 2025, only 9.3% of disputed amounts were actually returned [8]. Of almost 5 million requests in 2024 (up 98% over 2023), 69% were simply denied [9]. MED 2.0, mandatory since February 2, 2026, tries to fix this with cascading tracking, following the money even after multiple transfers between mule accounts [10]. The Central Bank's actual enforcement starts in May 2026. But the architecture requires automated real-time tracking, something impossible without graph models and AI.
3. The arms race: when the fraudster uses AI too
There's a brutal irony in today's landscape: the same generative AI banks use to protect themselves is being used to attack them.
According to Sumsub's Identity Fraud Report 2025-2026, deepfake fraud grew 126% in Brazil in 2025, making the country responsible for 39% of all deepfakes detected in Latin America [11]. Globally, sophisticated AI-driven attacks rose 180%, jumping from 10% to 28% of all fraud [11].
The most alarming technique is the "injection" attack: the criminal hacks the app and injects a deepfake-manipulated video in place of the live camera feed. In 2025, this method accounted for 45.5% of all fraud blocked [12]. Sophisticated fraud as a whole grew more than 1,000% in 12 months, peaking in Q4 2025 [12].
And it's no longer about faking a static selfie. Fraudsters now use AI tools to create complete synthetic identities, manipulate device telemetry and tamper with camera streams and API calls [11]. Brazil is already the 7th most targeted country in the world for digital fraud [11].
Even so, 73% of Brazilians prefer biometric systems for authentication [13]. The contradiction is clear: the technology the population trusts most is the one criminals target most.
The response demands a paradigm shift: from static liveness detection to continuously updated adversarial defense models. Anyone who doesn't update their deepfake detection models every quarter is already vulnerable.
4. Open Finance: 128 million consents and the bias nobody talks about
Brazil leads the global Open Finance ranking with 128 million active consents, ahead of 78 countries with sector regulation, according to a report by Sensedia in partnership with Let's Money [14]. The infrastructure generates more than 4.4 billion weekly communications between institutions [14]. For comparison: the UK has 15 million users; the US, 114 million connections via APIs [14].
That volume of shared data is both an extraordinary opportunity and a proportional risk.
The opportunity: alternative credit scoring models that include transactional, behavioral and relationship data can bring millions of Brazilians the traditional system ignores into the financial system.
The risk: when a credit scoring model is trained on historical data, it absorbs the biases of those past decisions. And alternative data without a bias audit only automates discrimination at scale. A model that uses ZIP code as a proxy feature is, in practice, using race and income as decision variables.
The institutions that take this seriously are investing in:
- Fairness constraints in the models, with metrics like equalized odds and demographic parity built into the loss function during training.
- Periodic audits broken down by demographic: measuring global AUC isn't enough; you have to measure AUC by segment.
- Explainability as a legal requirement, not a nice-to-have: in May 2025 Brazil's data protection authority (ANPD) published Technical Note No. 12 on automated decisions [15], and Article 20 of the LGPD guarantees the right to human review and explainability for any algorithmic decision. SHAP values and LIME aren't optional; they're compliance.
5. Back-office automation: where the ROI is brutal and nobody talks about it
There's an understandable fascination with the glamorous use cases: real-time scoring, predictive models and generative AI. But the biggest return on AI investment in payments is in something far less sexy: the back office.
The FEBRABAN Banking Technology Survey 2025, conducted by Deloitte, found that AI implementation drove an average 11.4% increase in process efficiency, with 38% of banks reporting improvements above 20% [16]. The sector's technology budget was projected at R$47.8 billion for 2025 (up 13% over the R$42.3 billion invested in 2024), with the share going to AI, analytics and big data growing 61% [16]. Consolidated 2025 data and 2026 projections are due at FEBRABAN Tech 2026, in August.
In practice, this translates into:
- Automated payment reconciliation. Classification models learn to categorize exceptions that used to require manual analysis.
- Dispute management with NLP. Natural language processing models trained on Brazilian Portuguese extract information from receipts, emails and customer accounts accurately enough to automate first-pass chargeback triage.
- Process mining for operational bottlenecks. Algorithms map the real flow of processes and surface inefficiencies invisible to the human eye.
The critical point: these projects pay for themselves in months, not years. And unlike fraud models (where ROI is hard to isolate), back-office automation ROI is direct and measurable.
6. What really separates having AI from doing AI
Eight out of ten Brazilian banks have already adopted generative AI, according to FEBRABAN [16]. But adopting isn't the same as transforming. The difference between success and theater comes down to three fundamentals:
MLOps as a discipline, not a project
Most institutions treat the model as the final product. It isn't. The model is an artifact that has to be versioned, monitored, retrained and eventually retired. Without mature MLOps (CI/CD pipelines for models, drift monitoring and A/B testing in production), the model becomes a liability.
Concept drift in Brazil is particularly violent. Regulatory changes (new PIX rules, nighttime limits, MED 2.0), seasonality (Black Friday 2025 alone generated 297 million PIX transactions in a single day [3]) and evolving fraud tactics mean a model trained in January is degraded by April.
Data before models
Real maturity starts with data governance: catalog, lineage, quality and access. LGPD adds another layer: having the data isn't enough; you need a legal basis to use it, consent traceability and the ability to handle deletion requests without breaking the training pipeline.
People who understand both worlds
The biggest bottleneck isn't technological; it's human. There's a shortage of professionals who understand both the payments domain (regulation, flows and risks) and machine learning (modeling, deployment, monitoring). The companies that solved this invested in hybrid squads: data scientists sitting with risk specialists and platform engineers. Not in separate silos. At the same table.
7. What's ahead, without buzzwords
Instead of listing generic trends, here are three concrete moves already underway:
Agentic commerce is already here
Mastercard launched Agent Pay in Latin America, with issuing banks enabled since February 2026, in partnership with Getnet, Bemobi, MagaluPay and others [17]. These are AI agents that buy, negotiate and pay, autonomously, on behalf of the consumer, using dynamic tokens ("Agentic Tokens") that replace real card data [17]. Visa is preparing Intelligent Commerce for the second half of 2026. According to Google Cloud data, 88% of early adopters of agentic AI already report positive ROI [18].
Fragmented but converging regulation
The Central Bank has confirmed it won't issue AI-specific rules before the end of 2026 [19]. That doesn't mean there's no regulation: the 2026 Regulatory Agenda lists AI as a priority [20], the ANPD is moving forward with Technical Note No. 12 on automated decisions [15], and Article 20 of the LGPD already requires explainability. Regulation is coming. The question is whether your model audits will be ready when it arrives.
Defensive AI as a permanent race
With deepfakes growing 126% [11] and injection attacks accounting for almost half of blocked fraud [12], payments security has become an arms race between offensive and defensive AI. Liveness detection, telemetry analysis and adversarial detection models will need continuous updates: no longer yearly, but quarterly or monthly.
Conclusion
AI in the Brazilian payments market isn't a technology story. It's a story about operational maturity. About understanding that the model is 20% of the problem and that the other 80% (data, infrastructure, people, governance and regulation) decide whether AI creates value or creates cost.
Brazil has unique conditions to become a global reference: massive scale (79.8 billion PIX transactions in 2025), proactive regulation (world-leading Open Finance with 128 million consents) and a digitally engaged base of 170 million users. But realizing that potential means going beyond the pretty slide.
It takes the hard work nobody applauds at conferences.
All data was verified against public sources between January and March 2026. The views on architecture and strategy are my own and don't represent the positions of any specific institution.
