Digital Wallets Face New Consumer Protection Rules
As digital wallets and crypto products scale, new consumer protection rules are emerging to address heightened fraud risks from AI, with security now a

Digital wallets and cryptocurrency products are reaching a mass market, bringing new consumer protection rules and heightened fraud risks. Spreedly Chief Information Security Officer Jennifer Rosario told PYMNTS that the scale attracts more malicious actors, a problem intensified by the accessibility of generative artificial intelligence.
AI tools are removing the clues consumers once used to spot phishing attempts. Rosario identified synthetic identification and deepfake videos as major challenges for companies verifying new customers or commercial partners. Consumers accustomed to decades of card-based protections are entering markets where safeguards are not identical. Credit card fraud controls evolved over years of attacks and regulation, but new digital asset products do not necessarily carry the same requirements.
Security as a Product Question
Security architecture is now a fundamental product consideration, not only a technical one. Providers must decide what to protect, which risks to accept, and which controls to prioritize before an incident forces their hand. Rosario stated there is no single solution. Priorities must be driven by a company's specific environment, industry, geography, data, and risk tolerance, integrating technology with people and processes.
Onboarding Becomes a High-Risk Front Line
The initial customer onboarding process has become a primary security concern. Synthetic IDs and convincing deepfakes complicate know-your-customer and merchant verification when admitting users to an ecosystem. Onboarding, in my opinion, is one of the biggest areas of concern just because of the nature that AI is driving a shift in risk there, Rosario said.
For payments, security obligations extend well beyond onboarding. Rosario pointed to updated PCI DSS 4.0 requirements that focus on securing payment page integrations and managing threats like card testing and skimming. This includes monitoring third parties operating on a payment page and managing vulnerabilities. A key complication is that payment companies and merchants often depend on outside providers whose security practices they cannot directly control beyond contracts.
Balancing Controls with Convenience
Implementing more security controls can increase user friction. Digital wallets and financial products compete heavily on convenience, forcing providers to judge when an extra authentication step justifies the interruption. This requires experimentation. Rosario explained that Spreedly's security team collaborates with product and engineering groups, allowing room to test new technology while applying the company's risk appetite to decide where controls are needed.
The goal is practical. Engineering teams need hands-on experience with AI tools to understand how they can also be used to automate attacks. Spreedly is working toward ISO 42001 certification for AI management systems, using that framework to structure its AI-related risk controls. Rosario highlighted that regulatory and standards work, particularly in Europe, is useful for establishing requirements proactively. "You don’t want to be reactive when building that structure," she said. Companies need time to plan and build a sound program before an incident occurs.





