When a customer reports suspected identity theft, an AI agent should triage fast (freeze affected accounts, capture the specific facts, route to fraud investigators), not attempt to resolve. Identity-theft cases are sensitive, regulated, time-critical, and often involve criminal investigation. The AI's value is in the first hour: stopping further damage and getting the case to humans with the authority and training to investigate.

A customer messages support late at night: "someone has been using my account, there are charges I didn't make." Before AI, this contact often waited until business hours for a fraud specialist to read it. AI can freeze the affected accounts immediately, capture the customer's specific facts in the language the fraud team will need, and have the case ready for the team that comes in at 8am.

What people in the field are saying

Service Matters covers contact-centre security and fraud in "Is your contact centre a cybersecurity...", naming that AI's role in fraud cases is more about routing speed and evidence capture than about decision-making.

What should AI do in the first hour?

Three things. Freeze the affected accounts (or cards, or sessions) immediately. Capture the customer's facts: what they noticed, when, which charges or actions they did not authorise. Reassure briefly without minimising; the customer is anxious and the AI's tone matters here as much as the action. Route to the fraud team with the captured facts and the audit trail of recent account activity.

What should AI not do?

Investigate. Decide which charges to refund. Tell the customer what happened. Make commitments about criminal involvement. Each of these requires authority, training, and often legal context the AI does not have.

What about verification in this case?

The freeze action should require minimal verification (it is low-risk: freezing protects the customer, and they can always unfreeze later). Everything else (transaction reversal, account changes, replacement cards) requires step-up verification once the human team is involved. The freeze comes first because waiting risks more damage.

What does the customer need to hear from the AI?

Brief acknowledgement that the situation is serious. The action just taken (account frozen). The next step (a specialist will contact them within X hours; here is the case number). A reassurance that further charges cannot post on the frozen account. Nothing more; certainly nothing that sounds dismissive or scripted.

What is the practical first step?

Define the detection patterns (customer mentions theft, fraud, unauthorised charges, stolen card). Wire the freeze action behind those patterns with minimal verification. Connect to the fraud team's queue with full case context. Audit a sample monthly to confirm the AI is triaging well and not over- or under-freezing.

Related: use case 6: replacing a compromised card, authentication, and AI in regulated industries.