Skip to main content

Fraudsters succeed when they learn and adapt faster than organizations can respond. Insights from one fraud scheme can inform the next, enabling sophisticated networks to change tactics quickly while the controls designed to stop them can take months or years to update.1 The cost can be enormous: The US Government Accountability Office estimated annual federal fraud losses of $233 billion to $521 billion between fiscal years 2018 and 2022.2

For federal and state health agencies, building a resilient fraud defense means more than detecting fraud. Agency reviewers and investigators work alongside oversight and law enforcement partners to protect patients, reduce burdens on compliant providers, and preserve program resources for the people and purposes they’re intended to serve. They also assess which potential fraud signals warrant review, what evidence is needed to pursue a lead, and how applicable policy and authority can inform response.

In practice, fraud control is often reactive: Pay the claim, detect the anomaly, investigate the lead, and try to recover the loss. But what if government could learn and adapt as quickly as fraudsters?

Agentic artificial intelligence, or agentic AI, offers a potential path forward toward more proactive fraud detection. Agency reviewers and investigators could use agentic AI systems not only to accelerate investigations, but also to help identify policy vulnerabilities before they’re exploited, flag emerging risks early, and learn from investigation outcomes. Over time, this approach could shift more fraud-fighting activity from recovery to prevention.

What is agentic AI, and how does it work?

Agentic AI refers to systems that can help accomplish specific goals by planning and carrying out multistep tasks with limited supervision, within defined guardrails and under human oversight. In fraud control, agentic AI builds on predictive analytics, which typically estimates risk or flags anomalies, by organizing and contextualizing those signals for reviewers. An agentic AI system could gather evidence from multiple sources, evaluate it against program rules and policies, suggest next steps, and capture outcomes to inform future analyses. Agency reviewer and investigator judgment remains essential in every fraud assessment (figure 1).

How health agencies can use agentic AI to fight fraud

Agentic AI has the potential to reshape how health agencies approach fraud detection and prevention. The following three capabilities illustrate where it could have the greatest operational impact.

1. Prevent fraud by design

Fraud investigations often begin after an agency has already made payments or incurred losses.3 Agency reviewers and investigators may identify suspicious behavior months or even years after a provider enrolls, changes ownership, begins billing, or exploits a policy vulnerability.4 As agentic AI systems detect fraud, they provide insights that can help inform an agency’s decisions to safeguard against new and evolving threats.

Design policy with fraud risk in mind from the start

Agentic AI systems could test the strengths and vulnerabilities of new policies to help agencies make informed decisions on payment models. By simulating how different actors might respond to proposed rules, AI agents could help surface unintended incentives or administrative weaknesses and recommend alternative approaches that achieve the same policy objectives with lower fraud risk. That makes it easier to embed fraud risk assessment into the design of legislation, regulations, and sub-regulatory guidance before vulnerabilities are locked in.

Close loopholes in existing policies

Fraud risks can increase when policy or regulatory requirements are unclear.5 Even when policies are clear, complex rules and requirements can be challenging to apply in practice, particularly when managing multiple, conflicting policies.

AI agents could help by tracking policies across programs and surfacing conflicting rules for agencies to review. Health agencies can then systematize that knowledge and clarify rules through usable formats like checklists. Where requirements are ambiguous or conflicting, AI agents could flag the gaps and suggest options to fix them, which might save costs in the long run (figure 2). All AI agent suggestions should be verified by agency reviewers and investigators.

Monitor provider risk continuously, not just at enrollment

Enrollment reviews help prevent bad actors from entering programs, but risk doesn’t end once a provider is approved. Ownership changes, licenses expire, billing patterns shift, and new connections can emerge between providers and sanctioned entities.

AI monitoring agents could flag those changes as they happen, and support an auditable record. This would enable health agencies to intervene sooner rather than waiting to catch those leads at the next revalidation, which may be two to five years away.6

Where to start

  • Monitor one high-risk provider category, continuously evaluating for licensing, ownership, and enrollment changes.
  • Review one high-impact policy area, focusing on rules that are unclear or repeatedly exploited.
  • Measure prevention and not alerts to track whether suspicious activity surfaces earlier than under current processes.

2. Investigate fraud faster, and at scale

Agencies often have to compile evidence across fragmented systems before they can evaluate a potential fraud leads, requiring extensive time and attention. Automating much of that preparation can help staff spend more time on judgment and less on information gathering.

Assemble evidence from multiple sources into a single package

Bringing together information from multiple sources, AI agents could help compare findings against program rules, identify inconsistencies, and produce concise summaries for review. A consolidated evidence package can then help investigators spot high-risk leads that claims or transaction data alone may miss.

For example, AI agents could scan online reviews as signals of whether a provider is still operating and cross-check multiple sources to verify license status, saving reviewers time. As AI agents continuously scan provider data, agencies could maintain a living risk profile rather than a static file (see “Fight fraud smarter with a continuously-learning fraud defense”).

Fast-track actionable fraud leads

This also changes how agencies prioritize work. Instead of relying only on predefined risk scores and referrals, agentic AI could help improve this process by evaluating each lead against policy requirements, available evidence, and likely impact. That helps enable health agencies to focus on actionable leads where evidence is strong, the basis for agency action is clear, and potential for patient harm due to benefit changes is low and can be assessed and managed (figure 3).

Use AI agents to target fraud patterns with custom search analytics

Agency reviewers and investigators have long had access to sophisticated analytics, but those tools rely on predefined search terms, which can make it harder to flag anomalous billing patterns, limiting the ability to query freely, test new hypotheses, or look for repeat fraud patterns. With agentic AI systems, staff could ask plain-language questions that combine provider characteristics, program rules, network relationships, and fraud signals. This could help identify repeat fraud patterns. For example, an agency reviewer might ask an AI agent to flag every provider who lost an appeal, has been removed from a healthcare program, or had funds recovered.

The shift from searching for long-understood patterns to uncovering ones never before queried could help detection keep pace with fraud that constantly evolves. The same approach could support faster action across related leads.

Where to start

  • Build an agent to target one high-risk fraud pattern.
  • Pick a single fraud typology, such as durable medical equipment, build an agent to assemble the evidence an investigator needs to act, and reuse it across every case of that type.

3. Fight fraud smarter with a continuously learning defense

Detecting fraud earlier and investigating it faster matter, but the bigger gains may come from helping agencies learn across programs and over time.

Build institutional memory across programs

To identify fraud patterns across programs, agencies need consistent mechanisms to adjudicate shared signals, determine appropriate actions, and coordinate responses. Doing so requires clear authority, repeatable processes, and trust frameworks that enable agencies to share and act on information responsibly. Where secure sharing is possible, agentic AI could help synthesize signals across sources, identify related investigations, and surface risks that may not be visible within any single program.

Privacy-preserving approaches can help agencies learn from shared fraud patterns without centralizing sensitive data. A similar approach has shown promise in the private sector: The Society for Worldwide Interbank Financial Telecommunication used AI on cross-border payment fraud data from 13 financial institutions, resulting in a twofold improvement in detection of known fraud while keeping each institution’s data secured in-house.7

And even when full data integration isn’t feasible, agencies can still share risk signals and outcomes. The goal is not simply to move more data around; it’s to create a shared learning layer that enables one program’s signal, action, or result to help improve another program’s prevention efforts.

Continuously learn from fraud signals, controls, and outcomes

Health agencies could use agentic AI to support a continuous learning loop. This process can bring together fraud signals across the ecosystem, compare them with current policies and controls, and continuously update a multidimensional risk profile for each provider. Since the most useful signals often sit outside claims data, integrating these sources can reveal patterns that would otherwise be difficult to detect. As new signals arrive, the risk profile evolves, which could help agencies surface emerging schemes earlier and identify where interventions are working or falling short. Results from interventions can feed back into the process, informing real-time adjustments to operations, policies, and prevention and detection strategies.

The prevention payoff is straightforward: As agencies validate and incorporate pattern knowledge over time, they could use agentic AI systems to help identify emerging fraud schemes before they fully materialize and potentially prevent losses. Sharing these insights across agencies can strengthen fraud defenses over time. A signal in one program can become context for another, and an outcome in one jurisdiction can sharpen risk prevention and detection elsewhere (figure 4).

Where to start

  • Close one loop, such as payment suspensions, and use the outcomes to improve detection logic.
  • Partner with another agency on one fraud pattern, such as duplicate billing.

Manage risks and establish safeguards

Responsible use of agentic AI requires strong guardrails: Systems should be secure, privacy-preserving, transparent, explainable, fair, accountable, and reliable. Human review of AI-generated fraud leads, with governance and validation, can provide feedback that can help the system distinguish likely fraud from legitimate variation, and may improve lead prioritization over time. Each risk should be managed with an appropriate safeguard (figure 5).

What needs to be true for this to work

Human judgment, strong safeguards, and iterative testing are given. Beyond those, three conditions matter most.

  • Capture knowledge before scaling. Fraud prevention often depends on health agency expertise, informal practices, and complex policy interpretations. Agencies should document that knowledge, along with the operating procedures around it, before scaling agentic AI systems.
  • Build fraud prevention in from the start. Fraud risk begins when a policy is designed, not after the first false claim is filed. Agencies should review fraud vulnerabilities alongside legal and privacy considerations.
  • Measure what prevention makes possible. Track dollars recovered, but also how quickly risks are identified, how much investigative capacity is freed, which leads drive action, and how much fraud is stopped before payment.

Learning at the pace of fraud

Agentic AI can’t eliminate healthcare fraud, but it could help agencies stay ahead of it. By combining human judgment with systems that continuously learn across programs—from policy design and enrollment to review and investigation—health agencies could spot vulnerabilities earlier, investigate faster, and strengthen fraud defenses.

As adoption accelerates across the public sector, health agencies could lead the next wave of innovation in fraud prevention. The result might just be a fundamental shift from recovering losses to preventing fraud by design.

Continue the conversation

Meet the industry leaders

Kelly Bowman

Principal | Enterprise Operations & Risk | Government & Public Services | Deloitte Transactions and Business Analytics LLP

Lauren Allen

Principal | Enterprise Operations & Risk

Danielle Gewurz

Director | Deloitte Consulting LLP

Jamia McDonald

U.S. National Health, Human Services and Labor Leader, Deloitte US

Amir Drusbosky

Managing Director

By

Kelly Bowman

United States

Lauren Allen

United States

Danielle Gewurz

United States

Stephen Mahmood

United States

Alison Muckle Egizi

United States

ENDNOTES

  1. CMS, Urinary Catheter Case Study: CMS’ Swift Action Saves Billions at https://www.cms.gov/files/document/cpi-urinary-catheter-case-study.pdf, N.D.

  2. US Government Accountability Office, “Fraud risk management: 2018-2022 data show federal government loses an estimated $233 billion to $521 billion annually to fraud, based on various risk environments,” April 16, 2024.

  3. Centers for Medicare & Medicaid Services, “Crushing fraud: Annual report 2025,” accessed Aug. 12, 2026.

  4. Centers for Medicare & Medicaid Services, “Urinary catheter case study: CMS' swift action saves billions,” Sept. 23, 2024.

  5. US Department of Health and Human Services Office of Inspector General, “Unclear Medicare requirements led to differing interpretations of inpatient rehabilitation facility documentation, coverage, and billing requirements,” May 12, 2026; National Association of Medicaid Directors, “Why did they do it that way? Understanding Medicaid policymaking,” April 10, 2023.

  6. Centers for Medicare & Medicaid Services, “Revalidations (renewing your enrollment),” accessed Aug. 12, 2026; Susan Morse, “CMS mandates state Medicaid directors to validate providers,” Healthcare Finance News, May 1, 2026.

  7. Swift, “Swift AI innovation creates blueprint for banks to stop fraud faster through cross-border collaboration,” press release, Sept. 15, 2025.

ACKNOWLEDGMENTS

The authors would like to thank Nicole Savia Luis who supported research, writing, and figure design for this article. We are grateful to Jamia McDonald, Amir Drusbosky, Calvin Krishen, Gary Cantrell, Thomas Smith, Barton Bishop, Jason Lund, Fernando Alvarez, Amina Popowich, Anastasia Andreadis, William D. Eggers, Grant McLaughlin, and Natalie Young for sharing their insights which helped inform this study. Lastly, we would like to thank the Deloitte Insights team for their creativity, ideas, and collaboration on this article including Rebecca Knutsen, Harry Wedel, Natalie Pfaff, and Sayanika Bordoloi.

Editorial (including production and copyediting): Rebecca Knutsen, Sayanika Bordoloi, and Pubali Dey

Design: Natalie Pfaff and Harry Wedel

Cover image by: Sanaa Saifi

Knowledge services: Agni Wagh

COPYRIGHT