Why This Suddenly Became a Real Problem
Fourteen months ago, almost none of the fake receipts flagged by expense-fraud detection systems were AI-generated. By mid-May 2026, they were the majority.
That's the finding from AppZen, a finance-automation company that scans corporate expense submissions for fraud. In March 2025, AI-generated receipts accounted for essentially 0% of the fake receipts its systems caught. By May 2026, that number had climbed to 70.8%. Over the trailing 12 months, AppZen detected 1,471 AI-generated receipts submitted by 745 employees across 174 companies, representing $148,143 in claimed expenses.
If you run a small business and reimburse employees for travel, meals, or supplies, this isn't an abstract enterprise problem. It's a shift in how ordinary people cheat on expense reports, and it's happening at every company size, not just the Fortune 500.
What Changed: From One Big Fake to a Pile of Small Ones
Before generative AI tools became widely accessible, fabricating a receipt took some effort — usually editing a template in image software or physically altering a real one. Fraudsters who went to that trouble tended to swing big: AppZen found that older, template-based fake receipts averaged $182 each.
AI changed the economics. A large language model or image generator can produce a convincing restaurant receipt, complete with a plausible merchant name, itemized totals, and even a fake scanner watermark, in seconds and for free. That has flipped the incentive structure entirely.
AppZen's CTO, Kunal Verma, put it plainly: "AI generators are free, instant, and good enough to fool a person." He added that AI "basically flipped the game from one fake big enough to be worth the risk to a pile of tiny ones nobody bothers to review."
The numbers back this up. AI-generated receipts in AppZen's dataset averaged just $101, with a median of only $32 — well under the auto-approval thresholds most expense systems use to fast-track small claims without manual review. Instead of one $500 fake dinner that might catch an approver's eye, the new pattern is a dozen $30-$40 claims that each look unremarkable on their own.
It's Not Just an Enterprise Problem
The scale of individual incidents AppZen documented is striking. One Fortune 10 company had 142 employees across 22 countries submit 340 AI-generated receipts totaling $34,953 — more than all 25 of AppZen's European customers combined. India led in submission volume, while Australia showed the highest concentration per receipt, including one telecom employee who claimed $12,900 across just 11 forged receipts.
But small and mid-sized businesses are exposed too, often more acutely, because they typically lack a dedicated fraud-detection team and rely on a manager's eyeball review or a bookkeeper's spot check. A European optical retailer in the AppZen data had a single employee submit 45 fraudulent receipts spread across 15 separate expense reports before anyone noticed a pattern.
And this isn't a fringe behavior. A separate survey of 2,000 workers by expense-management company Emburse found that 40% of U.S. respondents admitted to using AI to generate a fake receipt. Of those, 19% said they fabricated a purchase entirely, 15% used AI to inflate the value of a real expense, and 6% used it to recreate a receipt for a purchase they'd genuinely lost the paper trail for.
Worth noting: not everyone using AI here is trying to steal money. Some employees are using it to reconstruct a legitimate lost receipt rather than commit fraud from scratch — a nuance worth keeping in mind before you assume every flagged claim is malicious. But from a controls standpoint, an AI-fabricated document is an AI-fabricated document regardless of the motive behind it, and it breaks the assumption that a receipt is proof a transaction happened.
What AI-Generated Receipts Actually Look Like
The fakes have gotten sophisticated enough that visual inspection alone often isn't enough to catch them. Examples from AppZen's dataset include:
- Forged restaurant receipts with fabricated scanner watermarks and convincing handwritten-style signatures
- Fake AT&T and Xfinity bills, suggesting fraud is expanding from one-off meal and travel claims into recurring monthly "expenses"
- Itemized totals and tax calculations that are internally consistent enough to pass a quick glance
Template-based fakes — the older method — made up 95% to 100% of flagged fraud a year earlier. By May 2026, they'd fallen to just 29% of the total, with AI-generated receipts taking over the majority share. The tools got better, cheaper, and more accessible, and fraud tactics moved with them.
Why This Matters for Every Business, Not Just Large Ones
Corporate travel and expense fraud is already a meaningfully sized problem — one broader fraud-exposure study estimated $3.5 billion in total expense and travel fraud exposure, with roughly $175 million of that specifically tied to AI-generated documents. Expense and travel fraud also stands out for being unusually document-driven: an estimated 85% of schemes in that category involve some kind of paperwork, meaning receipts and invoices are the primary attack surface.
For a small business, the exposure isn't proportional to headcount — it's proportional to how much you rely on unverified paper (or PDF) trails. If your expense approval process is "an employee submits a receipt and a manager clicks approve," you have exactly the control gap this fraud pattern is built to exploit.
How to Protect Your Business
You don't need enterprise fraud-detection software to meaningfully reduce this risk. A few practical changes go a long way:
Stop treating receipts as proof by themselves. A receipt is a claim, not evidence. Cross-reference it against something independent — the actual card or bank transaction, merchant records, a calendar entry, or a travel itinerary. If a $38 lunch receipt doesn't correspond to an actual card charge that day, that's your signal, not the receipt's appearance.
Reassess your auto-approval thresholds. Fast-tracking small expenses under a dollar threshold is reasonable for keeping reimbursements quick, but it's also precisely the gap AI-generated fraud is designed to exploit. Consider random sampling of "under the threshold" claims rather than approving 100% of them automatically — even a 10% audit rate changes the risk calculation for anyone considering padding a report.
Don't rely on a single detection signal. Some finance teams lean on embedded file metadata (like image EXIF data) to spot AI-generated images. That's fragile — metadata is easily stripped by screenshotting, converting file formats, or simply re-saving the image. Layer multiple checks instead: does the vendor exist, does the amount match a real transaction pattern, does the timing make sense.
Watch for patterns across small claims, not just large ones. A single $30 questionable receipt might be a rounding error. Ten of them from the same employee over three months is a pattern worth a conversation. Aggregate views — sorting by employee, by vendor, by round-number amounts — surface what individual review misses.
Where Clean Books Make This Easier
The businesses best positioned to catch this kind of fraud aren't necessarily the ones with the fanciest detection software — they're the ones with expense data that's easy to query, cross-reference, and audit in the first place. If your bookkeeping lives in a format that's hard to search or compare against bank records, spotting a pattern of small, suspicious claims becomes a manual slog.
This is one of the quieter advantages of plain-text accounting. Beancount.io keeps your ledger in a version-controlled, human- and script-readable format, so cross-referencing an expense claim against the actual transaction — or writing a quick query to flag every reimbursement just under your approval threshold — is straightforward rather than a spreadsheet archaeology project. Get started for free and see why developers and finance-minded business owners are switching to plain-text accounting.