PayPal uses artificial intelligence (AI) and machine learning to assess payment and account risk in real time. Those models can recommend approval, decline, a temporary hold, extra verification or human review. They work alongside passkeys, encryption, secure network connections, account controls, investigations and consumer- and merchant-protection programs. AI improves the speed and context of fraud decisions, but it is not a guarantee that every scam, account takeover or cyberattack will be stopped.
How PayPal’s AI security system works
- Signals are collected. Depending on the product and event, PayPal may evaluate payment and buyer details, purchasing patterns, device intelligence, IP address, email, phone information, login and session behavior, geolocation and relationships among accounts, devices and transactions.
- Models compare context. Machine-learning systems look for patterns associated with legitimate activity, fraud, account takeover or likely disputes. Public documentation describes the categories of inputs, not the complete model architecture, training data or feature weights.
- A risk assessment is produced. Fraud Protection Advanced documentation describes a real-time score from 0 to 100, where 0 represents no risk and 100 high risk, for the transactions covered by that merchant product.
- A policy determines the next step. PayPal or the merchant can approve, decline, hold or route a transaction for verification or review. The model’s score is decision support, not proof that a customer is dishonest.
- Outcomes inform future controls. Confirmed fraud, disputes and investigation results can help improve rules and later risk modeling.
PayPal says its merchant systems use intelligence from both sides of its network—consumers and sellers—rather than relying only on one merchant’s history. Its current U.S. business page displays PayPal-reported figures of $1.79 trillion in annual payment volume, 12.8 billion digital identifiers and 98.5% of buyers recognized. These are scale and recognition claims, not independently audited measures of model accuracy, fraud-loss reduction or false-decline performance: PayPal business risk management.
What kinds of fraud the models can detect
Payment fraud
An unusual card, rapid sequence of transactions, high-value purchase or connection to known risky entities can increase a payment’s assessed risk.
Account takeover
Changes in login behavior, device, location or session context can indicate that someone other than the account holder has obtained access. A familiar device is not conclusive protection if that device itself is compromised: PayPal’s fraud-analytics overview.
#1 Best Overall
New-account and synthetic-identity fraud
With little account history available, models may use email, session, enrollment and third-party information to identify suspicious sign-up patterns: PayPal’s machine-learning explainer.
Chargebacks and friendly fraud
Risk tools can identify transactions more likely to produce a dispute and help organize chargeback work. A prediction is not a finding of dishonesty: a genuine unauthorized payment, delivery problem or customer misunderstanding can resemble “friendly fraud.”
Phishing and social engineering
AI can flag activity after an account is compromised, but it cannot ensure that a person will not be persuaded to disclose a password, code or payment information. PayPal continues to warn users about phishing and account compromise: PayPal Security Center.
Why the system sometimes adds friction
The objective is not maximum blocking. A rule that catches more suspicious payments can also reject legitimate customers, reduce approval rates and create review costs. PayPal describes balancing fraud losses, approvals and customer friction. A routine purchase from a familiar device and location may require little intervention; a high-value purchase from an unusual device or location may receive a hold, decline or additional verification. That is a description of risk-based decisioning, not a guaranteed rule for every transaction: PayPal fraud-management guidance.
Recommended Free Tools
Consumer protections that are not AI
- Passkeys: Where available, users can authenticate with a face, fingerprint, device passcode or PIN. PayPal describes passkeys as phishing-resistant.
- Monitoring and alerts: PayPal says it provides 24/7 fraud monitoring and early fraud alerts for eligible cards.
- Encryption and TLS: Secure connections protect data in transit; they do not stop a user from authorizing a scam.
- Key pinning: PayPal says its mobile apps establish TLS connections with verified PayPal servers to help prevent interception by impostor servers.
- Notifications and reporting: Payment confirmations and suspicious-activity reporting help users identify and respond to unauthorized activity.
- Security research: PayPal has used vulnerability reporting and bug-bounty work, including a HackerOne partnership.
Details, eligibility and availability can vary by device, browser, account and market: PayPal secure technology.
Tools available to merchants
| Tool | Typical fit and capabilities |
|---|---|
| Fraud Protection | Integrated PayPal intelligence, machine learning and configurable risk controls for merchants using eligible PayPal processing. |
| Fraud Protection Lite | A more self-service option for teams wanting automated decisioning with less operational setup. |
| Fraud Protection Advanced | For merchants with dedicated fraud teams; includes risk scoring, custom filters, allowlists, blocklists, reviewlists, manual review, dashboards and audit trails. |
Merchant controls can include automatic approve, reject or review rules, historical transaction testing, analytics and dispute tools. Testing a filter against historical data lets a merchant estimate its effect before activating it. Product availability, supported integrations and terms vary by market and account; PayPal does not publish a universal standalone price on the cited pages: Fraud Protection Advanced documentation and PayPal help.
AI’s limits and failure modes
- False positives: Travelers, shared devices, VPNs, browser resets, unusually large purchases and new customers can look risky.
- Changing attacks: Criminals adapt, distribute activity across accounts and try to mimic normal behavior.
- Incomplete data: A new account or compromised familiar device may provide too little reliable context.
- Explainability: PayPal does not publish complete model logic, training corpus, weights or error rates.
- Privacy and governance: Network intelligence raises questions about data use, retention, cross-border processing and access controls.
- AI-enabled scams: Generative AI can make phishing, impersonation, deepfake voice and synthetic-identity attacks more convincing.
PayPal’s FY2025 filing acknowledges that AI can involve flawed, biased or insufficient data and create additional privacy, cybersecurity, intellectual-property and regulatory risks. AI cannot guarantee that every fraudulent payment is blocked, every legitimate payment is approved, an account cannot be taken over, or PayPal’s systems will never suffer an outage or attack: PayPal FY2025 Form 10-K.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Cybersecurity beyond transaction scoring
PayPal describes a broader program guided by the NIST Cybersecurity Framework, ISO 27001 and other controls. It reports vulnerability testing, resilience and continuity planning, a 24/7 Cyber Defense Center, incident-response procedures, workforce training, third-party risk management and board and Risk & Compliance Committee oversight. Those corporate controls address infrastructure and operational threats; they are different from deciding whether one payment looks fraudulent.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
What PayPal’s AI governance adds
According to PayPal’s 2026 proxy materials, the company adopted an Enterprise AI Governance Framework in 2025. It includes an AI Governance Charter, an executive council, working groups, enterprise policy and standards, and oversight within PayPal’s risk structure. Its stated principles cover data privacy, security and resilience, fairness, explainability, reliability, accountability and transparency. Governance can set accountability and testing expectations, but it does not make a model infallible: PayPal 2026 proxy statement.
Practical steps for users and merchants
Consumers
- Use a passkey and multifactor authentication where available.
- Use unique credentials and secure the email account and phone number linked to PayPal.
- Do not use links or phone numbers in suspicious messages; open PayPal directly.
- Review notifications and report unauthorized activity promptly.
Merchants
- Track approval, decline, fraud and dispute rates together.
- Test filters on historical transactions before deployment.
- Use manual review for high-value or ambiguous orders.
- Protect administrator accounts with strong authentication and limit privileges.
- Treat a risk score as evidence for a decision, not an absolute verdict.
The Bottom Line
PayPal’s security advantage is layered: real-time AI risk assessment and network intelligence are combined with authentication, encryption, monitoring, human review, merchant controls and cybersecurity governance. That combination can reduce fraud and unnecessary friction, but users and merchants still need their own controls because AI is probabilistic—not a magic shield.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




