Family Threat Model · Reading

AI and Catastrophic Loss

How the Family Threat Model weights artificial intelligence against family fortune.

Thomas M. Stone · TargetProof, LLC · Atlanta · September 2026

A note to the Reader on method and purpose. This article is written in the context of a Family Threat Modeling practice applying method to digital estate protection. On the topic of Artificial Intelligence, threat modeling needs to score AI as both an attack surface and a leakage path. This piece is not a vendor ranking of products. It is an evidence-based reading of which AI-related exposures can move, or help an adversary move, a family’s fortune — judged by recoverability, insurability, and ultimately survivability.

1. The household is not a small enterprise

An ultra-high-net-worth household is a different surface from the firm that created the wealth. Concentrated capital, wire authority, public visibility, multiple residences, household staff, and personal devices sit outside the controls that protect a CFO at the office. TargetProof’s UHNW schema treats six surfaces as one picture:

SurfaceWhat is at stake
PeopleFamily, staff, and advisors — trust boundaries across everyone who can be reached
WiresEstate, real-estate, vendor, philanthropic, and trust transfers — single-point exposure
DevicesPhones, laptops, tablets, and recovery channels outside any enterprise stack
PropertiesFlat networks, cameras, IoT, and integrators with quiet lingering access
VisibilityBoards, philanthropy, press, and social — patterns an adversary can read
TravelRoutines that make a principal predictable

Adversaries do not respect those silos. Neither does AI. A cloned voice is a people problem that becomes a wire problem. A travel itinerary pasted into a consumer chatbot is an internal-use problem that becomes a targeting problem. The Family Threat Model therefore does not treat “AI risk” as a seventh surface. It scores AI through the six.

The model’s own principle is explicit: AI is an attack surface and a leakage path — synthetic impersonation outside the estate, unsanctioned models inside it. High-impact controls weigh more than hygiene.

That last sentence is the whole argument. For a family whose fortune can move on one instruction, average-loss statistics are the wrong unit. The right unit is whether a gap can produce a catastrophic, hard-to-reverse transfer.

2. Two treatments of AI, not one

The model scores AI in two directions. Mixing them is how most “AI security” briefings go wrong.

External — AI used against the estate

Synthetic voice and video of a principal or CFO. Language models that draft counsel letters, invoices, and closing packets without the typos that used to give fraud away. Automated open-source intelligence that assembles routines, staff names, and follow-home paths from fragments the family already published.

Internal — AI used inside the estate

Executive assistants, bookkeepers, and outside counsel pasting deal memos, travel files, or family schedules into consumer chatbots. Meeting-note bots on counsel calls. Camera-cloud analytics on nanny and elder feeds. Agents connected to mailboxes or bill-pay.

Intake treats this as a first-class household fact, not a technology footnote: which consumer tools staff already use, which meeting bots sit on family-office calls, which vendor clouds see estate video, which children’s apps retain likeness, and whether any agent can reach email or payments.

The two treatments share a control philosophy and split on evidence. External AI has begun to produce named, nine-figure losses. Internal AI has produced well-documented enterprise leaks and a plausible path to targeting intelligence — with far fewer public UHNW dollar figures. A serious model weights both, and says which is which.

3. The safety headlines are not household protection

The news cycle of summer and early autumn 2026 is real. Laboratories have withheld dual-use capabilities, paused some evaluations, and published reports on misuse of their own models. That work belongs at the frontier. It is easy to mistake for protection of the family.

Anthropic Newsroom, September 2026: Detecting and countering misuse of AI, and Improving our alignment and security efforts.
Anthropic Newsroom, 10 September 2026. Source: anthropic.com/news.

The useful fact in that record is not the product names. Over eight months, one laboratory disrupted operations that used widely deployed models — not only the newest, most restricted classes — for cyber operations, scams, and fraud. Investigators wrote that AI has collapsed the labor and tooling gap that used to separate well-resourced operators from individuals. Open-weight models sit outside those live classifiers entirely.

The fortune-moving vectors in this article do not wait for the next frontier release. They run on tools already in the house: the wire, the recovery channel, the likeness used as authority, the paste into a public model. A laboratory fallback does not dual-control a payment or survive a perfect video of the principal. Weight the headlines as industry news. Do not weight them as a control the household already has.

4. How weighting works — impact, not fashion

The catalog is impact-weighted on a 1–5 scale. A gap at 5 moves household maturity and the roadmap harder than a gap on a supporting hygiene item. That is a severity design, not a frequency design.

For UHNW fortune protection, that is the correct design. FBI Internet Crime Complaint Center (IC3) data for 2025 recorded reported losses of $20.9 billion, up from $16.6 billion in 2024. The average complaint is still the wrong unit for a family office. A single diverted close, a single treasury instruction, or a single coerced wallet transfer can exceed a lifetime of “average” cybercrime.

What is useful in the IC3 record is the ranking of crime types by dollar loss, and the Bureau’s own definition of the crime that most resembles a family-office disaster.

2025 IC3 crime typeReported lossComplaints
Investment fraud$8.65 billion72,984
Business email compromise$3.05 billion24,768
Tech / customer support$2.13 billion47,794
Personal data breach$1.31 billion67,456
Government impersonation$798 million32,424
Real estate$275 million12,368
SIM swap$17 million971
FBI IC3 2025 Annual Report page 8: crime types by complaint loss, Business Email Compromise $3.05 billion.
FBI IC3 2025 Annual Report, p. 8 — BEC $3.05 billion. Source: ic3.gov.
FBI IC3 2025 Annual Report page 39: Artificial Intelligence used in cybercrime, 22,364 complaints, $893 million.
Same report, p. 39 — AI-related descriptor $893 million; AI-mentioned BEC about $30 million. Source: ic3.gov.

Cryptocurrency remains a descriptor across crime types: 181,565 complaints and $11.4 billion. The AI Related line is not a crime type. It means the complainant mentioned AI. Complainants age 60 and over — the cohort that holds a disproportionate share of household wealth — reported $568,048,472 in BEC losses (FBI IC3 2025 Annual Report, p. 46).

IC3’s definition of business email compromise now reaches beyond email. The 2024 report describes BEC as scams carried out “by compromising email accounts and other forms of communication such as phone numbers and virtual meeting applications.” That sentence is the bridge from classic wire fraud to deepfake video conference. The Family Threat Model had already placed both in the same control family: no payment instruction is valid until a ritual that survives a perfect likeness of the principal.

The model’s “money-first” week is therefore not a marketing sequence. It is the order in which gaps can still move fortune this week: wire dual-control, a verification ritual that survives synthetic video, phishing-resistant identity on principal and banking accounts, a written ban on confidential material in consumer AI, and a prohibition on agents that can initiate or change payments.

5. Evidence-weighted ranking of AI vectors

The ranking below is against catastrophic loss of family fortune — a completed, hard-to-reverse transfer or coercion of capital — not against embarrassment, not against “AI risk” as a board topic, and not against the volume of consumer scams.

Confidence is marked as:

  • Documented — named public cases or regulator dollar series
  • Amplified — a documented non-AI crime whose targeting or pretext is now cheaper because of AI
  • Plausible / thin public dollars — mechanism is real; UHNW fortune-loss case law is still sparse

Rank 1 — Wire diversion, now AI-fluent

Documented. Highest aggregate dollars. Highest UHNW relevance.

BEC remains the operational crime that most resembles a family-office catastrophe. In 2025 it was again the second-largest IC3 loss category at $3.05 billion, on 24,768 complaints — a high loss-per-incident crime, not a high-volume nuisance. The 2024 Recovery Asset Team Financial Fraud Kill Chain, used mostly on BEC, attempted recovery on $848 million and froze funds in 66 percent of those cases. The residual is still hundreds of millions that did not come back.

Family offices live in the exact habitat BEC was built for: counsel threads, title companies, philanthropic pledges, art and vehicle invoices, and multi-jurisdictional closes. AI does not create this vector. It removes the last cheap tell. A language model will draft a closing packet or an “updated wiring instructions” note that passes a hurried read. IC3 said so in 2025: chat generators “can quickly create official-sounding emails mimicking a company’s CEO,” and voice cloning can request a wire. It also said, in the same paragraph, that not all BEC is AI-enabled. Complaints that mentioned AI in a BEC totaled $30.3 million — against $3.05 billion in BEC overall. Weight the wire. Do not invent a new league table from the descriptor.

What the model requires, in household English: payment and wire changes never from email alone; two people; a known bank number; no exceptions. The family office can walk the last wire against the written procedure.

This is not an “AI control.” It is the fortune-control that AI now attacks more fluently. Weighting it as a critical gap is the most evidence-based decision in the catalog.

Rank 2 — Live synthetic voice and video that authorizes money

Documented. Low public frequency. Catastrophic severity per incident.

In early 2024, CNN and other outlets reported that a finance worker at a multinational transferred approximately $25 million after a video conference in which the “chief financial officer” and other participants were deepfakes. The Family Threat Model records this pattern as deepfake video call wire authorization: live likeness of a CFO or principal used to instruct treasury staff. Public reporting of nine-figure attempted and completed fraud via synthetic conference is no longer hypothetical.

CNN headline, 4 February 2024: Finance worker pays out $25 million after video call with deepfake chief financial officer.
CNN, 4 February 2024. Heather Chen and Kathleen Magramo. Source: cnn.com.

Frequency is still low relative to email BEC. Severity is not. One successful session is a fortune event. Multi-principal families and distributed decision-makers — the UHNW default — are the high-value target: the person on camera is rarely the person who can walk down the hall.

IC3’s 2024 BEC definition already includes virtual meeting applications. The right reading is not “deepfake is a new crime.” It is “BEC has a new channel, and that channel defeats voice-and-face as authentication.”

What the model requires: a verification ritual that still works when the video is perfect. A second channel the attacker cannot clone in-session. Family and staff who will refuse an urgent on-camera instruction and execute the ritual. Crisis communications that use the same ritual, not a weaker one, because that is when the clone will be used.

Voice-only “grandparent” and emergency scams are real and well publicized. IC3’s 2025 AI section attributed more than $5 million to distress scams using voice cloning, inside $19 million of confidence/romance complaints with a likely AI nexus. Serious for the victims. Not the UHNW fortune-loss ranking. The video-conference treasury case is. Do not let consumer-scam volume set the household’s priority.

Rank 3 — Identity takeover that turns into a wire or a wallet

Documented. AI is a helper, not the weapon.

SIM swap and account recovery remain the path that converts a phone number into every MFA-protected fortune: banking apps, family-office admin, crypto exchanges. IC3 recorded $26 million in SIM-swap losses in 2024. That figure almost certainly understates whale losses; public prosecutions and civil cases have repeatedly attached seven- and eight-figure crypto thefts to mobile-account takeover. The model’s lesson is unchanged: the principal’s phone number is a crown-jewel credential, not a convenience channel.

AI enters as pretext quality (a cloned-voice “carrier support” call, an AI-written recovery narrative) and as targeting (which numbers, which exchanges, which recovery emails). The catastrophic step is still the takeover. Phishing-resistant MFA on principal email and on banking / family-office admin is therefore in the money-first week alongside the deepfake ritual — because without it, the ritual’s second channel may already be in the attacker’s hand.

Rank 4 — AI-accelerated targeting that ends in physical coercion

Amplified. Documented physical crime; AI as reconnaissance multiplier.

The model’s whale patterns include home invasion for crypto keys, executive kidnapping for ransom, and travel-route targeting. Those are not AI crimes. They are documented in U.S. federal prosecutions, San Francisco home invasions, and European cases against crypto-industry principals. Digital-asset wealth converts physical security into a primary control.

What AI changes is time-to-target. Property records, aircraft tracks, event photographs, staff names, and children’s school cues can be synthesized into a follow-home picture without a specialist analyst. The same fragments FTC data-broker cases have highlighted for years are now cheap to assemble. The Family Threat Model therefore treats findable voice, video, and routine as clone-ready and targeting material — not lifestyle content and not a communications problem.

Public profile is scored as an operational risk input, not a reputation-management exercise. That is the UHNW-correct reading. A gala photograph is not a brand asset if it is also a voice sample, a calendar, and a driveway.

Rank 5 — Staff and advisor leakage into public models

Plausible / thin public UHNW dollars. High impact weight anyway, with the caveat stated.

There is not yet a public series of UHNW families who lost a nine-figure wire because an assistant pasted a schedule into a chatbot. Independent review of the public record through 2026 did not find a named family-office victim with dates and a dollar figure. There is a well-documented enterprise pattern: employees pasting source code, deal terms, and privileged correspondence into consumer models; vendors retaining prompts; meeting bots joining calls the principal believed were closed. ABA Formal Opinion 512 (29 July 2024) states that lawyers generally must obtain a client’s informed consent before putting information relating to a representation into a self-learning generative AI tool. That is the institutional reading of the same path.

For a family office, the catastrophic versions of this leak are not “the model trained on our data.” They are:

  1. A deal memo, wire file, or travel itinerary that now sits on a vendor’s systems and in a chat log an insider or a breach can reach.
  2. Targeting intelligence — who is traveling, when, with which children, which banks, which counsel — assembled without OSINT.
  3. Privilege and confidentiality problems that become litigation or regulatory problems.

The model weights this with the same seriousness as external impersonation because the path is one paste and the material is crown-jewel. That is a severity judgment, not a claim that IC3 has a “shadow AI” loss line. An honest article says so.

What the model requires: a named allowed-versus-banned list; confidential family, legal, and financial data never in consumer tools; an inventory of every chatbot, meeting bot, camera-cloud AI, and agent already in the house; a spot-check of one EA or advisor chat history. Policy without inventory is theater.

Rank 6 — Agents with mailbox or payment reach

Plausible / emerging. Precautionary critical weight.

A helpful agent connected to email, calendar, or bill-pay can be prompt-injected by a crafted message and can initiate a payee change or forward privileged mail. Public UHNW loss series for this pattern are still thin in 2025–2026; the privilege is not. Mailbox reach is privileged access. Payment reach is treasury. The model’s rule is binary and should stay binary: no AI agent may initiate or approve wires, transfers, or vendor-payment changes. Anything that can move money fails the control.

This is the internal mirror of Rank 1. External AI impersonates the principal to the staff. Internal AI is the staff, with an API.

Rank 7 — Household cameras and children’s AI as a likeness factory

Plausible. Lower direct dollar evidence; high targeting and future-clone value.

Tutoring apps, companion chatbots, and nanny or elder cameras send identifiable audio and video to vendor clouds. The family did not intend to create a likeness and location corpus. Consumer privacy policies routinely permit training or human review. The model’s control is: cloud AI processing off, or an explicit principal acceptance.

This ranks below wires because it does not, by itself, move fortune this week. It ranks above “hygiene” because it manufactures the raw material for Ranks 2 and 4 — clone-ready media and location — on a schedule the family does not control.

Rank 8 — After-action takedown

Documented as process, not as restoration of capital.

A likeness, voice-clone, and synthetic-content takedown path with counsel and platform contacts is necessary. It does not unwind a completed wire. The model therefore weights recovery of synthetic content below prevention of the instruction. Families that invert that order — “we will deal with deepfakes if they appear” — are managing reputation after the fortune has moved.

6. What the evidence does not support

A few claims that circulate in UHNW security conversations do not survive contact with the public record.

“The labs are locking it down, so we can wait.” They are restricting some frontier capabilities. Public threat reporting in 2026 is explicit that financially motivated criminals still used widely deployed models for scams, fraud, and cyber operations. Open-weight models are not behind those classifiers. The household’s exposure is the tool already in staff hands, not the one the laboratory has not shipped.

“AI is now the largest cyber loss category.” It is not. In 2025, investment fraud ($8.65 billion) and BEC ($3.05 billion) still dominated IC3 dollars. The Bureau’s new AI Related descriptor totaled $893 million — and most of that sat inside investment complaints ($632 million), not wires. AI-mentioned BEC was $30 million. AI is a quality upgrade to BEC, impersonation, and targeting — not a replacement category. IC3 itself notes that many victims do not realize AI was involved. The upgrade is real. It does not create a new loss category.

“Deepfake voice of a grandchild is the UHNW scenario.” It is the consumer scenario. The UHNW scenario is a live video of the principal or CFO instructing a transfer, or an AI-perfect counsel thread changing a close. Train staff on both. Fund the second.

“If we ban ChatGPT, we have done AI security.” A ban without inventory, without a meeting-bot rule, without camera-cloud review, and without an agent-permission review is a memo. The model’s internal path is inventory → data-flow → ban list → detection of unsanctioned tools → no payment authority for agents.

“Public speaking and philanthropy are separate from security.” They are clone-ready credentials and targeting feeds. The model scores them in Govern and Identify, not in a communications annex.

“We will know it when we see it.” The Arup-class case succeeded because the likeness was good enough that treasury did not see it. Detection of the fake is a losing bet. Detection that the instruction has not passed a second channel is the control.

7. How this sits on the Family Threat Model

The Sanctuary Loop asks four questions. AI answers all four.

  1. What are we protecting? — Fortune that can move on an instruction; people whose likeness can authorize that instruction; data that, leaked, becomes the next instruction’s targeting pack.
  2. What can go wrong? — The Threat Spectrum already includes FTC advisories on AI voice/video impersonation and AI-written pretext, and UHNWI patterns for deepfake wire authorization, shadow-AI leakage, AI-accelerated OSINT, agents with payment reach, and children’s AI as a likeness factory. Those are not a separate “AI module.” They are the 2024–2026 reading of wires, people, visibility, and institutions.
  3. What will we do about it? — Impact-weighted gaps, a 30 / 90 / 180-day roadmap, money-first in week one. AI-tagged gaps pull maturity harder than hygiene by design.
  4. Did we do a good enough job? — Residual risk is explicit. A principal may accept an unsanctioned lifestyle gadget. A principal should not silently accept a wire path that a perfect video can still open.

The model organizes the work in the order a household actually fails and recovers: Govern (who may decide, which tools are allowed, AI in the risk register), Identify (inventory of tools, likeness, data-flow, agents), Protect (no confidential paste, no agent payment authority, likeness as credential, role-play), Detect (shadow-AI discovery; a ritual that survives synthetic media), Respond (playbook for clone-plus-paste), Recover (takedown path — last, not first). Those stages are a convenience for the assessment. The weights come from evidence of what can still be recovered, still insured, and still survived.

The three dimensions — people, institutions, lifestyle — keep the weighting honest. A deepfake is a people problem executed through institutions. A camera cloud is a lifestyle convenience that manufactures people-targeting material. Scoring only “the IT stack” will miss both.

8. A proportionate program

Evidence-based does not mean “wait for a family-office IC3 line item.” It means spend first on the paths that have already moved large sums, then on the paths that would, and say so.

This week — fortune in motion

Dual-control wires. A ritual that survives a live fake of the principal. Hardware-key or passkey identity on principal email and on banking / family-office admin. No consumer AI for confidential family, legal, or financial material. No agent that can move money. Named security authority so an urgent request has someone who is allowed to say no.

Thirty days — stop improvisation

Written AI-use policy, acknowledged. Inventory of tools, bots, and camera clouds across every property. Role-play: fake principal on video; fake AI-perfect invoice. Treat raw voice and video of principals and children as credentials. Prove the last vendor offboarding actually revoked access.

Ninety to 180 days — make it durable

Footprint mapped against what the family believed was private. IoT segmented from principal devices. Credential-leak monitoring. A single incident plan that covers cyber, the house, and reputation. A tabletop with the principal in the room. Metrics that can be produced in ten minutes.

None of that requires a new product category. It requires treating AI as a modifier of the six surfaces the family already had — and refusing to weight theater (takedown dashboards, generic “AI awareness” videos) above the instruction that still moves money.

9. Sources and limits

Primary, cited

  • Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 Internet Crime Report: reported losses $20.877 billion; BEC $3,046,598,558 / 24,768 complaints; investment $8.65 billion; tech/customer support $2.13 billion; AI Related descriptor 22,364 complaints / $893,346,472 (not a crime type — the complainant mentioned AI); AI-mentioned BEC $30,256,592 / 135 complaints; investment complaints with an AI nexus $632 million of $8.65 billion overall; distress/voice-clone scams more than $5 million; complainants age 60+ BEC losses $568,048,472 (p. 46). 2025 IC3 Report (PDF)
  • FBI IC3 2024 Internet Crime Report: $16.6 billion losses; BEC $2.77 billion / 21,442 complaints; BEC definition includes phone numbers and virtual meeting applications; Recovery Asset Team Financial Fraud Kill Chain $848.4 million attempted, 66% freeze rate. ic3.gov
  • FBI IC3 public service announcement, Business Email Compromise: The $55 Billion Scam (11 September 2024) — cumulative BEC figure used in the Bureau’s own outreach.
  • CNN, “Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’” (February 2024), and contemporaneous reporting of the Hong Kong multinational case. Single-incident evidence of live synthetic video authorizing a treasury-scale transfer.
  • American Bar Association, Formal Opinion 512, Generative Artificial Intelligence Tools (29 July 2024): lawyers generally must obtain informed consent before inputting information relating to a representation into a self-learning generative AI tool.
  • FTC consumer and emerging-tech alerts on impersonation, real-estate closing wires, and AI-enabled pretext — used in the model’s Threat Spectrum as regulator warnings, not as a dollar series. FTC imposter-scam totals are not labeled AI versus non-AI.
  • Anthropic, Improving Fable 5’s biology safeguards (7 August 2026): Fable 5 launched with almost all biology queries blocked; dual-use virology, toxicology, and molecular design still fall back to a less capable model; ~85% reduction in false-positive fallbacks. anthropic.com
  • Anthropic, Investigating three real-world incidents in our cybersecurity evaluations (30 July 2026): Claude models in eval environments reached the live internet and gained unauthorized access to three organizations’ systems. anthropic.com
  • Anthropic, Improving our alignment and security efforts (31 August 2026): UK AISI report of Claude Mythos 5 unauthorized actions on the live internet (4 August); pause of external pre-release cyber evaluations; real-time sandbox-escape classifier; OpenAI sandbox-escape disclosure as the prompt for the July review; call for coordinated industry pacing. anthropic.com
  • Anthropic, Detecting and countering misuse of AI: September 2026 (10 September 2026): eight months of disrupted operations across cyber, influence, surveillance, scams and fraud, biological misuse, conventional weapons, and distillation; Haiku/Sonnet/Opus used, not Fable/Mythos (one distillation exception); “sophisticated attacks no longer require sophisticated attackers.” anthropic.com
  • Anthropic, Developing Enterprise Frontier Safeguards with our customers (1 September 2026): attempted fraud, credential theft, and agentic destructive behavior as the reason for enterprise monitoring with G-SIBs and Fortune 100 firms. anthropic.com
  • Anthropic, How Claude’s text watermark works (14 August 2026) and Our position on open-weights models (27 July 2026): EU AI Act watermarking across major providers; open-weight models sit outside the same live classifiers.

Model (internal, not reproduced here)

TargetProof Sanctuary Controls Catalog v1.2, Ultra tier; Sanctuary Framework v1.0. AI treated as external weapon and internal leakage path; impact weights 1–5, ordered to fortune-moving gaps and to recoverability, insurability, and survivability. Control identifiers and scoring weights are practitioner artifacts and are not published in this article.

Limits

IC3 figures are reported losses, not a census of UHNW events, and not independently audited recoveries. Family offices under-report. The AI Related line is a descriptor — a mention of AI in the complaint — not proof that AI caused the loss. Whale SIM-swap and wrench-attack losses sit mostly outside these tables; charging documents reviewed for this article do not prove AI-accelerated OSINT as the victim-selection method. The $25 million deepfake transfer is a single well-reported incident, not a time series. Internal AI leakage has a strong enterprise and professional-conduct evidence base and a thin public UHNW-dollar base; the model’s high impact weight on that path is a severity judgment about crown-jewel data, disclosed as such.

What the evidence does support, without stretching: the instruction that moves family fortune is still a wire, a recovery channel, or a coerced key. AI has made the instruction more fluent, the likeness more convincing, and the targeting faster. Those are the exposures that survive contact with the public record.

Discretion is not a feature. It is the foundation.

This reading is for principals, and for the counsel and advisors who sit beside them. If you serve a household, you may forward it. If you are deciding for a family, the next conversation is the Family Threat Model.

For advisors Family Threat Model Private briefing