Talk to our expert team today!
sales@openmindnetworks.com

Operators deploy sender ID registries. Fraudsters spoof them anyway. Scam folders help until they don’t. Registries become compliance theater—a box to tick while fraud losses keep climbing. Regulators issue guidance. Operators implement half-measures. Subscribers keep losing money.

The issue isn’t that regulators don’t care. It’s that they’re not making fraud expensive enough for operators to prioritize fixing it. Compliance checkbox? Yes. Real consequences? Not really.

 In Australia, the last few years have seen the introduction of automated anti-scam blocking implemented at the telco provider level. This has seen a huge drop in the number of subscriber-reports from 2024 to 2025 [from 77,365 reports in 2024 down to just 29,058 reports in 2025]. However, reported losses in this same time from SMS phishing have increased in value from $84m to $97m. Anti-scam filters do a lot of good work but they do not eradicate the problem based on recent numbers. A point borne out in other jurisdictions. The response from ACMA has been interesting. Australia’s Communications and Media Authority are now working on something different. Instead of mandating process—sender ID registries, filtering frameworks, reporting cadences—they have created a liability model.

Here’s how it works in practice:

When smishing campaigns exploit an operator’s network, the ACMA holds that operator financially accountable for subscriber losses. Not symbolically. Not with fines that operators absorb as a cost of doing business. Accountable in a way that makes the CFO pay attention.

The framework shifts the burden of proof. It’s no longer “did you have a filter?” It’s “did you do enough to prevent this damage, and if not, you are liable to the subscriber who has been affected.”

That changes behavior overnight.

An operator running minimalist fraud detection suddenly has a balance sheet problem. An operator that invested in real-time detection infrastructure—network-edge capabilities, AI-driven pattern matching, rapid response—suddenly has a competitive advantage. They can prove due diligence. They can demonstrate that they were proactive in preventing losses and, as such, are not liable to compensate.

This isn’t regulation by process. It’s regulation by outcome.

Let’s be honest about why sender ID registries and scam folders don’t always work:

  1. Fraud is a feature race, not a compliance checkbox. Fraudsters are actively working to evade whatever filter you deploy. They don’t care about your registry. Yesterday’s spam folder workaround is today’s problem.
  1. Process compliance isn’t aligned with operator incentives. An operator can implement a “sender ID registry” and call it done. They’ve complied. The fact that fraud still flows through? That’s not their problem—it’s the subscriber’s problem. Or the regulator’s. Or the bank’s or enterprise’s. 
  1. Subscriber losses aren’t on the operator’s P&L. Under the old model, smishing losses were abstract. The operator had filtered traffic but the subscriber still got scammed. Hopefully, the bank dealt with the fraud dispute. Not a good outcome for anyone in the chain.

Financial accountability changes that. Now the operator feels the cost.

Here’s what this looks like operationally:

Before: Operator deploys sender ID registry. Checks compliance box. Fraud losses continue. Regulator issues guidance. Cycle repeats.

After: Operator faces questions from its board: “We’re liable for subscriber losses if we don’t prevent fraud. What’s our detection infrastructure? How fast can we respond to emerging attack patterns? Can we prove we did everything reasonable?”

Suddenly, operators are asking:

  • What’s our false-positive rate on AI-driven fraud detection?
  • Can we detect smishing campaigns in real-time or near-real-time?
  • How do we audit our own fraud prevention effectiveness?
  • What liability insurance do we need?

These are the questions that lead to actual infrastructure investment, not checkbox compliance.

The beauty of ACMA’s approach is that it creates symmetrical motivation.

Fraudsters are motivated by money—they make money when they successfully exploit operator networks. Under the old model, operators had no equivalent motivation to stop them. Compliance wasn’t costly. The status quo was acceptable.

Financial accountability changes that. Now operators are also motivated by money—but in the opposite direction. They lose money if fraud succeeds on their network. For the first time, the operator has the same financial incentive as the fraudster.

This isn’t a battle between “compliant” and “non-compliant.” It’s a fair fight between two parties with equal motivation: the fraudster trying to profit, and the operator trying to prevent losses. Whoever builds better capability wins.

That’s the fundamental difference:

  • Old model: Operator has process compliance incentive (low). Fraudster has financial incentive (high). Fraudster wins.
  • ACMA model: Operator has financial incentive (high). Fraudster has financial incentive (high). Outcome depends on capability.

Outcome-based liability is harder for regulators to administer than process-based compliance. It requires investigation, forensics, accounting. But it actually works because it finally makes operators compete against fraud with the same intensity that fraudsters compete for profit.

Europe’s telecom regulators are watching. OFCOM, BNetzA, and the national authorities across the EU have been signaling that Australian-style accountability is coming.

European operators that assume this is a regional quirk are making a calculation error. The model works. It forces action. And other regulators will adopt it.

For operators in scope, this means:

  • Understand your liability exposure under outcome-based models
  • Map your network edge fraud detection capabilities (or lack thereof)
  • Upgrade detection infrastructure to real-time, AI-driven capabilities
  • Invest in continuous learning systems that adapt to new attack patterns
  • Make fraud prevention part of your operator’s value proposition, for example, Network Security Services are already being offered by some operators to their enterprise clients

Process compliance doesn’t prevent fraud. Accountability does. ACMA are showing that when you make fraud expensive for operators—when they’re financially responsible for losses they could have prevented—they prevent fraud. Other regulators are building the frameworks now. And operators that treat Australian accountability as a regional anomaly will learn an expensive lesson.

Share this post:
Facebook
Twitter
LinkedIn

Blogs you might be interested in