The best thing would be to have your own physical machine act as an exit node instead of relying on a cloud instance. That would bring a whole series of new problems for keeping a machine up and running while you are away, but doable
Maybe once passkeys or hardware keys are widely adopted they can remove the atrocious fraud detection.
Whereas 99.999%? of the users won't use tor/$vpnCompany/cloud provider IPs. It's all in terms of which is less likely to lead to a support request.
I worked with a relatively big bank that used a tool like Akami or Cloudflare. With those tools you can just ban/block entire countries (think any IP from Iran, Russia, etc) or entire ASNs.
It’s probably the second most common geo rule after geoblocking.