Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
The Saturday Fraud Strategist

El auge de las operaciones agénticas, parte 4: Cómo monitorizar agentes de IA

Si uno de tus agentes de IA llevara seis semanas deteriorándose, ¿te darías cuenta? La mayoría de la gente me dice que no, y ese es el problema que estoy investigando.

Los agentes que sufren desviaciones pueden generar resultados que parecen correctos a simple vista, mientras su rendimiento se deteriora silenciosamente. En una entrega anterior de esta serie hablé del ciclo de reacción como el KPI principal de la eficacia en la lucha contra el fraude y de cómo la IA agéntica puede acelerar drásticamente ese ciclo. Esta vez quiero responder a la pregunta clave una vez que se han desplegado esos agentes: ¿cómo saber si siguen funcionando?

La mayoría de los paneles responden a las preguntas equivocadas y se limitan a indicar si un agente está en funcionamiento. La monitorización de agentes de IA consiste en hacer un seguimiento deliberado de un agente, y te explicaré paso a paso cómo hacerlo.

Lo que escucharás en este episodio:

  • Por qué un agente que se degrada es realmente más peligroso que no tener ningún agente.
  • Cómo medir la velocidad del ciclo de respuesta al fraude en cada etapa, en lugar de limitarse a observar un único indicador rezagado.
  • Por qué las métricas de rendimiento de los agentes de IA que los equipos antifraude deberían supervisar no necesitan estar totalmente automatizadas para resultar útiles.
  • La diferencia entre la supervisión de agentes con intervención humana y la supervisión autónoma de agentes que toman decisiones a gran escala.
  • Lo que realmente te indica un aumento en la tasa de rechazo.
  • Cómo detectar un agente autónomo que está fallando silenciosamente antes de que los daños reales se acumulen.
  • Un panel práctico de monitorización de agentes de IA de tres capas que los equipos antifraude pueden crear.

Deberías escuchar este episodio si:

  • Gestionas algún programa de supervisión de operaciones antifraude basado en agentes y quieres un marco sólido para detectar el deterioro de un agente antes de que se refleje en tus pérdidas.
  • Son responsables de las políticas de gobernanza y fraude relacionadas con agentes de IA y necesitan un lenguaje que vincule la supervisión técnica con los informes dirigidos a la alta dirección.
  • Han implementado herramientas con supervisión humana, como copilotos de investigación o agentes de recomendación de reglas, y quieren saber qué métricas deben monitorear realmente.
  • Utilizan agentes autónomos, como sistemas de etiquetado automático o de agrupación de alertas, sin que una persona revise cada decisión, y les preocupa que se produzcan fallos silenciosos.
  • Quieren elaborar un caso de negocio sólido para invertir en la detección del fraude del ROI de los agentes de IA utilizando el ciclo de reacción, en lugar de limitarse a contabilizar las horas ahorradas gracias a la automatización.
Notas del episodio y conclusiones clave

El tiempo de actividad no es lo que se debe monitorizar

La mayoría de los paneles solo indican si un agente está activo, y esa es la pregunta menos útil que se puede hacer. Un agente que se desvía de su objetivo puede parecer perfectamente saludable mientras su desempeño en la tarea para la que fue diseñado empeora silenciosamente. La verdadera monitorización de agentes de IA consiste en comprobar si el agente sigue aportando valor y comportándose según lo esperado, no solo si continúa en funcionamiento.

Divide el ciclo de reacción en etapas que realmente puedas medir

Conviene hacer un seguimiento por separado de la velocidad de detección, la velocidad de delimitación del alcance y la velocidad de diseño de la solución, en lugar de observar un único promedio que refleja los resultados con retraso. Nada de esto tiene que estar perfectamente automatizado para resultar útil. Basta con llevar un registro manual aproximado una vez por semana para comprobar si los agentes de IA están reduciendo de forma significativa el tiempo dedicado a cada una de estas etapas, y eso supone un mejor uso de tus esfuerzos que esperar a crear primero un sistema de medición perfecto.

Las métricas a nivel de ciclo llegan con retraso, y ese es precisamente el peligro

Las cifras del ciclo de reacción son promedios móviles, lo que significa que las señales de deterioro de los agentes de fraude pueden quedar ocultas en ellas durante semanas antes de que alguien las detecte. Para cuando la ralentización se refleja finalmente en el tiempo total del ciclo, el daño ya suele estar hecho. Necesitas señales que detecten esa desviación antes.

Los agentes con intervención humana dejan un rastro documental, pero los agentes autónomos no

Para los agentes que una persona revisa antes de que se ejecute cualquier acción, como los copilotos de investigación o las herramientas de recomendación de reglas, la tasa de aceptación y la tasa de rechazo son los mejores indicadores adelantados. En el caso de los agentes autónomos que toman decisiones sin ningún paso de revisión, como el etiquetado automático o la agrupación de alertas, los fallos pasan desapercibidos de forma predeterminada. La tasa de concordancia entre distintas fuentes y los cambios en la distribución son las señales que permiten detectar este tipo de desviación antes de que se agrave y se convierta en un problema real.

Estructura tu monitorización en tres capas

Las alertas en tiempo real deben detectar los incumplimientos de los umbrales el mismo día en que se producen. Una revisión semanal debe analizar las tendencias y el impacto general, no solo si se activó una alerta. Y un informe mensual debe relacionar el rendimiento del agente con los costes y el retorno de la inversión para la dirección. Nada de esto requiere nuevas herramientas, y la responsabilidad recae en el equipo de análisis de fraude.

Conclusión final

Abrí este episodio con una situación sencilla. Uno de tus agentes lleva seis semanas deteriorándose y aún no lo sabes. Si haces un seguimiento de la tasa de concordancia de tus agentes con supervisión humana, lo detectarías en cuestión de días. Si controlas la concordancia entre distintas fuentes y los cambios en la distribución de tus agentes autónomos, lo detectarías en menos de una semana. Al mismo tiempo, podrías demostrar exactamente cuánto valor generan esos mismos agentes, no solo en horas ahorradas, sino también en el dinero que ahorras al reaccionar más rápido ante el fraude. Esa es la verdadera diferencia entre gestionar a tus agentes y dejar que ellos te gestionen a ti.

Recursos y enlaces

Esto forma parte de una serie. Si has llegado aquí primero, quizá te convenga volver atrás y escuchar los episodios anteriores. Ya hemos tratado bastantes temas que harán que este episodio sea mucho más fácil de seguir.

Ponte al día con El auge de las operaciones de fraude agéntico, parte 1
Ponte al día con El auge de las operaciones de fraude agéntico, parte 2
Ponte al día con El auge de las operaciones de fraude agéntico, parte 3

¿Aún no quieres dejar de hablar de mi tema favorito, que espero que también sea el tuyo? Suscríbete al boletín The Saturday Fraud Strategist.

Conecta con Chen Zamir | LinkedIn
Presentador de The Saturday Fraud Strategist
Ayuda a las fintech a crear defensas contra el fraude más inteligentes
Coautor de «The Fraud Fighter’s AI Playbook»

Episode transcript
Chen Zamir
Chen Zamir
00:00
Here's a question I've been asking fraud leaders lately. If I told you one of your AI agents had been degrading for 6 weeks, would you know? Most would say no. And it's a problem because drifting agents are actually worse than no agents. They generate outputs that look fine from the outside while they degrade. And it's especially problematic when these outputs are being used as inputs for downstream processes like other agents. And so you can imagine how easy it is to encounter cascading events that very quickly get out of control. But the truth is that if you take a look at your average dashboard, it's designed to answer something else entirely than these questions. Is this agent even running? That is the least useful question to ask. I mean, of course, system health is important, but focus only on that and you'll miss the really important things to monitor. Whether your agents are improving your outcomes and not just whether they are live. So, how do you keep track of your agents? There are two things you want to watch for. First, is the agent actually contributing value? And the second, is it behaving as expected? Let's talk about it. In the first video of this series, I mentioned that in my view, the master KPI of fraud effectiveness is the reaction cycle. The time it takes your system to detect a gap and deploy a fix for it. And in the second video of the series, I outline how you can streamline your reaction cycle with Agentic AI to make it significantly faster. But how do you actually measure it? How do you connect AI agent performance metrics to how fast you're stopping fraud? Fraud AI agents can definitely help with that, but not necessarily in an even manner across the board. Here's what I would suggest to track and how. First, detecting coordinated fraud patterns faster. The first step in the fraud reaction cycle is detecting that there's a system gap. Without agents, this is slow by default. Alerts arrive and analysts eventually notices a pattern and then someone needs to pull related cases by hand to validate there's an issue. A new attack can run for days or even weeks before anyone connects a dots easily. But if you follow the steps in the second video of this series and you implemented alert clustering, a new ring can now surface in hours. Every alert triggers an agent that searches against known cases and matches events to existing rigs. So how do you track this? You track it by measuring the time from the first event of a new attack entering your system to when your team actually recognizing it. Now, I know what you're thinking. This is super tricky. So, I let you in on a little secret. Not every metric you measure needs to happen automatically. Just make sure that every week someone in your team goes through the alerts they've actually picked up and note down how long it took since the issue first started. Do it enough times and you'll be able to see a trend, especially if you start doing that before you implement agentic AI, as you should. The second thing you want to do is to scope fraud rings with AI agents. Once a pattern is flagged, the next question to ask is how big is it? How many accounts? What time period? What's the actual loss exposure? This is where Agentic AI moves from spotting a signal to mapping the full population at risk. Without AI, the scoping is manual and analysts will have to pull related cases, cross reference them with device data and build a picture account by account. But with AI agents, the same work can be done in a much shorter time window. How do you track this? Measure the time between when an issue got noticed to when you had it scoped in dollar or account exposure terms. Again, this doesn't have to be super sophisticated. The point isn't to say it takes 5 minutes and 12 seconds to scope an attack instead of 5 minutes and 36 seconds. It's being able to show it takes less than 30 minutes versus the day or two it took before. And that is pretty easy to do in the same manner I mentioned before by recording it manually once a week. By the way, I know that what I just said may sound like sacrilege to some of you. What? Do something manually when we talk about AI monitoring? How can I say that while I preach for more automation? But this is exactly where I see teams get distracted by investing their attention and tokens into productivity hacks instead of focusing on the right things. Don't get me wrong, if you can automate these metrics with or without AI, you should absolutely do so. But don't let it stop you from measuring them if you can't. Finally, the last thing you want to track is how fast you design and test fixes.
Chen Zamir
Chen Zamir
04:42
Once you understand the issue and what causes it, you need a fix. And AI agent can help with the two steps that used to consume the most time. Proposing a solution and proving it works. When fed a specific data set, agents can identify patterns, learn from labels, and propose a fix like a new rule. Then they can run the back test all before human even reviews it. So the analyst's job shifts from building the rule to stress testing and approving it. Now the reason why I would measure these two phases together is because in some cases like rule writing, it's a bit difficult to know when design ends and testing begins. And in other cases like SOP or policy changes, it might be that there would be no testing phase. So when you think about how to measure it, this one is a bit tricky. Supposedly you need to start measuring it when you have the root cause figured out, but this can prove to be quite a fuzzy definition. So again, you don't have to overengineer it and get a super accurate measure. It's enough to have a ballpark range for how much time it took since you started working on a solution and until it was approved for deployment. You want to see if when using AI agents, you can consistently shave a meaningful chunk of time. And if you don't see through rough measurements, it's likely not doing enough work anyway. Here's the problem with cycle level metrics. They lag. Meaning, you're likely going to measure some sort of a roll in average. And as we just discussed, a rough one at that. So if for example your rules agents start to degrade, it'll be quite hard to catch. Analyst would spend more time on prompting or tasks that it would oneshot before would now take several prompts to achieve. Or a labeling agent that started misclassifying 3 weeks ago will eventually cause your rules to drift and elevate fraud rates, but until you notice it and understand where it's coming from, it might be going on for weeks. And that's why you want to make sure your agents are not only live are not only noticeably making you react faster, but also that they do not degrade with time. And you want to know something is wrong before it shows up in your reaction cycle metrics as by then it's too late. But these signals look different depending on whether the agent has a human-in-the-loop or not. Human-in-the-loop agents are the first type of AI agents you'd monitor. These include investigation co-pilots or rule recommendation agents that have humans reviewing every output before anything gets actioned. And because you have a human in the loop, these agents are easier to monitor because the review itself creates a record. Did the human agree or reject the agents decision?
Chen Zamir
Chen Zamir
07:26
This creates a natural trail you can record and monitor. Agreement rate is the best leading indicator and one of the most useful agent metrics for human reviewed workflows. If investigators are ruling differently than the agent more often than they used to, then the agent is degrading. For rule recommendation agents, rejection rate is the equivalent. It's another AI agent performance metric that shows whether the agent is still producing useful outputs. It's a bit trickier because rejected rules don't reach production, so they don't necessarily impact your general KPIs. But a rise in rejection rate means the agent is generating faulty proposals that consume human time and resources without moving the needle. And by the way, there can be many reasons for agent degradation. Maybe there are underlying data issues. Maybe fraud has shifted. Maybe moving to a newer model didn't work well. Whatever the reason is, you could identify issues earlier by tracking these metrics. Meaning you could also start solving it faster. Exactly the concept behind the reaction cycle. Autonomous agents such as auto labeling and alert clustering don't have humans reviewing every decision they make. So when they fail, the failure is silent until something downstream breaks. Let me give an example. When an auto labeling agent starts misclassifying legitimate accounts could get labeled as fraud without anyone noticing. Obviously, no one wants that. This is why AI governance has to account for autonomous agents differently than human-in-the-loop flows. But the problem here is scale. The reason humans are not in the loop is because these flows simply make too many decisions or they make decisions in near real time. So not only you cannot track human agreement rates, the danger here is substantial. Any slight degradation can have a severe impact, but you can track other agreement rates coming from other sources or cross- source agreement rates. Let me give an example. Say you want to monitor your labeling agent.
Chen Zamir
Chen Zamir
09:31
It's not your only source of labels, right? You probably have at the very least the chargebacks you're getting as well. Now, if two sources for the same decision that were aligned 90% of the time drop to 70% of the time, you know something changed. You don't know which source is wrong yet, but you know where and when to look before the damage compounds. Another signal worth tracking is distribution shift. If your labeling agent starts flagging 40% more events as fraud in a segment that hasn't seen elevated fraud rates, that's worth investigating. Again, there can be many reasons for why an autonomous agent degrades. Just like with human in the flow agents, the point is that you now have the metrics and the alerts so you could catch it early. In the previous video of this series, I outlined how managing AI agents, including monitoring them, falls under the responsibility of your fraud analytics function. And from a tooling perspective, it's nothing new. What do we actually have here? Real-time alerts for threshold breaches. For example, when the agreement rate of a human-in-the-loop agent falls down below a certain value or when an autonomous agent's distribution skews more than a set rate. These alerts form the foundation layer of AI governance and should fire automatically on Slack or email or wherever your team catches alerts and get looked at the same day. Then you have weekly reviews of trend lines. Here you're not only making sure everything looks good regardless of whether an alert was fired or not. You also take a look at impact. Measure your reaction cycle speed and make sure that your agents provide actual value. And lastly, you have monthly reports on cost and ROI that you can share with your leadership team. And especially for the reaction cycle, it's pretty straightforward. If you can demonstrate an attack was blocked 4 days faster, you just save 4 days of losses. That's part of the ROI calculation, not just how many work hours you saved with automation. I started this video with a simple scenario. One of your fraud agents has been degrading for six weeks.
Chen Zamir
Chen Zamir
11:34
What do you know? If you're tracking agreement rates for your human-in-the-loop agents, you'd know in days. And if you're tracking cross agreements and distribution shifts for your autonomous agents, you'd know in a week. At the same time, you can now also track the value agents create. Not only how many hours you saved, but also how many dollars you saved by detecting and reacting to fraud quicker. That's how you connect your reaction cycle to your top KPIs. And this is the difference between you running agents and the agents running you.