SardineCon SF/2026

Learn More
The Saturday Fraud Strategist

The Rise of Agentic Fraud Ops, Part 1: Your fraud team is running at the wrong speed

Every fraud leader I've spoken to this year has heard the same message: cut costs. You've probably already had the conversation. You've explained why fraud isn't just another operating expense, why reducing investigators today often means higher fraud losses tomorrow, and why your team is already stretched thin. And yet the budget cuts are still coming.

Here's the question I'd rather ask. What if finance isn't actually your biggest problem?

In this episode, I introduce the idea of agentic fraud ops and explain why the real issue isn't shrinking budgets. It's that most fraud organizations are still operating at human learning speed while their adversaries have already moved to machine speed.

We talk about why fraud detection systems decay over time, why fraud rules and machine learning fraud detection models become less effective the moment they're deployed, and why the future of fraud prevention AI isn't about replacing analysts. It's about building systems that continuously learn.

Honestly, optimizing a slow system is still optimizing a slow system.

This episode explores what happens when AI-powered fraud detection becomes part of the reaction cycle itself instead of just another automation project. If we're going to redesign fraud operations, we first need to rethink what performance actually means.

What you'll hear in this episode:

  • Why agentic fraud ops changes how fraud teams should measure success
  • Why every fraud detection system begins decaying the day it goes live
  • How fraud detection rules, machine learning models, and manual review age differently
  • Why reaction speed is becoming the most important fraud metric
  • How AI agents for fraud detection can compress learning cycles from weeks to hours
  • Why fraud operations automation should focus on new capabilities instead of replacing people
  • How fraudsters are already using AI-driven fraud prevention techniques against defenders

You should listen to this episode if you:

  • Lead a fraud operations or fraud strategy team
  • Want to modernize your fraud prevention system
  • Are evaluating AI agents for fraud detection
  • Need to reduce costs without increasing fraud losses
  • Are planning the future of your fraud operations transformation
Episode notes & key takeaway

Agentic fraud ops starts with measuring learning speed

Most fraud teams optimize outcomes like chargebacks, false positives, approval rates, or fraud losses. Those metrics matter, but they're all downstream of something more fundamental: how quickly your organization learns.

That's the central argument behind agentic fraud ops. A fraud prevention system isn't defined by how sophisticated it was when it launched. It's defined by how recently it adapted.

If your fraud models refresh quarterly, your fraud detection rules change weekly, and your analysts only feed intelligence back into production after days or weeks, your system is already behind.

Every fraud detection system is decaying

Fraud stacks usually share the same architecture: machine learning fraud detection models, fraud detection rules, and manual review.

The problem isn't the architecture itself.

The problem is that every automated component starts degrading the moment it's deployed.

Rules become predictable.Models drift.Thresholds become outdated.Fraudsters adapt.

Manual review and AI agents are different because they're operating on fresh information rather than historical snapshots.

That changes how we should think about adaptive fraud detection.

Fraudsters have already reached machine speed

One of the biggest shifts discussed in this episode is that fraudsters aren't necessarily becoming smarter. They're becoming faster.

AI agents can now test attack variations, interpret denial signals, and evolve campaigns automatically. That means defenders can no longer rely on human-speed reaction cycles.

Improving meetings, dashboards, or staffing won't close that gap.

Only a fundamentally different operating model can.

AI should create new capabilities, not just automate work

This episode argues against the common idea that AI exists primarily to replace investigators.

Instead, fraud prevention AI should introduce capabilities that most teams never had the capacity to perform:

  • Continuously generating labels from fresh transactions
  • Clustering alerts into fraud rings
  • Recommending new fraud detection rules
  • Identifying model refresh opportunities
  • Accelerating fraud analytics and decision making

That is what agentic fraud ops actually means.

It's not faster analysts.

It's a faster learning system.

Final takeaway

Most fraud leaders are preparing for another round of cost pressure.

Some will spend the next year defending headcount.

Others will simply absorb the cuts.

But there may be a third option.

Use that pressure as the catalyst to rebuild your fraud prevention system around machine-speed learning.

Because the question isn't whether your fraud organization is going to change.

It's whether you design what comes next, or inherit it by accident.

Not ready to stop the conversation about my, and hopefully your, favorite subject? Subscribe to The Saturday Fraud Strategist newsletter.

Connect with Chen Zamir | LinkedIn
Host of The Saturday Fraud Strategist
Helping fintechs build smarter fraud defenses
Co-author of “The Fraud Fighter’s AI Playbook

Episode transcript
Chen Zamir
Chen Zamir
00:06
Every fraud leader I've spoken to this year has gotten some version of the same memo from finance. Cut costs. You've already had the argument. You've already explained that fraud isn't a typical cost center. That the cuts being proposed will cost more in losses than they save in headcount. And none of it has changed the answer. That cuts are still happening across the company and they're happening in your team. Whether you like it or not, for all the fraud leaders I talked to, this was bad news. But I want to offer a different perspective. It's only bad news if you don't use this pressure. Here's what I mean. Your fraud team is going to look very different 2 years from now, whether or not you actively shape it. The system you're running today was designed for an adversary that moved at human speed. And that adversary is rapidly being replaced. The team you've built around that system is going to come under strain regardless of what finance does this quarter because the system is what's breaking not the budget. So the cost cutting exercise and the breakage of your fraud stack are two symptoms that signal the same thing. It is time to rethink the future of your fraud prevention system. And if you treat cost cutting as the forcing function for the rebuild, you can actually use it to fund this transformation. But if you treat it as a fight, as a status quo which needs defending, you will lose the fight. Your headcount still gets cut and the system you're left with is still breaking. That's the reframe I want you to walk into your next paying meeting with. The question isn't how do we cut fraud ops costs. The guiding question every fraud leader needs to have in front of their eyes, both 5 years ago and certainly today, is how fast does our system learn? Because everything that matters, including cost, losses, false positives, approval rates, and what your team looks like two years from now, is downstream of that one metric. But here's the thing, the answer to both questions, how do we cut cost and how do we learn faster is also the same one with the help of agentic AI. Look at any fraud stack and you'll find the same architecture. Machine learning models at the bottom scoring the general population, rules in the middle catching what the models miss, and manual review at the top handling the gray cases that are left. I call it the three layer cake, and I've seen versions of it in pretty much any mature fraud system I ever encountered. And for a good reason, well-maintained, it works pretty well. But here's what gets glossed over.
Chen Zamir
Chen Zamir
02:38
Every layer of that cake starts degrading the moment it goes live. Rules degrade the fastest. The minute you ship one, the adversary starts probing around it and the pattern it was designed to catch mutates within days. Block lists rod the same way and many times even faster. Machine learning models decay slower, but they're far more expensive to refresh and a model refresh has a side effect that most teams underestimate. When a new model ships, the score distribution shifts, and every downstream rule that was calibrated against the old distribution suddenly needs retuning. So potentially hundreds of rules can break or misbehave unpredictably overnight, which is exactly why most teams don't even try to release models more frequently. Interestingly, there are two components of your fraud system that degrade very slowly, if at all. Manual review and AI agents. How come? They are both running on fresh data. Simply put, human investigators are reading what's in front of them right now, and agentic AI is doing the same in trying to mimic them. But everything else in your stack is working from a snapshot taken weeks or months ago. So, what is the main takeaway here? Pretty simple. A fraud system's effectiveness at any given moment is a function of how recently it learned, not how sophisticated it was when it was deployed. But in my experience, most leaders evaluate fraud systems mainly based on their sophistication. Better models, more features, smarter rules, tighter thresholds. They treat effectiveness as if it were determined at the moment of design. But effectiveness is actually determined at the moment of use, when the rule is fired, not when it is tested. And the gap between those two moments is the variable that controls performance. In most cases, against an attack that emerged only last week, a rough rule ship this morning will outperform a sophisticated one shipped two months ago. So the conclusion is straightforward. To avoid decay and ensure high performance, our systems need to learn more frequently. So how do we do that? We start with rethinking how we define performance. If I could measure one thing about a fraud team and one thing only, it would be the time it takes to learn about a system gap and deploy a fix for it. And I use the term system gap on purpose because it doesn't have to be a new fraud attack. It can also be a misbehaving rule or a sudden production bug that degrades data quality. And I call this process finding a gap and fixing it the reaction cycle.
Chen Zamir
Chen Zamir
05:14
And it has six steps split across two phases. The first phase, learning, covers detecting the threat, scoping it, and finding the root cause of the issue. The acting phase covers designing a fix, testing it, and deploying it. Everything we do at a fraud team is part of that cycle. The technology we run, the processes we follow, the skills on our team, the tools we use. Want to cut chargebacks, you need to react faster. Want to reduce false positives? You need to react faster. Cut down your cost, you need to, you guessed it, react faster. There is no version of improve fraud outcomes that doesn't run through this loop because every other metric you report on precision, recall, false positive rate, loss rate, conversion rate is a downstream manifestation of one number. How fast you close the gap between observing something and acting on it. But ask a fraud leader what the reaction cycle speed is right now and you'll get a long pause then a guess. Almost no team measures it explicitly. They measure everything that depends on it instead. And that's exactly why this is so easy to miss. Now let's consider what's happening on the other side. Fraudsters didn't get smarter over the last 2 years, they got faster. We've now seen multiple cases of a new category of attack behavior. We call it polymorphic fraud. What's polymorphic fraud? Essentially, these are attacks where we observe subsecond pattern adaptation. A defense goes live, starts blocking the fraud campaign, but within milliseconds, we see it mutate its behavior in a way that our fresh defenses aren't able to block as effectively anymore. What powers these attacks are AI agents which were weaponized by fraudsters to redenile signals in real time, test variations, and scale up whatever works. All in an autonomous manner, so there's no need for a human-in-the-loop. I've seen teams that had been forced into blunt mitigations like shutting down cards from entire issuers for weeks at a time or blocking whole geographies because their defenses couldn't adapt fast enough. But even setting aside the most sophisticated polymorphic attacks, we need to internalize that the baseline has shifted. Frosters are using AI agents for the boring parts of their work. Analyzing campaign performance, tweaking scripts, answering customer service emails, as funny as it may sound. And the time those agents save is now being used to outpace you. My point is this. The system every fraud team is currently operating was designed for a world where the gap between attacker adaptation and defender reaction was manageable.
Chen Zamir
Chen Zamir
08:00
Your reaction cycle was slow, but so was theirs because the adversary was a human working with humanized tools at human speed. But that's no longer the case. And that gap that used to be manageable keeps getting bigger. Now when you hit this kind of pressure, the instinct is to optimize. Shorter meetings, better dashboards, more analysts, cross functional task forces, or looking to edit another vendor to the stack. I've watched teams pour energy into all of those and none of them produce the kind of speed the moment calls for. How come? Because they're optimizing the wrong layer. Your reaction cycle isn't slow because the people running it are slow. It is slow because it was designed around human speed learning. Models refresh on quarterly cycles. Rules get reviewed in weekly cadence meetings at best. And insights from your frauds teams rarely make it back to the detection layer in any structured form. And even when it does, it arrives days if not weeks after the attack has already subsided. Best case, you can squeeze 20% improvement out of these steps. But no amount of incremental optimization fixes the fundamental design assumption. Running at human speed just doesn't cut it anymore. What's the solution for all of these issues? AI. But of course, now I'm very conscious of the fact that AI is beyond hype right now. It's the solution for all mankind's problems. It's what every vendor or service provider sells. It's also the reason why I'm even talking about this topic in the first place. It's what drives the trend of headcount reduction that is surging all around us. I'm not saying that you should use AI to automate tasks done today by humans. This framing is too simplistic. It lacks direction and it's likely setting organization up for failure. What I do want to point out is something much more specific. Your reaction cycle itself needs to run at machine speed instead of human speed. This calls for more than just replacing headcount with AI. It's about redesigning the system itself and how it functions. To run reaction cycles at machine speed, you need a different architecture, one that enables fast learnings. And automation alone would not get you there. So what breaks if you stop at automation? Your team will get faster at the work it was already doing. But what about the things that do not happen today at all?
Chen Zamir
Chen Zamir
10:25
Things that required so much effort that no team invested in them at all. Nobody on your team is labeling fresh transactions, clustering alerts across thousands of accounts to find the ring they belong to, or continuously retuning segmentation thresholds as user cohorts change their behavior. These aren't tasks to automate. These are capabilities most human teams never had the bandwidth to deliver. Make case review three times faster and you save investigation cost. That the reaction cycle itself doesn't move because what limits the cycle was never how fast investigators worked. It's that labels arrive weeks late. Rules are researched manually and model updates are pushed live long after the attack has moved on. All of these are things your team can and probably should start looking at when you're thinking about how to best utilize agentic AI. Agentic AI can cluster alerts into ring level cases. So, one ruling labels thousands of events. It can generate labels from fresh data continuously, closing the feedback loop in hours, if not minutes. It can propose new rules and surface model refresh candidates with back test results already attached. The reaction cycle speeds up because the loop is closing in places where it used to be ultra slow and you're now reacting at machine speed because you added capabilities your team never had. And so this isn't about automation or at least not only about automation. The teams that would win understand it's mainly about introducing new processes to their system. And this mainly means that in order to truly transform your team and your stack, you'll need to invest. It won't happen with a flip of a switch. But the rebuild and the cost cuts don't have to be separate projects. Cut frauds 30% on its own and you're running the same broken cycle with your investigators. But rebuild the loop first and the same 30% drop in headcount comes out of the other side as a consequence rather than the cause. And here's the thing, many fraud leaders are about to spend the next 18 months either resisting the cost pressure or breaking under it. The third path, using it deliberately as funding for the rebuild your system needs anyway, requires you to walk into your next leadership meeting with a different argument than the one you've been making. And what you get is a real argument, not for sparring your team from businesswide cuts, but a clear road map of what needs to be done in order to facilitate it. So, it's not about being right, it's about being smart. The fraud team you have today is going to break under the next 18 months of pressure either way.
Chen Zamir
Chen Zamir
13:00
The only question is whether you replace it with something designed by you or assembled by accident.