Banks need AI perception at the edge and deterministic decisioning at the core. Confusing the two is how institutions lose control of both fraud and accountability.
The fraud problem facing banks today is not that criminals have become smarter. It is that they have become faster, cheaper and more scalable than the systems built to stop them.
A synthetic identity that once took a fraud ring weeks to construct now takes minutes. A cloned voice convincing enough to pass a call centre check requires a few seconds of source audio. Forged documents that would previously have failed a trained eye now render cleanly at scale. What has changed is not the ambition of the attacker but the marginal cost of the attack, and that cost has collapsed.

Meanwhile, most fraud infrastructure remains rules-based. Rules are written by humans, deployed through change cycles measured in weeks, and updated only after a pattern has been seen enough times to be recognised. That worked when fraud evolved at human speed. It does not work when the adversary generates novel attack variants faster than the institution can write rules to catch them. Inside institutions, fraud teams describe a rising volume of cases that look legitimate at every individual checkpoint and reveal themselves only in aggregate.
The obvious conclusion, and the one most of the market has reached, is that banks should fight AI with AI. That conclusion is correct but dangerously incomplete.
The question is not whether to use AI, but where to put it
There is an important distinction, largely missing from the current conversation, between using AI to perceive and using AI to decide.
Perception is pattern recognition against sensory input. Is this face a live human or a rendered composite? Does this voice carry the traces of synthesis? Was this document scanned from a real original, or generated to look like one? These are tasks where machine learning is genuinely superior to rules, and where no rules-based system will keep pace.
Decisioning is different. Should this transaction be blocked? Should this account be frozen? Should this loan application be declined? These carry legal weight, regulatory exposure and consequences for customers who may be entirely innocent.
The mistake many institutions are about to make is treating both as the same problem and handing both to the same model. The result is a system that is fast, adaptive, opaque and impossible to defend when a regulator asks why a particular customer was denied service on a particular day.
It also fails at the point where fraud infrastructure is actually tested, which is not detection but what follows it. When a case moves from alert to investigation, and from investigation to filing or recovery, the institution has to reconstruct the sequence: what was seen, when, on what basis, and what was done. Systems that cannot produce that reconstruction leave the institution holding a loss it can identify but not evidence.
A better architecture separates the two. AI operates at the perception layer, where its probabilistic nature is an asset. Deterministic engines operate at the decisioning layer, where predictability and traceability are non-negotiable. The AI flags. The engine decides. The audit trail records both, with the confidence score, the model version and the rule that governed the outcome.
Why deterministic decisioning matters more, not less, as fraud gets smarter
The instinctive objection is that if the threat is adaptive, the defence should be adaptive throughout. But this misunderstands where adaptability is required. The detection surface must be adaptive, and it can be, because retraining a perception model is a design-time activity that does not change what the institution does when a signal fires. The response policy should be stable, deliberate and governed, because that is what makes it defensible.
Consider what happens when a fraud model is wrong in production, which it will be. If the model both detected the anomaly and decided the response, the institution has an unexplainable adverse action against a customer. If the model only flagged and a deterministic policy engine decided, the institution can show exactly what was flagged, with what confidence, under which policy, approved by whom, and why the outcome followed.
Institutions that build fraud infrastructure with the model on the decision path will find themselves retrofitting explainability into systems never designed to provide it. That is far more expensive than building the separation in from the start.
Modernising without rip and replace
The second constraint is that fraud infrastructure cannot be modernised in isolation. It sits at the intersection of onboarding, payments, lending, servicing and compliance, each with its own history, integration debt and change control regime.
This is why so many fraud modernisation programmes stall. The business case is compelling, the technology is available, and the project still takes eighteen months because it requires coordinated change across systems never designed to change together. In institutions running lending, deposits and payments on separately procured platforms, and most do, the fraud view is assembled after the fact from systems that never shared a signal in real time.
The way through is not to replace the core but to build an orchestration and configuration layer above it. Existing systems continue to run. New detection capability, policy logic and response workflows are configured rather than coded, and governed through the approval structures the institution already trusts. When a new attack pattern emerges, the institution should be able to update its response policy the same day, not schedule it into the next release cycle.
No institution sees enough fraud to defend against it alone
Everything above concerns what a single institution can do inside its own perimeter. That work is necessary and most institutions have not finished it. But it accepts a constraint the adversary does not.
A fraud ring does not attack one bank. It runs the same synthetic identity template, the same mule account structure, the same social engineering script across many institutions in sequence, refining it as it goes. Each institution sees a fragment. The attacker sees the whole campaign. Any detection model trained only on what one institution has directly experienced is, by construction, working from a partial view of a pattern the attacker has already industrialised.
The practical consequence is that the first institution hit pays the tuition, and everyone hit afterwards pays it again. That is an expensive way for an industry to learn.
The response is not data pooling, which is neither commercially nor legally realistic. It is shared domain intelligence: permissioned, governed models of fraud typologies, attack structures and emerging vectors that many institutions can draw on while every institution’s transaction data and customer records stay exactly where they are. Patterns travel. Data does not.
Think of it as a collective brain for the industry. Every validated typology, every newly identified attack structure, every confirmed false positive pattern strengthens every participant connected to it, rather than remaining locked inside the institution that happened to encounter it first. Intelligence compounds across the network the way the adversary’s already does.
The reasonable objection is that this erodes competitive advantage. It does not, because fraud typology is not where banks compete. No bank has ever won a customer because its fraud team recognised a mule account structure three weeks before the bank down the road. Competition belongs in innovation. Cooperation belongs in safety, and the industry is currently paying a significant collective price for not making that distinction.
What good looks like
Institutions building fraud infrastructure for this environment should test any proposed architecture against five questions.
First, where does the model sit relative to the decision? If it is on the decision path, the institution has taken on explainability risk it may not be able to discharge. Perception at the edge, deterministic policy at the core.
Second, can every outcome be traced? Not just the fact of a decision, but the signal that triggered it, the confidence attached, the model version in force, the policy applied and the human who approved that policy.
Third, how quickly can a response policy change? If the answer is measured in release cycles, the institution is structurally slower than its adversary. Configuration-driven policy change is not a convenience feature; it is an imperative.
Fourth, does the architecture assume the model will be wrong? Well-designed fraud systems are built around the certainty of false positives and false negatives, with escalation paths, human review thresholds and reversal mechanisms designed in.
Fifth, and this is the one institutions ask last and regret asking last: will the record this system produces hold up outside the institution? Fraud does not end at detection. It moves into internal investigation, regulatory reporting, and increasingly law enforcement. Each of those audiences needs a defensible account of what happened, not a model output. Infrastructure that produces alerts but not evidence solves the first ten per cent of the problem.
Control is the competitive advantage
Most of the enterprise AI conversation, in fraud and elsewhere, is about capability. Which model is most accurate. Which system has the highest true positive rate.
For regulated institutions, capability is necessary but it is not the differentiator. Detection models are commoditising quickly, and every serious institution will have access to broadly comparable capability within a few years. What will separate them is control: whether they can deploy that capability inside a governed architecture, explain every outcome it produces, and change their response posture faster than the threat evolves.
The banks that get this right will not be the ones that deployed AI most aggressively against fraud. They will be the ones most deliberate about where they let AI decide and where they did not, and most willing to treat fraud intelligence as something to be shared rather than hoarded. In a domain where every decision carries regulatory weight, customer consequence and increasingly evidentiary weight beyond the institution itself, that deliberateness is not caution. It is the foundation on which trustworthy fraud infrastructure is built.
Authored by Shrish Anand Lal, Executive Director and Chief Business Officer, New Street Technologies
