The Fraud and AML Guide to Agentic AI Attacks

Fang Yu, PhD

AI has moved past answering questions. It now does the work.

That shift is reshaping financial crime on both sides. Agents can plan, use tools, and carry out multi-step tasks at machine speed. The fraud and AML teams pulling ahead are the ones putting that same capability to work for them.

In DataVisor's September Defend webinar, Fang Yu, DataVisor co-founder and Chief Product Officer, and Antenor Neto, Senior Product Marketing Manager, walked through what top-performing teams do differently. They also showed a live demo: an AI agent logging into a bank account, and DataVisor Vera building a rule to block it in real time.

This article breaks down what they shared. Watch the full webinar on demand.

From AI That Answers to AI That Does the Work

Until recently, most people used AI as a chat interface. You asked a question and got a summary or a draft. Helpful, but limited.

AI agents work differently. They plan, use tools, and carry out a sequence of tasks, with or without human oversight. That's the shift reshaping every industry, including fraud prevention and AML.

This shift cuts both ways. Bad actors are using agents to run attacks. Fraud and AML teams can use agents to respond faster and smarter.

How AI Agents Are Changing Financial Crime

Synthetic identities and deepfakes get most of the attention. The bigger change is that agents can now take part in every stage of the financial crime lifecycle.

Agents Across the Full Financial Crime Lifecycle

  1. Find and rank targets
  2. Generate synthetic identities and forged documents
  3. Run personalized social engineering campaigns
  4. Execute coordinated account takeover or payment fraud

The difference is the handoff. Each step feeds the next without anyone manually stitching the operation together. And there's a learning loop: every failed attempt becomes feedback for the next one.

Polymorphic Attacks: Scale, Speed, and Adaptation

The result is polymorphic attacks, built on three capabilities:

  • Scale: more attacks across more channels, with more variations and personalization
  • Speed: attacks run at machine speed, not human speed
  • Adaptation: each failed attempt improves the next one

These are the same capabilities that make AI valuable to legitimate businesses. That's the opportunity: defenders can use them too.

Why Static Fraud Defenses Fall Behind

Polymorphic attacks make static defenses decay faster. A detection strategy built for last month's pattern can miss what's happening this week.

When attacks change at machine speed, the time between spotting a pattern and responding to it matters. That sets a new operating requirement: adaptive AI and real-time decisioning that work at scale.

Teams need to detect, decide, and adapt at the speed of the attacker. That's exactly what top performers are doing.

What Distinguishes Top-Performing Fraud & Risk Teams

They Redesign Workflows Instead of Adding AI to Them

McKinsey's research on the state of AI found that top performers redesign their workflows, and that redesign has the biggest effect on the financial impact they get from AI.

The default move is incremental. Teams add AI to an existing step to make it a little faster, while the underlying process stays the same. Top performers rethink the workflow itself: which steps are needed, how information moves between them, where AI can work end to end, and where human judgment belongs.

What Workflow Redesign Looks Like in Fraud and AML

Stage Incremental Approach Redesigned Workflow
Detection AI scores a payment, then sends flagged transactions to the same old queue Connects onboarding, login, and payment activity into a 360° view that surfaces coordinated fraud
Tuning Quarterly or yearly threshold changes through tickets and manual back-testing Continuously tests strategies and recommends changes, with evidence to approve them quickly
Investigation A chatbot summary, while analysts still tab-hop between systems Pulls the data together, runs the investigation SOP, explains the risk, and gives analysts full context
Reporting Polishing the final SAR narrative Assembles the SAR from the investigation evidence trail, consistent, auditable, and ready to file

The common thread: don't add AI as one more step. Rethink how the whole workflow runs.

Meet Vera: A New Operating Model for Fraud and AML Teams

Many financial crime teams still run on scattered tools, hand-coded rules, manual strategy testing, and ticket-driven tuning. Investigators move between systems, and busywork piles up. It's slow, inconsistent, and hard to scale.

Vera is DataVisor's AI agent, built into the DataVisor platform to take on the heaviest parts of the work. Vera helps teams create strategies, accelerate investigations, and prepare reporting with speed and control. Instead of stitching together tools and spreadsheets, teams run fraud and AML programs as one integrated workflow.

Your team keeps full control, visibility, and explainability. AI handles the execution. Teams can build, test, deploy, and update every part of the program, with Vera working at every step.

Early Results Across the Fraud and AML Lifecycle

Fraud and AML teams using Vera have already saved the equivalent of 1.7 years of work in early results. The value spans the full lifecycle:

  • Detection: spotting coordinated fraud attacks
  • Optimization: reducing false positives while keeping 100% of true positives
  • Investigation: dramatically shorter investigation times
  • Reporting: dramatically faster report preparation

Using AI Agents to Stop AI Agents: A Step-by-Step Demo

Winning against AI-driven fraud takes two things. First, recognize agentic activity across the customer journey and turn those signals into real-time decisions. Second, put AI agents to work on your side, end to end: building, testing, deploying, and optimizing strategies, with oversight through dashboards and reports.

Here's how that looked in the live demo.

Step 1: An AI Agent Logs Into a Bank Account

Fang started with a demo banking app. Anyone, including an attacker, can run a widely available AI agent locally. She told the agent to log in with a username and password, the kind attackers buy on the black market. The agent followed the instructions and logged in successfully, just as a customer would.

Step 2: DataVisor Detects the Agentic Activity

DataVisor looks beyond the user's event sequence. It also captures raw device and behavior signals from the browser at login, including:

  • An agent score identifying that an AI agent performed the login
  • Autofill on the username and password
  • Suspicious mouse movement and keyboard behavior
  • Web driver, emulator, and unusual hardware signals

Even when an attacker hides the agent well, these signals together reveal that something is off.

Step 3: Vera Builds a Rule in Plain English

The old way: manually write a rule that blocks logins when signals cross set values. With Vera, Fang asked in natural language for a rule that flags logins where the agent score exceeds a threshold, or typing speed is zero or unusually fast. The rule sends matching events to an alert queue and blocks the login.

Vera loaded its rule creation knowledge and parsed the feature names and thresholds from the request. Here the features already existed. If they hadn't, Vera would create them on the fly.

Governance stays with the team. An analyst approves the rule before Vera proceeds, then publishes it to production and organizes it into a rule set.

Step 4: The Agent Tries Again and Gets Blocked in Real Time

The agent tried to log in again with the same credentials. This time, the login was blocked. A new alert appeared in DataVisor case management in real time, showing which rule triggered the rejection and the review.

Step 5: Vera Tunes the Threshold, With or Without Labels

The first threshold, 75, was a best guess based on experience. Is 65 better? Fang asked Vera to investigate the rise in login events over the past 24 hours and tune the rule.

With labels, Vera runs a fine-grained mathematical optimization to pick the best threshold or add conditions. With no labels yet, which is common early in an attack, Vera runs unsupervised statistical analysis. It bins the distribution of typing speed and agent signals, then shows how much traffic each threshold would block. Most users score zero; the suspicious ones cluster high.

Based on Vera's recommendation, Fang raised the threshold to 70 with a single request.

Step 6: Vera Builds a Monitoring Dashboard and Alerts

Finally, Fang asked Vera to build a BI dashboard on login events, with special attention to device signals. In minutes, Vera produced a dashboard covering VPN use, web driver automation, emulators, and the range of AI vendors behind agent logins.

She then set an alert for when the AI agent login ratio crosses a set level, with notifications sent to email or Slack.

The takeaway: the attack came from agentic AI, and agentic AI helped the team create features, build and tune rules, and build monitoring, all at AI speed.

Run Fraud and AML at AI Speed

AI agents have changed what's possible on both sides of financial crime. Top-performing teams are getting ahead by redesigning their workflows, detecting agentic activity in real time, and putting AI agents to work across detection, tuning, investigation, and reporting.

With DataVisor Vera, your team stays in control while AI handles the execution.

Book a Vera demo to see it in action.

Frequently Asked Questions

How do you tell a good AI agent from a bad one?

Start with policy. Some businesses block all agents; others allow them. If you allow agents, combine device signals that detect the agent with what happens next: the actions taken after login. Step-up authentication can ask the user to confirm they authorized the agent. If they say yes, future actions proceed. If not, subsequent actions are blocked automatically.

What signals detect AI agent activity beyond typing speed?

Direct agent detection is the most deterministic signal. Others include autofill, VPN use, web driver automation, emulators, and other device and behavior intelligence. Activity before and after login matters too, such as a dormant account that suddenly becomes active. Unsupervised machine learning also catches coordinated behavior, surfacing fraud rings even when individual agents are well hidden.

Can you back-test rules created by Vera?

Yes. Vera back-tests rules quickly against historical data and shows how many events each rule would capture. Its statistical analysis during tuning is already based on historical data, and you can back-test again anytime.

What is a polymorphic fraud attack?

A polymorphic attack constantly changes its form. Powered by AI agents, it combines scale, machine speed, and adaptation, learning from each failed attempt so the next one is different. That's why adaptive, real-time defenses matter.

How does agentic AI help AML teams with SAR reporting?

Instead of polishing a narrative at the end, agentic AI assembles the SAR from the investigation's evidence trail. The result is more consistent, auditable, and ready to file.

About Fang Yu, PhD

Fang spent 8 years at Microsoft Research developing big-data algorithms and systems for identifying various malicious traffic such as worms, spam, bot queries, hijacked accounts, and fraudulent financial transactions across a wide range of Microsoft products.

‍

About Fang Yu, PhD

Fang spent 8 years at Microsoft Research developing big-data algorithms and systems for identifying various malicious traffic such as worms, spam, bot queries, hijacked accounts, and fraudulent financial transactions across a wide range of Microsoft products.

‍

Latest Content
No items found.

Your Source for Fraud & AML Intelligence

Subscribe for updates on cutting-edge research, industry events, and expert commentary from the leaders in AI-powered financial crime prevention—delivered straight to your inbox..