July 25, 2026
Expert Interview with Chen Zamir

AI’s Real Edge in Fraud Prevention Is Reaction Cycle Speed, Not Smarter Models

Sponsored Content

Chen Zamir has spent the past two decades helping fintechs fight fraud from PayPal to serving as the CTO and co-founder of the anti-fraud startup Fraugster and now as Head of Fraud Strategy at Sardine.  He is also the author of the popular Saturday Fraud Strategist newsletter published by his consultancy native[risk] and co-author of the soon-to-be published Fraud Fighter’s AI Playbook.

In our second interview with Chen, he argues the fraud prevention industry has been asking the wrong question about AI. It’s not “how much more accurate can it make us,” but “how much faster can we react.” That reframing, he says, is what turns AI agents into the biggest unlock fraud teams have seen in years.

The written version of the interview has been condensed and edited for length and meaning. For a snippet from the interview, click the embedded video. To get the full-length interview on video go to Fraudbeat’s Youtube channel here.

Ronen Shnidman: We’re going to continue this where we left it off with the previous interview with Chen on the layer kick approach to fraud prevention. And we’re going to address something that we barely touched on in the last interview, which is how AI and LLMs are impacting fraud prevention in the industry. Chen, take it away.

Every Defense Starts Rotting the Moment You Deploy It 

Chen Zamir: Where we left off last time was when we were discussing what I call the fraud stack layer cake, which is basically how we as fraud fighters or fraud strategists, how we use machine learning models, rules and manual reviews all together to get the best, most optimized results. And we discussed it a bit that each of these methods have pros and cons and only by layering these different approaches together do you get the performance or a stack that can cover for each of the different weaknesses of each approach.

The question that I get a lot in the last two years or so, what about AI? Is AI the silver bullet that will replace this three-layer cake? Is AI going to transform this layer cake into a four-layer cake? I think a lot of the ideas around how AI should manifest in a modern fraud stack are in my mind, rooted in a few misconceptions. 

I think what we’re trying to do with AI is more of the same. And this can be maybe in accuracy when it comes to models, for example, or this can be in efficiency when it comes to manual review. Maybe you do it with AI. AI can contribute to accuracy and efficiency, right? But I don’t think that this is the real step-change that AI represents for us.  

To explain what I mean by that and why I think like that, I’d like to take a step back and talk about a concept that I think I have been talking about for about a decade now, and that is that we all know that every fraud defense that we deploy starts rotting the second we deploy it. And by rotting, what I mean is that the performance starts to degrade, whether this is a model, whether this is a new rule, or whether this is a new investigation playbook.

RS: Well, in plain English by degrading you mean the fraudsters start to figure it out, essentially, and the value declines?

CZ: The point here is that this happens to everything. When we’re speaking about real time defenses, rules and machine learning models, this happens to every piece of code that you deploy. It’s not only about fraudsters. It’s about how your customers behave. It’s about how your business looks like, where you operate, what kind of products you have and so on.  

When you deploy something it may be close to perfect at that point in time, but it degrades. And this is for general software purposes. As you mentioned for fraud prevention, we also have an adversary that is actively trying to bypass our defenses. the fact that performance starts to degrade immediately and whether it takes a long time to degrade or less so, that’s a different question, but it degrades. That is not a new concept and I want to believe that everyone that is listening right now would not be surprised by that. But to me what it means is that what’s really important is not how accurate your rules were or your models were when you first deployed them. Because what matters is how accurate they are right now or how performant they are right now.

We also understand that the closer they are to the point of being released, the better performance we would have. So as time ticks by from the release, we’ll have worse results. What do we get from that? We want to deploy as frequently as possible. We want to monitor our rules all the time. We want to tweak our rules all the time. We want to develop and release new rules all the time. Same goes for machine learning models. And to an extent, the same goes for our manual review playbooks. We want to learn all the time from what’s happening, both on the fraud side and also within our system, to be able to tweak our defenses and make sure that they are fresh or as fresh as they can be all the time.

The Six Stages of the Reaction Cycle 

This concept is the concept of learning cycles or what I call the reaction cycle. How fast from a moment where I see that there’s like a performance issue, how fast can I correct it? How fast can I fix it? 

And when I say performance issues, that doesn’t necessarily mean a fraud attack. We keep thinking about us stopping losses and fraudsters trying to outsmart us and so on. It can also be that suddenly we have a data issue that is really skewing one of our models. It might be that we’ve released a rule or whatever happened, something happened in our system and suddenly a rule starts to create a lot of false positives. Or we have a spike in timeouts. So there can be a lot of different incidents that can happen in our system that don’t necessarily mean that we’re under a fraud attack. 

We still want to realize it straight away. We want to understand what’s going on there straight away and we want to fix it straight away. And this reaction cycle, the faster we can run one, the faster we can react, the better our system would be because it would be fresher. That’s basically the concept. What’s the reaction cycle? 

The reaction cycle has six stages:

  1. Alert — get notified that something is wrong.
  2. Assess — confirm it’s real and significant enough to prioritize.
  3. Learn — understand the root cause.
  4. Research — figure out what would solve it.
  5. Test — validate the solution.
  6. Deploy — ship the fix.

We need to go through these six stages of the reaction cycle and we want to do that as fast as possible and we also want to have as many such cycles running in parallel. If we have such a machine and this machine can churn these issues, churn these incidents as fast as possible, then the secondary effect, the byproduct is that we are more accurate. We have fresh up-to-date defenses. 

The point here is not necessarily to have our North Star be accuracy for accuracy’s sake, but to have our North Star be speed. We want to be fast in what we do. And fast and speed isn’t about how many milliseconds it takes a rule or a model to execute. Speed is not how much it takes an investigator how many minutes for him or her to review a case. Speed is how much time it takes us to basically change the autopilot, change the rule, change the model, change the playbook. This is the speed I’m talking about. 

At this point, we go back to AI. In my mind, the point with AI, especially with agentic AI, but also when we’re talking about data science and analytics is that now all of these processes that I just described, this reaction cycle always happens manually. Now we can delegate some of these parts and maybe even most of these parts, most of these phases in the reaction cycle to AI agents to do for us or at least with us. And this is how I see AI’s role in a modern fraud stack.

Why the Industry Got Stuck Chasing Accuracy 

RS: That’s very interesting. Before we go deeper on that, why do you think that conversations until now have been focused mostly on accuracy and not on speed?

CZ: I think it’s just emotion. It’s just inertia, right? I think that we have these glasses that we wear where we have been chasing for almost two decades better models with better false positive rates or whatever KPI that we want to optimize here. And I think a lot of folks are thinking, OK, can we train a foundation model using payment or whatever fraud data instead of text or images and create a model that would use AI algorithms instead of machine learning algorithms to have better performance in our scoring? And this thinking is kind of like more of the same. But I do think that we’re not at a place where we are searching for a faster horse. This is the step-change where we’re starting to think about an engine instead of horses. And this is why I think the real key here, the real enabling function is actually going to be AI agents and agentic workflows rather than foundation models themselves.

From Case Enrichment to Real Leverage 

RS: That’s very interesting. Okay, so where do we go from here? So you have agentic AI, we have agents helping us speed up the reaction cycles, and then what?

CZ:Before I get to the two areas I think matter most, I’ll acknowledge that teams and vendors are already implementing AI agents around investigations, both fraud investigations and AML/compliance investigations. Mostly this looks like agents helping investigators:

  • Enrichment — pulling the right data from the right vendor, running OSINT.
  • Structuring — organizing the investigation so it’s ready to file a SAR, or to be consumed and labeled consistently downstream.
  • Recommendations — surfacing a narrative and a suggested decision for a human to review.This is the narrative that we have around this case. This is the recommendation and you as the investigator, you’re in a position where you can review everything and decide whether you agree or not. 

This is already being done today to an extent. I think even if your team is not doing it today, you are probably going to at least experiment with it in the next 12 months. So this is, from my perspective, already a phase we’re in. And I don’t think that we need to talk about it too much. 

Unlock One: Stop Resolving Cases One at a Time 

Instead, I want to talk about two other things. The first thing I’d like to talk about is how to really unlock the potential of investigations. And here, instead of thinking, how can I make an investigation last five minutes instead of 20 minutes by doing everything that we just described? What we need to think about instead is, how can I make sure that with one ruling we can actually decide on multiple cases? And the point here is that fraud is never an isolated event. Fraudsters are never one-timers. They are no one-hit wonders. 

Fraudsters when they attack you do so in campaigns. They often come with multiple attempts and multiple cases. And it is very, very common to see campaigns of thousands, tens of thousands, even hundreds of thousands of accounts or payments or identities that are involved in a single campaign. And as an investigator, as an agent, you don’t necessarily see it. You basically just see whatever is in front of you in the queue and is being kind pushed onto your screen. But many times as analysts that review the data in the data warehouse, you can find these patterns, and can find these campaigns very easily. 

The first thing that I think that AI agents can do is exactly be able to take these single individual alerts and bunch them together as cases. This is something that is being done to an extent today automatically in some organizations. And many times it is done manually by the investigators themselves. But there’s so much room here for agents for every alert, every kind of event that is flagged, to match it against known campaigns and known patterns that we know that are currently active and associate them to this campaign. 

By doing that, you get basically two things. First of all, especially with fraud, it is way easier to make a decision. When I have 1,000 cases that are bunched together, it doesn’t matter if they are good or not, and usually if they are bunched together they are not good, it’s way easier for me to see the pattern, to see the fraud indicators and to decide that this is something bad. It’s much easier than looking at each case individually. Two, obviously I just made redundant all of these hundreds or thousands of other events that are sitting in my queue and I can auto-resolve them. I don’t need to go over them again because I looked at the ring and I resolved it. We have gained leverage twice here, right? Both from an accuracy perspective and also the time that it takes us to make the decision, but also the fact that we are making a resolution over multiple cases. But the real leverage that we get here is by being able to label cases or label events at scale. 

So if now, or if in the old world, quote unquote, we would have reviewed a specific event and decided this is fraud and now it is labeled as fraud and hopefully it would now be treated as such in our database and we can train our models and write rules according to it. Now with this single decision, with these five minutes that I spent, I can tag thousands of cases as fraud. And this ability to make decisions at scale, that’s the unlock. That means that I don’t necessarily now need to spend so much effort to find the needle in the hay stack fraud, which is usually a miniscule population in my flow. I don’t need to do that anymore in order to be able to understand what’s going on and how my defenses are performing and what I should do to fix them. 

RS: Calling that the unlock, or I guess you could say the prerequisite for the next… the new world, so to speak, really highlights your point in bold.

Unlock Two: Let Agents Label, Not Decide 

CZ: Exactly. This is the prerequisite. Another method that can help us gain this prerequisite to the new world, which is the second element that I mentioned, and that is to start labeling with agents. And what do I mean by that?

We already have agents reviewing each and every case. And now these cases are made by multiple events. So it’s also easier to make decisions on them. And we already have these agents recommending a decision. So the difference between recommending a decision and labeling is pretty low. The difference is semantics, basically.

Now you might ask, why do you need a human to govern an AI agent? Now you might ask, how come I’m not that comfortable with giving agents the permission to rule over investigations, but I am comfortable letting them label events. If it’s the same, why am I making these differentiated governance models?

I think the simple answer is that in investigations, I am actually making a real ruling over a real user. And if I’m making a mistake, I’m creating friction. With labels, I don’t really do that. So there are, of course, downsides to having bad labels. And the downside is that my simulations and in general, my reporting, everything is less accurate.

But I’m not necessarily putting myself into a hole with the user and maybe even with the regulators if I do that on scale. And I would also say that we know that labels as a default are always dirty, especially when it comes to fraud. There can be many reasons why events that are not tagged as fraud can be fraud and we don’t know about it. Under reporting, 3D Secure coverage that means that we don’t necessarily get the chargeback. There can be a lot of reasons. There can also be a lot of reasons why events that are tagged as fraud are not really fraud. For example, first party fraud or chargeback fraud. I say that it was an unauthorized use, actually it was me, but it’s tagged as fraud because I got a chargeback.

CZ: Labels are not accurate by default and of course agents can introduce more issues around that, but we know how to deal with that, we know how to create different sets of labels, we know how to measure their cleanliness, so there are ways to deal with it. The point here is that once I can label with agents, I can now basically run an agent for literally every event that runs through my system. It doesn’t need to happen within the same second, it doesn’t need to happen within the same minute. I have all the time in the world and instead of waiting for chargebacks that can arrive in 30, 60 days, now I can have labels from the same day.

So actually what it means is that when we are thinking about AI and agentic AI, we see that we have two ways for us to gain labels at scale and very fast, whether it is through scaling the decisions from investigations or whether it is really to use AI agents themselves to label my events. The point here is that we are not waiting for the chargebacks. And if we go back to idea of the reaction cycle, what we see here is that if for reaction cycles that depend on us knowing the fraud rates and how fraud matures and which events were fraudulent and which ones were false positives, suddenly the reaction time here compresses significantly because we don’t need to wait 30 to 60 days. We now have on-demand labels and that means that not only that we can now start building the next steps in the reaction cycles, the logics themselves and start training them and so on, but it already shortens the reaction cycle, probably it shortens the stage that takes the most amount of time, just sitting on your hands and waiting to see what was fraud two months ago. And that I think would be the step change with AI.

What Has to Happen Before Agents Make the Final Call 

RS: Yeah, it’s a huge difference. That’s sort of like a game changer in your opinion. But let me ask you this, I mean, you’re saying you don’t want to use agentic AI for decision making regarding the results of investigations, know, whether you approve the customer or you don’t approve the customer. What would need to change for you to be okay with that? You said you’re afraid of the customer insult and so on.

CZ: Yeah, so there are a few elements here. I’ll start by saying that I do think that eventually we will get there. And I don’t necessarily object to it from a theoretical perspective. I think a few things need to happen first. One, I think that teams would need to get comfortable with operating AI agents at scale. And that means: A. Trust, but trust comes with experience and experience comes with time. So A, we just need some time. B. There’s also an element of knowing how to monitor AI agents, how to assess AI agents, and how to correct AI agents. And so it’s not enough for us to say this agent, we have enough experience with it and we know how good it is or not, but it is also, okay, and then what do you do with it? How do you actually measure it? I think there’s this AI agent performance monitoring framework that teams would need to start putting in place.

It’s a prerequisite for running things fully automated. And if you think about it, this is what we have today for rules. This is what we have today for machine learning models. We have these frameworks around which we can say, OK, well, this is my system’s health, and these are the pain points, and this is where I need to go and have a closer look and so on. So the same thing we would need to develop for AI agents themselves. This is not going to be obviously a zero to one journey. It’s not going to be that one day we’ll have it and then we’ll move from fully manual or fully manual and human in the loop  to fully automated. I think that we will or teams would

recognize that certain flows, certain decisions are probably easier for agents to conduct with higher accuracy. And this would be part of gaining the experience of slowly moving bigger and bigger chunks of flows or populations or queues to be completely resolved with agents.

This is really just a matter of time in my mind. There is another question, which is the regulator. I think it is maybe a bit more relevant for compliance and AML investigations rather than fraud, because also here you need some kind of auditability,  explainability and so on. But I think this is more about understanding how this should look rather than a real technological challenge. It’s not that I’m saying that AI agents shouldn’t be ever used for making automated decisions. I just think that most teams are not there, and this is just a process.

Regardless, we will forever have a human in the loop. It would just not be on a single event decision. It would be, you know, as we are today monitoring rules and monitoring machine learning models, we will always have a human in the loop, even if it’s just sitting, monitoring and deciding when to tweak or when to deprecate or when to retrain.

RS:OK. So we’ll always have a human in the loop, but you think that we will get to a point where we have agentic decision making. It’s just a matter of time.

Start Where You Already Have Experience 

RS: Is there anything else you want to say in terms of reaction time and that being sort of the game changer that agentic AI brings to the world of fraud prevention right now?

CZ: I’ll say in general, in order to fully automate the reaction cycle, there are a few more things that teams would need to put into place. What we talked about today are the prerequisites for that, for automated rule writing, for example. But more than that, this is probably also the sensible place to start with agentic AI. It’s where we already have technology in place. We already have, as I mentioned, agentic products around investigation. So most teams have already today or will have very shortly some experience with that and starting to expand the capabilities and starting to expand how we think about it. It’s not about how accurate we make decisions on single events. It is not how much headcount we save. It is about how fast we can react and what these capabilities can help us achieve further upstream or downstream. When you start with, you know, when you start where you already have some experience and some technology and you start working your way up from there, that would lead you naturally to other more complex things that can be done and we can talk about it next time.

Darwinium banner ad

ABOUT RONEN SHNIDMAN

Before entering the field of fraud tech and founding Fraudbeat, Ronen spent close to a decade as a journalist. He began his career working at the newspapers The Jerusalem Post and Haaretz/The Marker and before shifting to trade journalism and covering the diamond industry. Ronen uses his past experience as a journalist to inform his approach to covering fraud trends and anti-fraud technology with the intent of giving the highest quality information from the sources most in the know.

View All Ronen Shnidman Latest Posts

Leave a comment

Your email address will not be published. Required fields are marked *