Subscribe to get high-signal insights on how modern fintech is built.

opinion

AI vs. AI in Financial Crime

Generative AI is producing synthetic identities faster than compliance teams can review them. Agentic AI is the defense. Who has the structural advantage?

By Alex Kugell ·

Who wins an arms race between AI that commits financial crime and AI that catches it?

The usual framing is speed. Generative AI produces synthetic identities faster than analysts can review them. Document deepfakes are projected to increase 3,900% year-over-year in 2026.

A complete identity package, driver's license, selfie, and personal details, sells for as low as $20 on darknet markets. A new identity theft victim appears in the US every 4.9 seconds.

I think this framing is wrong. Speed is the attacker's advantage, but speed alone doesn't determine who wins an arms race. The defender has four structural advantages that the attacker can't replicate, no matter how fast the models get. The problem is that most defenders aren't using them yet.

The attack is real

The scale of the attack needs grounding first.

Synthetic identity fraud costs US businesses $20 to $40 billion annually. That number is growing because the cost of producing a synthetic identity has collapsed. Creating a fake passport or driver's license used to require a skilled forger. Now it takes a text prompt.

The ACFE's March 2026 survey of 713 anti-fraud professionals found that 77% reported a sharp rise in deepfake social engineering, and 75% reported the same for AI-generated document forgery.

The 2026 National Money Laundering Risk Assessment, published by Treasury in March, explicitly names AI tools used to create fraudulent identities and launder funds. This isn't a hypothetical. Treasury is documenting cases where gen AI-produced synthetic identities were used to open accounts specifically for laundering.

Deloitte projects that global fraud losses enabled by generative AI will reach $40 billion by 2027, up from $12 billion in 2023.

So the attack is accelerating. But acceleration is a rate, and what matters in an arms race is the structural position each side holds. Attackers are getting faster. The question is whether defenders have assets that speed can't overcome.

I think they have four.

Advantage 1: Labeled data

FinCEN's suspicious activity reporting system turned 30 in April 2026. Over that period, financial institutions have filed 47 million SARs, 4.1 million in 2025 alone. Each one represents an investigation a human conducted: evidence gathered, patterns identified, a judgment made about whether activity was suspicious.

That's the largest labeled corpus of investigated financial crime in existence. Attackers have nothing comparable. A fraud ring has its own transaction data, maybe a few thousand cases. The collective banking system has 47 million investigated cases spanning three decades, with transaction data, entity relationships, and outcome labels attached.

For an agentic compliance system, that corpus is training data, retrieval context, and backtesting ground truth. When Footprint's Percy backtests against historical cases before going live, the quality of that backtest depends on labeled data accumulated over years of human investigation.

The attacker can generate a million synthetic identities. The defender has 47 million examples of what suspicious activity looks like, annotated by the people who investigated it. Scale favors the attacker on production. Scale favors the defender on detection.

Advantage 2: Regulatory authority

A compliance team can freeze an account, compel document production, issue subpoenas, and share intelligence with other institutions under legal safe harbor. An attacker can do none of these things.

FinCEN updated its Section 314(b) information-sharing guidance in June 2026. The FDIC encouraged participation in July. The OCC echoed the push in Bulletin 2026-30. All three federal banking regulators are actively pushing institutions to share more intelligence about financial crime, and the legal safe harbor protects banks that do.

An attacker who compromises one bank has to start over at the next one. A defender who identifies a pattern at one bank can, under 314(b), share that pattern with every other participating institution. The attacker iterates per identity. The defender iterates per pattern.

Consortium fraud platforms already demonstrate this at small scale. At just 5% network adoption, one platform identifies over 300 mule accounts daily and prevents $10 to $15 million in fraudulent transfers per day. A cross-bank model using consortium data reduced false positives by up to 20%.

Those numbers come from 5% adoption. The structural advantage scales with participation.

Structural Position
Defender
Labeled Data
47M SARs over 30 years
Largest investigated financial crime corpus in existence
Regulatory Authority
Freeze, compel, share
Attackers have no legal mechanism to compel cooperation
Institutional Memory
Investigations compound
Each finding becomes retrievable precedent for future cases
Network Effects
314(b) sharing + consortiums
One pattern blocks thousands of identities across institutions
Attacker
Production Speed
Identity every 4.9 seconds
Synthetic documents up 3,900% YoY
Cost
As low as $20 per identity
One image or text prompt creates a synthetic identity
Statelessness
Each identity is independent
Catching one compromises nothing about the rest

Advantage 3: Institutional memory

An attacker's operations are stateless by necessity. Every synthetic identity starts fresh. Every fraudulent document is generated independently. There's no institutional memory because there's no institution.

A defender can compound. We covered this in Part 2 of this series. When a compliance team's investigative findings, the evidence, the reasoning, the human decisions, become retrievable precedent, every future investigation starts with context instead of from zero. A Cyrillic transliteration that fooled a sanctions screening once gets caught the second time because the first investigation's findings are in the memory layer.

The attacker can produce variants faster than any human can review them. But an agentic system backed by institutional memory doesn't review each variant from scratch. It retrieves what the organization already knows about similar patterns and builds on it.

This is the advantage that's hardest to replicate. Labeled data can theoretically be stolen. Regulatory authority can be circumvented by jurisdiction-shopping. But institutional memory, the accumulated judgment of thousands of investigations, with provenance, policy context, and human decisions attached, exists only inside the institutions that built it.

Advantage 4: The rules are changing in the defender's favor

FinCEN's proposed AML effectiveness rule, published in April 2026, shifts the regulatory standard from "prove your compliance program exists" to "prove it works." That sounds like bureaucratic language. It's actually a structural change.

The old standard rewarded process. File your SARs, run your screening, document your procedures. Whether those procedures actually caught anything was secondary. Banks that deployed AI for compliance faced model risk management requirements under SR 11-7 that made innovation expensive and legally risky. Many chose not to.

The new standard rewards outcomes. It explicitly writes credit for effective AI use into enforcement factors. A bank that catches more financial crime with agentic AI gets regulatory credit for doing so. The model risk blocker that kept banks from deploying AI is being addressed.

This matters because the defender's structural advantages, the labeled data, the sharing networks, the institutional memory, are only valuable if they can be operationalized. Regulation that penalizes innovation locks those advantages in a vault. Regulation that rewards effectiveness unlocks them.

Why the advantage is latent

Four structural advantages. All real. And most compliance teams can't use them.

The labeled data exists but sits in siloed case management systems that investigation agents can't query. The sharing authority exists but most institutions participate minimally. Institutional memory is being built by a handful of companies while the majority still run stateless workflows where each investigation starts from zero.

The $206 billion the industry spends on financial crime compliance each year buys, mostly, manual labor. Analysts investigating 30 alerts a day at a 90%+ false positive rate, producing volume instead of depth, leaving every one to three years and taking their judgment with them.

The attacker's advantage is speed. The defender's advantage is position. But a positional advantage you don't activate is just potential energy. Defenders can win this arms race. The question is how fast they convert structural advantage into operational capability.

The agentic compliance stack is the conversion mechanism. Investigation agents that use the labeled data. Orchestration layers that connect the siloed tools. Identity networks that enable sharing. Memory layers that compound what the organization learns.

The attacker is fast. The defender is positioned. The race is between the speed of the attack and the speed of adoption.

Sources

Frequently Asked Questions

How much does synthetic identity fraud cost?
Synthetic identity fraud costs US businesses $20-40 billion annually. Gen AI has made creating synthetic identities trivial, requiring only one image or a text prompt, and document deepfakes are projected to increase 3,900% year-over-year in 2026.
Do financial crime defenders have an advantage over AI-powered attackers?
Defenders hold four structural advantages: 47 million SARs of labeled data, regulatory authority to freeze accounts and compel disclosure, institutional memory that compounds across investigations, and network effects from shared intelligence. Most of these advantages remain underutilized.
What is FinCEN's AML effectiveness rule?
Proposed in April 2026, the rule shifts the standard from proving a compliance program exists to proving it works. It writes credit for effective AI use into enforcement factors, removing a key barrier to banks deploying agentic compliance systems.

Built by Trio, a fintech-native engineering partner helping teams build the next generation of financial technology and infrastructure.

Subscribe to Ledger Drift for high-signal insights into how modern fintech is built, from systems to code to teams.

Keep reading

anatomyInstitutional Memory as InfrastructureCompliance analysts leave. Their investigative judgment leaves with them. What if the system remembered?
analysisThe Agentic Compliance StackEvery compliance platform now claims AI agents. The architecture underneath those claims is where the actual differences...
engineeringThe Model Gateway Is a Compliance BoundaryEvery company routing LLM calls across providers builds a gateway. In financial services, that gateway is a regulatory s...
View more ›