What problem does it solve?
Every fraud engine produces a queue. Transactions held for review, customer fraud claims, alerts from device and behavioural tools and warnings from card schemes all land with analysts. Each alert has to be worked, whether it turns out to be fraud or a genuine customer, and each one means opening several systems, reading the customer's history and deciding whether to call, release or block.
When queues grow faster than teams, genuine customers wait for a held payment and real fraud gets worked too late. Much of the work on an alert is gathering context from several systems before an analyst can judge it, and the reasoning behind a closed alert is not always recorded in a way that can be audited later.
- In a Feedzai survey of 562 fraud and financial crime professionals at financial institutions (March and April 2025), 43% reported increased efficiency within fraud teams from AI.AI Fraud Trends 2025: Banks Fight Back (2025)
- The same Feedzai survey found that 90% of financial institutions use AI to expedite fraud investigations and detect new tactics in real time.AI Fraud Trends 2025: Banks Fight Back (2025)
How does it work?
- Collect the alert. Alerts from the fraud engine, device intelligence, customer claims and scheme notifications arrive in one queue with a common structure.
- Enrich it. The agent pulls customer profile, recent transactions, device and location history, previous alerts and any contact the customer has had, through read only tools.
- Group and rank. Duplicate alerts on the same customer or event are merged, and a model ranks the rest by risk and value at stake.
- Propose a disposition. For each alert the agent drafts a disposition (release, contact the customer, block, escalate) with the evidence it used. Alerts that meet documented auto clear criteria are closed with that rationale stored.
- Hand over. Everything else goes to an analyst with the summary, the evidence and the suggested next step; the analyst decides and the decision is logged with the agent's draft.
- Audience
- Employee facing
- Autonomy
- Supervised agent
- Adoption
- Early adopters
- Channels
- Agent desktop, Internal tools
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
No public deployment has disclosed a measurable outcome yet.
Value drivers: Employee productivity, Speed and cycle time, Risk and loss reduction, Customer experience.
Indicative value
A retail bank whose fraud team works 200,000 alerts a year
USD 186,667 to USD 1.2 million
Analyst capacity released per year
How this is calculated
Formula: alerts * minutesPerAlert / 60 * timeSaved * costPerHour. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Fraud alerts worked per year alerts, alerts per year | 200,000 | 200,000 | The reference bank. |
| Analyst minutes per alert today minutesPerAlert, minutes per alert | 8 | 15 | Editorial assumption. Replace with your own time study. |
| Share of analyst time saved per alert timeSaved, fraction of handling time | 0.2 | 0.4 | Editorial assumption. The low end matches the 20% cut in alert handling time Feedzai claims for the investigations skill of its Farol agent; the high end stays well below the 75% cut in daily time per person on manual reviews that Oscilar reports for Coast, which measures staff time rather than time per alert. Replace with your own pilot results. Source |
| Fully loaded analyst cost per hour costPerHour, USD per hour | 35 | 60 | Editorial assumption. Replace with your own. |
What it leaves out: Counts analyst time only. It leaves out faster release of genuine customers' payments, losses avoided by working real fraud sooner, and the cost of the platform and integrations.
Who already uses it?
2 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
SEB
Europe · Banking · 2026
Feedzai launched Farol in September 2026, an AI agent embedded in its fraud platform that retrieves and summarises alert data for investigators and supports fraud strategy work such as rule suggestions. SEB, described in the release as a northern European financial services group, is quoted at launch through its fraud prevention business owner on using a single interface for data retrieval, insight generation and rule suggestions. The release does not say how or how widely SEB uses Farol, and no SEB specific results are disclosed.
No outcome disclosed.
Coast
United States · Payments and cards · 2024
Coast, a US fleet and fuel card provider, uses Oscilar's risk platform for fraud decisioning and case management, including rule based routing and assignment of cases, a feedback loop, and generative AI features for case assignment and fraud analysis. The vendor reports that the time Coast's staff spend on manual reviews fell from 2 hours per person per day to under 30 minutes. This is time per person per day, not time per case: queues and auto assignment also let entry level case managers work independently from analysts, so part of the drop may be work moved between roles.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Historical alerts with their final dispositions and the reason recorded
- Written procedures for each alert type, including what evidence an analyst checks
- Access to customer, transaction, device and contact history through APIs
Systems to integrate
- Fraud detection engine and alert queue
- Case management system
- Core banking and card platforms (read only)
- Device intelligence and authentication logs
- Contact centre and digital banking for customer outreach
Complexity: Medium
The agent only reads and drafts, which keeps the risk manageable, but it needs read access to many systems and a clear, approved definition of what may be closed without a human.
- 1
Profile the queue
Break the last year of alerts down by source, type, final disposition and handling time. This shows where the false positives sit and which alert types are safe to automate first.
- 2
Codify the procedures
Turn each alert type's procedure into explicit checks and evidence requirements that the agent follows, reviewed by the fraud operations lead.
- 3
Start as a copilot
Let the agent enrich and draft only, with analysts deciding every alert. Measure agreement between the draft and the analyst's decision per alert type.
- 4
Introduce auto clear per alert type
Where agreement is consistently high and the risk is low, approve documented auto clear criteria for that alert type, with a sample of closures reviewed independently every week.
- 5
Feed decisions back to detection
Share the reasons alerts turn out false with the detection team, so rules and models are tuned and fewer bad alerts are produced in the first place.
Guardrails
- Auto clear only for alert types and thresholds approved in writing, never for high value or vulnerable customer cases
- Read only access for the agent; blocks and releases need an analyst or a separate approved action
- Every disposition stores the evidence and rationale used, whether drafted by the agent or written by a human
- Weekly independent sampling of auto cleared alerts, with automatic rollback if the error rate exceeds a limit
- Customer data masked in prompts and logs where the model does not need it
KPIs to instrument
- Average handling time per alert, by alert type
- Share of alerts auto cleared and the error rate found in sampling
- Agreement rate between the agent's draft and the analyst's final decision
- Time from alert to decision for confirmed fraud
- Fraud that was later confirmed on alerts the agent had proposed to clear
Human in the loop
Analysts decide every escalated alert and any action that affects a customer's money. Fraud operations approves which alert types may be auto cleared and reviews a sample of those closures every week; quality assurance compares the agent's drafts with final decisions.
Common failure modes
- Rubber stamping
- Analysts accept drafts without reading them because they are usually right. Measure disagreement rates and include known fraud test cases in the queue.
- Auto clear drifting with the fraud mix
- Criteria that were safe last quarter clear a new attack pattern. Review auto clear performance monthly and tie it to changes in the detection rules.
- Missing context
- The agent drafts confidently from partial data when a system is unavailable. Make missing sources explicit in the draft and block auto clear when enrichment is incomplete.
What are the risks and rules?
EU AI Act
Minimal risk
Internal triage of fraud alerts is not listed in Annex III, and point 5(b) explicitly excludes fraud detection from the high risk creditworthiness category. Article 50(1) covers any system that interacts directly with people, analysts included, but it does not apply where the use of AI is obvious to a reasonably well informed user, as it is in an internal analyst tool; the marking duties for generated content in Article 50(2) sit with the provider. Reassess if its output feeds credit decisions. Decisions that affect customers remain subject to GDPR and consumer protection rules.
Rules that apply
Guidance
- Annex III: High-Risk AI Systems Referred to in Article 6(2) (European Union, Europe). Point 5(b) carves fraud detection out of the high risk creditworthiness category.
- APP scams (Payment Systems Regulator, Europe). Mandatory reimbursement for authorised push payment scams raises the cost of slow or wrong alert decisions.
Controls to put in place
- Written auto clear criteria per alert type, approved by fraud operations and risk
- Stored rationale and evidence for every closed alert
- Independent weekly sampling of auto cleared alerts with an error rate limit
- Access control so the agent cannot move money or change blocks on its own
- Inventory entry for the agent and its prompts, with change control
Frequently asked questions
- Can an AI agent close fraud alerts on its own?
- Only for alert types where it has proven it agrees with analysts and the risk is low, under written criteria, with a sample of closures reviewed every week. High value alerts, vulnerable customers and anything that blocks or releases money should stay with a human.
- How is this different from the fraud scoring model?
- The scoring model decides in real time whether to hold a payment. Triage starts after that: it works the alerts and held payments the model created, gathers context and prepares or makes the disposition, on a timescale of minutes.
- What results have organizations reported?
- Oscilar reports that Coast, a fleet card provider, cut the time its staff spend on manual reviews from 2 hours per person per day to under 30 minutes after adopting its case management platform with rule based routing, auto assignment and a feedback loop. Upstream of triage, Visa reports that active users of Decision Manager scoring shrank the manual review queue by 25% or more. Both are claims by the platform provider, not independent measurements.
- What should we be able to show an auditor or supervisor?
- Why each alert was closed. Store the evidence and rationale for every disposition, keep the auto clear criteria under change control, and be able to show sampling results.
How to cite this page
Blits.ai AI Use Case Library, "AI agent for fraud alert triage", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/fraud-alert-triage. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published