
Every two weeks, we spotlight an AI task from Unit21's task library, something many compliance and fraud teams are configuring and running inside their workflows today.
This edition is a live build, the same way Edition 06 was. Instead of a shipped capability, this is an Alert AI Agent created from nothing, on camera, given a single plain-English instruction, and backtested against two real alerts before either one meant anything for a live queue. The task is a before/after account takeover comparison, and what makes it worth watching isn't the build. It's what the agent finds when the two alerts turn out to be nothing alike.
Every account takeover investigation reduces to one question: is the activity after the reported access change still the account holder? Not the transaction that triggered the alert in isolation, the transaction in the context of everything the customer did before.
Answering that by hand means pulling the full transaction history, finding the moment access changed, splitting the data at that point, and comparing both sides across volume, amount, frequency, currency, and flagged activity. That's real work, and it's the kind that gets compressed under caseload pressure into a glance at whatever's most recent, which is exactly the wrong instinct when the whole point is to see the shift.
It's also work that resists a one-size-fits-all answer, because the two alerts in this backtest prove it. One looks like a takeover from a distance. The other looks like nothing until you compare it to itself.
Account Takeover Before/After Analysis: What it does
This task was configured in a single instruction, typed directly into the Agentic Task Builder: compare a customer's transaction pattern before and after the reported account access change, using the first flagged transaction as the pivot point, and summarize whether the post-change behavior is consistent with the account holder. No SQL, no schema knowledge, no engineering ticket.
From there, the agent did the mapping itself. It found the linked entities on each alert, explored the transaction schema, identified the first flagged transaction as the pivot for that specific alert, and computed the full set of before/after statistics on both sides of it.
The agent automatically reviews:
Account Takeover Before/After Analysis: What the agent outputs
Account Takeover Before/After Analysis: Why this matters
The backtest is where this task earns its keep, because the two alerts don't agree with each other at all.
The first is loud. Monthly transaction frequency rose 68%. Average transaction size climbed 26%. The minimum transaction jumped from $149.02 to $64,323.81, which means the small-value activity that had always been present simply stopped, and a floor appeared where one had never existed. That's the kind of shift an analyst would catch on a first read.
The second is quiet, and this is the one worth paying attention to. Monthly transaction frequency actually declined, from 2.11 transactions a month to 1.55. Average transaction amount rose only modestly and stayed within the account's historical range. The currency profile before and after was identical: the same five currencies, in the same order, with nothing new and nothing missing. Skimmed under caseload pressure, this alert reads as unremarkable, the kind that gets a quick "consistent" and moved along.
The agent didn't skim it. Across more than five years and 140 transactions, zero were flagged. In the period after the access change, all 10 transactions were flagged. It named that discontinuity as the primary indicator of anomalous activity, above the noisier metrics, and concluded the post-change pattern was not consistent with the account holder's history, on that alert, the same way it did on the loud one.
That's the argument for building this check instead of relying on a reviewer's read of the transaction feed. Consistency isn't just faster. It's a task that treats the quiet alert with the same rigor as the obvious one, on alert two just as much as alert one, and on alert two hundred the same as alert two.
Because it's built with Unit21's Agentic Task Builder, this runs inside your existing workflow, in plain English, with no engineering ticket and no waiting on a template that doesn't quite fit your definition of "before" and "after." And because every step of its reasoning stays visible, investigators can act on its findings, challenge them, or escalate them with the backing to defend that decision under examination.
The comparison gets done. Your investigators make the call.
The AI Task Spotlight runs every two weeks. Each edition covers one task from Unit21's library, covering what it does, how it works, and who it's for. If a task is solving a real problem for one team, it can probably solve the same problem for yours.
Want to learn more? Sign up for a demo of our AI. Alternatively, stay informed of our AI by signing up for our next AI Task Spotlight.

Gal Perelman is the Product Marketing Lead at Unit21, where she spearheads go-to-market strategies for AI-driven risk and compliance solutions. With over a decade of experience in the fintech and fraud sectors, she has led high-impact launches for products like Watchlist Screening and AI Rule Recommendations.
Previously, Gal held marketing leadership roles at Design Pickle, Sightfull, and Lusha. She holds a Master’s degree from American University and a Bachelor’s from UCLA, and is dedicated to helping banks and fintechs navigate complex regulatory landscapes through innovative technology.