
Every two weeks, we spotlight an AI task from Unit21's task library, something many compliance and fraud teams are configuring and running inside their workflows today.
This month, as students head back to campus, the task under the microscope isn't one build, it's two, run against the same regulatory language from opposite directions. On July 24, 2026, FinCEN issued FIN-2026-Alert004, warning financial institutions to watch for fraud rings using stolen and synthetic "ghost student" identities, and complicit "straw students," to collect Federal Student Aid refunds, then launder the proceeds through money mules, shell companies, and digital assets. The alert lists nine specific red flags. We ran it through Unit21 twice: once forward, to write a rule, and once backward, to re-examine the alerts already sitting in the queue.
A new FinCEN alert creates urgency and, usually, weeks of manual work: translating red flag language into monitoring logic, then re-checking every open alert against it by hand, one analyst, one PDF, one queue at a time. That work splits cleanly into two different jobs, and they don't have the same shape.
One job is prospective: turn a single red flag into a rule that stops the next ghost student before the refund clears. The other is retrospective: take all nine red flags at once and ask whether any alert already in the queue matches the pattern, tracing shared instruments and account activity an analyst would otherwise have to reconstruct by hand. A single tool built for one of those jobs won't do the other. This edition runs both, side by side, on the same alert.
Rule Writer Agent: What it does
Rule Writer Agent takes a single red flag, pasted word for word from the FinCEN advisory: funds from a student aid refund converted to digital assets and rapidly moved out for no business or apparent lawful purpose. Unit21 returns the variables it needs and its own interpretation of the typology, then assembles them into a trigger condition, ready for an analyst to review and deploy. No SQL, no schema knowledge, no engineering ticket.
Agentic Task Builder: What it does
Agentic Task Builder takes the opposite angle: all nine red flags at once, pasted as a single task brief for a custom Alert AI Agent, then backtested against real alerts already in the queue. The agent works through the data itself, schemas, transactions, entity history, tracing shared receiving instruments and shared IP or device access across flagged entities, and hands back entity-level findings with the evidence attached.
Between the two tasks, the agent automatically reviews:
What the agents output
Why this matters
The two tasks cover opposite ends of the same problem. Rule Writer Agent is prospective: it stops the next ghost student before the refund clears. Agentic Task Builder is retrospective: it re-examines the alerts already sitting in the queue against language regulators only just published, without an analyst rereading a single PDF. Between them, the alert is answered on both sides, and this went from PDF to a deployed rule and a backtested investigation in about the time it takes to read the advisory itself.
What's worth watching is what happens when the data doesn't cooperate. Backtested against one alert with no paycheck-type transactions in the dataset, the agent didn't force a match. It named the exact reason, no entities met the base criteria, and recommended next steps to confirm the transaction labels. A clean, documented negative is a real result, not a shrug, and it's the difference between a tool you can trust on the alerts that don't fit the pattern and one you can only trust on the ones that obviously do.
That distinction matters most on a case like this one. Ghost-student and straw-student schemes are built to look ordinary until the money moves in a specific direction, refunds redistributed to unrelated recipients, converted to digital assets, and pushed out with no lawful purpose. Catching that pattern consistently, on every alert, from language published days ago, is exactly the kind of check that doesn't scale by hand.
The reading gets done. Your investigators make the call.
The AI Task Spotlight runs every two weeks. Each edition covers one task from Unit21's library, covering what it does, how it works, and who it's for. If a task is solving a real problem for one team, it can probably solve the same problem for yours.
Want to learn more? Sign up for a demo of our AI. Alternatively, stay informed of our AI by signing up for our next AI Task Spotlight.

Gal Perelman is the Product Marketing Lead at Unit21, where she spearheads go-to-market strategies for AI-driven risk and compliance solutions. With over a decade of experience in the fintech and fraud sectors, she has led high-impact launches for products like Watchlist Screening and AI Rule Recommendations.
Previously, Gal held marketing leadership roles at Design Pickle, Sightfull, and Lusha. She holds a Master’s degree from American University and a Bachelor’s from UCLA, and is dedicated to helping banks and fintechs navigate complex regulatory landscapes through innovative technology.