AI Tasks

AI Task Spotlight | Edition No. 09: One FinCEN Alert, Two AI Tasks

Published
September 1, 2026
Read Time
6
mins
Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
Subscribe to stay informed
Table of contents

Every two weeks, we spotlight an AI task from Unit21's task library, something many compliance and fraud teams are configuring and running inside their workflows today.

This month, as students head back to campus, the task under the microscope isn't one build, it's two, run against the same regulatory language from opposite directions. On July 24, 2026, FinCEN issued FIN-2026-Alert004, warning financial institutions to watch for fraud rings using stolen and synthetic "ghost student" identities, and complicit "straw students," to collect Federal Student Aid refunds, then launder the proceeds through money mules, shell companies, and digital assets. The alert lists nine specific red flags. We ran it through Unit21 twice: once forward, to write a rule, and once backward, to re-examine the alerts already sitting in the queue.

Why One Alert Deserves Two Tasks

A new FinCEN alert creates urgency and, usually, weeks of manual work: translating red flag language into monitoring logic, then re-checking every open alert against it by hand, one analyst, one PDF, one queue at a time. That work splits cleanly into two different jobs, and they don't have the same shape.

One job is prospective: turn a single red flag into a rule that stops the next ghost student before the refund clears. The other is retrospective: take all nine red flags at once and ask whether any alert already in the queue matches the pattern, tracing shared instruments and account activity an analyst would otherwise have to reconstruct by hand. A single tool built for one of those jobs won't do the other. This edition runs both, side by side, on the same alert.

Introducing Unit21's AI Tasks: Rule Writer Agent and Agentic Task Builder

Rule Writer Agent: What it does

Rule Writer Agent takes a single red flag, pasted word for word from the FinCEN advisory: funds from a student aid refund converted to digital assets and rapidly moved out for no business or apparent lawful purpose. Unit21 returns the variables it needs and its own interpretation of the typology, then assembles them into a trigger condition, ready for an analyst to review and deploy. No SQL, no schema knowledge, no engineering ticket.

Agentic Task Builder: What it does

Agentic Task Builder takes the opposite angle: all nine red flags at once, pasted as a single task brief for a custom Alert AI Agent, then backtested against real alerts already in the queue. The agent works through the data itself, schemas, transactions, entity history, tracing shared receiving instruments and shared IP or device access across flagged entities, and hands back entity-level findings with the evidence attached.

Between the two tasks, the agent automatically reviews:

  • Red flag language pasted directly from the FinCEN advisory, word for word, as the input to both tasks
  • Inbound student aid transaction volume and timing over a rolling 30-day window
  • Outbound crypto transaction count and amount from the same account
  • Shared receiving instruments and shared IP or device access across flagged entities
  • Account age relative to when student aid refunds began arriving
  • Whether the queried data actually exists for a given alert, rather than forcing a conclusion

What the agents output

  • Rule Writer Agent returns a complete set of variables, its own interpretation of the typology, and a trigger condition assembled and ready to deploy, reviewed by an analyst before it goes live
  • Agentic Task Builder returns entity-level findings with amounts, dates, and instruments cited; in the backtest, one entity's student aid deposits were redistributed to three unrelated recipients within days, a distributor pattern that's a direct match to the FinCEN typology
  • An explicit "no matching data" call-out, with the specific reason (no paycheck-type transactions, no entities meeting base criteria, a data labeling mismatch, or empty tables) and recommended next steps, for any alert where the queried indicators can't be evaluated
  • A full reasoning trail for both tasks: every variable choice and every query step, visible end to end

Why this matters

The two tasks cover opposite ends of the same problem. Rule Writer Agent is prospective: it stops the next ghost student before the refund clears. Agentic Task Builder is retrospective: it re-examines the alerts already sitting in the queue against language regulators only just published, without an analyst rereading a single PDF. Between them, the alert is answered on both sides, and this went from PDF to a deployed rule and a backtested investigation in about the time it takes to read the advisory itself.

What's worth watching is what happens when the data doesn't cooperate. Backtested against one alert with no paycheck-type transactions in the dataset, the agent didn't force a match. It named the exact reason, no entities met the base criteria, and recommended next steps to confirm the transaction labels. A clean, documented negative is a real result, not a shrug, and it's the difference between a tool you can trust on the alerts that don't fit the pattern and one you can only trust on the ones that obviously do.

That distinction matters most on a case like this one. Ghost-student and straw-student schemes are built to look ordinary until the money moves in a specific direction, refunds redistributed to unrelated recipients, converted to digital assets, and pushed out with no lawful purpose. Catching that pattern consistently, on every alert, from language published days ago, is exactly the kind of check that doesn't scale by hand.

The reading gets done. Your investigators make the call.

About the AI Task Spotlight Series

The AI Task Spotlight runs every two weeks. Each edition covers one task from Unit21's library, covering what it does, how it works, and who it's for. If a task is solving a real problem for one team, it can probably solve the same problem for yours.

Want to learn more? Sign up for a demo of our AI. Alternatively, stay informed of our AI by signing up for our next AI Task Spotlight.

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21

Gal Perelman is the Product Marketing Lead at Unit21, where she spearheads go-to-market strategies for AI-driven risk and compliance solutions. With over a decade of experience in the fintech and fraud sectors, she has led high-impact launches for products like Watchlist Screening and AI Rule Recommendations.

Previously, Gal held marketing leadership roles at Design Pickle, Sightfull, and Lusha. She holds a Master’s degree from American University and a Bachelor’s from UCLA, and is dedicated to helping banks and fintechs navigate complex regulatory landscapes through innovative technology.

Learn more about Unit21
Unit21 is the leader in AI Risk Infrastructure, trusted by over 200 customers across 90 countries, including Sallie Mae, Chime, Intuit, and Green Dot. Our platform unifies fraud and AML with agentic AI that executes investigations end-to-end—gathering evidence, drafting narratives, and filing reports—so teams can scale safely without expanding headcount.
AI Risk Infrastructure
|
7
min

What's actually holding compliance teams back from AI

Tyler Allen
Tyler Allen
CEO, Unit21
This is some text inside of a div block.
AI Tasks
|
7
min

AI Task Spotlight | Edition No. 08: Account Takeover — Before vs. After Access Change

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
This is some text inside of a div block.
Risk and Compliance Operations
|
5
min

Progressive autonomy: the trust ladder for AI in compliance

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
This is some text inside of a div block.
See Us In Action

Boost fraud prevention & AML compliance

Fraud can’t be guesswork. Invest in a platform that puts you back in control.
Get a Demo