
Every two weeks, we spotlight an AI task from Unit21's task library, something many compliance and fraud teams are configuring and running inside their workflows today.
This month, the task under the microscope isn't one build, it's two, run against the same regulatory language from opposite directions. On June 30, 2021, FinCEN published its AML/CFT National Priorities: eight typologies U.S. financial institutions are expected to prioritize, including corruption, cybercrime (including virtual currency), foreign and domestic terrorist financing, fraud, transnational criminal organization activity, drug trafficking organization activity, human trafficking and human smuggling, and proliferation financing. Sitting inside the cybercrime priority is FIN-2020-A006, FinCEN's advisory on ransomware and the use of the financial system to facilitate ransom payments. It names a specific laundering pattern: a DFIR or cyber insurance carrier (CIC) customer receives funds, then shortly after sends an equivalent amount to a virtual currency exchange. We ran that pattern through Unit21 twice: once to investigate an alert already in the queue, and once to write a new rule from the advisory's own language.
A new red flag, whether it's freshly published or sitting inside a priorities list every institution already knows about, creates the same two jobs every time: work the alerts already in the queue against it, and make sure the next one gets caught automatically. Those jobs don't have the same shape, and a single tool built for one of them won't do the other.
One job is investigative: take an alert that's already fired and build the full evidentiary picture, prior activity, account risk, travel, adverse media, fast enough to recommend a next step with confidence. The other is prospective: turn the advisory's language into a rule that catches the next one before it slips through. This edition runs both, side by side, on the same underlying pattern.
AI Investigation Agent takes a flagged alert, in this case card spend rolling into a PayPal/Venmo offload, and works it the way an analyst would, only automatically. Three rules fire at once: P2P offload (a peer-to-peer payment offloading scheme), flow-through funds (pass-through activity with no economic purpose), and layering (new counterparties with no prior relationship). The agent reviews the prior activity behind each triggered rule, screens account risk (age-based vulnerability, HIFCA and HIDTA geography), runs an impossible-travel check, and searches for adverse media, then recommends a next step.
Rule Writer Agent takes the opposite angle: plain English in, deployable rule out. Describe the pattern from FinCEN's ransomware advisory, funds received from a DFIR or CIC customer, then rapidly converted to virtual currency, and the agent writes the trigger logic itself: an inbound wire or ACH payment, followed within 48 hours by an outbound transaction sending 80% or more of that amount to a virtual currency exchange. No SQL, no schema knowledge, no engineering ticket.
Between the two tasks, the agent automatically reviews:
FinCEN's priorities list isn't new, but turning any one line of it into working detection is normally the hard part: reading the advisory, agreeing on a pattern, writing the query, testing it, and separately, re-investigating whatever's already sitting in the queue, one analyst, one alert at a time. Here, both happened side by side. AI Investigation Agent worked an existing alert end to end and recommended escalation, while Rule Writer Agent turned the advisory's own language into a live, auditable rule, ready for review, from the same underlying pattern.
What's worth watching is what the AI Investigation Agent didn't do: force a conclusion it couldn't support. The travel analysis is marked inconclusive because there wasn't enough geolocation data for the past 60 days, and the adverse media search returned no usable results, with a recommended next step to retry. A clean, documented gap is a real result, not a shrug, and it's the difference between a tool you can trust on the alerts that don't fit neatly and one you can only trust on the ones that obviously do.
That distinction matters most on a case like this one. Ransomware laundering through DFIR firms and cyber insurance carriers is built to look like ordinary business activity until the money moves in a specific direction, received, then converted to virtual currency and pushed out within hours. Catching that pattern consistently, on every alert, using language regulators have already published, is exactly the kind of check that doesn't scale by hand.
The reading gets done. Your investigators make the call.
The AI Task Spotlight runs every two weeks. Each edition covers one task from Unit21's library, covering what it does, how it works, and who it's for. If a task is solving a real problem for one team, it can probably solve the same problem for yours.
Want to learn more? Sign up for a demo of our AI. Alternatively, stay informed of our AI by signing up for our next AI Task Spotlight.

Gal Perelman is the Product Marketing Lead at Unit21, where she spearheads go-to-market strategies for AI-driven risk and compliance solutions. With over a decade of experience in the fintech and fraud sectors, she has led high-impact launches for products like Watchlist Screening and AI Rule Recommendations.
Previously, Gal held marketing leadership roles at Design Pickle, Sightfull, and Lusha. She holds a Master’s degree from American University and a Bachelor’s from UCLA, and is dedicated to helping banks and fintechs navigate complex regulatory landscapes through innovative technology.