AI Tasks

AI Task Spotlight | Edition No. 10: One Ransomware Red Flag, Two AI Tasks

Published
September 28, 2026
Read Time
7
mins
Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
Subscribe to stay informed
Table of contents

Every two weeks, we spotlight an AI task from Unit21's task library, something many compliance and fraud teams are configuring and running inside their workflows today.

‍

This month, the task under the microscope isn't one build, it's two, run against the same regulatory language from opposite directions. On June 30, 2021, FinCEN published its AML/CFT National Priorities: eight typologies U.S. financial institutions are expected to prioritize, including corruption, cybercrime (including virtual currency), foreign and domestic terrorist financing, fraud, transnational criminal organization activity, drug trafficking organization activity, human trafficking and human smuggling, and proliferation financing. Sitting inside the cybercrime priority is FIN-2020-A006, FinCEN's advisory on ransomware and the use of the financial system to facilitate ransom payments. It names a specific laundering pattern: a DFIR or cyber insurance carrier (CIC) customer receives funds, then shortly after sends an equivalent amount to a virtual currency exchange. We ran that pattern through Unit21 twice: once to investigate an alert already in the queue, and once to write a new rule from the advisory's own language.

‍

Why One Alert Deserves Two Tasks

A new red flag, whether it's freshly published or sitting inside a priorities list every institution already knows about, creates the same two jobs every time: work the alerts already in the queue against it, and make sure the next one gets caught automatically. Those jobs don't have the same shape, and a single tool built for one of them won't do the other.

‍

One job is investigative: take an alert that's already fired and build the full evidentiary picture, prior activity, account risk, travel, adverse media, fast enough to recommend a next step with confidence. The other is prospective: turn the advisory's language into a rule that catches the next one before it slips through. This edition runs both, side by side, on the same underlying pattern.

‍

Introducing Unit21's AI Tasks: AI Investigation Agent and Rule Writer Agent

AI Investigation Agent: What it does

AI Investigation Agent takes a flagged alert, in this case card spend rolling into a PayPal/Venmo offload, and works it the way an analyst would, only automatically. Three rules fire at once: P2P offload (a peer-to-peer payment offloading scheme), flow-through funds (pass-through activity with no economic purpose), and layering (new counterparties with no prior relationship). The agent reviews the prior activity behind each triggered rule, screens account risk (age-based vulnerability, HIFCA and HIDTA geography), runs an impossible-travel check, and searches for adverse media, then recommends a next step.

‍

Rule Writer Agent: What it does

Rule Writer Agent takes the opposite angle: plain English in, deployable rule out. Describe the pattern from FinCEN's ransomware advisory, funds received from a DFIR or CIC customer, then rapidly converted to virtual currency, and the agent writes the trigger logic itself: an inbound wire or ACH payment, followed within 48 hours by an outbound transaction sending 80% or more of that amount to a virtual currency exchange. No SQL, no schema knowledge, no engineering ticket.

‍

Between the two tasks, the agent automatically reviews:

‍

  • Red flag language pulled directly from FinCEN's ransomware advisory, FIN-2020-A006
  • Card-spend-to-P2P-offload alert activity, rule by rule: P2P offload, flow-through funds, layering
  • Account risk factors — age-based vulnerability, HIFCA and HIDTA geography
  • Travel and geolocation data, with an honest call-out when there isn't enough to reach a conclusion
  • Adverse media, with a recommended next step when results aren't usable
  • Inbound wire/ACH payment and outbound virtual currency exchange activity within a 48-hour window, for the new rule

What the agents output

  • AI Investigation Agent returns a full evidentiary review, prior activity, account risk, event analysis, online research, and a clear recommendation: escalate for immediate and thorough investigation
  • Rule Writer Agent returns a complete trigger condition, variables, operators, and thresholds, assembled and ready to deploy, flagging entities that receive an inbound payment and send 80%+ of it to a virtual currency exchange within 48 hours
  • Two honest "can't complete" call-outs, from the same alert: an impossible-travel check marked inconclusive for lack of geolocation data, and an adverse media search that returned no usable results, with a recommended retry
  • A plain-English summary of the new rule, written back for review, audit, and approval before it goes live

Why This Matters

FinCEN's priorities list isn't new, but turning any one line of it into working detection is normally the hard part: reading the advisory, agreeing on a pattern, writing the query, testing it, and separately, re-investigating whatever's already sitting in the queue, one analyst, one alert at a time. Here, both happened side by side. AI Investigation Agent worked an existing alert end to end and recommended escalation, while Rule Writer Agent turned the advisory's own language into a live, auditable rule, ready for review, from the same underlying pattern.

‍

What's worth watching is what the AI Investigation Agent didn't do: force a conclusion it couldn't support. The travel analysis is marked inconclusive because there wasn't enough geolocation data for the past 60 days, and the adverse media search returned no usable results, with a recommended next step to retry. A clean, documented gap is a real result, not a shrug, and it's the difference between a tool you can trust on the alerts that don't fit neatly and one you can only trust on the ones that obviously do.

‍

That distinction matters most on a case like this one. Ransomware laundering through DFIR firms and cyber insurance carriers is built to look like ordinary business activity until the money moves in a specific direction, received, then converted to virtual currency and pushed out within hours. Catching that pattern consistently, on every alert, using language regulators have already published, is exactly the kind of check that doesn't scale by hand.

‍

The reading gets done. Your investigators make the call.

‍

About the AI Task Spotlight Series

The AI Task Spotlight runs every two weeks. Each edition covers one task from Unit21's library, covering what it does, how it works, and who it's for. If a task is solving a real problem for one team, it can probably solve the same problem for yours.

‍

Want to learn more? Sign up for a demo of our AI. Alternatively, stay informed of our AI by signing up for our next AI Task Spotlight.

‍

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21

Gal Perelman is the Product Marketing Lead at Unit21, where she spearheads go-to-market strategies for AI-driven risk and compliance solutions. With over a decade of experience in the fintech and fraud sectors, she has led high-impact launches for products like Watchlist Screening and AI Rule Recommendations.

Previously, Gal held marketing leadership roles at Design Pickle, Sightfull, and Lusha. She holds a Master’s degree from American University and a Bachelor’s from UCLA, and is dedicated to helping banks and fintechs navigate complex regulatory landscapes through innovative technology.

‍

Learn more about Unit21
Unit21 is the leader in AI Risk Infrastructure, trusted by over 200 customers across 90 countries, including Sallie Mae, Chime, Intuit, and Green Dot. Our platform unifies fraud and AML with agentic AI that executes investigations end-to-end—gathering evidence, drafting narratives, and filing reports—so teams can scale safely without expanding headcount.
Unit21 for AML
|
7
min

Where to start with AI in AML, and what actually decides whether it works

Tyler Allen
Tyler Allen
CEO, Unit21
This is some text inside of a div block.
AI Tasks
|
7
min

How to write AI agent prompts for AML investigations

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
This is some text inside of a div block.
AI Tasks
|
7
min

AI for detection: Rule writer agent

Gal Perelman
Gal Perelman
Product Marketing Lead, Unit21
This is some text inside of a div block.
See Us In Action

Boost fraud prevention & AML compliance

Fraud can’t be guesswork. Invest in a platform that puts you back in control.
Get a Demo