Everyone in fraud and risk is building AI agents. Almost nobody is asking the harder question: if every team has access to the same models, what's left that's actually yours?
In this episode of Fraudboxer, Jordan sits down with Richard Meng, founder and CEO of Roe AI (YC-backed, San Mateo), and Tal, an 18-year risk leader who has built and scaled programs across fintech, payments, lending, issuing, marketplaces, and merchant environments. Together they make the case that AI itself is becoming a commodity — and that the real competitive advantage is structured risk knowledge: the fraud typologies, investigation frameworks, and institutional expertise that live in your team's heads, in Jira tickets, and in Slack threads where no agent can reach them.
The conversation covers why single signals like velocity, device mismatch, and risky IP no longer mean what they used to; why fraud teams stay permanently reactive; what happens to entry-level analyst roles as AI absorbs L1 work — and what new roles replace them; whether rules and machine learning models are dying or just getting a makeover; and why the sub-300ms reality of real-time fraud decisioning means an LLM is never going to be the thing that blocks a transaction.
They also get into the idea of an open, industry-wide fraud typology map — a shared taxonomy of attack patterns and recommended investigations that any team's AI agents could consume. Not a data consortium, not PII sharing, and not the kind of closed, invite-only working group that leaves newer practitioners out in the cold. Whether that can actually get built is the open question of the episode.
If you work in fraud, risk, compliance, AML, trust and safety, or payments — or you manage a team that does — this one reframes what "using AI" actually means. As Jordan puts it: most people say they use AI, but they're reading AI, not using it. The fraudsters figured out the difference a while ago.
Why AI models are becoming a commodity, and contextual intelligence is the real moatFraud typologies - ATO, ACH fraud, friendly fraud, push payment fraud, triangulation schemes, return abuse, promo abuse - and why each needs its own investigation pathThe medicine analogy - why the diagnostic framework beats raw intelligenceVelocity, device mismatch, and risky IP - signals that no longer mean fraud on their ownWhat happens to L1 analyst roles, and the new jobs that get created insteadAre rules dead? A story from inside Uber's rules engine and the Grafana dashboard that showed fraudsters reverse-engineering rules in real timeWhy sub-300ms decisioning means rules and ML models aren't going anywhereRule performance monitoring - the thing almost nobody actually doesHow Roe AI is building a shared financial crime knowledge base, and whether it should be an open standardWhere fraudsters are already outpacing defenders on AI adoption
Roe AI: https://www.roe-ai.comRoe AI careers (they're hiring, including SMEs): https://www.roe-ai.com/careersRichard Meng on LinkedIn: https://www.linkedin.com/in/berkeleymeng/Tal Yeshanov on LinkedIn: https://www.linkedin.com/in/talyeshanov/WhoBilled.me: https://whobilled.me
This episode is brought to you by WhoBilled.me. Ever seen a charge on your statement like "POS CHECK CARD PURCHASE DEBIT * SUPERCELL" and had no idea what it was? Merchants get about 25 characters to identify themselves, your bank wraps its own labels around that, and a location field gets stapled on the end. The result reads like a ransom note — so people dispute their own kids' in-game purchases and shrug off the charges that were actually fraud. Paste the descriptor into https://WhoBilled.me and find out who really billed you, how to reach them, and what the charge was probably for.