From Know Your Customer to Know Your AI: 5 Takeaways From Darwinium's New Whitepaper

Image

Datos Insights and Darwinium just published a whitepaper with a blunt starting premise: KYC, as most institutions run it today, was built for a slower, human-driven fraud landscape. That landscape is gone. Fraudsters can now generate a synthetic identity, clone a voice, and adapt an attack in minutes, not months. A verification process designed to check a static identity once at onboarding was never built to keep pace with that.

Here are five takeaways worth sitting with.

‍

1. Static verification cannot compete with adaptive fraud

Traditional KYC treats identity as something you confirm once and file away. AI-enabled fraud doesn't hold still long enough for that to work. A synthetic identity can be built, tested, and refined in the time it takes a compliance team to review a single onboarding file. The whitepaper's proposed answer is a shift from KYC to what it calls Know Your AI: continuous, adaptive behaviour analysis running across every customer touchpoint, not a single checkpoint at the front door.

‍

2. Outdated technology is the top barrier institutions themselves admit to

Up to 69% of financial institutions surveyed cite outdated technology as their leading obstacle to preventing application fraud. That's not an external assessment. That's institutions naming their own gap. It lines up with what shows up in enforcement notices across the region: policies that were sound when written, running on infrastructure that was never upgraded to match how fraud actually moved.

‍

3. The skills gap is compounding the technology gap

Over 45% of institutions report a shortage of skilled personnel to handle evolving fraud threats. Better tooling alone doesn't close that. A continuous AI risk framework still needs people who can interpret its output, tune it, and know when to override it. Technology and headcount are not substitutes for each other, and treating a tooling upgrade as the whole fix leaves the second half of the problem untouched.

‍

4. Manual review is running out of road

89% of organisations surveyed are concerned about over-reliance on manual review. That concern tracks with a wider pattern this newsletter has covered before: detection tools that perform well in controlled conditions degrade once they hit real-world noise, and everything below the confidence threshold gets pushed to a human queue that was never sized for the volume arriving now.

‍

5. The cyber-fraud divide is a structural weak point, not a process detail

The whitepaper's fusion centre argument is worth taking seriously: cyber teams and fraud teams looking at the same institution's traffic, with different tools and different reporting lines, miss attacks that only make sense when both signals are read together. An account takeover attempt that shows up as a cybersecurity event on one dashboard and a fraud event on another is the same attack, seen by two teams that never compared notes.

‍

What Does This Mean for Your Organization?

Most institutions already know their fraud stack has gaps somewhere between detection and manual review. Fewer can point to a documented answer for who owns the handoff when a signal starts in the cybersecurity team and ends in the fraud team, or how long that handoff actually takes in practice. 

Contact us here to talk through where that line sits in your organisation.

‍

Why this whitepaper matters beyond its own numbers

None of these five points are surprising on its own. Institutions already sense that their tooling is aging, that headcount hasn't kept up, and that manual review is stretched thin. What the whitepaper adds is a framework for treating those as one connected problem rather than three separate budget lines. Know Your AI isn't a rebrand of KYC. It's an acknowledgment that verifying who someone is at one point in time no longer tells you enough about what they, or an AI agent acting on their behalf, will do next.

That reframing matters most in markets like Southeast Asia, where the fraud typologies the whitepaper describes rarely stay contained to a single institution. A continuous, AI-aware risk framework run well inside one bank still only sees that bank's own traffic. The synthetic identity or cloned voice that got past one institution's fusion centre this month is often the same one that will get tested against four others next month. Continuous monitoring closes the gap within an institution. It doesn't, on its own, close the gap between institutions, which is where a meaningful share of this fraud is actually moving.

This is the layer Level Five Group works on with institutions across the region: not replacing the continuous AI risk models this whitepaper argues for, but connecting what one institution's model sees to what its neighbours are seeing too.

‍

Download The Whitepaper Here