Back to Blog

Nobody Storms the Castle Anymore. They Fill Out the Form.

The perimeter did not fall to an attack. It fell to compliance. Today's most effective fraud looks like perfect adherence, and the design premise of one-time onboarding trust is what needs to change.

Views expressed are personal and do not represent any employer, partner, or client.

The opening panel at ISMG's Fraud Prevention Summit is about synthetic identities, agentic AI, and the collapse of the onboarding perimeter. That phrase matters because it captures something the industry is finally willing to say plainly: the system built to establish trust at the front door now needs to be redesigned.

That is not an admission of failure. It is the clearest description of the problem.

A synthetic identity is not simply a stolen identity. It is a constructed one: a persona assembled from real and fabricated information that belongs to no actual person. What makes it dangerous is not only that it evades controls, but that it often does so by satisfying the exact checks those controls were designed to reward.

This is what makes the current moment so uncomfortable.

The perimeter did not fall to an attack. It fell to compliance.

The older fraud model was, in its own way, easier to reason about. A stolen card, a forged signature, a claim that unraveled under scrutiny. Crossing the perimeter required violating a rule, and rule violations tend to leave evidence behind. Many of the industry's controls were built for that environment, and for a long time they performed well.

Today's most effective fraud often looks like perfect adherence. The synthetic identity clears KYC because it was engineered to clear KYC. The documents are consistent because they were manufactured together. The credit file is thin but clean, which is exactly what an underwritten newcomer might look like. The form is completed flawlessly, which may be the first signal that something is wrong, because real people are messy and real behavior usually is too.

The metaphor that keeps coming to mind is simple: the bouncer is still checking IDs correctly. The problem is that the counterfeit IDs have become more coherent than the genuine ones. The control may still be working as designed. The design premise is what changed.

Agentic AI pushes that problem further. When an AI agent opens an account, initiates a payment, or takes action under delegated authority, the identity question becomes less about a single verified person at a single moment and more about a chain of authority that must remain legible over time. Verified against what: the human who delegated, the agent that acted, or the permissions connecting the two? That is why point-in-time verification is becoming less sufficient. It assumes a stable person, a stable session, and a stable moment of trust. Increasingly, those assumptions no longer hold.

It is tempting to frame this entirely as a modeling problem. Better liveness detection. Better document forensics. Better risk scores. Those advances matter, and they will continue to matter. But the deeper issue is a product one. A perimeter is a product decision. It encodes the belief that trust is established once, at the door, and can then be safely inherited by everything that follows.

The opportunity now is to move trust from a moment to a relationship: continuous, contextual, and revocable.

That was sensible when identities were difficult to fabricate and every customer interaction was undeniably human. That idea increasingly shows up across continuous identity and continuous authentication thinking, where trust is maintained with live signals and stepped up only as risk changes.

In practical terms, that means designing systems that do not treat onboarding as the last meaningful identity decision. An account may be low-friction at creation, then face stronger verification when behavior changes, when access is delegated to software, or when money begins moving in ways the original trust decision never contemplated. Trust should behave more like it does in the real world: built gradually, reassessed in context, and never granted permanently.

That is why the best conversations in fraud prevention now have to cross disciplines. Fraud leaders see the attacks as they land in production. Product teams see how assumptions become workflows, interfaces, and customer experience. Identity teams understand where assurance degrades, and where it can be renewed. The most useful agendas are the ones that bring those views into the same room.

The real question is no longer how to defend the door. It is how to manage trust after entry.

For fraud teams, that means building controls that can be re-evaluated after onboarding, not only during it. For product teams, it means designing trust as a living system rather than a one-time event. For vendors, it means helping institutions support ongoing identity assurance across the full lifecycle of the account, the session, and the transaction.

The castle is fine. The moat is fine. The drawbridge works perfectly.

Now comes the harder and more important design problem: what happens after the door opens.


Shyam Menon is a product leader specializing in fraud and identity in financial services. This is one of a series of framework posts on how to think about fraud prevention, identity, and AI products in regulated industries. He writes at shyammenon.com.