Thought Leaders
Modern Fraud Has Outgrown the Old Decision Model

Research from the UK Cryptoasset Business Council estimates that UK banks have blocked or delayed roughly 40% of payments headed to crypto exchanges. One exchange alone observed close to £1 billion in declined transactions over the past year.
These restrictions applied even to FCA-registered businesses, and in many cases, customers were simply trying to move their own money.
And there is little reason to think legitimate high-risk payments are being blocked this aggressively only in the UK. The UK is where the scale of the problem has been quantified.
The defenses most businesses run assume the opponent moves at roughly the speed of the last rule change. That stopped being true once AI tooling got cheap: by the time a fraud team has written a rule for the pattern it saw last week, the attacker has already run it thousands of times and moved on to a version the rule will miss.
Yet the default response has remained largely the same: add another check, tighten another rule, or block anything that looks uncertain. That approach catches some fraud. But it also turns away customers who are ready to pay, and their revenue goes with them.
Attackers Can Change Faster Than Rules Can Be Rewritten
Rules work best when suspicious behavior repeats in a recognizable way. Once a pattern becomes clear in fraud or chargeback data, a rule can be built around it to flag similar transactions going forward.
AI makes that response cycle much harder to keep up with. The European Banking Authority warned in December 2025 that criminals are already using AI to automate parts of financial crime and evade detection. Attackers can test more variations with less manual work and switch tactics as soon as one approach stops working.
For a high-risk payments business, this becomes a problem at the point of purchase. The same signal can appear in both fraudulent and legitimate transactions, and a rule on its own cannot tell which it is looking at.I keep coming back to one analogy: if the other side has moved on to robots with laser guns, asking for faster horses and thicker armor only reinforces a defense built for an outdated fight.
Fraud Is Measured, Rejected Revenue Is Not
When a rule cannot tell fraudulent and legitimate transactions apart, declining is usually the safer option for the business.
Approve the wrong transaction, and the loss can show up as a chargeback. Decline a good customer, and the loss is much harder to see because the transaction never happens.
The pressure to decline has only increased under the latest rules for Visa’s Acquirer Monitoring Program (VAMP). Since April 1, 2026, the excessive merchant threshold has fallen from 2.2% to 1.5% for reported fraud and disputes against settled transactions.
The problem is that VAMP only sees what settles. A fraudulent transaction that gets approved can hurt the merchant’s ratio later, while a legitimate customer declined at checkout disappears from the metric entirely.
This ultimately gives fraud teams a strong reason to be more conservative. The stricter they become, the easier it is to keep questionable transactions out of the settled volume VAMP measures.
The paradox of VAMP is that merchants still feel the cost on both sides of the decision. Missed fraud can create chargeback exposure, while false declines cut off legitimate revenue before it ever reaches the business.
Regulators Are Moving Away from Blanket Risk Controls
For years, more friction has been treated as the safest response to financial crime. Yet the Financial Action Task Force (FATF), the global standard-setter, is now telling firms and supervisors to be more precise about the risk they are actually managing.
In February 2025, FATF replaced “commensurate” with “proportionate” across its risk-based standards. A proportionate measure, by FATF’s own definition, should correspond to the identified level of risk and mitigate it effectively. Lower-risk cases should also be eligible for simplified measures.
Its updated guidance pushes the same idea further by warning against de-risking that cuts customers off instead of assessing the risk in front of them.
Making that distinction before another check gets added is where most systems struggle. A good way to do that is passive intent scoring, because it gives firms more context before they decide whether another check is actually needed.
Behavioral and contextual signals are assessed in the background, so low-risk activity can move through with less friction and genuinely suspicious payments get a closer look.
Fraud Decisions Need Context, Not More Verification
If broad restrictions are the fallback when risk is unclear, then the real issue is how a business gets confident enough to make a more precise call.
KYC stays in place for compliance, and confirming who the customer is settles part of the fraud question. The rest depends on context the identity check never sees. A verified customer making an unusual payment is only a problem if it is unusual for that customer, and the identity check has no way to know what normal looks like for them.
The useful information comes from how those signals fit together in real time.
A payment that looks unusual based on the amount alone may make perfect sense once you consider the customer’s history, device, timing, and sequence of actions. Another can look ordinary on each measure and become suspicious only when those pieces are viewed together.
Behavioral machine learning already makes that assessment as the transaction happens, which gives the merchant a much clearer basis for the decision.
This is also where AI bolted onto a rules engine falls short. If fixed thresholds still make the final call, AI is only giving the same old decision process more information. Attackers can keep changing how they behave, while the rules underneath still depend on patterns the business already knows how to flag.
Declining More Does Not Solve the Underlying Problem
Systems that decline aggressively look safer on paper because false declines leave no footprint on fraud reports. That blind spot has shaped payment economics for too long.
Merchants must judge risk engines by total economic yield, balancing approved margin against fraud losses and rejected customer lifetime value.
More importantly, payment platforms must challenge the vendor status quo. Providers should not influence approval decisions while leaving merchants to absorb 100% of the chargeback exposure. True strategic partners back their decisioning with real balance-sheet skin in the game, assuming full financial liability transfer and guaranteeing approval rates.












