Curiouser & Curiouser
Curiouser & Curiouser is a podcast for leaders, builders, and curious minds navigating AI, GenAI safety, and governance in a rapidly changing world.
Produced by Alice, the enterprise trust, safety, and security platform for the AI era, the show draws on frontline adversarial intelligence to explore how AI systems are stress-tested, red-teamed, governed, and protected across their lifecycle.
Each episode looks at how AI is actually showing up in the real world, how organizations evaluate it, where it breaks, and what it takes to build systems people can trust.
We cut through hype and fear to explore how AI shapes trust, decision-making, and real-world work, one rabbit hole at a time.
Explore more from Alice:
Website: https://alice.io
YouTube: https://www.youtube.com/@Alice.io.advance.unafraid
LinkedIn: https://linkedin.com/company/alice-io
X: https://x.com/alice_dot_io
Curiouser & Curiouser
AI in Finance: From Money Laundering to Deepfakes
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Mo sits down with Dr. Janet Bastiman, Chief Data Scientist at Napier AI, to talk about why fraud is easier to catch than money laundering, how deepfakes got good enough to fool a finance team out of millions, and why the humans who oversee AI matter more than ever.
🔗 Podcast: https://alice.io/podcast
Follow the show so you don’t miss the next episode.
New episodes every two weeks. Stay curious.
The bad actors in our world do not work within regulation and they do not need to take anything slowly. So the faster that we can move as an industry, the more protected we'll be. Particularly in the financial compliance space, what I'm seeing is a desire to replace the low-risk, easy activities with automatic AI. We are at real danger of moving into a situation where we cannot validate and verify the outputs from AI. And that's a huge worry.
SPEAKER_01If AI has ever made you stop and think, wait, what is happening? You're not alone. I'm Mo, and I'm a security researcher asking the same questions. On Curiouser and Curiouser, we're having open conversations with experts, researchers, and leaders working at the edge of this space, talking through how AI is taking shape, what's shifting, and how people inside the work are thinking about it as it happens. So join us and listen in as the conversation takes shape. Hey, welcome back to Curiouser and Curiouser. I'm Mo, and today I'm really excited to have Dr. Janet Bastman with us here. She is the chief data scientist at Napier AI, and they do all sorts of fun things. I love fraud. Just kidding, I don't. But we love talking about fraud. Um and money is the other thing that we love talking about. And this is also something that Janet's pretty involved in, amongst other things. But I'll let you introduce yourself so I don't ruin the intro.
SPEAKER_00Thanks, Mo. So I've been, gosh, I've been working in IT for a very long time. I started coding in 1984 when my dad brought home a computer from uh the school he worked at and worked my way through. I did my PhD around the turn of the century, which is over a quarter of a century ago for those of you that aren't already feeling old enough. Um I've been working in big data and complex problems for all of my career, which the past six years have been at Napier AI, specifically focusing on the world of anti-financial crime, which we'll dig into later. Um, I'm also heavily involved with the Royal Statistical Society here in the UK. I am currently chair of the data science and AI section and vice chair of their AI task force, helping provide best practice in AI and data science.
The AI Work You Never See
SPEAKER_01You know, I saw RSS and I was like, wow, I didn't know that they have a whole society to focus on RSS. And well, I'm happy that it actually meant something way cooler. So, I mean, it seems like you have like so much uh, again, a really broad range of experience. It's always great to like have people that have seen other things that aren't just security. And I think you're one of a couple guests that we had that aren't just focused specifically in security. So when I think about like AI and finance, this is kind of like, you know, finance is one of those uh industries that's highly regulated, right? Um, we've seen some really bad incidents in finance, and finance was like, we don't want this to happen again. And they actually build out some of the strongest um, you know, anti-fraud programs, uh security programs, uh, et cetera. And usually when I talk about AI and finance with you know some of my friends and stuff, where we immediately think about like how they use ML models in um auto trading, right? And how you're really doing these um like like robot advisors. Um, but there's probably this entire other layer that we just aren't seeing because it's not what's top of mind for people. So what are those kind of things? Because I feel like the stakes are much higher outside of what we understand.
SPEAKER_00Yeah, absolutely. I think like a lot of industries, there's the bit that you you know and you hear about um on the news and generally, and then there's the activities and the use cases that the different financial institutions are using. So if we move away from sort of trading applications to get accounts and things like that, most of the regulation, particularly in the anti-financial crime space, is around making sure that you're not dealing with individuals who may fall under certain financial sanctions, whether that's individuals themselves or the countries or regions that they're involved in. Um, and also looking to make sure that the transactions that are flowing through your institution aren't potential criminal activities, either, as you mentioned, fraud, or a lot of what I do is particularly in the broader anti-financial crime space where we're trying to detect and prevent broader money laundering typologies. So looking at fund movement either to fund other crimes outside of the finance space or to obfuscate the proceeds of crime and try and stop those funds flowing through to bad individuals.
SPEAKER_01Again, there's like a ton in the fraud space and where money goes and how it moves throughout like this, you know, uh it's kind of funny because you you hand like a couple of dollars to a cashier and you you think you know exactly where your money's going. Um but like when you swipe your credit card, it's it feels almost a little bit different.
SPEAKER_00Yeah, I mean there's so many different points. So if you think of all the different types of financial assets, whether you're thinking of raw cash, you know, digital transactions that are backed off an account that may or may not have cash in it, crypto, and then you've got all of the valuable sort of fungible assets out there, it all needs to move through the system and go from one point to another. And how that passes through the system, passes through different individuals and different businesses, all impact the data points that we see, and you start to build up pictures of um what is potential criminal activity. And, you know, there are some things that are very easy to spot or more easy to spot. So I mean, fraud is a great example because generally, if someone gets defrauded, they immediately tell their bank, you know, either as soon as they notice or you know, a couple of days afterwards, or even as part of a broader program. So you've got those
Why Laundering Is Harder Than Fraud
SPEAKER_00very clear positive single transaction notifications that you can then spread out really quickly. When it comes to broader money laundering and where the money has come from or where it's going to, it's a lot more obfuscated through the system and it goes through different types of transactions, um, different financial institutions. And so that pattern spread is a lot more difficult to detect, and it's a lot um, it's a lot more unknown to the general public, I think, in terms of if you're in a shop or dealing with an individual, you just see that single transaction. Whereas there's a lot more downstream of that that you're probably not aware of.
SPEAKER_01Yeah, I was gonna say like these models that are used to kind of detect fraud are really, really high stakes, mainly because uh, you know, we we obviously understand that organizations have their own like behind it, like they don't want fraud to be accidentally or even money laundering, uh, any form of which uh to be caught or classified the wrong way, because you don't know who's gonna be impacted downstream, whether it's uh a mom and pop shop or a consumer or even potentially larger organizations that do have billions and potentially even trillions of dollars moving um daily. So what are kind of like the things that we make sure or we want to make sure when we have these financial models, like what are kind of the different safeguards that we have that just exist or that are employed to ensure that the detection's right? And I guess what level of comfort is used here? You know, in reliability, we have like those nines where like we'll only deploy something if there's a certain amount of nines involved. So like what is that for the financial institution?
SPEAKER_00Yeah, I mean there was a great quote um about the whole nines. Um, oh gosh, it's gonna bug me that I forget who it is, but it's generally it's like nines don't matter if the comp if the customer's not happy. So, particularly in this space, if if we get it wrong, the impact is huge. And that's getting it wrong in both directions. So if you start with a false positive, um, your you claim that an individual or a transaction is suspicious. If you put a block on that, whether that's temporarily or you permanently debank someone, that has a huge impact on their lives, you know, their material impact and what they can do with their funds. So you want to be really, really short before you get to that point. And one of the issues we have, particularly in the money laundering space, is that you have a problem that a lot of the typologies of people involved in money laundering, um, so for example, money mules and things like that, their profiles in terms of transactional behavior overlap a lot with individuals who are on um I'd say non-normal income patterns. So people that maybe work multiple jobs, maybe paid in cash a lot, or even if they're not paid in cash, have spiky income, which varies in weekly, daily, all over the place. And that tends to throw off models that have previously been designed for sort of a standard white-collar job where you get paid regularly at a certain time of the month at very similar amounts. So the first thing we have to do is look at our own internal biases of what we know about um financial security and safety, and make sure that all of the sample data that we use to build these models includes the full range of transactions, not just um for the country that we're building in, which is, you know, for me it's the UK, but all of the patterns worldwide and the different cultural expectations of money and how that differs between normal, everyday, valid, non-criminal transactions, and where you're you have bad actors trying to force funds through in order for their own justification. So we we have to have a lot of checks and balances around that. Every time we get an output, it needs to be fully explainable. So the types of models that we use and the types of outputs that we get out of that have to fulfill all of the audit requirements of the regulated industry. So, in the same way as a human analyst who's looking at what could be billions of transactions unfeasibly, has to come up with a report that details those transactions, the suspicions, the timelines, and all of the extra information. Our models have to do that as well and present that in a way that can be digested and finally decision by a human agent. And the majority of regions in the world have um strict requirements about what can be automated to what point and what needs to have that human oversight before action's taken. And then you've also got the differing levels of risk, so depending on what activities the final institution is doing, you know, whether it's um a full-on Worldwide Bank or whether it might be um sort of a gaming company that allows gambling, or potentially um a a solicitor or someone else handling money on behalf of someone else, all of those have different regulatory requirements, and the their attitude to risk will differ because you may have a a pot of funds to repay back people that were missing. Um, particularly in the fraud case, there's usually a a pot. So people, if they've lost their money, get paid back. And it's important to remember they never get their own money back. The criminals still have their money, they just get money back from this pot. Or in the sake of um money laundering, it may well be that if something turns up, then the regulator will fine them considerably for missing something that they should have picked up and allowed. So all of those different risk factors need to be built in to the models alongside all of the safeguards around making sure that we don't cause problems for genuine vulnerable people, or as you said, mom pop shops that really need to have um access to those funds.
SPEAKER_01It's it's a lot. Uh, and what I mean by a lot, there's a lot to think about when it when it comes to this space. And um, having been in the Bay Area for, you know, almost 10 years and uh spending a lot of time in the UK and spending a lot of time with friends in the UK who are on either security teams or at other vendors or just other practitioners, right? The big difference that um we usually talk about when it comes to AI and how it's implemented in an organization,
Govern First or Build Fast?
SPEAKER_01um, the way European organizations tend to do it is governance first. And the way organizations in North America, or at least the United States, have done it has always been like this uh build fast, right? And adopt really quick. And if something breaks, we deal with it as it happens. Um, but it's not gonna stop us from building and doing the thing. So with all that said, AI is super important to all these organizations, and everyone is rushing to prove that there's value in AI. So, what does that kind of look like in this highly regulated space from your point of view? Where are the trade-offs being made? Um, where are they moving as fast and as rashly as I tend to believe? Or um is it more of like that calculated it takes months to get things done because we want to make sure it gets done and safe?
SPEAKER_00So this is this is an interesting one. Um, because yeah, the the move fast and break things, um, as soon as you got something critical in the list. I I do remember being at a a conference when that started to be the buzzword for development, and someone flashed up a picture of a nuclear power plant and said you don't want to move fast and break things if you're in this sort of industry. Um, and I think particularly in finance, just because it has so much impact not only on individuals but also the backbone of countries, if you get it wrong, that there has been a much more cautious approach. I think that combined with a lot of these institutions that have been around a long time, they have existing long-term contracts. So the rate at which they adopt new software can be slower than other industries. And then you've got the regulatory aspect, and there's general reticence because they want the regulator to almost approve things first before they try out something new. And different regulators worldwide have had different approaches to this. Um, there are some, you know, Singapore particularly coming out and saying you need to be using AI, and here are the use cases that it's valid for, and actively pushing. Um, here in the UK, you've got the financial conduct authority saying, look, we don't regulate technology, we regulate outcomes. So as long as you can prove that your technology is doing what it should be doing to meet the regulatory standards, that's fine. And they're doing a whole load of innovation partnerships to help financial institutions and regtech firms actually prove that they're doing what they should be doing. So that really does vary. There's definitely that want for clarity, because no one wants to do something and then be told that it's wrong and get a big fine, which can stretch into an awful lot. Um, I think particularly going back to what you said about differences between sort of Europe and the US, um, obviously we've not only got financial regulation to consider, we've got broader sort of data protection and AI regulation to consider. And with the EU AI Act, that's got some very, very strict requirements on sort of medium and high-risk defined activities and the use of AI within that. And access to funds is one of their um high-risk things because that has a material impact to life and liberty if you can't access your accounts. So things like that have to be taken into consideration whenever you're putting these use cases together. So there isn't a you can just roll out a solution and it'll work for everyone. So the speed at which things can be delivered is a bit slower in this industry, which is a bit of a shame because fundamentally, just like in the security space, the bad actors in our world do not work within regulation and they do not need to take anything slowly. So the faster that we can move as an industry, the more protected we'll be.
SPEAKER_01That makes a lot of sense. And um, you know, it's it's always like uh the defensive side of security, we're always trying to keep up with attackers. And in this space, it's like attackers are 10x sometimes, you know, and even as we see like new pieces of uh software come out or like, you know, new AI models released from East Frontier uh companies, at the same time, these things get distilled into open source models and then they get used in open source attack platforms. And it's like even if they don't have the you know cutting-edge stuff, um, they really do attack faster than we're usually ready to defend. And you bring up a really interesting part about regulation too, where attackers don't have to worry about regulation. Uh regulation is for law-abiding citizens and countries, right? So, with all that said, you work pretty closely with a bunch of different organizations, um, including the FCA, that like do work in regulation. And you're pretty much closer than other people would be to where regulation is being made. Where do you feel like, um, in your opinion, where they are kind of missing out or like where regulation is just like not understanding the like real gaps that exist?
SPEAKER_00Yeah, it's it's a really good question because you're absolutely right in that there's there's this push, you know, to stay within the law as it should be in terms of data, in terms of um how we're using these models and making sure that everything is as it should be, which there just isn't on the other side. So what I'm seeing from the regulators is a changing push towards uh better working with the industry. So rather than just dictating how things should be, there's an understanding that they do need to start working together more closely. Um, Financial Conduct Authority, the FCA here in the UK have been doing some wonderful innovation sprints and inviting financial institutions and regulatory technology vendors and all manner of fintechs to come in, work with them, sort of share data sets, share ideas, and present back all the different things that they're doing just to help push innovation in a safe environment. And that's something that we're starting to see thought about in different patterns in regulators throughout the world. The regulators are for different regions are talking to each other about best practice, which is fantastic. We're seeing different regions try out different ways of um safe data sharing. So, how can we let other finance institutions and uh regtechs know what might be going on without sort of contravening data policy? So, all of these sorts of things and activities are going on, and I think the regulators are trying to be clear on don't just implement basic static rules that tick a box, actually understand the activity that's going on and make sure that you have the right controls in place for that. So I think, particularly with technology, there's less overwhelm on behalf of the financial institutions, and the regulators are saying, okay, now you can use more technology, you can do more reviews, and you can do them more accurately. Make sure that you're doing them as deeply and correctly as you need to do. And we're seeing that collaboration between regulators and industry, and that's something that we really need. I'd love to see, you know, personally, I'd love to see far more interaction because again, you go back to what you're saying, the bad actors, not only do they not need to work within the law, but they've got no problem with sharing data and collaborating potentially with each other in order to get what they need done. So we need to have a defense that's very similar to the security space. So, you know, if if a vulnerability becomes available, it's propagated through everyone very, very quickly. And we need need to have something similar in the finance space so that when we identify um bad actors, bad accounts, um and we're we're very sure about that, we can spread that information out as well as new ways of of laundering money, new fraud types, all of that, the faster that we can share that information, the better. And I think that's that's still where there's definite regional gaps.
SPEAKER_01Regulation's a pretty fun space when you think about how much needs to get done, but then how sometimes they just miss the things that really need a best that seem really practical. But that is that is neither here nor there. That's it's just an unfortunate way of the world. And we do need it. We do need it to make sure that everyone is at least sticking to the same type of guidelines. And um to be fair, the job that regulators have is not easy. The standards they need to be broad enough for all organizations to be able to adopt especially where you know you're required to and they also need to be flexible enough so that they can be adapted for a changing time. I will say that you're probably one of the first people that was talking about this pretty interesting problem that we're about to go into, which is deepfakes and fraud and the again we still have a little bit about it, but uh maybe before it was the uh the cops and robbers problem with uh fraud in and banks, but in this term uh cat and house. So uh a few years ago I remember you were demoing this like uh this deepfake video and at the time you know deepfakes were pretty horrible. Um I know even up until recently um the Will Smith spaghetti video is kind of like how we did we kind of did
How Deepfakes Got Scary Good
SPEAKER_01uh informal benchmarking of deepfakes, right? And now they're actually getting really really good. Um I'd say even maybe like two years ago you could get a really good video of Barack Obama saying some stuff you have definitely known he's never heard. I know nowadays all I see on Instagram are like deep fakes of political figures saying absolutely ridiculous uh Gen Z coded things. Um yeah I guess back in the day uh or you know eight years ago all right when you were first doing your deep deep fake research what were people saying to you? Like what were people thinking about the problem? Where were they at?
SPEAKER_00So that's a really interesting one because yeah I think gosh it might be you said eight years it might might already be a a decade um which is kind of scary to think about. So a lot of this technology has been around for a while and if you think about the movie industry considerably you know they've been mapping faces for ages. It's just the amount of effort it took has got smaller and smaller. So back when I did um my initial we need to be worried about this this is very easy which was actually at a security conference um I think 2017 I put my own face on um one of the astronauts on the International Space Station and to make it realistic um I um I tried to find someone that had a similar face shape to me just to make it really easy and I also did a um sort of a voice mapping based on what they were actually saying to make it my own voice and tried to get the timing correct to match the the mouse movements as well so that because they were speaking English so it was um I could easily dub my own voice and if I got the cadence right then I could match it. And that was using tools that were 100% open source and available on GitHub repos back in 2016, 2017. They're probably still there now. But it did take a bit of effort and in order to generate it and it was a it was a pre-done video which isn't far off some of the deepfakes you see now. That was easy 10 years ago if you knew what you're doing with a bit of tech it's now become remarkably easy even if you don't know what you're doing. And like you say the Will Smith videos that if you want to do something complicated like eating spaghetti it has taken time to get up but we've had a few years now where just talking to you like I am now it's very easy to use someone else's voice and someone else's face and um last year and maybe two years ago now I showed how easy that was to just swap my own face out live and just go, okay, well this is me. I'm going to switch to a a different camera input which is already doing the pre-filter and I changed my voice I changed my face and the only thing I had to be careful of was getting my fingers too close to where the face um covering was going. But in that environment I could easily hold up a newspaper with today's date on it or whatever as long as again I didn't get it in front of my face. So it's been very easy for a while to create these deep fakes and we had um we had a horrible issue with a company where someone in their finance team thought they were speaking to a CFO in another country and it was all deep faked it started off with a phishing attack with a similar looking email to get them to jump on a call it looked like the person they were expecting to see there were other people on the call that looked like they were the people that were in the in in the company and they gave this individual instructions to transfer money and millions was transferred and once it had been transferred it was immediately sent off to other accounts and irrecoverable before they had all of their other checks in place. So it's something that standard sort of security policies in all businesses need to be aware of how easy it is. And similarly as everyday individuals we also need to be aware I mean I speak to my daughter about this all the time I've shown her those scam texts that I'm
The Deepfake That Stole Millions
SPEAKER_00sure everyone in the world is getting where it's like hey mum I've lost my phone this is my new number send me money and we're not far off those being you know WhatsApp style video calls. It would be very easy to do that even based on a single static picture and potentially a small amount of audio and so what I've been saying to everyone is standard security practice of verify don't trust you know have those old school offline question-answer responses that aren't available online that you can just double check that it is the person you're talking to because we're definitely moving into a world where we can't guarantee that the person on the camera is the person you think it is and whether that's on computer or on phone or any other device. So it's just got super easy. And when I demoed it back in 2017 it was done on a laptop that was already old. So you move that on to today's technology and how quickly and easily you can do it on the laptops that I any teenager would have in their bedrooms right now.
SPEAKER_01So the one thing that really gets me about that right um like you mentioned the three fingers in front of the face and I'm immediately reminded of like the Jim Browning video where you know he's got a scammer on the call and he's like oh yeah hold up the you know hold up your fingers in front of your face and like nah like what if I did this you know um it's kind of funny. But every time we make a defense right or every time we have like this verification method um it seems like that can become more training data for a better attack or a better model right so I mean how do you keep you know making how do you make a strategy around something that is shifting so quickly so fast and every time like this is the fastest iteration of like attack defense attack defense attack defense that we've probably ever experienced.
SPEAKER_00Yeah it's it's really hot because you're exactly right I mean the whole deep fate thing is um adversarial networks so you have a situation where you're deliberately saying do this and if there is something obscure in the face then keep that good you know it's it's something that you can train and work out it's not necessarily a priority because there are far easier things to do. I mean it's the same with glasses. I mean my I've got quite short sighted prescription so you the sides of my face come in through my glasses and when um when I try and do a generative overlay to change my face that's something I have to take into account sometimes I take my glasses off and just deal with it you know if I was wearing contacts that would be easier but if someone's trying to steal my face they don't always get that right because the AIDS mapping software doesn't um doesn't detect that um and I think that's quite generic because I have that problem going through um facial recognition um at airports as well it's like they can't work it out if I'm not wearing the same glasses. So that's one thing. The fingers are another but all of this will will change over time. So we need to come up with methods that aren't visual, that aren't based on our voice print because any of those sorts of biometrics that are being digitized contain artifacts and can be replicated. So it was going back to how I was saying that I interact with my daughter it's like we have questions that only we know and I have similar questions with my parents that are different from the questions with my daughter. So that if she ever phoned me from someone else's phone and said that you know she'd lost her phone, she needed money, I could ask her that question and it's not on the internet anywhere, it's not written down anywhere, it's something that only she knows and she has the same for me says those challenges and we need to start thinking about non-digital offline authentication and you know potentially there needs to be an in-person component. However that in itself is not enough I have interviewed in the past where the person that I've done a telephone call is not the same person that's turned up for the face-to-face interview and you know the voice is different the way they answered questions were different and it's like you can tell that this isn't right in the same way that we're seeing exactly as in the example you said people pretending to be someone else in video interviews so as an entire IT industry we need to think that as how we can get around that so that when we're speaking to strangers for the first time we can verify rather than just trusting the person that we see on screen.
SPEAKER_01I think it brings us to um kind of a really interesting problem set which is human in the loop um I was at a conference a while back I think it was actually last year and the speaker made this really funny comment and it was basically that um the entirety of security we're always told that we treat every employee at a company is the front line or first line of defense. And this is very specific to like fishing right um but it's the easiest way to get into an organization through the people. Now we're saying that your people are like and you know we usually call them the weakest link um because that's usually how attacks get through um now we're saying that people are the only line of defense when it comes to AI like okay we have all these other systems but at the end of the day a human needs to make the decision. Yeah yeah but you know what I mean uh it's one of the strongest mechanisms now um where we're kind of back in the same kind of place where it's like okay um now humans you are back uh you're popular again you're cool um you are also like uh one of the the fail fail uh fail safes for AI and there's this like version of human oversight that's almost comical because it's uh you know you've got this junior person kind of just rubber stamping whatever the model says they don't really have enough experience to say it um
Humans as the Last Line of Defense
SPEAKER_01and I'm pretty sure that this happens a lot more than I'd like to think you know I don't really have any evidence this is a me just uh thinking back to my own analyst days and how like reviews used to get done or at least how I saw some reviews get done.
SPEAKER_00I guess like how common is that kind of thing happening in specifically the financial industry um so there's the thing whether it should or shouldn't be and how much of it it is um I would hope that there isn't just general rubber stamping going on and all of the regulation about human in the loop says that it can't just be rubber stamping the AI decision. It needs to be considered what we have a huge risk of with the the use of AI instead of humans or even to make human roles easier is that we might encourage rubber stamping rather than good investigation. And it's the truism of anything if you measure people they will maximize that measure so if you're saying you must get through this volume of alerts and review them they will do what it takes to get through that volume of alerts whereas what we should be measuring on is much harder which is the quality of those investigations. And I think you know that's that's true across all human activities is that we tend to measure the wrong things. So particularly in the financial compliance space what I'm seeing is a desire to replace the low-risk, easy activities with automatic AI, we are at real danger of moving into a situation where we cannot validate and verify the outputs from AI. And that's a huge worry because the incentive for financial institutions to just adopt as much as possible is huge because it's a huge problem and they have so many transactions and things to check that it's the only way they can really keep up with the amount of financial crime we're seeing. But at the same token we need to be training up those fresh graduates and make sure that they got the discernment in order to check and also correct models that aren't getting it right as well as having um the creativity and insight to look at new patterns that the AI might not be checking. So that in itself is is a big industrial problem that we need to address. I think we're also at the same point where when you go back to the regulation side that some businesses are looking to adopt but holding back because they don't feel that they can in certain areas. So some bits are pushing forward and some bits aren't and some bits are pushing forward too fast when maybe they should be retaining all that expertise.
SPEAKER_01Yeah so when you mentioned that like just with the knowledge piece going away it's really scary when especially when it comes to financial institutions and specifically the area that you're focused in which is fraud um and again all sorts of fraud um so when you've got this kind of like knowledge transfer that's not happening between the junior people, the senior folks and you're saying okay we want to move faster we want to do better I guess um what does that loss of institutional knowledge actually cost at the end of the day? Like what's more valuable? Is it more valuable to be making sure we are hiring and training people who can actually human stamp these types of things, right? And human approve and like learn how these systems are supposed to work or is this actually an opportunity for us to get better with AI and train AI better so that it makes mistakes less?
SPEAKER_00I guess what's the real cost that's happening really interesting question because it's um it's I mean you can measure the cost of you know human
The Knowledge We're About to Lose
SPEAKER_00salaries and training them up but what we can't measure very well and we have to estimate and estimates are very wide on this is the actual impact of AI. Because when you look at the different accuracy levels particularly when you've got some complex models that don't necessarily have good feedback because again going simple fraud generally the customer will tell you that it's an incorrect transaction. When you look at broader financial crime and money laundering the feedback loops aren't there immediately. So getting back that this transaction this set of transactions these accounts were 100% true positives compared to these ones which needed escalating but turned out to be false positives is really really difficult as a problem. So properly validating and scoring how good the AI is is hard. So having a comparison and understanding what the ROI is of both is going to be very very difficult. So yes we could probably invest in training of AI and we should do that 100% because we need those tools to help to help the human agents but at the same time are we ever going to get to a point where we are willing as a society to offload that trust completely and I think that's the question. So if you look at you know aircraft fly on autopilot all the time but we still demand that you've got two human pilots in there to take over for the more complex things and also just in case something goes wrong. Current self-driving cars, I think until it's one of those things until they're the only thing on the road that can talk to each other are we as humans going to be comfortable not having that override mechanism I think it's unlikely. So as a society we need to make that decision that are we going to say yep we are happy for automated systems to fully take the wheel and we have no problem with having zero human oversight in which case yeah we go hard and heavy on that route but if in any scenario we want human oversight we have to maintain that education pipeline. Maybe we don't need as many, but we still need human experts that can not only understand the models but their training data how to improve them and how to override them. And I think that's true of any industry using AI at the moment.
SPEAKER_01The one thing that I I'm also thinking about when we talk about this it's there's something in AI that like or there's something in humans that like AI can't replace and I've seen it a couple of times um most recently one of my friends just got a new job um and I remember another one of our friends or a colleague in the in the group was basically like oh wow like this is great and they're like yeah but he like vibe coded this whole thing and it's almost like five million lines of code and we have no idea what it does. So there's this part where we talk about institutional knowledge and it's like it's so valuable because as soon as you lose it it's gone and like there are both really good amazing processes that we learn there's also bad things that like you maybe like you can't explain or documentation isn't right. And if you just train an AI on it right now you've got bad training data that you don't know the origins from. So I think there's got to be a balance between how we actually are using AI um but more importantly how we're treating the institutional employees especially um how we're training up new ones um to be able to kind of carry the torch and you know really earn that spot of uh most valuable human in the room.
SPEAKER_00Absolutely it's it's something that we need to really understand as a society particularly at the moment we're using AI to summarize everything. We are just looking at distilled summaries of articles written by AI based on maybe something that someone's thought about the vibe coding example and that loss of understanding of how things work um is critical and it's um you know anyone that's read Ray Bradbury's Fahrenheit 451 is very much that first step is only allowing people to see summaries and not the raw data. So I think we need to find a good balance for the future.
SPEAKER_01Yeah. And with that I think we're just at about time um and it was so great to have you today. I'm very thankful that we have such great people that come in and are willing to talk to us about this very hard topic, I think um just a lot of confusing terms to understand and um it's good to see how you're thinking about it from that financial fraud and um that institutional space. Any final thoughts? Any um are you going to be anywhere? Are you working on anything cool that you want to tell everybody about?
SPEAKER_00So I the cool thing that I've been working on recently um we did some really cutting edge stuff with the Financial Conduct Authority where we're looking at financial crime in the same way as you'd look at pollution in a river. So you don't see the start and end points but you see the downstream implication. So we're basically using fluid dynamics to find money laundering in data which is really quite cool and exciting. It's always good using different branches of science and being inspired by things outside of your own narrow field. So that's something we're working on we've just done a few blog posts and videos about that. In terms of speaking engagement I am all over the place my LinkedIn's probably the best place to see where that is so I'm very easy to find on LinkedIn. I think I'm maybe the only Janet Basterman in the world um bearing that Napier.ai website or any of the Royal Statistical Society data science pieces, you can see me popping up there as well.
SPEAKER_01Well thanks for your time and thanks so much and I'm honestly looking forward to hearing more about that fluid dynamics thing. That's pretty cool. I like when people apply different uh again like you said different uh areas of sciences to different arts of technology and um I've heard gravity um being brought to risk but I haven't heard fluid dynamics being brought to um financial fraud.
SPEAKER_00Yeah it's um it's been a lot of fun it's one of those things where it's you need to read outside your own area
Where AI in Finance Goes Next
SPEAKER_00just to keep your own curiosity and intellect up and one of those things where just reading a paper on the archive and then you have one of those sort of 3 a m thoughts and do a proof of concept and it works. It's it's really exciting. So I'm looking forward to getting that in the product live.
SPEAKER_01Well um unfortunately you said the word curiouser so now you've triggered a bad tagline for me. So um obviously we love being curiouser and curiouser here. Ha ha um but yeah we're gonna end it there before I before I have any more time to make bad jokes. So thanks all um we'll see you next time did this episode help cut through the noise like or subscribe so you don't miss what's next. Thanks for spending time with us until next time stay curious