Skip to main content

Arjun Ramakrishnan

Researcher

Sep 2, 2026

4:55
How much growth are you seeing in websites created partially or entirely with AI?
5:00
A lot, right? But when I say a lot, it's a lot both on the legitimate side and on the fraud side, right? What I mean by that is even legitimate businesses now create their websites using AI, right? Everyone uses Lovable or whatever other platforms they might have to create a legitimate website to represent their business, right? And so do fraudsters.
5:17
So how do we tell the difference between the two is the biggest challenge now, right? So in the past, when a business used to open a payments account to accept payments for their business with us, One of the key indicators that we used to use to detect fraud was how legitimate is their website? Is it a very basic HTML website, which is just one page where you scroll and scroll and scroll and there's no depth to the website, it doesn't look sophisticated, it doesn't look serious.
5:43
A real business would have spent more money to build a website that represents their business better, right? But now that difference is pretty much gone, right? Fraudsters can now build a sophisticated website with layers, depth, and sophistication in minutes, right? So it's hard to tell if it is a legitimate business that owns that website, or is it a completely fraud entity that owns that website, right? So that vector and indicator that we use to distinguish between fraud and legitimacy is pretty much gone now.
6:12
So how do we go about now that that difference is gone, figuring out if a business is real or not, right? So in the past, we used to have models which scored the seriousness of a website, right? Now that doesn't work.
6:25
So you go one level deeper, right? And look into the metadata of, hey, what was the platform that built this website? Are there common IPs where a number of these websites have been created? Is the contact us information on this website? Is it common amongst like 30, 40 of these that onboarded on the same date, right? So you're beginning to look at aggregate data and common data points as opposed to looking at one individual specific website to see is it fraud or not, right? So we're moving from investigating individual data points on individual businesses and websites to the next layer on where we're trying to see across your portfolio, what are the common data points that you see between businesses, the websites that they have, the platforms that they were created in, the IP that they're coming from, does the template look similar, right? So you're looking at the aggregate level rather than individual businesses to figure out fraud.

15 MINS LATER

22:21
And I'd love to hear about what you're seeing with AI-enabled card
22:26
attacks.
15:50
No.
15:50
Yeah.
15:51
I, I think what we are also seeing is, uh, this idea of using AI to govern AI, uh, and adversarial AI within the AI system itself to kind of, uh, oppose the action that a authorized agent is taking and then see if it does, does it make sense or should it be blocked at that point of time.
16:10
Uh, it's, it's definitely going to require a combination of traditional static security controls, but without the dynamic security controls, it's going to be really difficult 'cause understanding the intent of the behavior, the intent and the behavior of an agent, that's not what any of our traditional tools were built for.

7 MINS LATER

23:55
Mm-hmm.
23:55
Yeah.
23:56
These emerging constructs are, uh, what's the right word? I mean, they are difficult to kind of figure out, right? Because they harness the power of AI, which is what we are all trying to do, but then the risks that come with it are so unknown.
24:13
It's only a, like an incident needs to happen before we realize.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.