As the fraud landscape continues to change, one truth is becoming clearer: a larger volume of data doesn’t always mean better protection. In fact, for many fraud prevention teams, more data is becoming a liability.
That was the resounding takeaway from a recent SEON-hosted panel featuring fraud leaders from digital-first innovators DoorDash and Bolster AI. Their message? In the age of AI-driven attacks and behavioral spoofing, quality beats quantity, and the smartest signals will win.
Key takeaways for fraud leaders
How has AI changed the way fraud is committed?
The rise of genAI has fundamentally changed how fraud is perpetrated, moving it from manual effort to industrial production. Rod Schultz, CEO of Bolster AI, didn’t mince words: “AI is making it very, very simple to create fraud and commit fraud; to trick customers into doing nefarious things.”
This isn’t just about bots filling out forms. It’s about automated identity fabrication, behavioral mimicry and real-time system probing, often faster than detection systems can respond. AI has shifted the game in fraudsters’ favor, creating an information asymmetry that traditional defenses can’t close.
Why can’t legacy detection see AI agents?
A model trained to recognize human behavior has no baseline for software that was never trying to look human.
While DoorDash recently demoed how an AI agent can order a pizza using OpenAI, the same capability could be used to commit fraud. The twist? These agents don’t behave like humans, and legacy detection systems — trained to spot human behavior — are blind to their patterns. The problem has since moved from checkout demos into production traffic.
Why doesn’t more data improve fraud detection?
Fraud teams have responded with what seems like a logical fix: collect more data. But as SEON’s Husnain Bajwa noted, this approach is backfiring: “People are leaning more and more into data volume because they don’t have the depth and breadth of data.”
Volume and depth get confused because both arrive as “more.” Volume is the same kind of evidence from additional sources. A fourth IP reputation feed tells you roughly what the first three told you, and hands you a fourth provenance chain to defend, plus a fourth set of disagreements to reconcile.
Depth helps you answer a question about evidence within a dimension, and breadth is the comparison of one dimension against other dimensions to see if your hypothesis holds up. To put this into perspective, knowing email deliverability is one thing, but if your insight about email is limited to that signal, it doesn’t really tell you much. Depth within a dimension should give you enough information to answer a suspicious question. Understanding how many data breaches have been associated with that email provides a proxy for the minimum email age, which can indicate greater evidence of existence, and the fraud history associated with that email can be another tell for whether you can trust the person. Test all the information you have about a person’s email address against another dimension, like online presence, and that tells you even more about a person’s history. A higher presence of online profiles takes years to accumulate and is a good sign that your platform is interacting with a real human.
The number worth pinning down is what high-value signals you can actually use in risk decisioning.
How do you collect more signals without adding friction?
Every signal you ask a customer for costs you something at the top of the funnel. For platforms like DoorDash, that balance is delicate. “There’s a natural tension between the signals that we collect and the friction that it creates,” said DoorDash’s Theo Schiades.
Drivers (Dashers) expect to be earning within minutes of signing up. Ask for too much verification, and they churn. But back off too much, and bad actors slip through.
Passive evidence resolves most of the tension, which is why real-time, low-friction trust signals are essential. Signals enriched from a signup form, like username, email, phone number and password, can provide significant insight into the intent of the customer by assessing a customer’s digital footprint associated with their email address and phone number, other available email and phone signals, device integrity, identity and other characteristics beyond basic fingerprinting and observing the overall session behavior of the signup process and beyond. Observing session behavior is key because trust isn’t static; a signup that passes every check can still be completed by someone else or the credentials could be sold to a different party. People change. Risk profiles evolve. The future of fraud defense lies in continuous, adaptive trust, not one-and-done KYC events.
What does a smarter signal look like?
The most successful fraud prevention teams are basing risk decisioning on high-context signals that deliver clarity, speed and confidence. What separates a usable signal from a stored field is what it lets an analyst establish.
| What it is | The question it answers | |
| Depth | The independent questions you can answer about one dimension | Do I know enough about the single piece of evidence to resolve a suspicion? |
| Breadth | The independent dimensions you can test against one another | Does my hypothesis survive contact with unrelated evidence? |
| Time | The pace, sequence and continuity of the journey | Has the story held together across moments such as account registration, repeated logins and other platform interactions? |
Two properties sit beneath all three. A signal has to be high-fidelity, meaning it is verified against third-party evidence, has traceable provenance and is continuously updated in real time.
What should fraud teams do next?
Fraud is, at its core, an asymmetric information problem. The attacker knows more than the defender…unless the defender has better tools.
Closing that gap means ensuring you have a depth of signals you can test across multiple dimensions, and that you can actually take action and make risk decisions against. Having a lot of signals for the sake of signals that are just dressed up as metadata means nothing if they don’t provide value and aren’t actionable.
The future of fraud defense is signal-driven and the companies that embrace precision, speed and transparency will be the ones that stay ahead, not just of today’s threats but also of tomorrow’s.
Want to learn how SEON helps companies eliminate noise and focus on the signals that matter?
