#95 - The 3 myths behind rules vs. AI
"We're mostly rules-based."
I got this sentence from a prospect last week. But it wasn’t the words, it was how they said it.
Almost like they were apologizing for it.
I didn't think they had anything to apologize for (and I told them just that), but I get why they felt they had to excuse themselves.
It’s 2026 and we are expected to talk about AI. Or at the very least, Machine Learning.
And as a practitioner, it can get really awkward when your recommended course of action is to do what has been done for 20+ years - write rules.
I definitely get why that head of fraud felt slightly embarrassed.
They are used to getting the side-eye from their own manager for that.
And I also get their manager. They are indoctrinated to think that AI = good, and non-AI = bad.
That is a misinformed belief. One that I feel like I’ve spent most of my career fighting against.
Every time I encounter it, I notice the same repeating myths that underlie it.
Let's kill them one by one.
Human-written means error-prone
We’re all too familiar with the term "Human error".
So much so, that subconsciously we started associating humans with errors. And more importantly, the implied meaning - that machines don't make mistakes.
But do they? Yes, they do. Constantly. Especially on a problem as messy as fraud.
Every practitioner I know has a story about a model that missed something painfully obvious. Not your “normal” false positive, but something that would make you cringe.
Because here's what gets left out of the "humans are the weak link" story: the model was never fully separate from humans to begin with.
Someone chose the training data. Someone engineered the features. Someone decided which events counted as fraud and which didn't.
Someone signed off that validation looked clean enough to ship.
And that someone, at least in 2026, is still a human.
So if you don't trust human judgment, you shouldn't trust a model built with one.
More sophisticated means better
Does ML capture more nuance than a rule? Sure.
But nuance comes bundled with complexity. The more moving parts you have, the harder it is to keep it all well-tuned.
Think of it like a sundial next to a wristwatch. The watch is accurate to the second, until it isn't, and then you need a specialist to open it up and fix it.
The sundial is only accurate to the hour. But anyone can fix one - you just square the pole.
But unlike the sun, fraud is adversarial. Well, at least in its intentions.
Even more so, keeping track of an adversary drifts faster, as fraudsters mutate around your defenses on purpose.
And even without the adversary, the system we protect is inherently fragile:
Integrations break by accident and customer behavior shifts with the season, whether anyone touched the model or not.
Both rules and models go stale. Rules are just cheaper and faster to bring back into tune, and that gap compounds every time your system drifts.
Side note: I already wrote before why freshness is more important than accuracy in a different context.
Writing rules by hand means you're behind
The dark side of the AI bandwagon is that everything that isn’t AI is outdated and outclassed.
Many leadership teams have decided "AI-native" means model-first, rules-last.
I wish it were a new thing, brought about by the emergence of GenAI. But this sentiment has been prevalent in our industry for at least 15 years, since ML became a thing.
And it misses two points:
The first is that it’s not a binary decision. No one has to choose between rules and AI. In fact, the best teams always choose both.
The second is that these are two separate streams. That even if you have AI and rules, they themselves are mutually exclusive.
But that is simply not the case. Or at least it doesn’t have to be.
AI can be used to research rules, optimize rules, fix misbehaving rules, assist in monitoring them, and so much more.
There’s still a human in the loop, they are still critical in assessing business context and potential issues that lie outside of the dataset.
But the point is not to replace the human, it is to empower them to make better decisions, faster.
And so, clearly, writing rules and utilizing AI aren’t necessarily two different things.
Assessing two teams that both use rules for fraud prevention doesn’t mean they’ll both score the same.
Because if one of them is using AI, their rules are likely to be fresher, better monitored, and fixed quicker when something happens.
The bottom line
Choosing between rules and AI is a false decision no one has to make.
It is driven by three common-yet-wrong beliefs, that you now know how to counter:
Belief 1: Machines, unlike humans, never make mistakes
Counter: Machines are trained by humans and are exposed to the same biases
Belief 2: Sophistication is better than simplicity
Counter: What’s simpler to build is simpler to monitor, fix, and maintain
Belief 3: Choosing between rules and AI is a zero-sum game
Counter: Not only is it not, you can also use AI to write better rules
How are you managing the tension between being effective and showing you’re not resistant to change? Hit reply and share with me - I’m looking for more convincing arguments.
In the meantime, that’s all for this week.
See you next Saturday.
P.S. If you feel like you're running out of time and need some expert advice with getting your fraud strategy on track, here's how I can help you:
Free Discovery Call - Unsure where to start or have a specific need? Schedule a 15-min call with me to assess if and how I can be of value.
Schedule a Discovery Call Now »
Consultation Call - Need expert advice on fraud? Meet with me for a 1-hour consultation call to gain the clarity you need. Guaranteed.
Book a Consultation Call Now »
Fraud Strategy Action Plan - Is your Fintech struggling with balancing fraud prevention and growth? Are you thinking about adding new fraud vendors or even offering your own fraud product? Sign up for this 2-week program to get your tailored, high-ROI fraud strategy action plan so that you know exactly what to do next.
Sign-up Now »
Enjoyed this and want to read more? Sign up to my newsletter to get fresh, practical insights weekly!