The 45-Day Mule Account Gap: Why FRAML Needs Agentic AI

Money mule accounts stay active 45 days before detection. Here is how FRAML convergence and agentic AI are closing the gap for banks in 2026.

Emily Carter
By Emily CarterAI Strategy Consultant at Joinble
·10 min read
Share
The 45-Day Mule Account Gap: Why FRAML Needs Agentic AI
imageUse this imagedownloadDownload

A mule account almost never gets spotted while criminals still operate it. Discovery typically arrives forty-five days later — funds already gone, harm already done, investigators left with a cold trail.

European Banking Authority and European Payments Council figures released through the 2024–2026 reporting cycle show this is no one-off result. It is a structural average. Genuine accounts belonging to genuine people who then help move criminal proceeds stay live for 45 days before anyone flags them, mainly because the two systems that could stop them still sit in separate silos: fraud monitoring and anti-money laundering (AML).

FRAML exists to close that split. Agentic AI, in 2026, is what makes FRAML workable at the pace the threat now requires.

What a Money Mule Account Actually Is

Neither a synthetic identity nor a deepfake bypass describes a money mule account. Whoever opened it is a real, verified person who, at onboarding, fully met KYC requirements. That fact is exactly why this category is so hard to catch.

Recruiters work upstream. They go after people who already cleared identity verification and already hold legitimate accounts. 60 percent of mule recruits are under the age of 30, according to National Crime Agency estimates, typically reached through social media platforms, gaming communities, and fake job advertisements that promise easy income for "financial management" or "payment processing" work. Willing mules know they are helping crime. Witting mules think they have joined a legitimate grey-market activity. Unwitting mules — a growing minority — are truly deceived into handing over account details without grasping the purpose.

Edge cases these are not. The Financial Conduct Authority in the United Kingdom flagged over 207,000 personal accounts as active mule accounts in 2024 alone — a 22 percent year-on-year increase. They amount to an industrialized recruitment and deployment pipeline, large enough to undercut the idea that KYC verification, no matter how thorough, grants immunity from fraud later on.

Why KYC at Onboarding Cannot Catch This

A one-time identity check only tells you who someone was at signup. It says nothing about what they do afterward. For years, Perpetual KYC advocates have pressed that same point.

Six weeks later, an account that cleared every document check, liveness test, and sanctions screening at onboarding can turn into a mule account. The person is the same. The risk is not. None of that shift appears in the KYC record.

Account takeover fraud is a structurally different failure mode: a criminal hijacks a legitimate account. Mule accounts leave the holder in control, actively — if not always knowingly — helping the crime along. No unauthorized access has occurred, so traditional fraud heuristics miss it. Early-stage mule transaction volumes are calibrated to stay below threshold-based alerts, so traditional AML monitoring misses it too.

Mule accounts occupy that 45-day gap between the two systems: fraud detection and AML.

FRAML: When Fraud and AML Share a Brain

Fraud and anti-money laundering functions brought together — FRAML — is not a new idea, yet the urgency around it has sharpened considerably in 2026. Practitioners at an ACAMS New York event in March 2026 described the topic as "the collapse of silos in the age of AI and instant payments." That phrasing captures the stakes exactly.

Distinct teams, distinct data infrastructures, distinct alert queues: that is how the traditional organizational model keeps fraud and AML apart. The split made administrative sense when fraud was mainly a consumer protection issue — refunds, disputes — and AML was mainly a regulatory reporting obligation. Mule account activity erases the distinction. A mule account is both at once: a fraud vector, especially for authorized push payment (APP) fraud, and a money laundering mechanism.

The victim starts the transfer, which is why APP fraud is especially hard. Conventional fraud detection frameworks are nearly useless as a result — the account holder is authenticated, the transaction is authorized, and the KYC record is clean. APP fraud losses are projected to reach $5.25 billion across the US, UK, and India by 2026, growing at roughly 21 percent compounded annually. Worldwide, online payment fraud losses are expected to exceed $343 billion cumulatively between 2024 and 2027.

When a fraud event sends funds through a mule account, the event is now formally classified as a Bank Secrecy Act and AML failure. The Office of the Comptroller of the Currency said so directly in its 2025 Semiannual Risk Perspective. Stopping fraud is no longer enough — institutions are expected to track the movement of fraud-related funds downstream. Regulatory accountability has shifted in a material way.

Those silos come down under a FRAML framework. Fraud signals feed AML investigations. AML transaction patterns surface potential fraud networks. Behavioral data moves freely between both functions. Unified data infrastructure is required in practice, and — given the volume of transactions involved — so is machine intelligence able to work across that unified data in real time.

Instant Payments Change the Calculus

Urgency rose significantly once the EU Instant Payments Regulation took hold. Euro-area payment service providers had to receive instant payments by January 2025 and send them by October 2025. The UK's Faster Payments Service has already run at meaningful scale for years. Money can clear in seconds on real-time payment rails, so the average 45-day detection lag is more than an operational inconvenience. By the time a flag lands in the alert queue, recovery of the funds is a near-guarantee of failure.

Overnight runs, weekly reviews, quarterly reporting: traditional AML batch processing is architecturally incompatible with instant payment rails. Detection and investigation on a 24-to-48-hour cycle cannot keep up when transfers finish in under ten seconds. The compliance stack then runs on a fundamentally different timeline from the threat it is meant to catch.

What Agentic AI Adds to FRAML

Rules-based systems have consistently failed to reach the capability threshold needed to catch mule account activity at a useful speed. Mule typologies shift constantly — calibrated against known alert thresholds, deliberately varied so pattern matching fails, and spread across multiple accounts and institutions so the signal fragments.

Three specific changes to the operational model come from agentic AI.

Cross-account correlation. Weak signals come from a single mule account. Twenty mule accounts in a network — each taking small inflows from the same fraud origin and sending them onward to a consolidation point within hours — produce a graph signature that can be spotted, but only if data from all twenty accounts can be analyzed together. Unsupervised learning models can find these network-level patterns across millions of accounts without predefined typologies. Four case studies from operational banks in the Hong Kong Monetary Authority's June 2026 report on AI adoption in financial crime showed AI-driven mule ring detection collapsing time-to-identification from weeks to hours.

Behavioral anomaly at account level. Behavioral shifts often appear before a mule account is formally activated — abrupt changes in transaction frequency, new payees outside established patterns, inflows from unfamiliar counterparties. Agentic systems watch these signals continuously and start investigation workflows without waiting for a human to initiate them. ThetaRay's Ray platform, launched in January 2026, showed that agentic investigation pipelines — AI that not only detects but also runs a preliminary investigation and readies the case for analyst review — can cut case resolution time by more than 50 percent while lifting consistency across jurisdictions.

Sub-second data integration. Latency in moving data between fraud and AML systems is the core bottleneck in siloed approaches. Agentic AI architectures built on unified data infrastructure remove that latency, so fraud signals can shape AML alerts and the reverse within the same processing cycle. Feedzai's RiskFM, a tabular foundation model purpose-built for financial risk data and launched in 2026, treats mule detection as a cross-domain problem at the intersection of payment fraud and transaction monitoring — not as a problem belonging to either domain alone.

Institutions building agentic identity management infrastructure follow the same architectural approach: autonomous agents working across the full customer relationship lifecycle, not only the onboarding checkpoint.

What the Regulatory Environment Expects in 2026

Regulators have left little room for doubt. Detection liability sits squarely on receiving institutions under the OCC's BSA/AML failure designation for mule-facilitated fraud events. APP fraud liability rules from the UK Payment Systems Regulator, in force since October 2024, make sending and receiving banks share reimbursement costs — a direct financial reason for receiving institutions to hunt mule activity aggressively and proactively.

June 2026 supervisory guidance from the HKMA sets specific expectations on AI adoption for mule detection. Behavioral analytics, network analysis, and real-time transaction monitoring are named as expected capabilities for systemically important institutions. Mid-tier banks still below that capability level can read the document as a map of the compliance gap they still need to close.

Dimension Traditional Siloed Approach FRAML + Agentic AI
Detection lag 45+ days (EBA average) Hours or less
Data scope Fraud and AML kept in separate silos Unified cross-channel view
Mule ring identification Networks rarely spotted Graph-level correlation at scale
Threshold response Criminals calibrate around it Unsupervised anomaly detection
Regulatory exposure BSA/AML failure risk (OCC/PSR) Proactive compliance posture
Human analyst workload High — cases built by hand Agentic triage and pre-investigation

Mule risk does not vanish under a FRAML framework with agentic detection. The 45-day detection window is what collapses. Network-level behavioral monitoring plus unified fraud-AML data makes detection timelines of hours — rather than weeks — operationally achievable. On real-time payment rails, that is the only realistic route to fund recovery, and the only compliance posture regulators are prepared to accept.


FAQ

What is a money mule account?

A money mule account is a genuine bank account belonging to a real, KYC-verified person, then used to receive and pass on proceeds of crime. The holder may be a willing criminal, a witting participant, or an unwitting victim of social engineering. In every case the account clears onboarding controls, because the person who opened it is real and verified.

What is FRAML?

FRAML brings fraud detection and anti-money laundering together as one compliance function. Mule accounts sit where the two disciplines meet: they enable APP fraud from the victim's side and money laundering from the criminal network's side. FRAML knocks down the organizational and data silos that let mule activity drop between the two teams.

What is the 45-day detection gap?

European Banking Authority and European Payments Council data covering 2024–2026 shows money mule accounts stay active for an average of 45 days before anyone detects them. Data fragmentation is the main cause: fraud teams and AML teams run on separate infrastructures, so the combined behavioral signal that would mark a mule account is never assembled in one place at the right time.

How does agentic AI improve mule detection?

Agentic AI can correlate behavioral data across millions of accounts at once, spot network-level signatures of mule rings, and start investigation workflows without a human initiating them. Detection timelines fall from weeks to hours because latency between fraud signals and AML alerts disappears — and because the system runs continuously instead of in scheduled batch cycles.

What are the regulatory consequences of failing to detect mule accounts?

The OCC in the United States has codified that fraud which sends funds through mule accounts is a Bank Secrecy Act and AML failure — not merely a fraud loss. PSR liability rules in the UK force receiving banks to share APP fraud reimbursement costs, so institutions that fail to catch mule activity promptly are penalized directly.

How does mule account fraud differ from synthetic identity fraud?

Synthetic identity fraud fabricates an identity so it can pass KYC onboarding. Mule account fraud takes a real, verified identity and later uses it to facilitate crime. Synthetic fraud hits the onboarding layer; mule fraud hits the behavioral layer after onboarding. Each needs a different detection approach — and point-in-time identity verification alone resolves neither.

Emily CarterEmily Carter
Share

Related Articles

Know Your Human: KYC's Agentic Payment Gap
Compliance18 May, 2026

Know Your Human: KYC's Agentic Payment Gap

The IMF warns AI agents making payments expose critical KYC gaps. Discover why 'Know Your Human' is now the compliance imperative for agentic commerce.

SR 26-2: The Governance Gap in AI-Powered KYC
Compliance17 Aug, 2026

SR 26-2: The Governance Gap in AI-Powered KYC

The Fed's new model risk guidance explicitly excludes generative and agentic AI. For banks using AI in KYC, that gap is now a compliance liability.

Visa Launches Agentic Ready: AI-Powered Autonomous Commerce Gets Payment Infrastructure
News21 Mar, 2026

Visa Launches Agentic Ready: AI-Powered Autonomous Commerce Gets Payment Infrastructure

Visa introduces its Agentic Ready program in Europe with 21 issuing banks. We analyze what it means for identity verification, KYA, and digital trust in agentic commerce.