A founder’s note
The People Who Move America’s Money Are on Their Own
AI is making fraud cheaper. I think it can make institutional defense cheaper too. The question is whether we can get the second curve to the people who move other people’s money before the first one reaches them.
America has created a terrible job.
We ask the owner of a twenty-person escrow company to move millions of dollars for strangers. The office earns a small fee relative to the money at risk. It can complete hundreds of files correctly and still have one bad wire threaten the whole business.
The buyer does not care which layer failed. Neither does the seller. They trusted someone with money central to the transaction, and now it is gone.
For a long time, this bargain was survivable. I don’t think it is anymore.
The tools no longer work
The controls around a high-value transaction still depend heavily on our biological senses. Do I recognize this voice? Does this email look right? Is that really the person I spoke with last week? Does this PDF feel legitimate?
AI is attacking every one of those questions. It can help a criminal research a company, write a believable pretext, and generate the voice or image needed to support it. The FBI says generative AI reduces the time and effort criminals need to deceive their targets.1 In May 2025, the UK’s National Cyber Security Centre assessed that AI would almost certainly continue to make parts of cyber intrusion more effective and efficient through 2027.2
Business email compromise was already an industrial business before the latest generation of models. The FBI recorded $55.5 billion in reported domestic and international exposed losses from October 2013 through December 2023.3
I don’t think the defenses in small offices have kept pace.
A wire does not work the way most normal people assume it works. Under California’s version of UCC Article 4A, when the beneficiary name and account number identify different people and the beneficiary bank does not know it, the bank may rely on the number and need not determine whether the name and number match.4
Payee-name verification exists, but it is a pre-payment information control. The Federal Reserve Banks’ terms say their service does not stop a payment or other message from processing or settling.5
If you have spent your life assuming that a wire addressed to Jane Smith must arrive in Jane Smith’s account, the actual system can feel like using the internet with IP addresses alone.
Then there is the aftermath. Recovery and coverage depend on the facts, how quickly the problem is reported, the law, the banking agreement, and the insurance policy. The FBI tells victims to contact their financial institution immediately to request a recall or reversal; prompt action may reduce or eliminate financial loss.6 An office cannot assume that its bank or insurer will make it whole.
This is a ridiculous amount of adversarial risk to concentrate in a small business whose actual job is supposed to be helping people close a transaction.
AI cuts both ways
Here is the part I find hopeful.
The same technology making attacks cheaper may make parts of the defense cheaper too.
At a large financial institution, security is an operating discipline. Better sources. Strict permissions. Clear escalation. People whose job is to notice when something changes. Records that survive after the moment passes.
Small businesses do not have that machinery. Hiring a conventional security team to build it would be insane.
The hypothesis behind Veto is that AI changes the cost curve. Software and narrowly permissioned AIs can do the repetitive work of reading sources, comparing versions, tracking changes, and assembling a record. Experts can define the controls and handle the exceptions. The officer still decides.
We are not selling another dashboard. We are trying to deliver the work and the record.
I believe that can give a small office more institutional control discipline without recreating an institution’s headcount. We have not proved it yet.
The shorthand in my head is hedge-fund-grade financial security at TurboTax prices.
That is the ambition behind Veto.
Not an oracle
The obvious product in this market is an oracle on the hill. Send it a transaction and it tells you the probability of fraud. Stripe Radar for larger sums of money.
I understand why people want that product. I don’t want to build it.
If an oracle says “safe” and is wrong once, the office may lose everything. If it says “fraud” and is wrong, it can delay or kill a legitimate transaction. Either way, the software has quietly taken the wheel from the person who is actually authorized to decide.
Veto should make the officer harder to fool. It should not pretend to become the officer.
So there will be no Veto fraud score and no Veto verdict. Veto will not guarantee that a transaction is safe or promise what a bank, insurer, examiner, or court will conclude. It is not an insurer, a payment rail, or a generic IT provider.
The office decides and acts. Veto records the review.
Start with one decision
Where I want this to go is enormous. Where it starts is almost annoyingly specific.
Our first segment hypothesis is California independent escrow companies with about ten to thirty officers: large enough that the exposure may be salient, but small enough that an owner may be able to test a new control without a long procurement process.
We are starting with Buyer Funding. For many buyers, the process is unfamiliar. A criminal does not need to take over an entire institution. A convincing lookalike email, one changed destination, and the natural chaos before closing may be enough.
The first covered action is the office’s proposed release of one exact, file-bound funding-instruction version to its intended recipient. Veto does not release the instructions or move money. It is designed to assemble the material for the office’s decision: what changed, which source supports each fact, where the sources conflict, what could not be established, and which office policy applies.
The officer chooses what the office will do and records why. The candidate is designed to freeze the reviewed snapshot, the officer’s action, and the rationale as an immutable Review Record that someone else can understand later without reconstructing the file from memory, inboxes, and PDFs.
That record—not a fraud score or an isolated check—is the first product.
Today, it is a synthetic candidate, not a field-proven product. The first proof is boring: one officer uses it on an ordinary authorized file without me, finds the Review Record later, and does the full thing again on a second file. Then the office pays, and the work behind the software gets more repeatable instead of more bespoke.
If that does not happen, Buyer Funding is the wrong wedge. If offices want only a bank-account check, an insurance product, or a prettier audit trail inside software they already use, Veto is a feature, not a company.
We should know the difference before we wander into every fraud problem in America.
Why I am doing this
I have seen both ends of this problem.
At Millennium, security was built into ordinary work: how you logged in, how data moved, how people communicated. The system did not need everyone to be unusually vigilant all day.
In my family’s small business, the owner was also the security team, along with sales, payroll, customer support, and everything else that had to get done before dinner. Telling that person to “be more careful” is not a security architecture.
I also grew up across twelve households. I don’t know how to turn that into a tasteful founder origin story, and I don’t especially want to. The relevant part is that I learned early that systems built on everyone behaving well eventually meet someone who will not.
At Notion, Asana, and other startups, I spent years building data systems. A surprising amount of fraud is an unauthorized change to data: a different email, phone number, identity, instruction, account, role, or claim of entitlement. The dangerous version is often not obviously fake. It is almost correct.
I know what good institutional security feels like. I know why a small business does not have it. And I have spent much of my career thinking about where data came from, who was allowed to change it, and what broke downstream when they did.
I may be wrong about the wedge. I may be wrong about how much of the service can become software. I don’t think I am wrong about the gap.
Earn the first inch
This matters beyond escrow. Buying a home, funding a business, paying a supplier, acquiring a company, and distributing the proceeds of a life’s work all depend on organizations that often do not have a bank’s security budget.
To me, a country that cannot protect the moments when its citizens move their most important money has a national-capacity problem.
No organization entrusted with another person’s money should have to operate in fear.
Veto will not earn that mission by declaring it. We have to earn the first inch: one officer, one consequential action, one record that survives, and then a second file without us in the room.
If that works, we expand carefully. If it does not, we find another starting point rather than protect the story.
The people who move America’s money deserve the kind of security capacity that large institutions can sustain. AI may finally make that affordable. I want Veto to be the company that does it.
If you build systems where AI can do consequential work without being allowed to make the consequential decision, I want to hear from you: sebastian@tryveto.com.
Sources
- FBI Internet Crime Complaint Center, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, December 3, 2024.↩
- UK National Cyber Security Centre, Impact of AI on cyber threat from now to 2027, May 7, 2025.↩
- FBI Internet Crime Complaint Center, Business Email Compromise: The $55 Billion Scam, September 11, 2024. The figure is exposed loss reported to the FBI, law enforcement, and in financial-institution filings; it is not adjudicated or recovered loss.↩
- California Commercial Code § 11207, Misdescription of Beneficiary. Application and loss allocation depend on the facts, agreements, security procedures, law, jurisdiction, and timing.↩
- Federal Reserve Banks, Operating Circular No. 5 § 6.2, May 15, 2026.↩
- FBI Internet Crime Complaint Center, Account Takeover Fraud, accessed August 10, 2026.↩