Artificial Intelligence / Fraud Prevention
August 13, 2026
9 minutes

Infrastructure: What the Market Understands (and What Changes for Certta)

Infrastructure is a hot topic at Febraban Tech 2026. See what the financial market understands by the term, and how Certta sees it differently.

The Technical Definition Still Dominating the Financial Sector

Ask a bank executive what antifraud infrastructure means to them, and the answer will likely be technical: servers, availability, uptime. That definition explains not just how the sector built its systems, but also why antifraud operations evolved as a set of isolated tools rather than as a decision-making system.

The result was rigid flows, with little room to adapt the journey to each customer's actual profile or to each operation's risk appetite. That logic began to be questioned as fraud, artificial intelligence, and digital identity started demanding faster, more contextualized decisions. It's no coincidence that the topic has gained traction at events like Febraban Tech and Rio Innovation Week. From that debate, we set out to examine how the idea of infrastructure is changing in the financial sector.

The weight the topic carries at these events is no accident: it reflects the scale of investment already underway. According to the Febraban Banking Technology Survey, conducted with Deloitte, total technology spending by Brazilian banks reached R$47.8 billion in 2025 and R$50.4 billion in 2026, and 84% of executives prioritize cloud migration to sustain that operational resilience.

Infrastructure as a Sustaining Layer: The Prevailing View

Although this definition is being revisited, it remains the starting point for those who design and operate financial systems. In conversations with industry specialists, infrastructure continues to be described as the layer that sustains operations, ensuring availability, resilience, and connectivity so products and services function. Here's how one interviewee put it:

"When I think about infrastructure, I think a lot about that sustaining layer: the base of the chain that needs to exist so that, on top of it, I can build products and services. It's the difference between everything that sustains and the layer the customer actually sees, or the experience they have. That visible part would hardly be possible without a robust, resilient technology layer underneath, sustaining everything." - Igor Moraes Gonçalves, Group Product Manager

Yasodara Córdova, researcher and consultant in privacy and digital identity, adds to that definition by noting that infrastructure shifts location depending on what's being protected:

"Infrastructure is the word that defines the processes that form the base for a system to function. When I talk about privacy infrastructure, for example, I'm talking about basic cryptography. When I say that biometric security infrastructure is changing, I'm talking about large tech companies that have started betting on local data storage infrastructure, processing biometrics directly on the device instead of in the cloud." - Yasodara Córdova, researcher in digital identity and privacy

How the Evolution of Fraud Is Straining That Definition

But the evolution of fraud itself has started to strain that definition. If it used to be enough to keep systems available and integrated, today operations also need to interpret context, balance risk and experience, and respond in real time to increasingly sophisticated attacks, many of them driven by artificial intelligence. In certain use cases, infrastructure stops being just a set of components that keeps the operation running and starts incorporating mechanisms capable of guiding decisions throughout the user journey.

This shift in perspective also helps explain movements observed among companies in the sector. At Certta, a Verification Intelligence Hub, for example, the expansion of the product portfolio and the company's repositioning tracked this market evolution, moving from a focus centered on antifraud technologies to a verification infrastructure proposal capable of integrating different data sources and supporting decisions across the entire digital journey.

Why a Single Verification Flow Doesn't Serve Every Segment

In practice, this shift expands infrastructure's role within antifraud operations, optimizing and combining different tools, adapting journeys to risk context, and continuously evolving based on results.

This logic allows decisions once treated as development projects to become part of routine operations. A bank can, for example, test two biometrics vendors within the same flow, compare indicators like conversion and response time, and decide which one performs better without having to migrate the entire operation. Likewise, if a vendor experiences instability, the infrastructure can automatically redirect the flow to another technology, preserving the user experience and reducing the impact on the operation.

The table below illustrates why a single verification parameter doesn't serve every segment:

But this ability to route transactions intelligently also expands another responsibility for infrastructure: ensuring that decisions made throughout the journey are transparent, auditable, and governed. As different technologies begin operating in an integrated way, and artificial intelligence agents start participating in that process, it becomes equally important to understand why a given decision was made, which signals were considered, and which rules shaped the outcome.

AI Governance: When the Risk Migrates From Whoever Executes to Whoever Configures

This shift, however, is still reaching companies unevenly. That's the argument made by Edney Souza, professor and advisor on artificial intelligence, data, and innovation. According to him, the discussion stops being purely technical once artificial intelligence starts influencing decisions that used to be exclusively human.

"An agent that screens credit applications, projects cash flow, or flags fraud risk has taken on part of a decision that used to belong to an analyst, a manager, or someone who was accountable for the outcome. When that happens, the risk migrates from whoever executes to whoever configured the system and signed off on it." - Edney Souza

The Concept of Harness in AI Agent Governance

That's precisely why Edney advocates for the concept of a harness: the set of limits, oversight mechanisms, and logs that accompany an intelligent agent before it goes into production. Rather than just developing models capable of automating tasks, the concern shifts to building structures that make it possible to monitor their behavior, review decisions, and interrupt their actions when necessary.

This principle is already starting to show up in platforms that incorporate artificial intelligence as part of their verification infrastructure. At Certta, for example, Hubby was built to act as an interpretation layer over the operation. Rather than replacing the risk analyst, it reconstructs the path behind each decision, indicating which technologies were consulted, which rules were triggered, and which evidence led to an approval or rejection. In its official launch announcement, Certta describes Hubby as a copilot specialized in fraud: it understands context and transactional behavior, and helps teams make more strategic decisions.

If the trend of embedding automated models into business decisions keeps advancing, the differentiator will lie in the ability to explain how a decision was executed, which limits were established, and which evidence supported it. That combination of optimization, transparency, and governance has been gaining traction at the industry's main forums and helping redefine the role of infrastructure in digital verification operations.

The Gap Between AI Adoption and Governance Maturity

Although this debate has gained ground within companies, the maturity to govern the use of artificial intelligence is still advancing at a different pace. Recent corporate governance research shows that while AI already plays a role in the routine of many organizations, policies to guide its use and oversee automated decisions remain the exception. In other words, technology adoption is evolving faster than the governance mechanisms built to keep up with it.

The report Governance of AI: A Critical Imperative for Today's Boards, from the Deloitte Global Boardroom Program, measures exactly that gap on a global scale: based on 700 directors and executives across 56 countries, the study shows that the share of boards that still don't include AI on their official agenda dropped from 45% to 31% between the two most recent editions of the survey, but 66% of directors still report limited or no knowledge of the topic, compared to 79% in the previous survey.

For Edney, that gap between adoption and governance helps explain why so many organizations still treat AI as a purely technological issue.

"It's the most revealing scene I've ever seen on this topic: the board that needs to demand AI governance from the company sometimes doesn't even govern the AI it uses to read the agenda." - Edney Souza

Is a Bad AI Decision a Bug, or a Failure of Governance?

For Edney, the biggest risk isn't the adoption of artificial intelligence itself, but how it gets embedded into operations.

"The bigger risk is thinking a bad AI decision is a bug, when it's actually governance that no one exercised. A language model is probabilistic, it generates the most likely response, and the same question can come out differently on a different day. That's great for drafting, summarizing, or exploring a scenario. It's dangerous when the task requires the opposite: the same result every time, with an auditable path, like a tax calculation, a financial forecast, or any decision that affects someone's rights." - Edney Souza

The discussion about infrastructure, then, stops being limited to the ability to keep systems available. It starts to incorporate another increasingly relevant attribute in digital operations: the ability to explain how decisions were built, which rules guided that process, and who is accountable for them.

That's the same reasoning Yasodara Córdova applies when she looks at the industry as a whole: the layer we call infrastructure moves as the threat evolves, and recognizing that layer correctly, at the right moment, is what separates a company that merely sustains its operation from one that actually decides with it.

Frequently Asked Questions

What does antifraud infrastructure mean?

In the traditional vocabulary of the financial sector, infrastructure describes the layer that sustains the operation: servers, availability, resilience, and connectivity so that products and services function. As fraud, artificial intelligence, and digital identity increasingly demand faster, more contextualized decisions, this infrastructure also comes to incorporate mechanisms capable of guiding decisions throughout the user journey.

Why does the definition of infrastructure change depending on the security context?

According to researcher Yasodara Córdova, infrastructure is the word that defines the processes forming the base for a system to function, and that base shifts location depending on what's being protected. In privacy, it can mean basic cryptography. In biometrics, it can mean the decision to process data locally on the device instead of in the cloud, as Google has started doing.

What is Hubby, and how does it differ from a regular chatbot?

Hubby was built to act as an interpretation layer over the operation. Rather than replacing the risk analyst, it reconstructs the path behind each decision, indicating which technologies were consulted, which rules were triggered, and which evidence led to an approval or rejection. It's a copilot specialized in fraud that understands context and transactional behavior.

What is a harness in AI agent governance?

A harness is the set of limits, oversight mechanisms, and logs that accompany an intelligent agent before it goes into production. The concern shifts from simply developing models capable of automating tasks to building structures that make it possible to monitor their behavior, review decisions, and interrupt their actions when necessary.

Why hasn't AI governance reached boardrooms yet?

According to Edney Souza, the board that needs to demand AI governance from the company sometimes doesn't even govern the AI it uses to read the agenda. Recent corporate governance research shows that technology adoption is evolving faster than the governance mechanisms built to keep up with it.

What's the difference between an AI error and a governance failure?

A language model is probabilistic, it generates the most likely response, and the same question can come out differently on a different day. That's suitable for drafting, summarizing, or exploring a scenario. It becomes dangerous when the task requires the opposite: the same result every time, with an auditable path, like a tax calculation, a financial forecast, or any decision that affects someone's rights.

Key Concepts in This Article

Verification Intelligence Hub: the term Certta uses to describe its role, integrating different data sources and supporting decisions across the entire digital journey, rather than just sustaining the operation from underneath.

Harness: the set of limits, oversight mechanisms, and logs that accompany an intelligent agent before it goes into production, making it possible to monitor its behavior, review decisions, and interrupt its actions when necessary.

AI governance: the set of policies and structures that guide the use of artificial intelligence within an organization and oversee the automated decisions it takes part in.

Probabilistic model: a type of artificial intelligence model that generates the most likely response to a question, and can produce different results for the same question at different times. Suitable for drafting, summarizing, or exploring scenarios, but risky when applied to decisions that require an auditable path.

Privacy infrastructure: according to researcher Yasodara Córdova, an example of how the concept of infrastructure shifts layers depending on context, in this case referring to the basic cryptography that protects data.

Sources

Interviews with Igor Moraes Gonçalves, Yasodara Córdova, and Edney Souza, conducted for this article.

Febraban Banking Technology Survey, with Deloitte (2025/2026).

Deloitte Global Boardroom Program, Governance of AI: A Critical Imperative for Today's Boards, 2nd edition (2026), with 700 directors and executives across 56 countries.