AI arms race reshapes global AML: regulators demand 24/7 vigilance as crime gets smarter

Finance Magnates

The gist

Regulators worldwide are forcing banks to wage a 24/7 AI arms race against ever-smarter financial crime, demanding continuous monitoring and instant accountability as criminals—and compliance—go real-time.

What to know

  • By 2026, AML checks have shifted from periodic reviews to persistent, real-time monitoring across AI, cloud, and external data, with regulators like the OCC and FCA requiring auditable, decision-level oversight.
  • AI slashes false positives by over 50% (just ask Australia Post), but also turbocharges crypto crime and complex laundering, with Australia alone facing $87.39 billion AUD in losses and most of it unrecoverable.
  • Institutions are breaking down AML, fraud, and KYC silos—spurred by new laws like South Africa's COFI Bill and Asia-Pacific's crypto challenges—but must overcome legacy tech and fractured compliance cultures.

Compliance Goes Real-Time

Regulators now demand continuous, auditable oversight that maps every AI and data dependency, forcing banks to abandon episodic checks for persistent, decision-level accountability.

By early 2026, AML compliance has fundamentally shifted from the traditional model of periodic risk assessments to a continuous, real-time monitoring paradigm embedded within transaction and risk systems. Regulators such as the OCC, FDIC, and Federal Reserve have issued interagency guidance emphasizing ongoing validation and governance controls that extend beyond static vendor reviews to encompass interconnected risks across AI models, cloud providers, and external data services. This integrated oversight framework demands institutions map and monitor dependencies persistently, reflecting a move toward persistent, auditable decision-level accountability rather than episodic compliance checks.

Traditional AML frameworks relying on six-monthly or annual reviews are increasingly viewed as obsolete, as they fail to capture dynamic risk changes such as sudden sanctions or geopolitical shifts that alter client risk profiles without triggering immediate reviews. Experts like Kirketerp-Møller argue that continuous monitoring enabled by AI and automation allows compliance teams to focus on genuine human judgment areas while automating routine assessments, thereby enhancing efficiency and effectiveness. This evolution aligns with FATF and Basel Committee expectations for risk-based, outcomes-focused compliance that demonstrates reasoned, proportionate, and consistent decision-making.

AI-powered continuous monitoring transforms AML oversight from backward-looking periodic examinations—traditionally conducted every 12 to 18 months by regulators such as the FDIC and Fed—into persistent, real-time risk detection across diverse data sources including SEC filings, interbank exposures, and social sentiment. This shift enables institutions and regulators to identify emerging systemic risks earlier, akin to continuous vital monitoring rather than an annual physical, thereby improving the timeliness and precision of regulatory focus and risk mitigation.

Regulators worldwide, including the FCA and FATF, now mandate continuous, documented, and risk-proportionate AML compliance throughout the entire client lifecycle, moving decisively beyond periodic reviews. Enforcement actions against banks like Nationwide, Starling, and Monzo underscore the high stakes of systemic compliance failures. Integrated platforms such as KYC360 exemplify this new standard by linking onboarding, screening, enhanced due diligence, and ongoing monitoring into a single, auditable system with event-driven workflows that automatically update risk profiles upon trigger events, thereby eliminating data silos and supporting real-time supervisory visibility.

Sources
PYMNTSFinTech GlobalFast CompanyFinTech GlobalFinTech Global

AI: Ally and Adversary

AI slashes false positives but also fuels a surge in sophisticated crypto crime, leaving compliance teams overwhelmed as criminals weaponize automation faster than defenses can adapt.

By mid-2026, AI has emerged as a double-edged sword in AML compliance, dramatically enhancing detection capabilities while simultaneously empowering criminals to execute more sophisticated financial crimes. AUSTRAC and industry leaders like Sumsub and Elliptic have highlighted how AI accelerates identity fabrication, transaction structuring, and laundering automation, particularly in crypto and decentralized finance, outpacing traditional compliance frameworks and creating an arms race that strains resources. For example, Australia Post’s AI-driven AML system cut false positives by over 50% and increased suspicious activity detection by 135%, yet Napier AI’s AML Index estimates only $2.65 billion of the $87.39 billion lost to money laundering in 2024-2025 could be recovered, underscoring the persistent gap between AI’s promise and criminals’ evolving tactics.

The rapid proliferation of AI-driven financial crime in the crypto sector has forced compliance teams to rethink their strategies amid an overwhelming surge in alert volumes and complexity. As Simone Maini of Elliptic warns, the surge in AI trading is pushing existing AML systems to their breaking point, while AUSTRAC’s enforcement actions against major players like Binance Australia and Revolut Australia signal intensified scrutiny. However, legacy AML infrastructures, reliant on batch processing and static rules, hinder real-time decision-making and risk superficial compliance progress, emphasizing the need for transformational technological upgrades rather than incremental fixes.

Despite widespread recognition of cryptocurrency’s role in financial crime, there remains a critical underutilization of crypto tracing tools among cyber defenders and compliance teams, limiting their ability to attribute, disrupt, and analyze illicit networks effectively. As one expert noted, while nearly everyone encounters cryptocurrency in cyber threat intelligence, few have access to or employ tracing tools, leaving organizations vulnerable even if they do not directly handle crypto. This gap highlights the urgent need to integrate advanced crypto analysis into AML frameworks to keep pace with threat actors exploiting AI and virtual assets.

Australia’s regulatory environment is broadly supportive of AI adoption in AML compliance, positioning the country as a leader in this space. However, the primary barrier remains outdated institutional technology that lacks the modern, transparent, and configurable foundations necessary for effective AI integration. AUSTRAC’s upcoming expansion to regulate up to 90,000 new entities by July 2024 reflects heightened vigilance on AI and crypto risks, but without substantial infrastructure modernization, institutions risk obscuring rather than solving underlying AML challenges.

Sources
CryptoNews.netPYMNTSFMFinTech GlobalCryptoNews.netFinTech Global

Sanctions Drive Systemic Overhaul

The FCA’s crackdown on fragmented controls and weak screening is pushing firms toward integrated, end-to-end compliance systems that can withstand mounting geopolitical and regulatory complexity.

By mid-2026, the FCA's May report underscored how AML compliance complexity has surged due to the expanding scope of sanctions regimes and the broadening of regulated populations to sectors like payments, retail banking, wholesale financial markets, insurance, and digital assets. This regulatory intensification demands firms maintain robust, end-to-end systems that integrate onboarding, screening, monitoring, escalation, and reporting to effectively prevent and respond to sanctions breaches, reflecting a shift from siloed controls to holistic, life-cycle compliance processes.

Heightened supervisory scrutiny remains a persistent challenge, with the FCA identifying recurrent weaknesses in firms’ sanctions controls—ranging from inadequate screening systems and alert management to failures in customer due diligence and asset freeze implementation. These vulnerabilities are compounded by jurisdiction-specific complexities, notably the predominance of Russian sanctions breaches alongside emerging risks tied to Iran, North Korea, and Libya, compelling firms to tailor compliance processes to nuanced geopolitical landscapes.

The FCA further highlights the critical need for integrated, risk-proportionate compliance frameworks that blend internal intelligence with external data sources, especially as reliance on third-party vendors introduces additional risks related to data quality and accuracy. This integration is vital amid fragmented global regulations and escalating supervisory expectations, where cross-border inconsistencies in scope, thresholds, and enforcement require firms to adopt continuous, evidence-backed governance with clear audit trails demonstrating jurisdiction-specific compliance decisions.

A widening gap between the accelerating pace of regulatory change and traditional compliance workflows is creating significant operational risks, emphasizing the necessity for rapid access to reliable, cited regulatory intelligence and technology capable of nuanced, jurisdiction-specific policy assessments. Effective AML programs now depend on the triad of timely regulatory updates, practical internal policy testing against external mandates, and dynamic sanctions intelligence that can keep pace with evolving lists and overlapping jurisdictions.

Sources

Silos Shatter, But Not Expertise

Financial institutions are unifying AML, fraud, and KYC intelligence to outpace criminals exploiting organizational gaps—yet struggle to balance synergy with the need for deep specialist focus.

By mid-2026, a clear momentum had emerged among financial institutions to break down traditional silos separating AML, fraud, and KYC functions, driven by the recognition that criminals exploit gaps between these areas. Scott Nice of Label highlights how shared intelligence across these domains can uncover patterns invisible when teams operate independently, particularly in combating scams and authorized push payment fraud, where victim feedback loops necessitate close coordination. However, this convergence is not about erasing specialist expertise but rather about creating a connected intelligence layer that enables more holistic risk management.

Despite the acknowledged benefits, significant barriers remain in operational, technological, and organizational realms, slowing integration efforts. Taami Tamkivi of Salv points out that the majority of companies remain entrenched in siloed structures, with only a vocal minority advocating for unification. Moreover, there is a delicate balance to strike: while focusing AML efforts on faster-return areas like scams offers synergy, it risks neglecting complex, large-scale laundering schemes such as the Swedbank scandal, which lack obvious victim signals and require deep, sustained investigation.

Technological advances and evolving financial crime tactics have intensified calls to rethink fragmented compliance models, as Jon Elvin notes that digital behaviors and cross-channel signals defy traditional, isolated controls. Institutions are increasingly adopting modular, AI-driven architectures over monolithic platforms to enhance agility and responsiveness. Yet, Elvin cautions that there is no one-size-fits-all solution; both integrated and separated organizational models can succeed or fail depending on execution, underscoring the complexity of designing effective compliance frameworks in a rapidly changing landscape.

South Africa’s COFI Bill exemplifies regulatory efforts to dismantle siloed compliance by mandating unified frameworks that integrate AML, fraud, and prudential risk functions into coordinated workflows. This legislative push envisions real-time monitoring and intelligence sharing among firms, regulators, and law enforcement to mirror the collaborative nature of criminal networks. However, as highlighted at the FSCA 2026 conference, most firms currently lack the digital infrastructure COFI assumes—such as integrated KYC and AML workflows, explainable AI models, and scalable cloud platforms—making successful implementation contingent on significant technological and cultural transformation.

Sources
FinTech GlobalFinTech GlobalFinTech Global

Legacy Tech Hits Breaking Point

Traditional AML systems are buckling under fragmented research and jurisdictional complexity, driving a shift to modular, AI-powered platforms that promise agility without sacrificing human judgment.

By mid-2026, it became clear that traditional AML frameworks, designed for a less complex era, were buckling under the weight of siloed functions and fragmented solutions that hindered effective detection of sophisticated financial crime. Firms grappled with duplicated efforts across AML, fraud, and KYC teams operating independently, which not only missed interconnected risk patterns but also imposed unnecessary burdens on both customers and compliance staff. This operational fragmentation spurred a nascent but growing adoption of convergence strategies and integrated intelligence platforms aimed at breaking down data silos and fostering a shared understanding of risk without sacrificing specialist expertise.

Technological innovation, particularly the rise of AI and modular RegTech platforms, is driving a fundamental rethinking of AML compliance architectures. Institutions are moving away from monolithic systems toward flexible, event-driven platforms like KYC360 that unify onboarding, screening, enhanced due diligence, and monitoring into a single auditable environment. These platforms not only reduce false positives and integrate multiple data vendors but also support explainable AI governance, enabling firms to maintain robust specialist decision-making while responding swiftly to evolving regulatory demands and complex, network-driven financial crime patterns.

The operational challenges extend beyond technology to the very nature of regulatory compliance research, which remains fragmented and burdensome due to divergent AML requirements across jurisdictions like the UAE, UK, and EU. Despite shared FATF frameworks, significant differences in detailed obligations force compliance teams to conduct parallel research exercises, often relying on inconsistent and scattered regulatory sources. This regulatory complexity, combined with escalating supervisory expectations for clear audit trails and jurisdiction-specific evidence, strains traditional manual workflows and underscores the urgent need for domain-focused platforms such as Sherlocq that accelerate regulatory intelligence retrieval without replacing human judgment.

Data silos remain a pervasive operational bottleneck, particularly highlighted by AML teams in Australia and Asia-Pacific, where disconnected systems impede the integration of transaction records, trade documents, and counterparty data essential for detecting complex, network-driven financial crime such as trade-based money laundering. Rohit Mittal of LexisNexis Risk Solutions emphasizes that risk often resides in the connections between entities, which siloed data cannot reveal. This regional challenge reflects a broader industry imperative to develop integrated data platforms and collaborative intelligence frameworks that can dynamically assess multiplicative risk interactions across jurisdictions, channels, and ownership structures.

Sources
FinTech GlobalFinTech GlobalFinTech GlobalFinTech GlobalFinTech GlobalFinTech Global

Global Shakeup: Australia, Africa, Asia

Australia’s AML expansion, South Africa’s COFI Bill, and Asia-Pacific’s crypto surge are forcing mass digital transformation as legacy systems and disconnected data threaten to undermine compliance on every front.

Australia’s AML landscape is rapidly evolving under the dual pressures of AI-driven financial crime and a sweeping regulatory expansion. By mid-2026, AUSTRAC has spotlighted AI as a transformative risk, with criminals leveraging it to fabricate identities, automate laundering techniques, and scale illicit operations algorithmically—shifting money laundering into a 24/7 industrialized activity. This surge in complexity coincides with the July 2024 expansion of Australia’s AML/CTF regime, which brought 80,000 to 90,000 new entities such as real estate professionals and virtual asset providers under compliance obligations, forcing many businesses to scramble for effective programs amid persistent infrastructure challenges like data silos and disconnected systems. Despite AI-powered detection improvements—Australia Post’s system cut false positives by over 50% and boosted suspicious activity detection by 135%—the country still faces an estimated $87.39 billion AUD loss to money laundering in 2024-25, underscoring the urgent need for modernized, integrated AML frameworks beyond legacy batch-processing platforms.

South Africa is tackling its fragmented AML compliance environment through the phased rollout of the Conduct of Financial Institutions (COFI) Bill, which aims to unify siloed regulatory frameworks into a cohesive system. Building on the 2017 Financial Sector Regulation Act and the Twin Peaks model, COFI mandates real-time monitoring and stricter governance, requiring boards to provide audit trails evidencing AML, fraud, and conduct controls rather than relying on periodic reporting. This legislative overhaul fosters collaborative intelligence sharing among financial institutions, regulators, and law enforcement to mirror the coordinated nature of criminal networks. However, successful implementation hinges on digital transformation and RegTech adoption, including integrated AML workflows, explainable AI models, and scalable cloud infrastructure to create a single source of truth for automated reporting to the Financial Intelligence Centre.

Across the Asia-Pacific region, AML compliance challenges vary widely, shaped by differing market maturities and regulatory environments. Nearly 60% of practitioners identify cryptocurrency and mule or scam flows as the most difficult typologies to manage, particularly in high-volume payment markets like the Philippines and Malaysia, where transaction fraud and crypto risks dominate. In contrast, mature financial centers such as Singapore and Australia grapple primarily with beneficial ownership opacity, sanctions evasion, and fragmented internal data systems, with 70% of Singapore respondents flagging these issues. Hong Kong presents a dual risk profile balancing crypto compliance challenges (43%) with beneficial ownership concerns (29%). A pervasive operational weakness across the region is limited visibility caused by disconnected systems and data silos, cited by 27% of respondents, which impedes detection of increasingly network-driven financial crime and underscores the critical need for collaborative intelligence and integrated data views to uncover complex cross-border schemes.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.