What AI is doing to financial-crime compliance
Where generative and agentic AI are breaking KYC and AML controls, and where they're rebuilding them. Worked up from the primary sources, not from summaries of them.
Try the AI Prompt Builder →AML Screening Console
A transaction-monitoring queue over 6.3 million mobile-money transactions. Confirmed fraud by transaction type, volume across 743 hourly steps, highest-risk cases surfaced first, and the top 500 exportable for review. Runs in the browser with nothing to install.
Transaction Monitoring Is Not in Annex III
As of today, every high-risk AI system in production has to meet the EU AI Act's heaviest obligations. Look at what Annex III actually names on the financial services side, then look at what the FCA has spent five years fining banks for, and the two lists barely overlap.
The Firm With the Obligation Is the One Without the Context
In an agent-mediated payment, the bank sees an instruction and the agent platform knows why it exists. Anti-money-laundering duties attach to the party moving the money, which for thirty years has also been the party who decided to move it. Agentic commerce quietly separates those two things.
Everyone Reads the £44 Million Fine. Nobody Reads the £5,500 Ones.
A year of UK anti-money-laundering enforcement, with the control failure named against each case. The pattern that emerges is not the one the industry talks about: by volume, most enforcement is not about firms with bad controls. It is about firms nobody was supervising at all.
Fifty Thousand Wires Nobody Was Watching
FinCEN's record penalty against UBS Financial Services is being read as another transaction monitoring failure, which it is. The specific finding underneath it describes something narrower and considerably more uncomfortable: tens of thousands of payments that the monitoring system never saw at all.
I Did Age Verification by Hand. The Internet Is About to Learn What That's Actually Like
Every argument about online age checks treats identity verification as a technical problem waiting for a technical answer. It isn't. Behind a betting shop counter the check was never the hard part, and the part that was hard is the part nobody is building for.
Identity Was Never the Hard Part of Agent Payments
By April this year every major payment network had shipped or unveiled a Know Your Agent primitive, so that a merchant can cryptographically verify which AI agent is asking before a transaction settles. It is a good answer to a question that was never the hard one.
The Agent Did the EDD. Who Signs It?
Agentic AI can already run adverse media research, draft EDD narratives and triage alerts with no human touching the middle steps. The technology changes fast. The accountability question doesn't move at all, and most teams haven't worked out where it actually sits.
The AI Act Exempts Fraud Detection and Not AML
Two AI systems can look almost identical, scoring a transaction, flagging it, routing it for review, and still sit in completely different regulatory categories under the EU AI Act, for a reason that has nothing to do with how they work and everything to do with what they're labelled for.
Two Regulators, Same Technology, Opposite Instruments
No AI-specific rulebook, no bespoke licensing regime: the FCA has said twice now that it isn't planning one. That reads as a deliberate bet rather than regulatory neglect, and it puts more weight on the judgment a compliance team already has to exercise.
Cyclone Ditwah and the Control Gaps a Disaster Opens
Cyclone Ditwah displaced over two million people and triggered a multi-billion-dollar relief effort. Large-scale disasters test more than emergency response. They test every assumption a KYC/AML programme makes about identity, cash and oversight.
How I Work a Suspected Deepfake Onboarding Case
Deepfake selfies, GAN-forged IDs and synthetic identities are already inside the funnel. Here's a repeatable method for catching them before they clear KYC, and for building a defensible case file when they don't.
The Fraud With No Victim to Call
It isn't stolen identity and it isn't fully fake identity. It's both, blended, and aged like a real customer. Here's why that combination breaks conventional fraud detection.
KYC, CDD and EDD, in the Right Order
The three terms get used interchangeably in job postings and casually in conversation. In practice they're a hierarchy, and knowing where one ends and the next begins is what separates a checklist analyst from a risk-based one.
Writing a SAR the UKFIU Can Actually Use
A suspicious activity report that reads as a summary of a gut feeling doesn't hold up to regulatory review. One that reads as a chain of specific, dated observations does. The difference is almost entirely structural.
What Layering Looks Like When Someone Has Built It Well
Placement, layering and integration is the model everyone memorises for the exam. Shell company structures are where 'layering' stops being an abstraction and becomes a genuinely hard research problem.
New pieces by email
One email when something new goes up
No schedule, no digest, no marketing. A piece goes up roughly every couple of weeks and you get one line and a link. Your address is stored by the form handler and used for nothing else. Unsubscribe by replying once.