The Typology Files

What AI is doing to financial-crime compliance

Where generative and agentic AI are breaking KYC and AML controls, and where they're rebuilding them. Worked up from the primary sources, not from summaries of them.

Try the AI Prompt Builder →

Built, not written about

AML Screening Console

A transaction-monitoring queue over 6.3 million mobile-money transactions. Confirmed fraud by transaction type, volume across 743 hourly steps, highest-risk cases surfaced first, and the top 500 exportable for review. Runs in the browser with nothing to install.

AI & Compliance

Transaction Monitoring Is Not in Annex III

As of today, every high-risk AI system in production has to meet the EU AI Act's heaviest obligations. Look at what Annex III actually names on the financial services side, then look at what the FCA has spent five years fining banks for, and the two lists barely overlap.

Aug 3, 20268 min read
AI & Compliance

The Firm With the Obligation Is the One Without the Context

In an agent-mediated payment, the bank sees an instruction and the agent platform knows why it exists. Anti-money-laundering duties attach to the party moving the money, which for thirty years has also been the party who decided to move it. Agentic commerce quietly separates those two things.

Sep 4, 20268 min read
Regulatory Update

Everyone Reads the £44 Million Fine. Nobody Reads the £5,500 Ones.

A year of UK anti-money-laundering enforcement, with the control failure named against each case. The pattern that emerges is not the one the industry talks about: by volume, most enforcement is not about firms with bad controls. It is about firms nobody was supervising at all.

Aug 29, 20269 min read
AI & Compliance

Fifty Thousand Wires Nobody Was Watching

FinCEN's record penalty against UBS Financial Services is being read as another transaction monitoring failure, which it is. The specific finding underneath it describes something narrower and considerably more uncomfortable: tens of thousands of payments that the monitoring system never saw at all.

Aug 24, 20268 min read
Regulatory Update

I Did Age Verification by Hand. The Internet Is About to Learn What That's Actually Like

Every argument about online age checks treats identity verification as a technical problem waiting for a technical answer. It isn't. Behind a betting shop counter the check was never the hard part, and the part that was hard is the part nobody is building for.

Aug 12, 20267 min read
AI & Compliance

Identity Was Never the Hard Part of Agent Payments

By April this year every major payment network had shipped or unveiled a Know Your Agent primitive, so that a merchant can cryptographically verify which AI agent is asking before a transaction settles. It is a good answer to a question that was never the hard one.

Aug 4, 20269 min read
AI & Compliance

The Agent Did the EDD. Who Signs It?

Agentic AI can already run adverse media research, draft EDD narratives and triage alerts with no human touching the middle steps. The technology changes fast. The accountability question doesn't move at all, and most teams haven't worked out where it actually sits.

Jul 28, 202610 min read
AI & Compliance

The AI Act Exempts Fraud Detection and Not AML

Two AI systems can look almost identical, scoring a transaction, flagging it, routing it for review, and still sit in completely different regulatory categories under the EU AI Act, for a reason that has nothing to do with how they work and everything to do with what they're labelled for.

Jul 26, 20269 min read
AI & Compliance

Two Regulators, Same Technology, Opposite Instruments

No AI-specific rulebook, no bespoke licensing regime: the FCA has said twice now that it isn't planning one. That reads as a deliberate bet rather than regulatory neglect, and it puts more weight on the judgment a compliance team already has to exercise.

Jul 24, 20268 min read
Regulatory Update

Cyclone Ditwah and the Control Gaps a Disaster Opens

Cyclone Ditwah displaced over two million people and triggered a multi-billion-dollar relief effort. Large-scale disasters test more than emergency response. They test every assumption a KYC/AML programme makes about identity, cash and oversight.

Jul 22, 202611 min read
Fraud Detection

How I Work a Suspected Deepfake Onboarding Case

Deepfake selfies, GAN-forged IDs and synthetic identities are already inside the funnel. Here's a repeatable method for catching them before they clear KYC, and for building a defensible case file when they don't.

Jul 18, 202613 min read
Fraud Detection

The Fraud With No Victim to Call

It isn't stolen identity and it isn't fully fake identity. It's both, blended, and aged like a real customer. Here's why that combination breaks conventional fraud detection.

Jun 30, 20269 min read
Fundamentals

KYC, CDD and EDD, in the Right Order

The three terms get used interchangeably in job postings and casually in conversation. In practice they're a hierarchy, and knowing where one ends and the next begins is what separates a checklist analyst from a risk-based one.

Jun 12, 20268 min read
Regulatory Update

Writing a SAR the UKFIU Can Actually Use

A suspicious activity report that reads as a summary of a gut feeling doesn't hold up to regulatory review. One that reads as a chain of specific, dated observations does. The difference is almost entirely structural.

May 22, 20268 min read
Regulatory Update

What Layering Looks Like When Someone Has Built It Well

Placement, layering and integration is the model everyone memorises for the exam. Shell company structures are where 'layering' stops being an abstraction and becomes a genuinely hard research problem.

Apr 15, 202610 min read

New pieces by email

One email when something new goes up

No schedule, no digest, no marketing. A piece goes up roughly every couple of weeks and you get one line and a link. Your address is stored by the form handler and used for nothing else. Unsubscribe by replying once.