Garance Lequeurre, AML Product Manager
AI in AML Compliance: Where Innovation Meets Responsibility
AI in AML Compliance: Where Innovation Meets Responsibility
Much of contemporary life is about navigating the balance between old systems and new technological developments and attempting to seamlessly bridge the gap between the two. Working on our AML product here at Fourthline, it’s a tension I think about every day: how to leverage old methods that form the backbone of regulatory compliance, but which are insufficient in today’s changing world.
Rule-based detection has been the core of AML compliance since the first EU AML directive in 1991. Fixed thresholds, static alert scenarios, uniform checks: these tools were logical, auditable, and approved by regulators. However, today the landscape they were built for has changed beyond recognition. Financial flows have multiplied, KYC data, sanctions lists, UBO registers, adverse media, and relationship networks all feed into a compliance picture that is significantly more complex than it was even ten years ago. What's more, financial crime has evolved in lock step with technological progress, increasingly leveraging crypto-assets, deepfakes, and fragmented international circuits specifically designed to evade detection.
This means that compliance teams are being asked to monitor more data, across more channels, against more complex typologies than ever before. And in many cases, they're doing it with systems that were designed for a simpler problem. These legacy systems generate high volumes of false positives, and alerts that consume significant compliance resources without meaningfully improving risk detection at all.
Both the industry and regulators understand that this is a problem part of which is being addressed by the EU’s Anti-Money Laundering Regulation (AMLR). At the centre of all of this sits AI, which is both accelerating the threat of fraud while simultaneously giving companies the tools to stop it.
Where AI is changing risk detection
Rule-based systems essentially operate through pattern-matching against known scenarios. But these systems are siloed: they can’t detect what they haven't been told to look for. Nor can they talk to each other to build a complex and nuanced picture.
Machine learning can surface correlations and behavioural patterns across large, complex datasets that no fixed rule and no human reviewer could reliably catch at scale. But the more important shift is in how AI enables a risk-based approach to fighting fraud.
Instead of applying standardised alert thresholds to every customer, machine learning models can calibrate detection on an individual level, tailored to their transaction history, sector, geography, and evolving risk profile. This directly reduces one of the most resource-intensive problems in compliance: false positives. Alerts that turn out to be nothing consume enormous compliance capacity — capacity that could be directed at genuine risk.
What this means for KYC
On the KYC side, AI is reshaping what ongoing customer due diligence looks like. The traditional model, which entailed a periodic manual review of customer files, only gives you a snapshot of risk at a fixed moment in time. Continuous monitoring, by contrast, evaluates client risk profiles on an ongoing basis, flagging changes as they occur rather than waiting for a scheduled review.
This is increasingly the regulatory expectation, as the EBA (European Banking Authority) has recommended moving toward real-time, pre-execution monitoring, and the AMLR will embed ongoing due diligence obligations directly into EU law.
Learn more about AML and KYC here.
Generative AI: A shift in the compliance analyst's role
Since Generative AI began accelerating rapidly 2024, two years after the release of ChatGPT, the conversation has moved far beyond fraud detection. Today, generative AI is effectively at the heart of compliance: drafting internal procedures, synthesising document analysis, preparing control files, and even pre-drafting Suspicious Activity Reports.
Why does this matter? Well, in our field, the burden of manual investigations has always been one of the most resource-intensive parts of AML compliance. Investigating potential hits without actionable results is expensive, time-consuming, and frequently leaves compliance teams with grey areas rather than clear conclusions.
Let me be clear: generative AI won’t be removing human analysts or their invaluable judgment. Instead, it will be doing the assembly work that currently consumes so much of the analyst's time.
All this will change the infrastructure of compliance monitoring. The job will involve less data collection and processing, more supervising, interpreting, and signing off on AI-generated output. But this shift comes with its own set of demands. As our Head of Data & Machine Learning, Sam Devakumar explained, GenAI in regulated environments introduces higher uncertainty, stricter governance requirements, and a tendency for outputs to degrade over time if not carefully monitored.
Which brings us to the hardest problem AI in AML has yet to fully solve.
Responsibility and justification: The problem no one can ignore
When talking about AI in AML, efficiency gains are an important (even major) part of the picture. But they’re not the whole story. AMLR also requires companies to justify their decisions, keep extensive records, and to be able to show regulators the exact criteria behind an alert.
Many AI models simply can’t do this, at least, not yet. They produce outputs that don’t always include a fully legible reasoning chain. In a regulatory world where compliance officers must account for every decision, a black-box system is a liability. And as we've seen across GenAI deployments more broadly, the risks around explainability and auditability aren’t always present or visible from the outset. Instead, they often show up later as blockers.
From my perspective, the direction of travel is toward Responsible AI, systems designed to surface not just what they decided, but why. I mean this in terms of what a compliance officer can review, document, and defend.
A relevant regulation here that’s not getting enough attention is the EU AI Act, which came into force for high-risk AI systems on August 2, 2026. Importantly, it classifies many AML and fraud detection tools as high-risk, meaning companies must meet baseline requirements around technical documentation, automatic logging of decisions, data governance, and human oversight.
From this vantage point, the question of whether AI-assisted AML is prudent to use isn’t especially fraught: the answer is yes. The more important question is how to use it in a way that is aligned with our needs and accountable to our objectives.
What good AI in AML actually looks like
The tension I described at the start of this piece (old systems, new complexity, and the gap between them) can only be resolved when AI is deployed in a way that's honest about what it can and can't do.
The AMLR, AMLA, and the EU AI Act are converging on the same set of expectations: AI that truly enhances detection and analysis, with human judgment put into play in the moments when accountability is paramount. That's the only architecture that can actually work in a regulated environment.
At Fourthline, that's what we build toward: conclusive outcomes rather than probability scores, full audit trails, and human oversight at every decision point that matters.
Much of contemporary life is about navigating the balance between old systems and new technological developments and attempting to seamlessly bridge the gap between the two. Working on our AML product here at Fourthline, it’s a tension I think about every day: how to leverage old methods that form the backbone of regulatory compliance, but which are insufficient in today’s changing world.
Rule-based detection has been the core of AML compliance since the first EU AML directive in 1991. Fixed thresholds, static alert scenarios, uniform checks: these tools were logical, auditable, and approved by regulators. However, today the landscape they were built for has changed beyond recognition. Financial flows have multiplied, KYC data, sanctions lists, UBO registers, adverse media, and relationship networks all feed into a compliance picture that is significantly more complex than it was even ten years ago. What's more, financial crime has evolved in lock step with technological progress, increasingly leveraging crypto-assets, deepfakes, and fragmented international circuits specifically designed to evade detection.
This means that compliance teams are being asked to monitor more data, across more channels, against more complex typologies than ever before. And in many cases, they're doing it with systems that were designed for a simpler problem. These legacy systems generate high volumes of false positives, and alerts that consume significant compliance resources without meaningfully improving risk detection at all.
Both the industry and regulators understand that this is a problem part of which is being addressed by the EU’s Anti-Money Laundering Regulation (AMLR). At the centre of all of this sits AI, which is both accelerating the threat of fraud while simultaneously giving companies the tools to stop it.
Where AI is changing risk detection
Rule-based systems essentially operate through pattern-matching against known scenarios. But these systems are siloed: they can’t detect what they haven't been told to look for. Nor can they talk to each other to build a complex and nuanced picture.
Machine learning can surface correlations and behavioural patterns across large, complex datasets that no fixed rule and no human reviewer could reliably catch at scale. But the more important shift is in how AI enables a risk-based approach to fighting fraud.
Instead of applying standardised alert thresholds to every customer, machine learning models can calibrate detection on an individual level, tailored to their transaction history, sector, geography, and evolving risk profile. This directly reduces one of the most resource-intensive problems in compliance: false positives. Alerts that turn out to be nothing consume enormous compliance capacity — capacity that could be directed at genuine risk.
What this means for KYC
On the KYC side, AI is reshaping what ongoing customer due diligence looks like. The traditional model, which entailed a periodic manual review of customer files, only gives you a snapshot of risk at a fixed moment in time. Continuous monitoring, by contrast, evaluates client risk profiles on an ongoing basis, flagging changes as they occur rather than waiting for a scheduled review.
This is increasingly the regulatory expectation, as the EBA (European Banking Authority) has recommended moving toward real-time, pre-execution monitoring, and the AMLR will embed ongoing due diligence obligations directly into EU law.
Learn more about AML and KYC here.
Generative AI: A shift in the compliance analyst's role
Since Generative AI began accelerating rapidly 2024, two years after the release of ChatGPT, the conversation has moved far beyond fraud detection. Today, generative AI is effectively at the heart of compliance: drafting internal procedures, synthesising document analysis, preparing control files, and even pre-drafting Suspicious Activity Reports.
Why does this matter? Well, in our field, the burden of manual investigations has always been one of the most resource-intensive parts of AML compliance. Investigating potential hits without actionable results is expensive, time-consuming, and frequently leaves compliance teams with grey areas rather than clear conclusions.
Let me be clear: generative AI won’t be removing human analysts or their invaluable judgment. Instead, it will be doing the assembly work that currently consumes so much of the analyst's time.
All this will change the infrastructure of compliance monitoring. The job will involve less data collection and processing, more supervising, interpreting, and signing off on AI-generated output. But this shift comes with its own set of demands. As our Head of Data & Machine Learning, Sam Devakumar explained, GenAI in regulated environments introduces higher uncertainty, stricter governance requirements, and a tendency for outputs to degrade over time if not carefully monitored.
Which brings us to the hardest problem AI in AML has yet to fully solve.
Responsibility and justification: The problem no one can ignore
When talking about AI in AML, efficiency gains are an important (even major) part of the picture. But they’re not the whole story. AMLR also requires companies to justify their decisions, keep extensive records, and to be able to show regulators the exact criteria behind an alert.
Many AI models simply can’t do this, at least, not yet. They produce outputs that don’t always include a fully legible reasoning chain. In a regulatory world where compliance officers must account for every decision, a black-box system is a liability. And as we've seen across GenAI deployments more broadly, the risks around explainability and auditability aren’t always present or visible from the outset. Instead, they often show up later as blockers.
From my perspective, the direction of travel is toward Responsible AI, systems designed to surface not just what they decided, but why. I mean this in terms of what a compliance officer can review, document, and defend.
A relevant regulation here that’s not getting enough attention is the EU AI Act, which came into force for high-risk AI systems on August 2, 2026. Importantly, it classifies many AML and fraud detection tools as high-risk, meaning companies must meet baseline requirements around technical documentation, automatic logging of decisions, data governance, and human oversight.
From this vantage point, the question of whether AI-assisted AML is prudent to use isn’t especially fraught: the answer is yes. The more important question is how to use it in a way that is aligned with our needs and accountable to our objectives.
What good AI in AML actually looks like
The tension I described at the start of this piece (old systems, new complexity, and the gap between them) can only be resolved when AI is deployed in a way that's honest about what it can and can't do.
The AMLR, AMLA, and the EU AI Act are converging on the same set of expectations: AI that truly enhances detection and analysis, with human judgment put into play in the moments when accountability is paramount. That's the only architecture that can actually work in a regulated environment.
At Fourthline, that's what we build toward: conclusive outcomes rather than probability scores, full audit trails, and human oversight at every decision point that matters.
Solutions
Solutions
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.
Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.
Copyright © 2026 - Fourthline B.V. - All rights reserved.