Paris 23:55
New York 17:55
London 22:55
Blogkyb

AI in AML compliance: what regulators actually require and from when

Vasco Alexandre

Vasco Alexandre

September 29, 2026

AI in AML compliance: what regulators actually require and from when

No regulator forbids AI in KYC and AML. What they require is narrower and harder: a person who meaningfully intervenes in decisions about a customer, an explanation the customer can obtain and staff who understand the tools they use.

Most of it is binding law with a date, and the date that matters most for AML teams is not in the AI Act. It is 10 July 2027, when Article 76(5) of the AMLR, the EU Anti-Money Laundering Regulation, starts to apply.

The hard part is proving that the human in the loop is not a rubber stamp. On Dotfile over the past year, when our AI marked a screening hit as a false positive, the analyst who closed it overturned it about 1 in 1,600 times. Is that an accurate model, or a team that stopped looking? The rules below are built to make you answer that question.

What is binding, and what is guidance?

SourceTextStatusAppliesWhat it means for KYC and AML
EUAI Act, Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744BindingAI literacy since 2 February 2025; transparency since 2 August 2026 (2 December 2026 for marking content from systems already on the market); Annex III high-risk from 2 December 2027KYC and AML are not high-risk as such; biometric identification and credit scoring can be
EUAMLR, Regulation (EU) 2024/1624, Article 76(5)Binding10 July 2027Automated or AI decisions allowed, with meaningful human intervention and a right to an explanation
EUGDPR, Article 22, Regulation (EU) 2016/679BindingSince 25 May 2018No decision "based solely on automated processing" with significant effects, unless an exception applies
EUEBA Guidelines on remote customer onboarding (EBA/GL/2022/15)Guidance, comply or explainSince 2 October 2023Say which steps are automated and which need a person; test automated onboarding with samples
EUAMLA, Single Programming Document 2026-2028Work programmeFebruary 2026AMLA "will guide the private sector in the responsible use of AI"
UKFCA, AI and the FCA: our approachStatementSince 2024No AI-specific rules; existing ones (SYSC, Consumer Duty, SM&CR) apply
GlobalFATF, Opportunities and challenges of new technologies for AML/CFTGuidanceJuly 2021Technology can make AML "faster, cheaper and more effective"; explainability is a key challenge

Is KYC or AML software high-risk under the EU AI Act?

Not as such. Annex III, the list of high-risk uses, does not mention customer due diligence, sanctions screening or transaction monitoring. Two entries come close, and both are drawn carefully:

  • Biometrics. "Remote biometric identification systems" are high-risk, but the entry excludes "biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be" (Annex III, point 1(a)). Matching a selfie to the ID document in onboarding is verification, not identification.
  • Credit. Evaluating the creditworthiness of natural persons is high-risk, "with the exception of AI systems used for the purpose of detecting financial fraud" (Annex III, point 5(b)). A lender scoring sole traders is in; a fraud model is out.

The AI Act mentions anti-money laundering in recital 59, and only for financial intelligence units, not banks. So for most AML tools the AI Act's heavy obligations (risk management, logging, human oversight under Article 14) do not apply. What does apply to every deployer is Article 4 on AI literacy, softened by the 2026 amendment to "take measures to support the development of AI literacy" of staff, and Article 50's transparency duties for chatbots and generated content, in force since 2 August 2026. The Omnibus kept that date, with one grace period: systems already on the market before it have until 2 December 2026 to mark generated content as such (Article 50(2)).

The dates moved in 2026. Regulation (EU) 2026/1744, the "Digital Omnibus on AI", in force since 27 July 2026, pushed Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and high-risk AI in regulated products to 2 August 2028.

What does the AMLR say about AI?

This is the binding rule for AML teams, and it is short. From 10 July 2027, an obliged entity "may adopt decisions resulting from automated processes, including profiling, [...] or from processes involving AI systems", provided that (Article 76(5), Regulation (EU) 2024/1624):

  1. the data used comes from customer due diligence;
  2. any decision to enter, refuse or maintain a business relationship, or to raise or lower the due diligence applied, "is subject to meaningful human intervention to ensure the accuracy and appropriateness of such a decision";
  3. the customer "may obtain an explanation of the decision reached [...] and may challenge that decision", except for suspicious transaction reports.

Add Article 18(3): the customer's risk profile and the decision to enter the relationship are among the tasks that can never be outsourced. A vendor's model can prepare the decision. Your team owns it. Our AMLR 2027 guide covers the rest of the regulation, and the AML regulatory calendar every date around it.

What do the EBA, AMLA, the FCA and the FATF say?

  • EBA. The remote onboarding guidelines ask firms to set out "which steps are fully autonomized and which steps require human intervention" (paragraph 9(c)) and to monitor automated solutions with alerts, sample testing and manual reviews (paragraphs 20 and 21). Its November 2025 AI Act factsheet found "no significant contradictions" with banking law.
  • [AMLA](https://www.dotfile.com/resources/amla-eu-aml-authority). Its 2026-2028 programme commits to guiding the private sector on responsible AI and to "safe AI governance" inside the authority, naming "model drift and bias". No AI guidance for obliged entities yet.
  • FCA. "We do not plan to introduce extra regulations for AI." Its AI Live Testing second cohort, announced in April 2026, includes AML detection and KYC use cases.
  • FATF. Beyond the 2021 report, its horizon scan on AI and deepfakes warns that deepfakes "can be used to bypass traditional AML/CFT/CPF controls" and encourages "advanced forms of 'liveness checks'".

A worked example: one onboarding, four AI uses, three regimes

A payment institution in Lyon onboards a sole trader who also asks for a small credit line.

AI useAI ActAMLR and GDPR
Match the selfie to the ID documentBiometric verification, excluded from Annex IIIPart of due diligence
Pre-classify screening hits as likely false positivesNot in Annex IIIA person decides; from July 2027, meaningful intervention
Auto-reject the application when the file is incompleteNot in Annex IIIA solely automated refusal engages GDPR Article 22 today and Article 76(5) from July 2027
Score the trader's creditworthiness for the credit lineHigh-risk, Annex III point 5(b), from 2 December 2027Separate from AML

Only the last use is high-risk. The third is the one most teams have missed.

How do you prove the human intervention is meaningful?

By measuring it. "Meaningful" is the AMLR's word; the AI Act names the failure: "automation bias", the tendency of "automatically relying or over-relying" on a system's output (Article 14(4)(b)). That article binds high-risk systems only, but it is the clearest description of what a supervisor will look for.

That 1 in 1,600 is the question from the introduction. You tell the two answers apart with three things:

  1. An explanation per decision, written by the system, that the analyst can check against the hit.
  2. Blind sampling: a share of hits reviewed without the AI's suggestion, to compare.
  3. A tracked override rate, by analyst and by list type, reviewed by someone senior.

Based on AML screening hits analysed by AI on Dotfile over the past year; aggregates only.

Frequently asked questions

Is AI allowed in AML compliance?

Yes. The AMLR explicitly allows decisions from automated processes and AI systems, with meaningful human intervention and a right to an explanation (Article 76(5), from 10 July 2027).

Is KYC and AML software high-risk under the EU AI Act?

No, not as such. Annex III does not list customer due diligence, sanctions screening or transaction monitoring; remote biometric identification and creditworthiness scoring of natural persons are the exceptions. AI literacy (Article 4) still applies to every deployer, and so does transparency (Article 50) if you run a chatbot or generate content.

When do the AI Act's high-risk rules apply?

From 2 December 2027 for Annex III systems and 2 August 2028 for AI in regulated products, after Regulation (EU) 2026/1744.

Does the FCA have specific AI rules?

No. It applies its existing rules, including the Consumer Duty and the Senior Managers and Certification Regime, to AI.

Where Dotfile fits

Dotfile's AML AI Assistant pre-qualifies screening hits and writes a rationale for each, and reviewers validate its recommendations before approval. Autonomy reviews checks under AI policies each team writes, and every decision carries a full reasoning report on the case. Who decided what, and when, stays in the case history. If your analysts already paste case data into chat tools, read why a governed door beats a ban. For the full KYB picture, read what is KYB.

Ready for Anywhere?

Verify any business, enter any market, defend every decision. Every signal orchestrated, every decision traceable, from one platform.

Book a demo