Every AML compliance program is about to be graded on a different rubric, and most teams are not ready for it.
Four regulators moved in the same direction in the first quarter of 2026. AMLA took over EU-wide AML/CFT supervision from the EBA on January 1. In February, the FATF plenary in Mexico City shifted its country evaluations from technical compliance to measurable effectiveness. In March, FinCEN closed the largest BSA penalty ever brought against a broker-dealer, $80 million against Canaccord Genuity. Then on April 7, FinCEN and the banking agencies proposed the biggest AML overhaul in more than a decade, moving supervision from box-checking to whether your program actually works.
I have spent more than a decade in this market, and I have never seen four independent regulators line up like this in a single quarter.

The message is consistent across all four. You will be judged on whether your AML program works, not on whether it looks like it should. Good documentation will not save a program that cannot produce useful output. Technology you installed but never reviewed will be treated as a willful failure, not a technical one.
That is a problem, because the fundamentals have not moved. Global AML fines rose 417% year over year in the first half of 2025. 90% of banking leaders now rate improving financial crimes compliance as critical or important over the next 12 to 24 months. Budgets are up about 7% a year. And the false-positive rate, the hours per alert, and the integration debt are all about where they were.
This post is what is driving that gap, where the data says the market is heading, and what I would tell any AML leader to do about it now.
The false-positive tax is a symptom, not the cause
The number that defines most AML compliance programs sits in the alert queue.

53% of banks are running false-positive rates above 20%, and 26% are above 40%. The middle of the distribution is the real story: 27% sit in the 21% to 40% band, and another 21% in the 41% to 60% band. Every one of those flags triggers a manual review. 37% of banks review more than 40% of their alerts by hand. 53% spend an hour or more per alert, and a quarter spend four hours or more.
False positives get most of the attention, but they are not the root cause. When we asked AML leaders to name their single biggest transaction monitoring challenge, the top answer was integration with existing banking systems at 27%. False positives came second at 16%, and detecting sophisticated schemes third at 15%.
That reframe matters. A well-tuned rule running on siloed, stale, or incomplete data will throw false positives no matter how good the tuning is. The reason a quarter of banks still sit above a 40% false-positive rate after a decade of vendor spend is that the data underneath the detection logic is fragmented. Fix the tuning without fixing the data, and you have solved a local problem while the system keeps generating alerts.
What changed in 2026 is the cost curve. Budgets are up roughly 7% a year, enforcement is accelerating on both sides of the Atlantic, and fines jumped 417% in a single half. You cannot keep spending like that and keep routing most of every alert dollar into manual review that confirms nothing.
This is where AI lands first in AML. The economics of manual review are impossible to defend to a CFO, and AI is the only approach that handles integration and detection in the same layer.
AI agent adoption is no longer optional
When we published the AI Agents in AML whitepaper in April 2025, the open question was how fast AI would land in anti-money laundering compliance, not whether it would. The signals were already there: budget pressure, false-positive economics, and a regulatory posture that had moved from skeptical to curious. The data has caught up.
In business and entity verification, 95% of practitioners are using or planning to use AI agents. In KYC it is 83%. In AML transaction monitoring, 78%. This has moved well past experimentation.
There is clear consensus on where AI goes first. 79% of KYC teams and 76% of transaction monitoring teams name sanctions and PEP screening as the ideal task to automate. It is high volume, rule-based, and easy to audit, which makes it the safest place to start in the AML stack.
The expected payoff is just as consistent. 71% of transaction monitoring practitioners expect AI agents to speed up alert resolution and cut their investigation backlog. 63% expect better detection of complex crime patterns. 61% expect a lighter manual workload.
One divide stands out. Product teams lead AI adoption at 50%, fraud and risk teams at 36%, compliance teams at 35%. The teams closest to the regulators are the most cautious about the tools that would cut their workload the most. That tension will define the next two years.
Regulators are catching up fast. The April 7 FinCEN proposal says institutions responsibly experimenting with innovative technologies “will not incur any additional risk of enforcement actions.” That is as close to a green light for AI in AML as Treasury has ever given.
The experience premium
Almost everyone wants AI. About half worry the regulators will reject it.
72% of practitioners flag potential bias as a top concern, 67% cite a lack of explainability, and 56% worry about accuracy. Those are the same concerns regulators have been raising, which shows how closely the two groups are converging.
The split that matters comes next. Practitioners already using AI and machine learning in AML are 83% confident regulators will approve generative AI. Among those not using it, that drops to 31%.
I have started calling that 52-point gap the experience premium. Once you have actually run AI inside a regulated workflow, with audit trails, model governance, and real examiner conversations, the regulatory risk stops feeling existential. Before you have done it, it looks like the hardest problem in the market.
The institutions piloting AI now are building the evidence base that defines what “approved” looks like: model governance, audit trails, explainability frameworks. They are writing the template regulators will eventually use to grant approval. The ones waiting for clarity will inherit the standards set by the institutions that did not wait, and that gap widens every quarter.
The framework is being rewritten underneath everyone
Three regions are moving at once, each with its own philosophy, and a multinational institution has to answer to all of them.

United States. On April 7, FinCEN and the banking agencies proposed a two-pronged AML framework that judges whether a program is well designed separately from how it is implemented, reserves serious enforcement for material or systemic failures, and explicitly encourages AI. Comments close June 9. It is the most substantive shift in BSA/AML supervision in more than a decade, and it is moving quickly.
European Union. AMLA took over all AML/CFT mandates from the EBA in January and published its first multi-year Single Programming Document on February 4. Direct supervision of about 40 high-risk cross-border institutions starts in 2028, with the selection method piloted through 2026 and 2027. The single EU rulebook is not theoretical anymore.
United Kingdom. The FCA issued more than £124 million in fines in 2025, most of it tied to AML systems and controls failures, and its new non-financial misconduct rules take effect September 1, 2026. The direction is clear: more transparency, more individual accountability, more willingness to make investigations public.
For a multinational bank, that is three supervisors expecting three kinds of evidence, all graded on effectiveness instead of form. The technology underneath your AML program has to hold up in all three regulatory languages at once. A rules engine that passed examination in 2020 will not satisfy AMLA in 2028.
What I would tell any AML leader to do right now
Three things, in order.
Fix the data layer before you tune another rule. Integration is the top transaction monitoring challenge at 27%, ahead of false positives and detection. If your analysts cannot see a unified customer view across products, channels, and geographies, you are generating alerts your rules engine was never going to get right. Treat data unification as an AML investment, not an IT project. The return shows up in the alert queue.
Pilot AI agents on sanctions and PEP screening first. That is where practitioner consensus is tightest, 79% in KYC and 76% in transaction monitoring, and where the audit trail is cleanest. Regulatory tolerance is now explicit: the April 7 FinCEN proposal says institutions responsibly experimenting will not take on extra enforcement risk. Start on proven ground, build the governance muscle, then expand. Every quarter you wait, the experience premium grows for the institutions that started.
Buy for platform depth, not point solutions. 67% of banks tell us they want a platform, either one-stop or AML-focused. Only 11% want best-in-class point tools. 41% expect to switch a transaction monitoring vendor in the next 12 months, and the same share expect to add one. The institutions that win the next cycle are buying for explainability, auditability, and multi-jurisdictional defensibility, not just detection accuracy. Rewrite your vendor criteria before your next RFP, not after.
I have watched a lot of compliance markets change, and this one is moving faster than any of them. The fines will keep coming, the frameworks will keep shifting, and the math on manual review keeps getting worse. Your AML program is going to change. The only real choice is whether it changes on your timeline or a regulator’s.
Want the data behind this analysis? Liminal Command is the intelligence layer AML leaders use to track vendor capabilities, regulatory shifts, and market signals in one place. For the underlying research, see the Liminal Index for AML Transaction Monitoring.
Frequently asked questions
How are AML compliance programs evaluated in 2026?
Regulators in the US, EU, and UK have shifted from rule-based box-checking to effectiveness-based evaluation. AMLA took over EU AML/CFT supervision in January 2026, FATF moved country evaluations toward measurable outcomes in February, and FinCEN proposed a two-pronged framework in April that grades programs on whether they actually detect financial crime.
What is a typical false-positive rate for AML transaction monitoring?
53% of banks run false-positive rates above 20%, and 26% are above 40%. Every alert flagged triggers a manual review, and 37% of banks review more than 40% of their alerts by hand, which makes false positives the single largest cost driver in most AML programs.
Are banks allowed to use AI in AML compliance?
Yes, and regulators are now actively encouraging it. FinCEN’s April 7, 2026 proposal says institutions responsibly experimenting with innovative technologies will not incur additional risk of enforcement actions, and the UK FCA has issued more than £316 million in fines in 2026 for outdated systems and controls failures, not for AI adoption.
How many AML teams are using AI agents?
95% of practitioners are using or planning to use AI agents in compliance workflows. Adoption is highest in KYC at 83% and transaction monitoring at 78%, and 79% of KYC teams and 76% of transaction monitoring teams ran sanctions and PEP screening as their first agent deployment.
Why do regulators reject some AI-based AML systems?
72% of practitioners flag potential bias as a top concern, 67% cite lack of explainability, and 56% worry about accuracy. Regulators approve AI that operates inside a governed workflow with audit trails, model governance, and real examiner conversations. This is the experience premium: institutions that have run AI in production hold a 52-point approval advantage over those piloting it.





