BankThink

Adding AI to money-laundering compliance introduces new risks

  • Key insight: In a new paradigm of anti-money-laundering compliance, success increasingly depends not on obtaining information faster, but on recognizing when machine-generated intelligence should not be trusted.
  • Supporting data: Industry estimates suggest that generative AI could improve productivity across a wide range of banking functions by approximately 20% to 30%.
  • What's at stake: Unlike traditional analytical models, large language models can produce outputs that appear technically accurate, professionally written and highly persuasive while containing factual errors or even entirely fabricated information.

Artificial intelligence has rapidly become one of the defining strategic priorities for the U.S. banking industry. In a remarkably short period, the majority of U.S. banks announced ambitious plans to integrate generative AI into their long-term business strategy despite the absence of any regulatory requirement to do so. Regulators, however, have adopted a noticeably more cautious approach. That distinction became particularly evident in April 2026, when the OCC, Federal Reserve and FDIC clarified that their updated interagency guidance on model risk management does not apply to generative AI, recognizing that the technology presents challenges extending beyond the scope of traditional predictive models.

Processing Content

For banks, the economic rationale is straightforward. Industry estimates suggest that generative AI could improve productivity across a wide range of banking functions by approximately 20% to 30%, from customer service and software development to compliance, legal and risk management. Once a handful of market leaders begin realizing these gains, AI adoption quickly becomes less a matter of innovation than of competitive necessity. Institutions that delay implementation risk falling behind competitors in both cost efficiency and decision-making speed. In this sense, generative AI creates a classic competitive cascade: Banks are no longer adopting AI simply because they want to, but increasingly because they cannot afford not to.

Supervisory authorities, however, view the same transformation through a different lens. For nearly four decades, banks and regulators guided by the Basel framework and successive supervisory initiatives have invested enormous resources in reducing operational risk arising from human error, model limitations and control failures. Generative AI introduces a fundamentally different governance challenge. Unlike traditional analytical models, large language models can produce outputs that appear technically accurate, professionally written and highly persuasive while containing factual errors or even entirely fabricated information. The emerging risk therefore lies not merely in incorrect answers, but in the growing possibility that machine-generated conclusions will be accepted, relied upon and acted upon by experienced professionals. In this sense, AI hallucinations should be understood not primarily as a technology problem, but as a governance problem. More precisely, they represent the emergence of a new source of operational risk — one created not by humans or machines acting independently, but by the interaction between human judgment and machine-generated intelligence.

The governance implications extend even further. For decades, effective bank governance has rested on one fundamental assumption: Every significant decision must ultimately have an accountable human owner. Whether embedded in the four-eyes principle, maker-checker controls, approval hierarchies or regulatory expectations, banking has traditionally been built around a simple question: Who made the decision? Compliance professionals often joke that BSA stands not only for the Bank Secrecy Act, but also for "Blame Someone Always."

Read more:

Behind the humor lies one of banking's most fundamental governance principles. When a compliance failure occurs, accountability must ultimately rest with an identifiable individual or institution. Decisions can be reviewed, responsibilities assigned and control weaknesses remediated precisely because the decision-making process remains transparent and traceable. Generative AI complicates this principle in a way that extends far beyond technology. Rather than replacing human decision-makers, it increasingly becomes an influential participant in the decision-making process itself. As machine-generated analysis becomes embedded across banking operations, responsibility no longer follows a single, linear path. Instead, it is distributed among the individuals relying on AI-generated outputs, their managers, internal governance functions responsible for oversight, and the institutions that determine how the technology is deployed. The governance challenge therefore extends beyond validating AI-generated information. Financial institutions must also determine how accountability should be allocated when business decisions increasingly result from collaboration between human judgment and machine-generated intelligence. Viewed from this perspective, AI governance is not simply another technology initiative. It represents a fundamental evolution in the architecture of decision-making inside financial institutions. The central question is no longer whether artificial intelligence will participate in critical business processes, but how governance frameworks should evolve to preserve accountability when those decisions are increasingly shaped by machine-generated intelligence.

Among all banking functions, compliance may become the first to experience the practical consequences of this governance shift. Unlike many operational processes, AML investigations, sanctions reviews and customer due diligence depend almost entirely on the collection, interpretation and assessment of information. Generative AI can dramatically accelerate each of these activities. Yet it also changes the nature of the analyst's work in a fundamental way. Traditionally, investigators created value by finding relevant information, evaluating evidence and developing their own analytical conclusions. Increasingly, however, analysts begin their work not with a blank page but with AI-generated summaries, risk assessments, investigative narratives and legal research. Their role is gradually shifting from information retrieval to information validation. Put differently, the modern AML analyst is no longer searching for information; increasingly, the analyst is searching for machine mistakes. This distinction is far more significant than it may initially appear. The principal challenge is no longer simply that AI can generate hallucinations, fabricated citations or confidently presented but inaccurate conclusions. Experienced investigators have always encountered unreliable information. The new risk arises because these errors are embedded within analysis that appears professionally written, logically structured and operationally credible. AI therefore changes not only the speed of compliance work, but the competencies required to perform it effectively. Success increasingly depends not on obtaining information faster, but on recognizing when machine-generated intelligence should not be trusted.

Artificial intelligence does not replace traditional operational risk. It changes its nature. The greatest threat is no longer that machines make mistakes, but that humans increasingly rely on machine-generated intelligence when making critical business decisions. The resulting risk should not be viewed simply as AI risk. It represents a new form of AI-induced operational risk, emerging from the interaction between human expertise and machine-generated analysis. Managing this risk will require more than technical safeguards or model validation. It will require governance frameworks capable of preserving accountability, professional skepticism and independent judgment in an environment where artificial intelligence increasingly participates in decision-making. Ultimately, AI may transform banking efficiency but governance will determine whether it transforms banking resilience.


For reprint and licensing requests for this article, click here.
Artificial Intelligence AML Regulation and compliance Bank technology Risk
MORE FROM AMERICAN BANKER
Load More