The Unguarded Verdict: The EU AI Act's Financial Crime Blind Spot
- Elizabeth Travis

- 11 minutes ago
- 7 min read

New rules that took effect in the United Kingdom on 28 April 2026 require banks to give a customer at least 90 days' notice before closing their account, and to set out the reasons in writing. Yet the reform, meant to answer years of anger over debanking, carries an exception that reaches to the heart of the matter: a provider need give neither notice nor explanation where it has reasonable grounds to suspect the account is connected to serious crime. That judgement, whether a customer is a financial crime risk, is increasingly made at scale by machines: transaction monitoring models, sanctions screening engines and customer risk-rating tools that decide, in effect, whether a person may remain inside the financial system. It is also the judgement that the European Union's landmark attempt to govern artificial intelligence does not treat as its highest concern. The Act guards the AI that decides whether a customer can borrow. It says almost nothing about the AI that decides whether they belong.
That silence is the subject worth examining. The Artificial Intelligence Act, Regulation (EU) 2024/1689, is built to protect people from AI that judges them. On 29 June 2026 the Council of the European Union gave final approval to the Digital Omnibus on AI, pushing the high-risk compliance deadline for standalone systems from August 2026 to 2 December 2027. The delay dominated the coverage. The more revealing fact went unremarked: the financial crime function, where an automated verdict can cut a customer off from the regulated economy, sits largely outside the Act's most protective tier. This is not a drafting accident but a decision, conscious or not, about whose harm the law was written to prevent.
Financial crime sits outside the net
Annex III of the Act lists the use cases that make an AI system high-risk. In financial services it names two: systems that evaluate the creditworthiness of natural persons or establish their credit score, and systems that carry out risk assessment and pricing in life and health insurance. Anti-money laundering monitoring, sanctions and watchlist screening, alert triage and suspicious activity detection appear nowhere on that list. They are not high-risk under the Act; they are unclassified.
The exclusion is deliberate. Annex III carves out an explicit exception within the credit-scoring category for AI systems used to detect financial fraud, and Recital 58 states that systems intended for fraud detection in financial services, along with those used for prudential purposes such as calculating capital requirements, should not be considered high-risk. The stated intent was to avoid burdening the tools that protect financial integrity. The effect is that the AI at the core of financial crime prevention has been placed in the lightest-touch part of the regime.
Supervisors have already seen the confusion this breeds. In its second thematic review on the use of artificial intelligence in the Luxembourg financial sector, published in May 2025, the Commission de Surveillance du Secteur Financier reported that firms rated only five per cent of their AI use cases as high-risk, and that those cases referred mainly to credit scoring, internal ratings-based models and AML or fraud detection. The regulator was blunt: the last two are actually excluded from the high-risk list in Annex III. Firms were classifying their financial crime AI as high-risk when the Act does not. The perception of risk and its legal classification had come apart.
The borrower, not the banished
The asymmetry is stark once the two judgements are set side by side. A wrong credit score closes a door; a wrong financial crime flag expels a person from the building. The first is contestable, appealable and, under the AI Act, high-risk, wrapped in requirements for data governance, human oversight, record-keeping and, for deployers, a fundamental rights impact assessment before the system goes live. The second can freeze an account, trigger a suspicious activity report and sever a banking relationship, often with no explanation the customer is permitted to see, and the Act asks for none of that machinery. The stronger protection attaches to the smaller harm.
The people on the receiving end are rarely the powerful. FATF warned as long ago as October 2014 against the wholesale cutting loose of entire classes of customer without regard to their individual risk. A decade of its own reporting since has shown the result: de-risking drives remittance firms, non-profit organisations and whole communities out of the regulated system and into the shadows.
These are the customers an automated model is most likely to misread, and least equipped to challenge. A well-resourced borrower can dispute a credit decision. A small money service business, flagged by an algorithm and quietly exited, often cannot even learn why.
The only real backstop is the General Data Protection Regulation. Where an automated system produces a decision with legal or similarly significant effect on an individual, Article 22 grants a right to human intervention and to contest the outcome. This matters, but it is a thinner protection than the high-risk regime: it offers recourse after the decision, not the engineered safeguards, the oversight by design and the assessment before deployment, that the AI Act reserves for creditworthiness. The strongest procedural protections in European AI law attach to the judgement about a person's money, not the judgement about their integrity.
Exemption is not absolution
For firms, a system that escapes the high-risk label does not escape governance; it changes which rulebook governs it. This is the distinction most easily lost in the relief of a deferred deadline.
The obligations that bear on financial crime AI arrive through other instruments. The Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, most of whose provisions apply from 10 July 2027, requires obliged entities to understand, document and control the tools they use to meet their monitoring and reporting duties. The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) took up operations in Frankfurt on 1 July 2025 and inherited the AML mandate from the European Banking Authority in January 2026. It will begin direct supervision of selected institutions from 2028, with the selection process starting in July 2027. AMLA will not ask whether a transaction monitoring model was labelled high-risk under the AI Act. It will ask whether the model works, whether the firm understands it, and whether its outputs can be explained and defended.
Audit comfort is the real danger
The most serious risk created by the exemption is not legal but cultural. It is the temptation to read a favourable classification as a governance holiday. Nothing in the AI Act's silence on transaction monitoring reduces the consequences of a model that misses a laundering network, floods investigators with false positives, or embeds a bias that shutters legitimate businesses. The exemption removes a set of documentation duties. It does not remove the failure.
This is where control effectiveness, rather than control existence, becomes decisive. A firm can hold a defensible position on paper, its AI systems correctly logged as outside the high-risk tier, while running a monitoring estate that no one can fully explain. The Act's requirements for high-risk systems, data governance, human oversight, technical documentation, record-keeping and post-market monitoring, describe what good model governance looks like in any context. Treating them as optional because the label does not apply is to confuse the absence of a requirement with the absence of a risk.
There is a deeper mismatch beneath this. The AI Act ranks systems by the risk they pose to fundamental rights; the money-laundering regime ranks them by the risk they pose to financial integrity. A transaction monitoring model can score low on the first measure and high on the second, and it is the second that determines whether a firm keeps its licence. Assuming that a comfortable position under the AI Act signals a comfortable position everywhere is the error the exemption invites. The two frameworks measure different things; a favourable answer to one is not an answer to the other.
The prohibitions still apply
Exemption from the high-risk tier is not exemption from the Act. Article 5, in force since 2 February 2025, bans some practices outright, including social scoring that penalises people in contexts unrelated to where their data arose; customer risk models that reach across unrelated behaviours should be tested against that line. The Article 4 duty on AI literacy has applied since the same date, and a compliance analyst leaning on an alert score they cannot interrogate is already a problem, not a future one. Generative tools now draft suspicious activity reports and summarise alerts, and a hallucinated fact in a regulatory filing is a failure whatever the model's classification. The Digital Omnibus confirmed that, for systems built on general-purpose AI models, financial institutions answer to their own national supervisors rather than a distant AI office. That makes alignment urgent.
What firms should reassess
The immediate task is to separate two questions the deferral has blurred. The first is what the AI Act formally requires, which for most financial crime systems is modest. The second is what supervisory, legal and ethical accountability demands, which is not. Firms should map every AI system touching their financial crime controls and record what it actually does, not what the label assumes. One caveat matters most: a tool that pairs fraud detection with creditworthiness assessment loses the exemption and becomes high-risk. And where a customer is harmed, no supervisor will accept that a system was out of scope as an answer to whether it was fair.
Beyond mapping, the deadlines that govern financial crime AI are not the AI Act's at all. They are the application of the AML Regulation in July 2027 and the arrival of direct AMLA supervision from 2028. An institution that spends the next two years preparing for a high-risk deadline that does not apply to its monitoring systems, while neglecting the anti-money laundering and data-protection obligations that do, will have prepared for the wrong examination.
Conclusion: The verdict returns
The EU AI Act was built to make the judgement of machines answerable to people. In financial crime it has left its most consequential verdict, the finding that a person is a risk to be removed rather than a customer to be served, almost entirely unguarded. The classification is a map, and this part of the territory is missing from it. A monitoring model that fails does not fail more gently because Annex III declined to name it, and a customer wrongly locked out of the financial system is not consoled by an exemption. When the map is wrong, it is not the institution that disappears from the economy; it is the person the algorithm decided did not belong. The firms that come through this well will govern their financial crime AI for what it does to people, not for what the label permits.
Are you confident your firm could explain, and defend, every automated decision that removes a customer from the financial system?
At OpusDatum, we help financial institutions close exactly this gap, mapping AI systems against the AI Act, the AML Regulation and AMLA's supervisory expectations, and building governance that answers for outcomes rather than resting on classification. Our work focuses on control effectiveness, not audit comfort. If this gives you pause, contact us.
%20-%20C.png)


