Governance must evolve with the technology
As AI capabilities increase, so does the importance of governance. Financial institutions need to understand what the technology does, what data it accesses, how outputs are generated, how it was tested, where errors can occur, and which decisions require human approval.
In April 2026, the Federal Reserve, FDIC, and OCC revised their supervisory guidance on model risk management. Traditional statistical and quantitative models, as well as non-generative, non-agentic AI, remain within the scope of the guidance. The agencies clarified that novel and rapidly evolving generative and agentic AI models are not currently within their scope. Institutions should use their risk management and governance practices to determine appropriate controls for tools outside the guidance.
In addition, other agencies have developed or pointed to frameworks to help financial institutions understand governance requirements. The Conference of State Bank Supervisors recently released an AI Supervisory Framework that could shed light on the general approach, types of questions, and the information that a state examiner may request regarding the institution’s AI-based products, services, and tools. Abrigo also has resources, including an AI governance vendor questionnaire.
AML professionals evaluating AI in AML/CFT monitoring should consider whether investigators can understand and challenge AI output, how performance will be monitored, what happens when the technology is wrong, and what controls apply to third-party providers. Controls should reflect the use case. A tool that summarizes case notes does not pose the same risk as an agent that performs multiple tasks across customer and transaction systems.
Start with the AML problem
Many financial institution staff can get overwhelmed thinking of the possible uses of AI, but a good place to start is with the AML problem:
- Where are investigators spending unnecessary time?
- Which monitoring scenarios generate large numbers of alerts with little investigative value?
- Is relevant data difficult to retrieve?
- Are investigators repeatedly performing the same manual research?
- Are new products or payment channels creating risks that existing processes struggle to monitor?
Once the problem is clear, the institution can determine whether rules, machine learning, generative AI, agentic AI, or a better process is the appropriate solution.
This approach also keeps the focus where it belongs. Experienced AML professionals understand customers, recognize context, connect information, and apply judgment. Technology should help them spend more time on work that requires those skills.
The future of AI in AML/CFT monitoring
AI capabilities will continue to evolve, and agentic AI could eventually change how financial crime investigations are performed. Financial institutions do not need to move directly from traditional monitoring to autonomous agents.
A deliberate approach allows institutions to identify where machine learning can strengthen monitoring, explore generative AI where it can safely assist investigators, establish appropriate governance, and evaluate agentic AI based on the risks and benefits of the tasks it would perform.
The strongest AML programs will combine experienced financial crime professionals with technology that helps them identify relevant information, recognize risk sooner, and spend their time whe