Financial-crime compliance is one of the largest and least satisfying cost lines in banking. One estimate holds that the industry detects only around 2% of global financial crime flows, even though compliance spending rose by up to 10% a year in some advanced markets between 2015 and 2022, and banks commonly assign 10–15% of their full-time staff to KYC and AML work1. More people reviewing more alerts has not produced materially better outcomes.
The reason is structural. Most of an analyst's day is spent gathering and reconciling evidence — registry lookups, ownership charts, screening hits, transaction histories, adverse media — before any judgement is made. That assembly work is exactly what agentic AI is suited to.
Three waves of AI in financial crime
It helps to separate three generations of technology, because each changes a different part of the work1:
- Analytical AI improves detection — scoring transactions and customers more accurately than static rules, and reducing false positives.
- Generative AI assists the investigator — extracting data from documents and drafting case narratives and suspicious-activity reports.
- Agentic AI executes the investigation workflow — agents that retrieve, check, screen, analyse and assemble a case file end to end, with humans stepping in for oversight, exceptions and complex decisions.
The first wave is already proven at scale. When a global bank adopted a cloud provider's AML AI as a core transaction-monitoring system, the bank reported detecting two to four times more suspicious activity while reducing alert volumes by more than 60%, and cutting the time to analyse billions of transactions from several weeks to a few days2. In fraud and scams, a large Australian bank reported a 30% drop in customer-reported frauds, aided by generative-AI-powered suspicious-transaction alerts, and a 50% reduction in customer scam losses supported by AI-enabled safety features3.
Reported results from AI in financial crime and fraud
Bank-reported outcomes; not directly comparable across institutions
| Bank | Application | Reported outcome |
|---|---|---|
| Global bank | ML-based AML transaction monitoring | 2–4x more suspicious activity detected2 |
| Global bank | ML-based AML transaction monitoring | Alert volumes down more than 60%2 |
| Global bank | Processing of transaction data | From several weeks to a few days2 |
| Australian bank | Gen AI suspicious-transaction alerts and related measures | 30% drop in customer-reported frauds3 |
| Australian bank | AI-enabled safety and security features | 50% reduction in customer scam losses3 |
Note: Global bank figures from the cloud provider's announcement [2]; Australian bank figures from that bank's newsroom [3].
How an agent squad works
The agentic model reorganises investigation around small teams of specialised agents. Published research describes a global bank that built a KYC ‘factory’ of ten agent squads, each with four or five agents — a lead agent, two or three expert-practitioner agents and a quality-assurance agent1. Each squad owns one step and passes its output to the next:
Anatomy of an agentic KYC factory
Illustrative squad responsibilities in one bank's end-to-end KYC workflow
| Squad | What it does |
|---|---|
| Data extraction | Pulls client data from websites, annual reports and filings |
| Registry check | Validates incorporation, registered shareholders and directors |
| Ownership analysis | Maps ownership structure and ultimate beneficial owners |
| Screening | Runs sanctions and politically-exposed-person checks |
| Relationship & transactions | Checks purpose and nature of relationship; analyses transactions |
| Adverse media | Screens and summarises negative news |
| File assembly | Compiles a consolidated KYC file for human review |
Note: Ten squads of four to five agents each; a human supervisor reviews the consolidated file.
Source: Published research, “How agentic AI can change the way banks fight financial crime” (2025)
In this model, the research reports, one human practitioner can typically supervise 20 or more agent workers, with productivity gains of 200% to 2,000% — compared with uplifts of around 15–20% from analytical and generative AI alone1. Those ranges are wide and should be read as potential rather than a planning assumption. The important point is the shape of the work: the investigator stops being a data gatherer and becomes a reviewer and decision-maker.
Two design choices determine whether a squad is an improvement or a new source of risk. The first is where the agents sit relative to existing detection. In the designs we consider sound, calibrated scoring models and rules continue to generate alerts; agents work downstream, enriching, triaging and documenting. That keeps the validated part of the control stack intact and makes agent performance measurable against a known baseline. The second is the quality-assurance layer. A QA agent that checks each squad's output against policy — and a human who samples the QA agent's decisions — is what turns speed into reliability.
Narrative drafting deserves particular care. Generative models are good at producing fluent case summaries and suspicious-activity narratives, but fluency is not accuracy. Every factual statement in a draft should link back to a retrieved record, and investigators should be able to see and challenge that evidence before they sign. Banks that build this traceability in from the start will find model validation and regulatory review far easier.
What supervisors expect
Regulators have generally encouraged innovation in financial-crime controls, but the direction of travel on AI governance is clear. The Monetary Authority of Singapore's proposed Guidelines on AI Risk Management, published for consultation in November 2025, explicitly cover generative AI and AI agents and set expectations for board oversight, AI inventories, risk-materiality assessment and lifecycle controls including human oversight4. In the United States, the April 2026 interagency model-risk guidance rescinded the 2021 statement on model risk management for BSA/AML systems and excluded generative and agentic AI from its scope, with the agencies committing to a separate request for information on AI5. In the EU, the AI Act's high-risk category for creditworthiness assessment expressly excludes AI systems used to detect financial fraud6 — but that does not remove AML and data-protection obligations.
Taken together, the message for banks is consistent: an agent may assemble the case, but the institution must be able to show who decided, on what evidence, under which policy, and how the agent's performance is monitored. Human-in-the-loop is not a slogan here; it is the control.
An agent can gather the evidence. Only an accountable person can file the SAR. Design the workflow so that line is never blurred. (SCIKIQ view)
Getting started without creating new risk
The practical sequence we see working is to start where the evidence is structured and the outcome is easy to verify — sanctions and PEP hit disposition, periodic KYC refresh, alert enrichment — then extend to narrative drafting and full case assembly once quality is proven. Throughout, keep the rules engine and the human decision; let agents do the gathering, cross-checking and drafting in between.
Data is the other prerequisite. Agents that cannot reliably resolve a customer across onboarding, core banking and payments systems, or that retrieve stale ownership data, will produce well-written files built on the wrong facts. Entity resolution, reference data and lineage are therefore part of the financial-crime programme, not a separate IT concern.