Site icon Finance Derivative

The Next Financial Crime Challenge Is Not AI Capability. It’s AI Accountability

Business Team Meeting and discussing to audit financial planning sales. Financial advisor teamwork and accounting concept.

By Jason Shane, Head of Financial Services Strategy and Innovation, SymphonyAI.

The question that compliance leaders were asking twelve months ago was whether AI was ready for production use in regulated environments. According to the FinCrime Frontier 2025-26 Report, that question is now largely settled, with nearly 80 percent of financial institutions planning to innovate with AI in compliance by 2026. The capability has been proved, the pilots have been delivered, and adoption is accelerating.

A harder question has taken its place. When an AI system makes or informs a consequential compliance decision, can you explain exactly how it reached that conclusion, to the standard a regulator will require?

For most institutions, the honest answer is “not yet.”

The say-do gap

Every conversation I have with compliance leaders right now follows the same shape. AI is working: false positive rates are down, investigation times are compressed, and the business case for scaling is clear. But the governance gap surfaces the moment scrutiny arrives.

Jason Shane

Consider a regulatory examination into a transaction monitoring decision. The institution must demonstrate far more than why the alert was generated. It needs to evidence which AI model, agent or detection logic was used, why it was appropriate for the institution’s risk profile, the complete lineage of the data it relied upon, every workflow action performed, and the reasoning behind the AI’s recommendation. Re-assembling that chain of evidence involves multiple teams, takes days, and frequently produces an incomplete answer.

Rebuilding the decision trail after the fact is not governance. It is evidence that governance was never there.

The problem is structural: policy gets made in committees and documents, execution runs in increasingly autonomous systems, and audit only catches up months later. Just 17 percent of institutions currently have fully operational AI governance frameworks. The majority are scaling AI into compliance workflows without the infrastructure to defend those decisions when an examiner asks for them.

Regulators aren’t asking whether you have an AI policy. They’re asking about accountability – and governance is the infrastructure that makes accountability demonstrable rather than aspirational.

What accountability actually looks like

Governance in an AI-native compliance environment cannot be a retrospective exercise. It has to be the workflow itself. The test is straightforward: can you explain and defend how your AI reached a specific decision, on demand, for any decision it made today? If the answer requires a sample, an audit cycle, or a working group, governance has become a reporting exercise rather than a control.

There are three things, I’ve found, that separate the AI deployments that hold up under regulatory scrutiny from the ones that don’t.

The first is end-to-end lineage. Every decision in a compliance workflow – an alert flag, a risk score, a SAR recommendation – must be traceable backwards from outcome to input, through every model and agent action in between. Lineage is the difference between telling a regulator what your AI did and being able to prove it.

The second is explainability by design, not by exception. Each type of model in a compliance stack – predictive, generative, agentic – requires a different explainability mechanism. An institution that can explain one but not the others hasn’t solved the accountability problem – it’s relocated it.

The third is continuous human oversight at the system level. The volume of AI-driven decisions in a modern compliance programme makes per-decision human review impossible.

Regulators increasingly expect something more: a governance function that tracks AI behaviour around the clock, sampling outputs, detecting model drift, and logging every guardrail intervention as an audit-grade event. The OWASP Top 10 for Agentic Applications, published in December 2025, names risks such as agent goal hijacking, unsafe tool use, and rogue autonomous behaviour among the highest-impact threats to agentic AI systems. That makes ungoverned agents an active security surface, not just a compliance risk.

The regulatory direction is consistent across jurisdictions. The EU AI Act classifies certain compliance AI systems as high risk, requiring documentation and human oversight that most current frameworks do not yet provide. The FCA’s outcomes-based supervision framework assesses AI-driven decisions on defensible outcomes, not the existence of an AI policy.

Winners are defined by governance, not by models

The institutions furthest ahead in scaling compliance AI didn’t get there with better models – they got there by embedding governance before the first agent went live. As a result, they can resolve a regulatory challenge faster, remediate model drift at lower cost, and deploy subsequent AI use cases on shorter timescales because the accountability infrastructure is already in place rather than being rebuilt each time.

The capability question in financial crime compliance is largely answered. The institutions that invested in governance from day zero will not just pass the next examination more cleanly. They will scale further, faster, and with less remediation cost than those that treated accountability as something to address once the AI was already running. That gap compounds. The time to close it is before the regulator asks the question, not after.

Exit mobile version