
Bank security with AI
December 02, 2022Technology is changing our society at an unimaginable rate, and financial institutions are no exception. When this article was first published in 2022, much of the financial crime compliance work in banks was still done by people, and many banks were wary of AI because they were unsure how reliable its decisions would be when detecting suspicious activity.
That has changed quickly. In a 2024 survey by the Bank of England and the Financial Conduct Authority, 75% of UK financial services firms said they were already using AI, including 94% of international banks. Firms named anti-money laundering and fraud prevention among the areas where AI brings the biggest benefits today.
The need for automatic processing of user actions to enforce the rules on financial flows is clear. According to Banking & Payments Federation Ireland (BPFI), more than 12 million euros were moved through the accounts of "money mules" in the first half of 2022, and the number of bank accounts linked to money mules almost doubled from a year earlier, to over 3,000.
BPFI data also showed that debit and credit card fraud (including ATM fraud) reached 14.5 million euros in the second half of 2021, an increase of 18.5% and the highest level since the first half of 2017. Most of the increase came from online, "card not present" fraud.
Figures like these put heavy pressure on compliance teams, and banks have also launched training projects to help employees meet cybersecurity requirements.

Where AI helps compliance teams
Financial crime compliance functions are responsible for KYC verification processes, transaction monitoring, and user action analysis. Much of this is manual, routine work that takes up a significant portion of an employee's workday. To improve productivity, these tasks can be moved to machine processes: algorithms can analyze user behavior, collect and assess behavioral factors, and screen new customers.
This frees up the time of skilled analysts for cases that need human judgment. Some banks have published results. HSBC, an early tester of Google Cloud's Anti Money Laundering AI, found that the system identified two to four times more suspicious activity while reducing alert volumes by more than 60%, according to Google Cloud's June 2023 announcement.
What the EU AI Act means for banks
Developments at the EU level also shape how banks can use AI. In April 2021, the European Commission published its proposal for the AI Act, the first comprehensive legal framework for AI systems. The Act entered into force on August 1, 2024, and its obligations apply in stages.

The AI Act groups AI systems by risk: unacceptable (banned since February 2, 2025), high, limited and minimal. For banks, two points stand out. AI systems used to evaluate the creditworthiness of individuals or set their credit score are classed as high-risk, while systems used to detect financial fraud are expressly excluded from that category. The high-risk rules were originally due to apply from August 2, 2026, but the Digital Omnibus on AI, an amendment adopted in 2026, moved the date for these systems to December 2, 2027.
This approach leaves room to use AI in compliance functions. Processing vast amounts of data to identify complex criminal networks and illicit money flows in financial institutions is hardly possible without AI, although banks still need to manage familiar AI risks such as bias and security.
Over the past few years, the banking system has lost the trust of many users, which it will have to work to regain. Security and data processing systems should help speed up this process by guaranteeing the safety of funds held at a particular bank.