Listen to this article
Jump to a section
In this article
Executive Summary
Regulators worldwide issued more than 61,000 regulatory events in a single year, about 234 a day, and the median compliance team tracking them has four people and a spreadsheet. The gap between what is published and what gets read is where most compliance failures start, and the penalties for those failures ran to US$3.8 billion last year. AI is well suited to the reading half of the problem: classifying each alert for applicability, extracting the obligations from the rule text, mapping them to existing policies and controls, and flagging the gaps. It is poorly suited to the interpretation half. The best legal AI tools tested by Stanford still invented or misread the law between 17 and 33 percent of the time, and every regulator I work with treats the AI’s reading as the institution’s own. The design that works keeps the model on triage and drafting, keeps a named person on every interpretation, and records the source clause behind every output.
234
regulatory alerts per day, from 61,228 regulatory events tracked across 1,374 regulators in 190 countries in 2022, Thomson Reuters Regulatory Intelligence
US$3.8bn
in AML, KYC, sanctions and due-diligence penalties on financial institutions in 2025, with APAC fines up 44 percent on the year, Fenergo
75%
of UK financial services firms already use AI, and only 34 percent say they fully understand the AI they use, Bank of England and FCA survey, 2024
17 to 33%
hallucination rate of the leading AI legal research tools on 202 expert-scored legal queries, Stanford RegLab, 2024
Core conclusions
- Regulatory change is a volume problem before it is a judgment problem. AI earns its place by reading everything, sorting it by applicability and turning rule text into an obligations register linked to controls. That is the work nobody has time for and the work most misses come from.
- AI should not decide what a rule means for the institution. Interpretation is where language models are most confident and least reliable, and the regulator holds the institution to the interpretation regardless of who produced it.
- The compliance AI is itself a regulated system. MAS, the FSB and the EU all now expect governance, validation and human oversight of AI used in financial institutions, so the tool that manages compliance needs its own controls before it manages anyone else’s.
The argument, in ten slides
Save it, or send it to whoever runs your compliance function.










Regulatory change is a volume problem first
Thomson Reuters Regulatory Intelligence tracked 61,228 regulatory events in 2022, from 1,374 regulators across 190 countries. That is 234 a day, every day, and the third-highest annual total since the firm started counting in 2008. In its survey of compliance practitioners the following year, 73 percent expected regulatory activity to increase again, and 62 percent expected their compliance headcount to stay the same.
Those two numbers describe the job of a regulatory change function. Somebody has to read what came out today, decide whether it applies to this licence, this business line and this jurisdiction, work out what it obliges the institution to do differently, find the policy and the control that carry that obligation, and put a name and a date against the gap. Regology’s 2025 survey of compliance professionals put the median compliance team at four people, found 44 percent naming the pace of regulatory change as a major challenge, and found about three quarters still running the process manually, most of them in spreadsheets. That survey is cross-industry and vendor-run, so I grade it accordingly below, but it matches what I see. The register is a spreadsheet, the horizon scan is an inbox, and the applicability decision is made by whoever opened the email.
The volume has a shape that makes it worse. A single change rarely arrives alone. In the past two years a bank operating in Singapore and Europe has had to absorb the EU’s Digital Operational Resilience Act, which applied from January 2025, the EU AI Act’s classification of consumer credit scoring as high-risk, the Basel capital reforms on their various national timetables, and the Monetary Authority of Singapore’s proposed Guidelines on AI Risk Management, consulted on from November 2025 with a twelve-month transition proposed once issued. Each of those touches dozens of existing policies. None of them tells you which ones.
Where the cost of a missed change lands
Fenergo’s count of enforcement penalties for anti-money laundering, know-your-customer, sanctions and customer due-diligence failures came to US$3.8 billion in 2025, down from US$4.6 billion in 2024 and US$6.6 billion in 2023. The fall is a regional shift. North American fines dropped 58 percent while EMEA rose 767 percent and APAC rose 44 percent. The single largest penalty of the year was US$985 million, imposed by French authorities on a Swiss bank.
In Singapore the pattern is closer to home. On 4 July 2025 MAS imposed composition penalties of S$27.45 million on nine financial institutions in connection with the S$3 billion money laundering case uncovered in 2023. The shortcomings MAS named were ordinary: customer risk assessment, corroborating source of wealth for high-risk customers, transaction monitoring, and following up on suspicious transaction reports. Every one of those was an obligation the institutions already knew about. The failure was operational, in the distance between the rule on paper and the control in practice.
The US example that best illustrates the point is Citigroup. In July 2024 the OCC and the Federal Reserve fined Citi US$135.6 million for making insufficient progress against a 2020 consent order that required an enterprise-wide risk management, compliance risk management and data governance programme. That is a fine for failing to build the machinery, four years after being told to.
I draw one conclusion from these cases. The expensive failures in financial services compliance are rarely a rule nobody knew about. They are a known rule that did not reach the right control, or a control that drifted from the rule while nobody was comparing the two. That is a reading, mapping and monitoring problem, and it is the problem AI is good at.
Five jobs AI does well in regulatory change
The financial sector already uses AI at scale. The Bank of England and FCA’s 2024 survey found 75 percent of UK firms using it, with a further 10 percent planning to within three years. The LexisNexis study that put global financial crime compliance costs at US$206 billion also found 72 percent of institutions using analytics or AI in their compliance procedures. Most of that use sits in transaction monitoring and fraud, where the results are measurable. HSBC reported that the anti-money laundering model it built with Google Cloud identified two to four times as much suspicious activity as its rules-based predecessor while cutting alert volumes by more than 60 percent. That is a vendor-published figure and I grade it as such, but the direction is consistent with what every large bank running these models reports.
Regulatory change management has had far less of this attention, and the same techniques apply. Five jobs, in the order I would automate them.
Horizon scanning and triage. A model reads every publication from every regulator on the institution’s list, on the day it appears, and classifies it: which entity, which licence, which business line, which jurisdiction, consultation or final rule, effective date. The output is a queue sorted by applicability and urgency instead of an inbox sorted by arrival. This is the least risky use because the model is sorting, not deciding, and a wrong sort is caught by the person who opens the item.
Obligation extraction. Given a final rule, the model produces a draft obligations register: each discrete “must”, “shall” and “should”, the clause it comes from, who it applies to, and the effective date. A 200-page notice becomes forty rows with citations. A compliance officer reviews forty rows in an afternoon. Reading 200 pages to find the forty took a week, and the week is why the register was always out of date.
Mapping and gap analysis. With the obligations extracted, the model compares each one against the institution’s existing policies, procedures and control library and proposes a mapping: this obligation is already covered by that policy clause and that control; this one is partially covered; this one has nothing behind it. Retrieval over the institution’s own documents is what makes this work, and it is the same architecture that governed RAG systems in other high-stakes settings use.
Drafting. Policy redlines, the board paper explaining what changed, the response to a consultation, the attestation letter. The model drafts from the obligation and the current policy text; a person edits and signs.
Control evidence and reporting. Once the mapping exists, the model can check whether the evidence a control is supposed to produce is being produced, on schedule, in the form the regulator expects, and assemble the periodic returns from it. This is where continuous monitoring replaces the annual scramble.

The common thread is that each job turns unstructured regulatory text into structured records with a source clause attached. That structure is what makes the rest of the compliance function auditable, and it is the thing spreadsheets never delivered.
Where AI gets regulation wrong
The reading is where the model helps. The interpretation is where it hurts, and the evidence on this is clearer than most vendors would like.
Stanford’s RegLab tested the leading AI legal research tools in 2024, products from LexisNexis and Thomson Reuters marketed at the time as hallucination-free because they retrieve from a verified corpus. Across 202 legal queries scored by hand by legal experts, the tools produced a false or misgrounded answer between 17 and 33 percent of the time. The failures were not random noise. The model would cite a real authority for a proposition it did not support, or state a rule that had been superseded, in fluent and confident prose. That is the precise failure a compliance function cannot afford, because the output looks like the work of a competent junior and nobody rechecks the work of a competent junior.
Regulatory text is worse than case law for this. It is dense with cross-references, defined terms that change meaning between notices, and transitional provisions that make the effective rule depend on the date and the entity. A model asked “does Notice 626 require us to re-verify this customer’s source of wealth” will answer. Whether the answer is correct depends on retrieval finding the right version of the right notice and the model not filling the gap from its training data when it does not. The same BoE and FCA survey that found 75 percent adoption found only 34 percent of firms claiming complete understanding of the AI they use. A compliance function that cannot explain how its tool reached an interpretation cannot defend that interpretation to a supervisor.
The regulator’s position on this is settled. The institution is responsible for its compliance, whatever tool produced the analysis. MAS’s proposed AI risk management guidelines set out expectations for oversight, lifecycle controls, independent validation of higher-risk uses and human accountability, and they apply to AI used inside the compliance function as much as to AI that scores credit. The Financial Stability Board’s 2024 report named model risk, third-party dependency and misaligned AI systems operating outside legal and regulatory boundaries as the vulnerabilities supervisors should watch. A regulatory change tool that decides applicability on its own is exactly the system those documents describe.
Free tool
ISO 42001 AIMS Readiness Checklist
Check whether the governance around your compliance AI, from risk assessment to validation and human oversight, would satisfy an auditor or a supervisor reading the MAS guidelines.
Three design rules follow. Every output the model produces carries the clause it came from, and the person reviewing it opens the clause. The model draws only from the institution’s own controlled regulatory library, versioned by effective date, with no fallback to whatever it learned in training. And no interpretation, no applicability decision and no sign-off leaves the function without a named person’s approval recorded against it. The model has made the person faster. It has not made the person optional.
How far each compliance job can be handed to AI
The rule I apply to agentic AI in every sector holds here: autonomy should rise with reversibility. A wrong sort in a triage queue costs an hour. A wrong applicability decision that goes unnoticed costs a consent order. The table sets the boundaries I would start with.
| Compliance job | What the AI does | Where the human stays | Autonomy |
|---|---|---|---|
| Horizon scanning and triage | Reads every regulator publication daily, classifies by entity, licence, business line, jurisdiction and effective date, ranks the queue | Opens the queue and confirms or corrects the sort; owns the regulator list | Acts, within a taxonomy |
| Obligation extraction | Produces a draft obligations register from the rule text, each row with its clause | Reviews every row against the clause; approves the register | Drafts only |
| Applicability decision | Proposes whether and how the rule applies, with the reasoning and the clauses | Makes the decision; the decision and the person are recorded | Recommends |
| Mapping and gap analysis | Matches obligations to existing policies and controls; flags partial and missing coverage | Approves each mapping; assigns an owner and a date to each gap | Recommends |
| Policy and paper drafting | Drafts redlines, board papers, consultation responses from the obligation and current text | Edits and signs; nothing is issued from the draft | Drafts only |
| Regulatory interpretation | Answers questions against the controlled library with citations | A qualified person reads the cited clause before relying on the answer; unsupported answers are rejected | Recommends, with citation |
| Control evidence and returns | Checks that control evidence exists and is current; assembles periodic returns | Reviews exceptions; approves every submission | Drafts, submits on approval |
| Transaction and screening alerts | Scores and prioritises alerts; suppresses low-risk duplicates within tuned thresholds | Investigates and decides every escalation; owns the tuning and its validation | Acts, with human investigation |
”Acts, within a taxonomy” means the model may complete the task unsupervised along a fixed classification it cannot extend. “Recommends” means a named person makes the decision every time. “Drafts only” means nothing is issued, filed or relied upon without a recorded approval.
Free tool
Agent Risk Assessment Matrix
Place each of the eight compliance jobs above on the autonomy and consequence grid and get the ISO 42001-referenced controls each one needs before it touches a regulatory obligation.
What to measure in the first ninety days
A regulatory change function that has done the triage and extraction work properly will see it in four numbers, and none of them is hours saved.
Days from a regulator’s publication to a recorded applicability decision with an owner, with the target inside five working days for final rules. Share of applicable obligations that have a mapped policy and control, which should climb from wherever it starts toward the high nineties. Share of mapped obligations with current control evidence on file. And the number of open gaps past their assigned date, which should trend to zero and stay there.
Alongside those, one number that must not move: findings raised by internal audit or a supervisor that the function was not already tracking. If that rises after the AI arrives, the model is sorting things out of sight instead of into it, and the programme should stop until the triage is retuned and revalidated.
Evidence & Methodology
The volume and penalty figures come from firms that sell compliance products and count for a living. The adoption numbers are regulator surveys. The hallucination figure is a preregistered academic study. My own claims about where AI helps and where it hurts come from governance and assurance work with regulated firms. Here is the grading.
| Claim | Source | Grade |
|---|---|---|
| 61,228 regulatory events in 2022 across 1,374 regulators in 190 countries, 234 a day; 73% expect more regulatory activity; 62% expect flat compliance headcount | Thomson Reuters Regulatory Intelligence, Cost of Compliance 2023. The firm sells the regulatory intelligence feed it is counting | Measured, vendor-counted |
| Median compliance team of four; 44% name keeping up with regulatory change a major challenge; about three quarters run manual processes | Regology 2025 State of Regulatory Compliance survey, cross-industry, run by a regulatory change software vendor | Reported, vendor survey |
| US$3.8bn in AML, KYC, sanctions and CDD penalties in 2025, from US$4.6bn in 2024 and US$6.6bn in 2023; APAC up 44%, EMEA up 767%, North America down 58%; US$985m largest fine | Fenergo enforcement penalties report, 2025 | Measured, vendor-counted |
| S$27.45m in composition penalties on nine financial institutions, 4 July 2025, for shortcomings in customer risk assessment, source-of-wealth corroboration, transaction monitoring and STR follow-up | MAS enforcement action, 4 July 2025 | Measured, regulatory text |
| Citi fined US$135.6m in July 2024 for insufficient progress on its 2020 consent order covering risk management, compliance risk management and data governance | OCC and Federal Reserve orders, 10 July 2024; Citigroup Form 8-K | Measured, regulatory text |
| 75% of UK financial services firms use AI, 10% more plan to within three years; 34% report complete understanding of the AI they use | Bank of England and FCA, third AI survey, 118 firms, November 2024 | Measured, regulator survey |
| Global financial crime compliance costs US$206bn; 72% use analytics or AI in compliance procedures | LexisNexis Risk Solutions, True Cost of Financial Crime Compliance, 2023, survey-based estimate by a compliance data vendor | Reported, vendor estimate |
| HSBC’s AML model found 2 to 4 times more suspicious activity with 60% fewer alerts | Google Cloud, June 2023, publishing its own customer’s result | Reported, vendor-published |
| Leading legal AI research tools hallucinate 17% to 33% of the time | Magesh et al., Stanford RegLab, 202 queries, preregistered, tested May 2024, published in the Journal of Empirical Legal Studies 2025 | Measured, academic |
| MAS proposed AI risk management guidelines apply to all FIs with a twelve-month transition; FSB names model risk, third-party dependency and misaligned AI as vulnerabilities | MAS consultation paper, 13 November 2025 to 31 January 2026, final guidelines not yet checked at the time of writing; FSB report, 14 November 2024 | Measured, regulatory text |
| The expensive failures are known rules that did not reach a control; AI helps on reading and mapping and hurts on interpretation | My own read, from AI governance and assurance work with regulated firms | My call |
Sources
- Thomson Reuters Regulatory Intelligence. (2023). Cost of Compliance 2023.
- Regology. (2025). State of Regulatory Compliance in 2025: survey results.
- Fenergo. (2026). Global financial regulatory penalties fall by 18% in 2025 as enforcement shifts from US to EMEA and APAC.
- Monetary Authority of Singapore. (2025). MAS takes regulatory actions against 9 financial institutions for AML-related breaches.
- Compliance Week. (2024). OCC, Fed fine Citi $136M for repeated risk management, data governance failures.
- Bank of England and Financial Conduct Authority. (2024). Artificial intelligence in UK financial services, 2024.
- LexisNexis Risk Solutions. (2023). Global financial crime compliance costs for financial institutions total more than US$206 billion.
- Google Cloud. (2023). How HSBC fights money launderers with artificial intelligence.
- Magesh, V., Surani, F., Dahl, M., Suzgun, M., Manning, C. D., & Ho, D. E. (2025). Hallucination-free? Assessing the reliability of leading AI legal research tools. Journal of Empirical Legal Studies.
- Monetary Authority of Singapore. (2025). Consultation paper on proposed Guidelines on Artificial Intelligence Risk Management for financial institutions.
- Financial Stability Board. (2024). The financial stability implications of artificial intelligence.
Where to start this quarter
Take the last ninety days of regulator publications for the entities you are licensed under and measure one thing: the median number of days from publication to a recorded applicability decision with a named owner. Most functions have never measured it. When they do, the number is usually weeks, with a tail of items that were never formally decided at all. That single figure is the business case for everything above.
Then put the model on the first two jobs only, triage and obligation extraction, for one regulator and one business line. Keep the applicability decisions and the mapping with the people who make them today, and give them the model’s draft register instead of the raw notice. Run it for a quarter against the regulators still handled by hand and compare days to decision and share of obligations mapped. If the lift is there, add the next regulator. Leave interpretation with a qualified person, with the clause open in front of them. That was never the part to automate.

How to Build Governed RAG 2.0 Systems for High-Stakes Use Cases
The controlled-library, versioned-source design that keeps a regulatory assistant from answering out of its training data.

AI Can Triage. It Can't Be Accountable. Most Enterprises Have the Order Backwards.
The principle behind the autonomy table: the model sorts and drafts, a named person owns the decision.

An AI Management System Is Not a Policy Binder. It's the Machine ISO 42001 Actually Audits.
What the management system around an AI tool has to contain before a supervisor reading the MAS guidelines will accept it.

Why Autonomy Readiness Should Cap Your Agentic AI Score
Why the autonomy column in the table is a ceiling set by controls, not by what the model can do.
If your compliance function is deciding where AI goes first, the ninety-day measurement above is the conversation I usually start with. My consulting work covers scoping that first deployment and building the validation and sign-off controls around it.
Was this useful?





