ClickCease

Something we said? Don’t leave just yet!

For more information about latest events, news and insights, leave us your email address below.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form
Dismiss

Tackling Money Laundering and Terrorist Financing Risks in Australia with AI

Australia lost an estimated $87.39bn to money laundering in 2024-25. Jeff Jones explains why AI must strengthen AML foundations, not bypass them.

Jeff Jones
August 25, 2026

For an industry that has spent the better part of a decade talking about transformation, financial crime compliance is at risk of falling behind the very threats it was designed to address.

The Financial Action Task Force (FATF) Ministerial Declaration in April made that clear. AI misuse, virtual assets, and increasingly complex financial structures are now top priorities for the 2026–2028 period. That’s not a forward-looking concern—it’s a reflection of what is already happening.

From a systems and data perspective, the uncomfortable reality is this: in key areas of digital finance, detection is not keeping pace with the threat.

AML detection challenges

If we strip away the noise, a small number of typologies are consistently exposing weaknesses in modern anti-money laundering (AML) systems.

Stablecoins and crypto layering are obvious examples. These mechanisms allow value to move across borders with speed and opacity that traditional monitoring systems struggle to track in real time. Synthetic identity fraud is another—where entirely fabricated digital personas can operate long enough to integrate into the financial system before being detected.

Trade-based money laundering remains a persistent blind spot, particularly as digital platforms accelerate cross-border commerce without necessarily improving transparency.

But perhaps the most telling signals come from what we are seeing in market-specific data.

In the Napier AI / AML Index, Australia provides a useful case study. The most common criminal activities and their corresponding typologies are not theoretical, they are operational:

  • Human exploitation and trafficking enabled through money muling networks
  • Drug-related financial flows via informal systems such as unregistered money service bureaus or hawala networks
  • Cyber and financial crime, particularly smurfing at scale

What’s changing is not the typology itself but the economics behind it.

Criminals are now leveraging AI to automate and scale these activities. Smurfing, for example, has become a high-volume, low-cost exercise. AI can generate transaction patterns, distribute funds across accounts, and continuously adapt behaviour to avoid detection. It is, at its core, a numbers game, and AI has tipped the balance.

Global trends in digital banking and AML

Organised crime is no longer constrained by geography in any meaningful sense. Digital finance infrastructure allows criminal networks to move proceeds across jurisdictions faster than most financial crime compliance teams can report them.

What this creates is a timing problem as much as a detection problem.

By the time an alert is generated, investigated, and escalated, the funds have often moved multiple steps further along the chain. Traditional batch processing models—still prevalent in many institutions—are fundamentally misaligned with this reality.

At the same time, regulatory reform is attempting to close gaps in the ecosystem. In Australia, AUSTRAC’s expansion of AML obligations to new sectors—real estate, legal services, and virtual assets—is a direct response to known vulnerabilities.

This mirrors what we saw with PSD2 and Open Banking in Europe and the UK; increased access and interoperability drove innovation and competition, but also created new attack vectors for financial crime.

In a connected ecosystem, AML effectiveness becomes a shared responsibility. Data accuracy, timeliness, and accountability are no longer confined to regulated banks—they extend across the entire payments chain.

The AI adoption & effectiveness gap

There is a persistent narrative that AI is already transforming AML. In reality, the gap between what AI can deliver and what most institutions are actually running in production remains significant.

The Napier AI / AML Index quantifies this disconnect.

Australia lost an estimated $87.39 billion (AUD) to money laundering in 2024–2025. While AI could potentially recover $2.65 billion, the broader trend is more telling. Money laundering losses are increasing at 3% year-on-year, while the cost of compliance is rising at 9%—well above global averages.

This is not a sustainable trajectory.

Australia is currently considered an effective leader in balancing compliance costs and outcomes. But that position is fragile. Without meaningful adoption of AI that drives real efficiency and effectiveness, there is a risk of tipping into what can only be described as inefficient overspending: more cost, without better results.

And that’s the crux of the issue. Many institutions are investing in AI, but not in a way that fundamentally changes outcomes.

Responsible AI for AML: defining best practice

AI is not a panacea for financial crime compliance and regulators are increasingly explicit about that.

AUSTRAC has been clear: institutions cannot simply hand over compliance responsibilities to AI.

Responsible AI in AML starts well before any model is deployed. It starts with a risk-based assessment. What level of risk is acceptable? Which alerts should always be reviewed? Where can automation safely reduce noise?

Without clear answers to those questions, AI simply amplifies existing inefficiencies.

In practice, many of the gains available today do not even require advanced AI. Multi-configuration screening, risk-based segmentation, and more granular customer profiling can significantly improve outcomes. But they require institutions to understand and articulate their risk properly.

When AI is introduced, it must be done with a compliance-first mindset—where explainability, auditability, and validation are built in from the outset.

We are already seeing the consequences where that hasn’t happened. A recent Federal Court of Australia judgement cautioned against the use of large language models to summarise complex material without human validation. The issue was not the technology itself, but the absence of accountable oversight.

The principle of human-in-the-loop remains non-negotiable.

AI can gather data, identify patterns, and prioritise alerts. But the final decision—particularly in high-risk scenarios—must sit with a human who can interpret, challenge, and validate the outcome.

And that human oversight must be informed. Model outputs should be continuously tested against institutional knowledge. If experienced analysts are identifying risks the system misses, the model needs to be recalibrated. Validation is not a one-off exercise; it is continuous.

Crucially, it cannot be owned solely by data scientists. Effective AI in AML requires a productive tension between technical and domain expertise. If the outputs cannot be explained in terms a compliance professional understands, they cannot be relied upon.

Preparing AML systems to be AI-ready

If there is a single practical takeaway, it is this: institutions need to reconnect AI adoption with foundational AML capabilities.

Most legacy platforms were not designed for the current threat landscape. They operate on batch processing, static rules, and manual investigations. Layering AI on top of that does not create transformation, it creates complexity.

A compliance-first approach to AI begins with fixing those foundations.

Start with a robust risk-based assessment. Define what effectiveness looks like: not in terms of volume reduction alone, but in terms of detection quality and investigative accuracy. Accept that this is not a race to zero false positives, but a process of prioritisation and precision.

Then address the infrastructure. Modern AML requires systems that can operate in real time, adapt continuously, and integrate data across the ecosystem.

Only then does AI deliver what it promises.

Because the real measure of effectiveness is not how much you spend, or even how many alerts you process. It is whether you are identifying and stopping the activity that matters.

Right now, in too many cases, that answer is still no.

And that is what should be keeping compliance leaders awake at night.