Ai Anti-Money Laundering Systems And Financial Access Control .
AI Anti-Money Laundering Systems and Financial Access Control in Europe
1. Introduction
AI anti-money laundering (AML) systems are automated or semi-automated systems used by banks, payment institutions, fintech companies and other regulated entities to detect and manage risks of:
money laundering;
terrorist financing;
sanctions evasion;
suspicious transactions;
beneficial-ownership concealment;
fraud connected with financial crime;
unusual customer behaviour.
AI can analyse transaction histories, customer profiles, geographic information, payment patterns, corporate structures and other data to generate a risk score.
The system may then trigger:
enhanced due diligence;
requests for additional documents;
transaction delays;
account restrictions;
refusal to open an account;
termination of a banking relationship;
suspicious transaction reporting;
sanctions screening.
This creates a difficult legal problem:
AML law requires financial institutions to control financial-crime risks, but automated AML systems can also determine whether an individual receives or loses access to essential financial services.
The European legal framework increasingly recognises this tension. Regulation (EU) 2024/1624 expressly permits AML processes involving automated individual decision-making and profiling, while simultaneously requiring compliance with GDPR safeguards, accuracy, proportionality and fundamental-rights protections. (Eur-Lex)
A particularly important recent authority is Jenec, C-81/24, decided by the CJEU on 11 June 2026. The Court held that merely appearing on a US sanctions list was not, by itself, sufficient to justify refusal of a basic payment account; an individualised assessment of money-laundering or terrorist-financing risk was required. (Curia)
2. Meaning of Financial Access Control
Financial access control means the mechanisms through which a financial institution determines:
who may open an account;
who may maintain an account;
which services a customer may use;
whether transactions can proceed;
whether payments should be blocked;
whether enhanced verification is required;
whether the customer relationship should be terminated.
Traditionally, these decisions were made by compliance officers.
Increasingly, they can involve:
Customer data → AI model → risk score → alert → human review or automated decision → financial access
This creates a legal intersection between:
AML law + GDPR + fundamental rights + banking/payment law + consumer law + administrative supervision.
3. European Legal Framework
A. AML Regulation 2024/1624
Regulation (EU) 2024/1624 is the central new EU AML regulation.
It establishes harmonised requirements concerning:
customer due diligence;
beneficial ownership;
risk assessment;
suspicious transactions;
politically exposed persons;
sanctions;
internal controls;
transaction monitoring.
The Regulation expressly requires a risk-based approach rather than treating every potentially suspicious customer in the same way. (Eur-Lex)
This is extremely important for AI.
An AI system should ideally determine:
What is the actual risk presented by this customer or transaction?
rather than:
Does this customer belong to a category that the algorithm has labelled as risky?
4. AI and Automated Individual Decision-Making
The AML Regulation expressly recognises that obliged entities may use automated individual decision-making, including profiling, under GDPR Article 22.
At the same time, it requires appropriate safeguards. (Eur-Lex)
The Regulation also emphasises that AML personal-data processing should be:
accurate;
reliable;
up to date;
necessary;
limited to AML purposes;
consistent with fundamental rights.
It specifically warns against discriminatory outcomes resulting from irrelevant sensitive personal information. (Eur-Lex)
Therefore:
AI is permitted for AML purposes, but AML does not create a legal exemption from data-protection and fundamental-rights requirements.
5. Case Law
Case 1 — Jenec, C-81/24 — Basic Payment Account and AML Risk
This is currently one of the most directly relevant authorities.
Facts
A Slovenian bank refused to open a basic payment account for a customer because the customer appeared on a US OFAC sanctions list.
The customer had not been convicted of the offence underlying the listing and was not subject to UN, EU or Slovenian sanctions. (curia)
CJEU ruling
The Court held that inclusion on the US list alone was insufficient to justify refusal of a basic payment account.
A bank must conduct an individualised assessment of the customer's money-laundering or terrorist-financing risk. (Curia)
Importance for AI AML
This principle has major implications for automated systems.
An AI model should not simply operate:
US-list hit = automatic account refusal
Instead, the system should consider:
source of funds;
actual transaction behaviour;
relevant sanctions;
customer circumstances;
geographical exposure;
ownership structure;
other reliable evidence.
Legal principle
AML screening cannot automatically replace individualised risk assessment.
This is particularly important where AI produces a binary financial-access decision.
6. Case 2 — SCHUFA Holding (Scoring), C-634/21
Although this case concerned credit scoring rather than AML, it is highly relevant to automated financial access.
The CJEU examined automated scoring under GDPR Article 22.
A credit-information company calculated a probability score concerning an individual's ability to meet payment obligations. That score was then used by third parties in making decisions. (Infocuria)
Principle
The Court treated certain forms of automated scoring as falling within the framework governing automated individual decision-making.
AML application
An AML platform might calculate:
AML Risk Score = 94/100
A bank might then automatically:
freeze an account;
refuse a payment;
terminate the relationship.
The SCHUFA reasoning demonstrates that the legal significance of the AI system cannot be avoided simply by saying:
"The computer only produced a score; the bank made the decision."
The actual role of the automated score in the decision-making chain matters.
7. Case 3 — Dun & Bradstreet Austria, C-203/22
This is another highly important analogy.
In Dun & Bradstreet Austria, the CJEU considered automated credit scoring and the individual's right to receive meaningful information about the logic involved in automated decision-making.
The judgment was delivered on 27 February 2025. (Infocuria)
Principle
A person affected by automated scoring must receive information sufficient to understand and challenge the decision, subject to legitimate interests such as protection of trade secrets.
AML application
Imagine:
AI system assigns customer a "high AML risk" classification.
The bank then closes the customer's account.
The customer asks:
"Why was I classified as high risk?"
A financial institution cannot necessarily answer:
"The algorithm said so."
Meaningful information may be required regarding the relevant decision logic, subject to AML confidentiality and anti-tipping-off requirements.
Difficult balance
There are therefore two competing interests:
Customer
→ wants enough information to challenge an inaccurate decision.
AML authorities/bank
→ must avoid revealing suspicious transaction reports or information that could undermine investigations.
The AML Regulation expressly recognises this tension and allows restrictions concerning disclosure of suspicious-transaction information while preserving avenues for lawful review. (Eur-Lex)
8. Case 4 — Luxembourg Business Registers and Sovim, Joined Cases C-37/20 and C-601/20
These cases directly concerned AML legislation and beneficial-ownership information.
The CJEU considered whether beneficial-owner information could be made available to any member of the general public.
The Court held that unrestricted public access constituted a serious interference with fundamental rights to privacy and personal-data protection and invalidated the relevant provision. (curia)
Importance for AI AML
AI systems can process huge amounts of beneficial-ownership data.
But:
AML purpose does not mean unlimited data collection or unlimited data disclosure.
An AI AML system should therefore distinguish between:
information necessary for customer due diligence;
information necessary for supervisory purposes;
information that can lawfully be shared;
information that should not be exposed publicly.
Principle
AML objectives must be reconciled with privacy and data-protection rights.
9. Case 5 — Steiermärkische Bank und Sparkasse, C-291/24
This is a very recent AML judgment, delivered on 29 January 2026.
The case concerned:
AML obligations;
penalties;
liability of legal persons;
attribution of AML violations committed by natural persons;
supervisory enforcement.
The CJEU examined Articles 58–60 of Directive 2015/849. (Infocuria)
Importance for AI systems
AI does not remove institutional responsibility.
A bank cannot simply argue:
"The algorithm made the mistake."
The regulated institution remains responsible for maintaining effective AML controls and complying with its legal obligations.
This is particularly significant when banks outsource AML technology to:
AI vendors;
cloud providers;
screening companies;
transaction-monitoring platforms.
Principle
Delegating AML technology does not automatically delegate regulatory responsibility.
10. Case 6 — Commission v Ireland, C-550/18
In Commission v Ireland, the CJEU dealt with Ireland's failure to transpose and notify measures required under the EU AML framework.
The Court's judgment concerned Directive 2015/849 and enforcement of Member-State obligations. (Infocuria)
Relevance
AML compliance is not merely an internal bank policy.
It forms part of a broader European regulatory structure involving:
Member States;
financial institutions;
supervisory authorities;
EU institutions.
AI implication
AI AML systems therefore have to operate within a legally structured compliance framework.
A bank cannot create a private algorithmic AML regime that effectively replaces statutory requirements.
11. Case 7 — Ryneš, C-212/13
Ryneš concerned the application of data-protection law to video surveillance.
Although not an AML case, it is useful for understanding the boundaries of automated surveillance.
The CJEU interpreted the scope of EU data-protection law in relation to systematic recording and processing of personal data. (Infocuria)
AI AML relevance
Modern AML systems can perform extensive behavioural monitoring:
transaction networks;
payment relationships;
geographical patterns;
device information;
behavioural indicators.
The same basic principle is important:
Automated monitoring involving personal data remains subject to data-protection law.
12. Case 8 — Digital Rights and Fundamental-Rights Proportionality
The AML framework also has to operate within the EU Charter of Fundamental Rights, particularly:
Article 7 — private and family life;
Article 8 — protection of personal data;
Article 16 — freedom to conduct a business;
Article 47 — effective judicial protection;
Article 21 — non-discrimination.
The Luxembourg Business Registers/Sovim judgment demonstrates how AML objectives can be limited where data-processing measures become disproportionate. (curia)
13. AI False Positives
One of the greatest problems is the false-positive AML alert.
Example:
A customer regularly receives:
€20,000 from overseas;
payments from several jurisdictions;
transfers involving crypto exchanges.
The AI system flags the customer.
But the customer is actually:
a legitimate international business;
an exporter;
a charity;
a multinational employee.
If the bank automatically closes the account, the consequences may include:
inability to receive salary;
inability to pay rent;
inability to pay suppliers;
inability to conduct business;
reputational harm.
Therefore:
High AML risk does not necessarily equal unlawful activity.
14. False Negatives
The opposite problem also exists.
An AI system may fail to detect:
sophisticated layering;
shell companies;
beneficial-owner concealment;
transaction splitting;
mule accounts;
synthetic identities.
Therefore, AI AML systems should not be treated as infallible.
A proper compliance framework should combine:
AI detection + human review + escalation + audit + periodic model testing.
15. Discriminatory AML Algorithms
An AML model can unintentionally correlate risk with:
nationality;
ethnicity;
religion;
geographic origin;
language;
immigration status;
socioeconomic characteristics.
Some characteristics may correlate statistically with particular financial risks, but that does not automatically make them lawful decision variables.
The AML Regulation specifically addresses this concern by stating that sensitive personal data should not be used as the sole basis for AML decisions where it is irrelevant to the actual ML/TF risk. (Eur-Lex)
16. Example of Algorithmic Discrimination
Suppose an AI system learns:
Customers from Country X = high risk.
It then:
requests additional documents;
delays transactions;
closes accounts.
But two customers have identical:
income;
business activity;
transaction history;
ownership structures.
The only significant difference is nationality.
That raises serious questions concerning:
necessity;
proportionality;
accuracy;
discrimination;
data minimisation;
individualised risk assessment.
17. Automated Account Closure
Account closure creates the most serious financial-access problem.
The sequence may be:
AI alert
↓
risk score
↓
automatic restriction
↓
account closure
↓
loss of access to financial services
The legal concern becomes much greater when there is:
no human review;
no meaningful explanation;
inaccurate data;
no correction mechanism;
no appeal;
no individualised assessment.
The Jenec judgment is particularly relevant because the CJEU emphasised individualised assessment before refusing a basic payment account on AML-related grounds. (Curia)
18. Human Review
Human review should not necessarily be purely formal.
For example:
Weak system
AI:
"High risk."
Human:
"I accept the algorithm."
Stronger system
AI:
"High risk because of transactions A, B and C."
Compliance officer:
checks the underlying transactions;
verifies customer explanations;
checks data accuracy;
examines alternative explanations;
assesses proportionality;
records reasons.
The second model provides stronger safeguards against automated error.
19. Right to Challenge
Where an AI AML decision materially affects financial access, the customer may need mechanisms to:
correct inaccurate information;
contest relevant data;
request human review where legally applicable;
seek supervisory review;
obtain judicial protection.
The Dun & Bradstreet judgment is important because it confirms the importance of meaningful information concerning automated decision-making. (Infocuria)
However, AML law creates an important qualification:
The customer does not necessarily have an unrestricted right to receive information that would reveal a suspicious transaction report or undermine AML investigations.
The AML Regulation expressly recognises this limitation. (Eur-Lex)
20. Explainability Problem
AML AI can be technically complex.
A bank may use:
neural networks;
graph neural networks;
anomaly detection;
behavioural models;
transaction embeddings;
network analysis.
The resulting risk score may be difficult to explain.
But financial access decisions can have significant consequences.
Therefore, the legal problem is:
How much explanation is required without exposing sensitive AML detection methods?
The solution is not necessarily disclosure of the source code.
Instead, meaningful explanation could concern:
relevant data categories;
important factors;
detected transaction patterns;
significant inconsistencies;
applicable risk indicators;
review procedure.
This is consistent with the reasoning reflected in Dun & Bradstreet. (Curia)
21. Data Accuracy
AI AML systems depend heavily upon data quality.
Incorrect data can come from:
outdated sanctions lists;
mistaken identity matching;
duplicated identities;
inaccurate corporate ownership records;
stale addresses;
false associations;
incorrect adverse-media matches.
The AML Regulation expressly emphasises accurate, reliable and up-to-date personal data. (Eur-Lex)
Example
John Smith is flagged because the algorithm matches him to:
"John Smith — suspected financial criminal."
But the database concerns a different person.
If the bank automatically closes John's account, the resulting decision may be based on fundamentally defective data.
22. Adverse Media Screening
AI systems increasingly search:
news articles;
court records;
websites;
social media;
corporate databases.
The problem is that:
An allegation is not necessarily proof of criminal conduct.
An AI system should distinguish between:
conviction;
charge;
allegation;
investigation;
civil dispute;
media report;
anonymous accusation.
Treating all adverse information as equivalent can generate unfair risk scores.
23. Beneficial Ownership and AI
AI can assist banks in identifying:
shareholders;
directors;
subsidiaries;
parent companies;
nominee structures;
ultimate beneficial owners.
This is important because criminals may hide ownership through complex corporate structures.
But Luxembourg Business Registers/Sovim demonstrates that beneficial-ownership transparency has limits imposed by fundamental rights. (curia)
Therefore:
more data ≠ automatically better AML compliance.
The data must be:
relevant;
necessary;
accurate;
lawfully processed.
24. Financial Inclusion
AML controls can unintentionally produce de-risking.
A bank may decide:
"This customer category is too risky."
It then refuses services to an entire group.
The new AML Regulation specifically recognises the importance of financial inclusion and states that certain higher-risk geographic circumstances should not, by themselves, automatically justify refusal or termination, particularly in relation to civil-society organisations; the risk-based approach requires assessment of the individual relationship and proportionate mitigation. (Eur-Lex)
This is highly relevant to AI.
An algorithm should generally assess:
individual risk
rather than simply:
category = prohibited.
25. Charities and Humanitarian Organisations
This issue is especially important where organisations operate in conflict or high-risk jurisdictions.
A crude AI model might calculate:
High-risk country + charity + cross-border transfers = extreme AML risk.
The legal framework, however, expects a more holistic and proportionate risk assessment. Regulation 2024/1624 expressly cautions against automatically refusing financial services to civil-society organisations solely because of activities in higher-risk jurisdictions. (Eur-Lex)
26. Sanctions Screening vs AML Screening
These are related but distinct.
Sanctions screening
Asks:
Is this person/entity subject to a relevant sanction?
AML screening
Asks:
Does the relationship or transaction present a money-laundering or terrorist-financing risk?
An AI system should not necessarily treat the two questions as identical.
This distinction is particularly important after Jenec, where the CJEU considered the consequences of a US sanctions-list inclusion for access to a basic payment account. (Curia)
27. AI Vendor Responsibility
Banks increasingly purchase AML systems from third-party vendors.
Possible vendors include:
transaction-monitoring providers;
sanctions-screening companies;
identity-verification platforms;
adverse-media providers;
AI analytics companies.
A contractual arrangement might state:
"The bank is responsible for all regulatory decisions."
That does not necessarily eliminate all legal issues involving the vendor.
The bank remains responsible for its regulatory compliance, as illustrated by the institutional-responsibility concerns addressed in Steiermärkische Bank. (Infocuria)
Potential contractual disputes can concern:
defective software;
inaccurate data;
excessive false positives;
inadequate documentation;
cybersecurity failures;
failure to update sanctions data;
model-performance failures.
28. AI Model Validation
A financial institution should test:
Accuracy
Does the system correctly identify suspicious transactions?
False positives
How many legitimate customers are flagged?
False negatives
How many suspicious activities are missed?
Bias
Does performance vary across customer groups?
Stability
Does the model continue to work after changes in transaction behaviour?
Explainability
Can compliance staff understand significant alerts?
Auditability
Can the institution reconstruct why the system generated the alert?
29. Model Drift
Criminal behaviour changes.
For example:
Old pattern:
Multiple cash deposits.
New pattern:
Crypto transfers + shell companies + digital payment platforms.
An AI model trained on old patterns may become ineffective.
Therefore AML systems need:
continuous monitoring;
retraining;
validation;
human oversight;
independent testing.
30. Fundamental Rights Balancing
The central legal balance is:
Public interest
Prevent:
money laundering;
terrorism financing;
sanctions evasion.
Individual interests
Protect:
privacy;
personal data;
non-discrimination;
financial access;
reputation;
property interests;
effective judicial protection.
The Luxembourg Business Registers/Sovim judgment demonstrates that even important AML objectives do not permit unlimited interference with fundamental rights. (curia)
31. Direct and Analogical Case-Law Table
| Case | AML connection | AI relevance |
|---|---|---|
| Jenec, C-81/24 (2026) | Direct AML/payment-access case | Individualised risk assessment |
| Steiermärkische Bank, C-291/24 (2026) | Direct AML enforcement case | Institutional responsibility |
| Luxembourg Business Registers & Sovim, C-37/20 & C-601/20 | Direct AML/data case | Privacy and proportionality |
| Commission v Ireland, C-550/18 | Direct AML implementation case | Regulatory compliance |
| SCHUFA, C-634/21 | Credit scoring | Automated financial decisions |
| Dun & Bradstreet, C-203/22 | Automated scoring | Explanation and contestability |
| Ryneš, C-212/13 | Data surveillance | Automated monitoring/data protection |
The first four are particularly useful for AML law itself; the SCHUFA and Dun & Bradstreet cases are especially valuable for the AI decision-making dimension.
32. Legal Test for an AI AML Financial-Access Decision
A court or regulator could examine the following sequence.
Step 1 — Legal basis
Was there a legitimate AML/CFT or sanctions basis for processing the data?
Step 2 — Data quality
Was the information:
accurate?
current?
reliable?
relevant?
Step 3 — Risk assessment
Was there an individualised assessment?
Step 4 — Automated decision
Did AI materially determine the outcome?
Step 5 — Human intervention
Was meaningful human review available where required?
Step 6 — Explanation
Could the affected person understand enough to challenge an erroneous decision, subject to AML confidentiality restrictions?
Step 7 — Proportionality
Was refusing or terminating financial access necessary and proportionate?
Step 8 — Non-discrimination
Did irrelevant protected or sensitive characteristics influence the decision?
Step 9 — Remedy
Could the customer challenge inaccurate data or an unlawful decision?
33. Hypothetical Example
Facts
A bank deploys an AI AML system.
The system assigns a customer:
AML Risk Score: 97/100
because:
the customer receives international payments;
some counterparties are in high-risk jurisdictions;
the customer previously had an adverse-media match;
the customer's name resembles a person on a sanctions list.
The bank automatically freezes the account.
Legal problems
Problem 1 — Identity matching
Is the sanctions match actually the same person?
Problem 2 — Data accuracy
Is the adverse-media information accurate?
Problem 3 — Individual assessment
Were the customer's actual activities considered?
Problem 4 — Automated decision
Did the algorithm effectively make the decision?
Problem 5 — Financial access
Does the customer have a legal entitlement to the relevant payment service?
Problem 6 — Explanation
Can the customer challenge the decision?
Problem 7 — Proportionality
Would enhanced monitoring have achieved the AML objective without complete account closure?
The reasoning in Jenec, SCHUFA, and Dun & Bradstreet becomes particularly relevant. (Curia)
34. Remedies
Possible remedies can include:
correction of inaccurate personal data;
renewed individualised assessment;
human review;
lifting an unjustified restriction;
reopening an account where legally required;
supervisory intervention;
administrative penalties;
compensation under applicable law;
judicial review;
injunctions;
contractual remedies.
The precise remedy depends on the applicable EU and national legal framework.
35. Core Legal Principle
The emerging European approach can be summarised as:
AML obligations justify sophisticated risk detection, but they do not automatically justify opaque, inaccurate or indiscriminate AI-based exclusion from financial services.
The strongest current authority is Jenec, because it directly connects AML risk assessment with access to a basic payment account. The Court's insistence on individualised assessment is particularly important for automated systems. (Curia)
At the same time, SCHUFA and Dun & Bradstreet show how European data-protection law treats automated scoring when it materially affects an individual, while Luxembourg Business Registers/Sovim demonstrates the fundamental-rights limits applicable even to AML-related data processing. (Infocuria)
36. Conclusion
AI AML systems are legally permissible and increasingly important, but their use creates a new financial-access problem.
The central issue is the transition from:
AI as a compliance-support tool
to
AI as a gatekeeper of financial access.
Once an AI system can determine whether someone may:
open a bank account;
receive payments;
transfer money;
maintain a banking relationship;
access financial services,
its legal significance becomes much greater.
European law therefore requires a balance between:
AML effectiveness + financial security
and
privacy + accuracy + proportionality + non-discrimination + financial inclusion + effective remedies.
The most important cases to remember are:
Jenec, C-81/24 — individualised AML assessment before refusal of basic payment access.
Steiermärkische Bank, C-291/24 — institutional responsibility for AML compliance.
Luxembourg Business Registers & Sovim, C-37/20 and C-601/20 — AML transparency limited by fundamental rights.
Commission v Ireland, C-550/18 — enforcement of Member-State AML obligations.
SCHUFA, C-634/21 — automated scoring and Article 22 GDPR.
Dun & Bradstreet Austria, C-203/22 — meaningful information concerning automated decision-making.
Ryneš, C-212/13 — limits on automated personal-data surveillance.
Exam Keywords
AI AML – transaction monitoring – automated decision-making – profiling – Article 22 GDPR – AML Regulation 2024/1624 – Directive 2015/849 – customer due diligence – enhanced due diligence – sanctions screening – suspicious transaction – financial access – basic payment account – de-risking – false positives – false negatives – algorithmic discrimination – explainability – human review – data accuracy – beneficial ownership – financial inclusion – proportionality – Charter Articles 7, 8, 21 and 47 – Jenec – SCHUFA – Dun & Bradstreet – Luxembourg Business Registers – Steiermärkische Bank.

comments