A new survey from ComplyAdvantage, drawing on 200 senior compliance leaders across the UK and France, finds that over 9 in 10 are confident upcoming AI regulation will effectively mitigate the risks that matter most: decision explainability, deepfake fraud, algorithmic bias, and governance standards. That's a striking level of confidence in rules that, in most cases, haven't been finalized yet.
It sits next to a second, less comfortable finding in the same report: while investment in AI across financial crime compliance is now near-universal, a significant gap remains between the intent to use the technology and the ability to govern it, and much of the market still lacks established assurance programs. Confidence in the destination and readiness for the journey are not the same thing, and this survey is one of the clearer pieces of evidence yet that the gap between them is real.
The report draws a distinction worth pondering: trusting that a regulatory framework will work is a different thing entirely from demonstrating, inside your own firm, that your own controls do. A regulator asking why an alert was closed, why a customer was cleared, or why a payment was allowed through doesn't accept confidence in the rulebook as an answer. It wants the specific decision trail.
The report's own warning is direct: firms most confident that incoming regulation covers them may be the least prepared for that scrutiny, if they haven't done the harder work of documenting what their own systems did, and why. Confidence in a future rule is not evidence of a present control. Those are two different assets, and only one of them holds up under examination.
Eighty-eight percent of organizations say including AI in a compliance modernization proposal increases the likelihood of approval and funding, rising to 95% among UK firms specifically. That's a genuine signal of market trust in the technology. It's also, per the report's own analysis, a structural risk: once the market believes AI reliably unlocks budget, the incentive to include it grows whether or not it's the right answer to the problem at hand, and investment cases built primarily around AI as an approval mechanism tend to create governance gaps later, with tools deployed because they cleared the budget process rather than because the firm understood what it was deploying them to do.
That's a governance failure mode that has nothing to do with whether the underlying AI works. A tool selected to win a budget argument doesn't automatically come with a plan for who monitors what it's actually doing once it's live.
Ninety-seven percent of European firms rely on two or more separate systems for customer screening alone, and 42% are running between eight and ten disconnected systems that don't share a common view of the customer. When a supervisor asks a firm to reconstruct how a specific decision was reached, a fragmented screening architecture is harder to evidence, audit, and defend than a unified one, according to the report, regardless of how sound each individual system is in isolation.
That's the same problem showing up at a different layer: even firms doing genuine monitoring work often can't easily produce a single, coherent account of it, because the evidence is scattered across tools that were never built to talk to each other.
None of this is specific to AML or to Europe. It's the same structural problem showing up everywhere compliance and risk functions rely on AI or third-party systems: a credential, an approval, or a confident policy position is not the same thing as continuous, evidenced proof that controls are actually working in real time. Open finance accreditation has the identical failure issue when it stops at onboarding. Vendor certification has it when a single assessment gets treated as a permanent clearance. AI governance has it, per this survey, when confidence in future regulation substitutes for present-day documentation.
The fix looks the same in every version of the problem: continuous monitoring and evidencing built in from the start, not assembled retroactively the first time a regulator asks a hard question.
See how the Invela Network applies standardized accreditation paired with continuous risk monitoring, so proof of control is available before a regulator has to ask for it.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place. Open finance, covered.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.