6 min read

Building Resilient Frameworks (Part 3 of 3)

Published on
March 27, 2026
Share

The 2026 Compliance Landscape (Part 3 of 3)

Criminal enterprises are deploying AI more effectively than most compliance functions.

This is not exaggeration. This is the 2026 operating environment.

This concludes our series on the 2026 compliance landscape. Part 1 addressed the regulatory shift — FATF’s proportionality mandate, enforcement divergence, and compressed remediation timelines. Part 2 examined the liability revolution — fraud reimbursement obligations, stablecoin regulation, and ESG fragmentation.

Part 3 focuses on the technology dimension and its human consequences.

1. The AI Governance Imperative

In 2025, generative AI remained largely experimental in compliance contexts. That phase has concluded.

Agentic AI — systems capable of autonomous multi-step task execution, decision-making, and action — now operates within over 70% of major financial institutions. Applications include automated transaction monitoring, intelligent case management, and real-time risk assessment.

Governance frameworks have not maintained pace with deployment.

Fundamental questions remain unresolved: accountability, explainability, bias. When an AI system flags or fails to flag a transaction, where does responsibility reside? When algorithms encode historical biases that exclude vulnerable populations from financial services, who bears accountability?

The adversarial dimension compounds these concerns.

Sophisticated fraud operations now leverage AI capabilities that frequently exceed those available to compliance teams. Pig butchering scams, synthetic identity fraud, and deepfake-enabled social engineering have scaled industrially.

The same AI capable of drafting compliance policies can generate thousands of personalised scam messages. The same voice cloning enabling accessibility features enables CEO fraud. The capability asymmetry is substantial and widening.

Operational Implications:

• AI Governance as Differentiation: Organisations establishing robust AI governance frameworks — clear accountability, explainability standards, bias testing — position themselves advantageously as regulation matures. The EU AI Act is operational; other jurisdictions will follow.

• Defensive AI Investment: The capability race is real but winnable. Institutions investing in AI-powered fraud detection, behavioural analytics, and anomaly detection can match and exceed criminal capabilities. Speed of adoption is critical.

• Human-AI Integration: The most effective models are not fully automated. They combine AI pattern recognition with human judgement. Systems should augment analysts, not replace them.

Risk Considerations:

• The Governance Deficit: Deploying AI without governance deploys risk. Every AI system requires clear ownership, documented decision logic, and regular bias audits.

• Vendor Opacity: Many institutions rely on third-party AI solutions without understanding underlying models. When regulators inquire how a system reached a decision, “the vendor manages that” will not constitute an acceptable response.

• Automated Exclusion: AI trained on historical data can perpetuate historical exclusion. Models flagging entire demographic groups as “high risk” do not manage risk — they encode discrimination.

2. Cybercrime Professionalisation and the Corruption Nexus

Cybersecurity threats have evolved beyond traditional criminal enterprise models.

Certain nation-states now actively partner with criminal organisations, blending geopolitical objectives with financial crime. Ransomware, extortion, and data theft serve both profit and statecraft.

The enabling factor often overlooked: corruption.

Scam compounds across Southeast Asia do not operate independently. They require protection from local officials, law enforcement, and border agents. Journalists and NGOs working to expose these operations frequently investigate the same networks enabling cybercrime proliferation.

When corrupt acts are suppressed faster than they can be documented, criminal enterprises flourish. Cybercrime professionalisation is not exclusively a technology narrative. It is a governance narrative. An accountability narrative. A corruption narrative.

Operational Implications:

• Integrated Threat Intelligence: Eliminate silos between cybersecurity, fraud, and AML functions. Networks launching ransomware attacks launder proceeds through payment systems. Integrated intelligence enables integrated response.

• Public-Private Collaboration: Coalitions addressing transnational cybercrime — including those formed through GASA and GCFFC — demonstrate collective action effectiveness. Institutions participating in information-sharing access threat intelligence unavailable through independent efforts.

• Corruption as Threat Indicator: Understanding the corruption enabling cybercrime helps predict threat emergence. Jurisdictions with weak governance and compromised enforcement incubate subsequent attack waves.

Risk Considerations:

• Geopolitical Exposure: Financial institutions increasingly operate within nation-state conflicts. Sanctions, counter-sanctions, and cyber operations create operational and reputational risks extending beyond commercial considerations.

• Third-Party Vulnerabilities: Institutional cybersecurity is constrained by the weakest vendor. Supply chain attacks targeting software providers to reach clients are escalating. Third-party risk management must incorporate cyber resilience.

• The Human Vector: Sophisticated technical controls can be bypassed by a single employee clicking a phishing link or a single insider with compromised loyalties. Social engineering remains the primary attack vector. Training and culture matter as much as technology.

3. RegTech Acceleration

Pressure to achieve more with constrained resources has accelerated RegTech adoption.

Real-time payment monitoring, no-code compliance platforms, and AI-driven automation are becoming standard rather than aspirational. The question has shifted from whether to invest in RegTech to how to select, implement, and govern these solutions effectively.

The value proposition is genuine: technology enabling smaller institutions to maintain robust compliance without global bank headcount. Technology processing in seconds what analysts require days to complete. Technology identifying patterns invisible to human review.

Technology is not neutral, however.

RegTech solutions encode assumptions about risk, behaviour, and financial services access eligibility. Without careful governance, automation risks encoding exclusion — building systems that are efficient but inequitable.

Operational Implications:

• Compliance Democratisation: RegTech can equalise capabilities. Smaller institutions and emerging market participants can now access capabilities previously exclusive to global banks. This expands competition and, ultimately, financial inclusion.

• Proportionate Controls: FATF’s proportionality mandate requires risk-based approaches. RegTech enables this — applying appropriate friction based on actual risk rather than blanket restrictions excluding legitimate customers.

• Real-Time Capability: The liability framework from Part 2 demands speed. When institutions bear responsibility for reimbursing fraud victims, real-time detection and intervention becomes essential. RegTech makes real-time response achievable.

Risk Considerations:

• Implementation Without Strategy: RegTech is a tool, not a solution. Deploying technology without clear objectives, integration planning, and change management creates expensive shelfware.

• Data Quality Dependency: AI and automation quality depends on underlying data quality. Before investing in sophisticated analytics, ensure data is accurate, complete, and accessible.

• The Inclusion Assessment: Every RegTech implementation should be evaluated against inclusion outcomes. Does this technology expand access or restrict it? Does it apply proportionate controls or blanket exclusion? Answers should inform deployment decisions.

The Human Dimension

Every trend in this series — fraud liability, AI governance, regulatory fragmentation, cybercrime escalation, corruption — produces the same downstream impact.

It affects the individual who loses retirement savings to a romance scam. The migrant worker whose remittance corridor closes because institutions cannot manage the risk. The small business owner in an emerging market denied basic financial services because compliance costs render them “unprofitable.” The journalist risking personal safety to expose the corruption enabling these systems.

Sophisticated frameworks that fail to protect the people the financial system is designed to serve accomplish little of lasting value.

Framework Requirements for 2026

The 2026 compliance landscape requires frameworks that are:

• Resilient: capable of withstanding regulatory fragmentation, enforcement divergence, and geopolitical volatility

• Integrated: eliminating silos between fraud, AML, cybersecurity, and anti-corruption functions

• Proportionate: applying controls based on actual risk, not blanket restrictions

• Inclusive: expanding financial services access while protecting against abuse

• Adaptive: evolving with threats, with governance frameworks maintaining pace with technology adoption

Strategic Assessment

Part 1 documented a regulatory landscape in transition — FATF requiring proportionality while enforcement fragments across jurisdictions. Part 2 revealed the liability revolution — fraud reimbursement rules, stablecoin formalisation, and ESG divergence reshaping accountability when failures occur.

Part 3 addresses the operational front: the AI capability race, the corruption-enabled cybercrime ecosystem, and RegTech acceleration that could either democratise compliance or automate exclusion.

The connecting element: human impact.

Every compliance failure produces victims. Every framework either protects or excludes real people.

The 2026 compliance landscape extends beyond regulatory risk management or enforcement avoidance. It concerns building financial systems that serve their intended purpose.

The technology exists. The regulatory direction is established. The question is whether organisations will build frameworks robust enough to stop criminals and inclusive enough to serve

Table of Contents

More Insights

6 min read
29 min read