Book a Discovery Call

A Turning Point in EU Anti–Money Laundering Regulation

Executive Summary

Moran Wilf
Moran Wilf

Regulatory Affairs Manager, ThetaRay

As of publication, the European Union has enacted its most transformative anti-money laundering (AML) reform in more than three decades—marking a decisive shift from fragmented oversight to a unified, enforceable regulatory framework. The newly ratified EU AML Package—including the EU AML Regulation (AMLR), the sixth Anti-Money Laundering Directive (AMLD6), the Revised Transfer of Funds Regulation (TFR II), and the creation of the EU Anti–Money Laundering Authority (AMLA)— standardizes compliance obligations across Member States1 and significantly expands the perimeter of supervision.

Key provisions, such as the EU AMLR’s direct applicability from 10 July 2027 and AMLA’s operational launch in mid-2025, remain on track (no formal changes to these milestones have been announced). However, since May 2024, the European Banking Authority (EBA) and European Commission have issued additional guidance on AMLR implementation, technical standards for beneficial ownership verification, and preparatory supervisory methodologies for AMLA’s first phase of oversight.

These developments signal accelerating regulatory readiness and give institutions more clarity on expectations well before enforcement dates.

For financial institutions, this marks a watershed moment. Supervisory expectations are rising. Reporting deadlines are tightening. And new rules now apply to entities that previously sat outside the formal regulatory perimeter.

But this is more than a compliance challenge. It’s a strategic inflection point—one that invites institutions to reimagine how they detect risk, scale controls, and integrate AML into business continuity and market trust.

In a financial ecosystem being reshaped by real-time payments, embedded finance, and crypto-fueled flows, AML reform offers an opportunity to modernize how institutions detect risk, scale controls, and embed compliance into operational and reputational resilience.

01
Key Pillars of the EU AML Package

A Single EU Rulebook (EU AMLR)

Regulation (EU) 2024/1624—commonly referred to as the EU AMLR—replaces the current system of AML Directives with directly applicable regulation. It enters into force on 10 July 2027, ensuring that the same rules apply across all EU Member States without the need for national transposition2. All obliged entities—including banks, PSPs, fintechs, crowdfunding platforms, and crypto-asset service providers—must implement the same due diligence procedures, reporting formats, and ownership verification practices across borders.

Key components include:

  • l Harmonized customer due diligence (CDD) procedures
  • l Standardized thresholds for beneficial ownership disclosure (25%+ ownership threshold)
  • l Designation of crypto and crowdfunding platforms as fully regulated obliged entities2

For institutions operating across multiple jurisdictions, this presents both complexity and clarity. Compliance frameworks must be realigned to meet common standards, while workflows and data architectures must support consistent monitoring and escalation procedures.

Establishment of AMLA

At the heart of the AML Package is the new EU Anti–Money Laundering Authority (AMLA). Headquartered in Frankfurt and operational from 2025, AMLA will directly supervise up to 40 high-risk financial institutions by 20283
. It will also coordinate Financial Intelligence Units (FIUs) and develop EU-wide supervisory methodologies.

What it means:

  • l Thematic inspections and direct oversight of systemically important institutions
  • l Stricter demands for explainability, model governance, and cross-border risk transparency4
  • l Higher expectations for real-time collaboration and escalation between institutions and regulators

This shift will push institutions to evolve from rule-checking into intelligence-led compliance—capable of adapting dynamically, justifying decisions clearly, and collaborating at scale.

Beneficial Ownership: Active Verification, Not Passive Reliance

To combat the misuse of complex legal entities, the AML Package enforces stricter controls on Ultimate Beneficial Ownership (UBO) verification. Static declarations are no longer enough5 —institutions must proactively validate ownership chains, assess risk signals, and reconcile discrepancies in real time.

National registers will be linked via the European Beneficial Ownership Register (EBOR), granting authorities live access to cross-border ownership data. Compliance systems must be able to surface discrepancies early—particularly in layered, cross-jurisdictional relationships.

Tighter Reporting Standards and Cash Restrictions

The EU AML Package significantly raises the bar for responsiveness and reporting precision. The AMLR imposes a five-working day deadline to financial intelligence units (FIUs) requests for information, while institutions are required to submit Suspicious Activity Reports (SARs) in a timely, standardized format.

Notably, while PS24/17 does not prescribe a fixed timeline for responding to Financial Intelligence Unit (FIU) requests, its emphasis on proportionality, governance, and explainability aligns with the EU AMLR’s focus on timely and precise reporting. Both frameworks create a consistent supervisory expectation across EU and non-EU jurisdictions for robust, well-documented, and prompt engagement with financial crime authorities.

This is not simply a matter of filing faster—it’s about producing clearer, higher-quality intelligence at speed, across increasingly complex transaction types and financial channels.

In parallel, additional enforcement mechanisms are being introduced:

  • l Cash transaction limits are now capped at €10,000, with ID verification required for cash payments over €3,000.
  • l Crypto exchanges and custodial wallet providers are formally recognized as obliged entities, bringing digital assets under the same scrutiny as traditional finance.

To meet these demands, institutions will require:

  • l Centralized investigative dashboards for end-to-end visibility
  • l Integrated case management systems to streamline SAR processing
  • l Scalable alerting and GenAI-powered summarization tools to accelerate decision-making and reporting

Together, these capabilities enable not just compliance, but faster intervention and stronger risk containment in real time.

Recommended Actions

Priority Area Recommended Steps

Beneficial Ownership

Standardize collection and verification processes; integrate with EBOR interfaces

Monitoring Infrastructure

Evaluate existing systems; invest in AI or anomaly-based detection for real-time risk

Cross-Border Consistency

Reconcile and harmonize AML practices across EU branches and subsidiaries

Regulatory Engagement

Establish internal working groups to track AMLA guidance and cross- border cooperation. UK firms should review alignment with PS24/17 updates — particularly around enhanced sanctions governance, AI-driven transaction monitoring, cryptoasset inclusions, and embedding Consumer Duty into financial crime frameworks.

02
Implications for Compliance Programs

1

Harmonization Is Non–Negotiable With the EU AMLR taking precedence over national laws, businesses must reassess and standardize their policies across Member States. Fragmented group-level compliance approaches will no longer be tenable.

2

Broader Scope and Stricter Controls Entities previously exempt—such as crowdfunding platforms and crypto-asset service providers—are now directly obliged. These sectors must immediately assess their exposure and begin aligning with core AML obligations.

3

Accelerated Response Requirements Obligated entities are required to respond to requests for information from a Financial Intelligence Unit (FIU) within five working days. If justified and for urgent cases, an FIU can shorten this deadline to less than 24 hours.

4

Heightened Supervision Institutions identified as systemically important across the EU should prepare for direct oversight by AMLA, including thematic reviews, intrusive audits, and data-sharing protocols with other regulators.

03
What a Future-Ready AML Program Looks Like

The future of AML compliance demands a bold transformation: a unified, intelligence-led operating model that embeds advanced technologies, streamlines decision-making, and turns compliance into a source of strategic strength.

By 2026–2027, the most resilient and high-performing AML programs will share a common architecture and mindset defined not just by regulatory alignment, but by efficiency, agility, and trust. Here’s what that future-ready AML operating model looks like:

AI at the Core of Detection, Not a Peripheral Tool
In the future, artificial intelligence isn’t bolted on after alerts are generated, it becomes the first line of defense. AI sits at the core of the detection layer, dynamically scoring risk, identifying unknown typologies, and filtering out low-risk noise before an analyst ever gets involved. This proactive model ensures that investigators focus on relevant, high-risk activity and that systems evolve in step with emerging threats.

Unified Compliance Infrastructure
No more silos. A future-ready AML platform consolidates screening, transaction monitoring, customer risk assessment, and sanctions controls into a single, seamlessly integrated system. Analysts no longer have to toggle between tools or re-enter case data. With unified data flows and centralized alert management, compliance teams gain a 360° view of customer activity and risk exposure, reducing redundancy and accelerating time to resolution.

SARs Filed in Hours, Not Days
Suspicious Activity Reports (SARs) become faster, sharper, and more consistent. Thanks to GenAI-powered narrative generation, investigators can convert high-quality alerts into regulator-ready reports within hours, not days. Automated pre-filling, embedded case links, and smart summarization tools drastically reduce filing time and increase the quality and clarity of submitted reports, while freeing up analyst capacity.

Real-Time Alert Prioritization in Analyst Workflows

In the target operating model, alert queues are no longer sorted by chronology or static rules. AI-driven prioritization ranks alerts based on behavioral risk, customer context, and typology patterns in real time. Analysts receive intelligent workflows that adapt based on historical decisions, case sensitivity, and operational load, leading to faster, more consistent decisions.

Executive-Level Oversight and Transparency

Compliance is no longer buried deep in the second line—it surfaces to the boardroom. A future-ready AML program includes global dashboards that visualize program performance, risk concentrations, response times, and regulatory KPIs. These insights empower C-level leaders and board members to track AML effectiveness, allocate resources strategically, and demonstrate control to external stakeholders.

Audit-Ready Explainability by Design

As regulatory expectations rise globally, transparency in how alerts are generated and resolved will no longer be optional. AML systems must be designed with
built-in explainability, clearly showing why a transaction was flagged, how decisions were made, and what data influenced the outcome. Institutions will need to demonstrate full traceability across detection logic, risk scoring, and investigative workflows to satisfy auditors and supervisors alike.

04
From Reactive to Resilient: A Strategic Shift

This is more than a technology upgrade, it’s a cultural and operational shift. Institutions that embrace this model are no longer reacting to alerts, chasing backlogs, or relying on legacy vendors to plug gaps. Instead, they are building adaptive, high-trust compliance programs that scale with business growth and respond dynamically to a shifting threat landscape.

Institutions that follow this model aren’t just meeting today’s standards, they’re building resilience against tomorrow’s complexity. This is the AML operating model of the future. And for institutions willing to act now, there are tangible returns:

Operational Efficiency

Traditional compliance teams often find themselves buried under a sea of alerts, the vast majority of which are false positives. Manual triage processes are slow, inconsistent, and expensive. AI brings speed and precision to these operations—automatically filtering out low-risk transactions, clustering related alerts, and assigning priority scores based on real-time behavioral insights. The result is a leaner investigative pipeline, faster resolution of cases, and a significant reduction in wasted analyst time. Compliance teams can focus on decision-making rather than data wrangling.

Deeper Risk Coverage

Criminals are becoming more sophisticated, using techniques that often fall outside of predefined rule sets—such as layering funds through microtransactions, using shell entities, or leveraging cross-border digital wallets. AI excels at identifying these subtle and evolving risk patterns. Unlike static systems that flag only known threats, AI can detect anomalous behaviors, discover hidden relationships between entities, and adapt to changing typologies. This expands an institution’s defensive capabilities, improving both detection and deterrence.

Reputational Protection

Regulatory fines for AML failures routinely reach into the hundreds of millions—and the reputational damage can be even more costly. AI not only improves detection but also enhances the quality of suspicious activity reports (SARs), supporting clearer narratives, more accurate risk indicators, and timelier submissions. Perhaps most importantly, AI platforms can be designed with explain ability and traceability in mind—offering regulators a transparent view into how decisions are made. This fosters regulatory trust, improves audit outcomes, and minimizes enforcement risk.

Strategic Agility

In a fast-moving financial ecosystem, compliance can either be a drag on innovation or a catalyst for growth. Institutions that leverage AI in AML programs are better equipped to scale into new markets, onboard fintech partners, and launch new digital services—without compromising their risk posture. Whether it’s entering a high-risk region, integrating crypto flows, or scaling real-time payments, AI-enabled compliance delivers the agility and confidence required to support business expansion. By reframing AML not as a regulatory burden but as a source of strategic advantage, AI shifts the compliance function from reactive to proactive. Institutions that invest now are setting the foundation not just for today’s regulatory demands—but for tomorrow’s opportunities. In this way, AI isn’t just a compliance tool—it’s a driver of performance, resilience, and growth.

At ThetaRay, we view this regulatory scrutiny as a turning point for compliance maturity. Our Cognitive AI-native
platform is designed from the ground up to help financial institutions easily meet the demands of the new
regulatory landscape with agility to adjust to changes.

ThetaRay’s Key Capabilities

1

Risk-Based Transaction Monitoring

ThetaRay leverages Cognitive AI at the detection layer to uncover subtle, complex risks that traditional rule-based systems overlook. Built for AMLA’s intelligence-led, risk-based approach, our platform continuously surfaces evolving threats and sophisticated behavioral patterns missed by legacy tools.

2

Cross-Border Payment Surveillance

ThetaRay delivers deep visibility into high-volume, cross-border transaction flows, including, but not limited to, SWIFT and SEPA networks. We help institutions meet AMLA’s enhanced due diligence requirements for correspondent relationships, tracing full transaction chains across jurisdictions for comprehensive risk oversight.

3

Explainability & Auditability

Our AI models are transparent and fully explainable giving analysts, auditors, and regulators clear visibility into how risk was detected and why an alert was triggered. We offer full traceability, displaying the impact details for each feature on the detected alert, and documentation for each step, decisions, and parameters in the process, making audit-readiness inherent, not an afterthought.

4

Dynamic Risk Scoring

Risk scoring dynamically adjusts in response to behavioral patterns and emerging typologies, helping compliance teams maintain alignment with evolving threats and supervisory expectations.

5

Multijurisdictional SAR Reporting

Ability to support regulatory reporting requirements for multiple jurisdictions under a single umbrella with e-Filing capabilities e.g. goAML (with a roadmap for specific countries), streamlining SAR submissions and standardizing compliance operations globally.

6

Dynamic Risk Scoring

ThetaRay’s solution significantly reduces false positives while increasing effectiveness in identifying truly suspicious transactions. Our GenAI-powered alert summaries also help accelerate investigation timelines. The result: improved operational efficiency,faster investigations, and more timely, accurate SAR filings.

7

Multijurisdictional SAR Reporting

Ability to support regulatory reporting requirements for multiple jurisdictions under a single umbrella with e-Filing capabilities e.g. goAML (with a roadmap for specific countries), streamlining SAR submissions and standardizing compliance operations globally.

8

Unified Compliance Platform

ThetaRay’s Screening, Transaction Monitoring, and Customer Risk Assessment capabilities operate from a single, integrated platform. This unified foundation ensures seamless data flow, centralized alert management, and faster time to value—without the complexity of stitching together siloed systems.

05
Conclusion

The EU AML Package represents a landmark in the evolution of financial crime regulation—signaling the end of fragmented frameworks and the beginning of a unified, intelligence-driven regime. As of publication, the core milestones remain unchanged: AMLA is expected to become operational in mid-2025, and the AMLR and AMLD6 will be fully enforceable from 10 July 2027. No official delays or amendments have been announced.

Since May 2024, the European Banking Authority (EBA), European Commission, and national regulators have issued further guidance and draft technical standards to assist institutions in preparing for these obligations. This includes detailed supervisory methodology proposals from AMLA, clarifications on beneficial ownership verification under EBOR, and early-stage alignment discussions with the EU’s forthcoming AI Act—highlighting the importance of governance and explainability in technology-enabled compliance.

The reforms set higher expectations for speed, transparency, governance, and the integration of advanced detection technologies. Institutions are now required to verify ownership actively, monitor risk across both digital and fiat channels, and respond to regulatory requests in near real time. Traditional, siloed approaches—manual alert review, static rule sets, and disconnected systems—are no longer sustainable.

The white paper has outlined not only the scope of regulatory change but also the opportunities it brings. Forward-thinking institutions are already designing operating models; from the integration of AI at the core of detection, to unified compliance infrastructures and board-level risk oversight This transformation is as much cultural as it is technological, requiring leadership buy-in, cross-functional collaboration, and the redefinition of compliance as a driver of trust and innovation rather than a regulatory cost.

The AML landscape is evolving rapidly, but so too is the opportunity to lead. Institutions that act now— leveraging the clarity of updated guidance, adopting advanced capabilities, and embedding resilience into their compliance DNA—will not only meet the letter of the new rules but set the benchmark for what strong AML looks like in the decade ahead.

Glossary

AMLA (Anti–Money Laundering Authority)
A new EU-level supervisory body established under the AML Package. Based in Frankfurt and operational from 2025, AMLA will directly oversee high-risk financial institutions and coordinate AML efforts across Member States.

AMLD6 (6th Anti–Money Laundering Directive)
Part of the EU AML Package, AMLD6 outlines criminal law provisions, sanctions, and rules for cooperation between Financial Intelligence Units (FIUs) and other supervisory authorities.

AML (Anti–Money Laundering)
A framework of laws, regulations, and procedures designed to detect and prevent the movement of illicit funds, including those derived from criminal activity or terrorism financing.

CDD (Customer Due Diligence)
A key AML obligation requiring financial institutions to verify the identity of customers, assess risk, and understand the nature and purpose of business relationships. Enhanced measures may apply to high-risk clients.

CASPs (Crypto-Asset Service Providers)
Entities offering exchange, custody, or other services related to crypto-assets. Under the AML Package, CASPs are formally designated as obliged entities and subject to the same AML obligations as traditional financial institutions.

EBA (European Banking Authority)
An EU regulatory agency responsible for developing technical AML standards, guidelines, and supervisory frameworks. It plays a central role in ensuring consistent application of AML/CFT rules across the EU financial system.

EBOR (European Beneficial Ownership Register)
An interconnected EU-wide system that consolidates national registers of beneficial ownership. It is designed to provide transparency into ownership structures and facilitate AML supervision across borders.

EU AMLR (European Union Anti–Money Laundering Regulation)
A directly applicable regulation under the AML Package that harmonizes AML/CFT obligations across all EU Member States. Effective from July 2027, it replaces the patchwork of national laws with a single, unified framework.

FIU (Financial Intelligence Unit)
A national authority responsible for receiving, analyzing, and disseminating information about suspiciousfinancial activity. In the EU, FIUs play a central role in the SAR process and cooperate with AMLA and law enforcement.

KYC (Know Your Customer)
A process by which financial institutions identify and verify customer identities, assess risks, and ensure compliance with AML requirements. It is a foundational element of due diligence and ongoing monitoring.

PSP (Payment Service Provider)
Firms that provide digital payment services such as money transfers or embedded finance. Many PSPs are now within the regulatory scope of the AMLR and must implement risk-based AML controls.

SAR (Suspicious Activity Report)
A report submitted to an FIU when a financial institution identifies unusual or suspicious transactions that may indicate money laundering or terrorism financing. Under the AML Package, SARs must be standardized and timely.

TFR II (Transfer of Funds Regulation II)
An updated EU regulation that applies the FATF’s “travel rule” to crypto transactions, requiring the exchange of originator and beneficiary information to improve transparency in virtual asset transfers.

UBO (Ultimate Beneficial Owner)
The individual(s) who ultimately owns or controls a legal entity. EU regulations mandate active verification of UBO data, and entities must report this information to national registers linked via EBOR.

WTR II (Wire Transfer Regulation II)
Another name for the Transfer of Funds Regulation II, aligning with FATF travel rule standards for fiat and crypto transfers. It ensures traceability of funds across payment systems.

Sources:
1 European Council press release, “Anti-money laundering package: Council adopts new rules to strengthen EU framework”, 30 May 2024
2 Regulation (EU) 2024/1624, Official Journal of the European Union, L 2024/1624
3 European Parliament press release, “EU agrees to establish new Anti-Money Laundering Authority”, 18 April 2024
4 Deloitte Legal (2024): “EU AML Package – A Turning Point in Financial Crime Prevention.”
5 European Commission AML Package overview, “Strengthening the EU’s AML/CFT framework”, 20 July 2021
6 Regulation (EU) 2024/1625 and Directive (EU) 2024/1626, AML Package, Official Journal of the EU