AI in KYC: Where it provides support and where its limits remain
As of: September 2026
Potential applications, limitations and legal framework
Artificial intelligence can support KYC and AML processes, particularly in information-intensive, preparatory tasks. These include extracting data from documents, verifying information, processing screening results, and creating a structured summary of an audit case. Whether this translates into reliable benefits depends on the quality of the data, the system design, and the implemented controls.
An AI application does not replace reliable sources or expert evaluation. Its results should be understood as a working tool that is reviewed and classified by responsible employees.
Typical applications of AI in KYC and AML processes
KYC and AML processes regularly require the consolidation of information from various sources. Tasks involving the review, comparison, and structuring of large volumes of data or documents for further processing are particularly well-suited for AI support.
Possible areas of application include:
- Compare documents and data: Depending on its technical design, a system can extract information from register extracts, shareholder lists, or customer documents and display discrepancies in names, addresses, legal forms, or shareholding percentages. A detected discrepancy is initially a warning signal and not yet proof of an error.
- Processing screening results: AI can help group hits, include name variations, and prioritize potentially relevant results. However, the attribution to a person or company, as well as the assessment of the source and its relevance under anti-money laundering law, still need to be verified.
- Structuring test cases: Information from approved sources can be consolidated, inconsistencies highlighted, and outstanding issues listed. During AML audits, a system can also process transaction relationships or cash flows and reveal suspicious patterns for further analysis.
- Detect changes: During the ongoing KYC process, an automated comparison may indicate new registry information, changes to master data, or additional risk signals. Whether this triggers an update or further action must be decided separately.
Agentic AI in KYC and AML processes
Agentic AI systems can coordinate multiple work steps and access data sources or tools within predefined boundaries. For example, such a system could retrieve customer data, check approved external sources, compare information, and then generate a case summary with open questions.
This is what distinguishes an agent from a fully defined workflow. The agent can select individual next steps based on previous results. This flexibility also increases the demands on permissions, logging, and approvals. Therefore, read-only access and clearly defined tasks are particularly suitable for a controlled start. Changes to customer data, external communication, or decisions regarding a business relationship should not be initiated without prior human approval.
Good AI needs reliable data.
Incomplete, outdated, or contradictory input data leads to unreliable results, even with AI-supported methods. Therefore, it must remain clear which source was used, how up-to-date it is, and whether information originates directly from the source or was aggregated or derived by the system.
With generative models, the added challenge is that seemingly plausible statements may be factually incorrect or unsubstantiated. A system should therefore clearly identify missing information and not fill gaps with assumptions. The more a result influences a KYC or AML decision, the more crucial source verification, validation, and documented human oversight become.
legal framework
The legal classification is not solely based on the use of AI. Decisive factors include the intended purpose, the specific data processed, the role of the respective company, and the significance of the result for the data subject.
AI Act
The AI Act has been largely applicable since August 2, 2026, with individual regulatory areas following later. KYC and AML applications are not categorically listed as high-risk systems in Annex III. Therefore, a system does not automatically become high-risk AI simply because it is used in a regulated KYC or AML process. Its intended purpose is the determining factor. If the same system is also used for a purpose listed in Annex III, such as assessing the creditworthiness of individuals, the classification may differ. Regardless of the risk class, other provisions of the AI Act may already be relevant. These include, in particular, prohibitions on certain AI practices and, depending on their specific design, transparency obligations. If individuals interact directly with an AI system, this must generally be made clear to them, unless a legal exception applies.
AMLR
The AMLR is essentially applicable from July 10, 2027. Article 76, paragraph 5 contains requirements for decisions resulting from automated processes or processes using AI systems. The data processed for this purpose must be limited to information collected in accordance with Chapter III of the AMLR within the framework of customer due diligence obligations.
Decisions regarding the establishment, rejection, or continuation of a business relationship, the execution or rejection of an occasional transaction, and the increase or decrease of the scope of due diligence measures must be subject to effective human review. The reviewing person must be able to assess the correctness and appropriateness of the decision. Customers must also generally receive an explanation and be able to challenge the decision. These rights do not apply to decisions related to a suspicious activity report.
GDPR
When personal data is processed, the GDPR applies in parallel. Special categories of personal data and information relating to criminal convictions or offenses are subject to additional requirements. Article 22 of the GDPR is relevant if a decision is based solely on automated processing and produces legal effects concerning the data subject or similarly significantly affects them.

Sophie Karl
