AMLA Drops Its First Real Playbook as Agentic AI Eats the Compliance Stack
- Koen Vanderhoydonk
- 1 day ago
- 5 min read

July 2026 is the month RegTech stopped being a pitch deck and started being an operating model. Between AMLA's Level 2 package, the FCA's Mills Review, and a wave of AI-powered launches, the compliance stack is being rewritten in real time.
If you work anywhere near AML, KYC or regulatory reporting, this month has felt less like a normal news cycle and more like standing under a fire hose of announcements. As of this week, three storylines have converged: the European Union's brand-new anti-money-laundering authority is shipping its long-awaited technical standards, agentic AI is quietly slipping into production compliance workflows, and both U.S. and U.K. regulators are publishing frameworks that decide how those AI agents get supervised.
For financial institutions, the practical question is no longer 'should we automate compliance?' but 'how fast can we retire our legacy stack without setting a regulator's hair on fire?'
AMLA's Level 2 Package: The Deadline That Actually Matters
The most consequential RegTech story of July 2026 was legislative, not commercial. According to financialregulations.eu, the EU's Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) had to submit 23 regulatory technical standards, implementing technical standards, and guidelines to the European Commission by 10 July 2026. Those RTS, ITS and guidelines will define the practical substance of AML/CFT obligations for every bank, payment firm, crypto-asset service provider and financial institution in the EU when the AMLR applies on 10 July 2027.
Translation: AMLA just handed the industry the compliance rulebook it will be graded on for the rest of the decade.
What actually shipped
Two AMLA publications from this month deserve highlighting. On 21 July 2026, per Norton Rose Fulbright's Global Regulation Tomorrow blog, AMLA published its final report on draft ITS on cooperation within the AML/CFT supervisory system for the purposes of direct supervision under Article 15(3) of Regulation (EU) 2024/1620. And on 22 July 2026, AMLA released an FAQ on the identification of provisionally eligible obliged entities, a very dry title that in practice tells firms whether they're inside or outside AMLA's direct-supervision perimeter.
By 10 July 2026, AMLA was also due to issue guidelines on ongoing and transaction monitoring, a set of expectations that RegTech Analyst has already flagged as tightening the definition of what 'effective monitoring' looks like in practice.
Protiviti's blog 'AMLA Readiness Starts Now' captures the operating reality: compliance teams have roughly 18 months between the standards being finalised and them becoming binding obligations. That's not a lot of runway for firms with legacy screening engines, static risk models, and periodic KYC refresh cycles.
Agentic AI Just Ate the Compliance Stack
If AMLA is the 'what,' agentic AI is the 'how.' As RegTech Analyst put it in July, 'Agentic AI is set to transform AML and KYC in 2026', and the data is starting to back the hype. According to reporting cited by BCLP in its July 2026 note on AI regulation in financial services, 62% of financial services firms have already deployed AI agents, and 93% of those firms have granted the agents some level of autonomy.
Read that again. Nearly two-thirds of the industry is running AI agents, and virtually all of them are letting those agents act with a degree of independence.
From periodic KYC to perpetual KYC
The most concrete effect, per RegTech Analyst's 2026 KYC/AML outlook, is a decisive move from periodic KYC refreshes to perpetual KYC, a shift that only works if you're prepared to accept AI-driven, event-triggered risk reassessments. Customer risk is evolving faster than annual review cycles can accommodate; agentic systems continuously read transaction data, adverse media, sanctions updates and beneficial-ownership changes, then re-score risk in real time.
RegEd put this shift into product form on July 22, announcing its Branch Examiner Assistant, an AI-powered enhancement to its Branch Audit Management solution. Per RegEd's GlobeNewswire release, the tool brings real-time regulatory intelligence to broker-dealer examiners so they can conduct more consistent, defensible branch examinations. It's a small piece of the compliance stack, but it's exactly the type of narrow, high-value deployment that will define the first wave of production agentic RegTech.
On the KYC side, Bitso Business announced a partnership with Sumsub this month to automate corporate onboarding, another sign that verification workflows are moving from static document review to continuous, AI-augmented pipelines.
The Regulators Are Watching (And Writing Rules About It)
The AI-in-compliance surge would be a compliance nightmare on its own, except regulators are moving in parallel.
FCA: The Mills Review
According to Bryan Cave Leighton Paisner's July 2026 analysis, the U.K.'s Financial Conduct Authority published the Mills Review in July, mapping how AI will reshape consumer finance from simple digital tooling into 'highly personalised, agentic AI that can act on customers' behalf.' The FCA, as reported by Global Policy Watch, has consistently signalled that AI will be overseen through existing regulatory frameworks rather than a bespoke AI rulebook, but has flagged bias, concentration risk, third-party dependencies, audit trails and human-in-the-loop protocols as 'live issues' for guidance in 2026.
U.S.: SR 26-2 Supersedes SR 11-7
On the U.S. side, per Aurascape's July 2026 analysis, model risk management is where AI compliance in banking concentrates, and the goalposts moved in April with SR 26-2, issued jointly by the Federal Reserve, OCC and FDIC. SR 26-2 supersedes the long-standing SR 11-7 framework and reaffirms core disciplines: model inventories, independent validation, ongoing monitoring, and governance of third-party models. For banks running vendor-supplied AI compliance tools (which is essentially all of them), SR 26-2 tightens the accountability screw.
FSB and the AI Act
The Financial Stability Board also published a consultation report on sound practices for responsible AI adoption this quarter. And the EU AI Act, now fully in force per RegTech Analyst, classifies AI systems used in financial crime compliance as high-risk, a classification that carries model documentation, human oversight and post-market monitoring obligations that many current-generation compliance AIs cannot meet out of the box.
Money Follows the Signal
The market is voting with capital. According to a July 2026 GlobeNewswire release, the RegTech market is projected to reach $29.20 billion in 2026 and grow at a 21.33% CAGR to $93.48 billion by 2032. Investment tracking cited by Landbase and Ellty put 2024 global RegTech investment at approximately $18.6 billion, with capital concentrating in AI-powered AML, eKYC, sanctions and fraud screening, automated reporting, and cloud-native compliance platforms.
Notable balance sheets speak for themselves: ComplyAdvantage has raised more than £70 million; Chainalysis has raised $436 million; Y Combinator's compliance cohort continues to churn out AI-native entrants such as Dili (S23), which is automating compliance across sectors that previously ran on spreadsheets and hope.
What to Watch Between Now and October
Three items should be on every compliance leader's radar over the next 90 days:
The AMLA guidelines rollout, expect industry consultations to intensify as firms ask AMLA to clarify grey areas in transaction monitoring and beneficial-ownership rules.
Australia's 'Tranche 2' reforms, per RegTech Analyst, which from 1 July 2026 extend AML/CTF obligations to lawyers, accountants and real estate agents, a template other jurisdictions will study closely.
U.S. bank supervision under SR 26-2, watch for the first supervisory findings under the new framework to land in Q4, which will shape how banks structure their AI governance for 2027.
The Bottom Line
RegTech in July 2026 is no longer a category defined by chatbots and dashboards. It is an operating discipline where AMLA's rulebook, agentic AI, and modernised model-risk supervision are all converging on the same compliance function at the same time. Firms that treat this as a technology-refresh project will underestimate the depth of change; firms that treat it as an operating-model transformation, with governance, audit trail and human-in-the-loop design baked in from day one, will be the ones still defensible in 2028.
The compliance officer of 2027 will look very different from the one of 2020. As of this week, that officer is being hired, trained and toolset-equipped in real time.
.png)