top of page

AMLA's Deadline Day: Europe's New Compliance Rulebook Drops as AI Rewrites the Playbook

AMLA's Deadline Day: Europe's New Compliance Rulebook Drops as AI Rewrites the Playbook

As of July 10, Europe's Anti-Money Laundering Authority has delivered the Level 2 and Level 3 measures that will bind every regulated firm on the continent from 2027. Meanwhile, an AI Act watermarking obligation lands August 2, Australia's Tranche 2 goes live, and a wave of RegTech funding suggests the compliance stack itself is being rebuilt in real time.

The Regulator's Fortnight


If you work in compliance, this month is not a slow one.

According to AMLA's own regulatory instruments schedule, the European Anti-Money Laundering Authority was required to deliver a wave of 23 Level 2 and Level 3 measures, regulatory technical standards, implementing technical standards and guidelines, by July 10, 2026. That deadline has now passed. The submissions to the European Commission define, in binding terms, what customer due diligence, transaction monitoring and beneficial ownership look like across all 27 member states from 2027 onward.


Norton Rose Fulbright's harmonisation briefing puts the significance plainly: once the Commission adopts these standards, they apply directly across the Union with no national transposition, no room for local interpretation, and no grace period for firms that failed to read the memo.


For a compliance function accustomed to twenty-seven flavours of "know your customer," this is a step change. The Single Rulebook is finally, actually, singular.


And Then There's Tranche 2

Across the Pacific, as reported by RegTech Analyst in its 2026 KYC/AML outlook, Australia's long-signalled Tranche 2 reforms took effect on July 1. The reforms extend AML/CTF obligations to lawyers, accountants, real estate agents and other designated non-financial businesses and professions for the first time.


Translation: an entire segment of the economy that previously operated outside the AML perimeter is now inside it. And they have exactly the amount of institutional muscle memory around suspicious matter reports that you'd expect: not much.


The AI Act Wrinkle That Lands Next Week


The regulatory pile-up doesn't stop with AML. According to Technology.org's July 17 breakdown, the machine-readable marking obligation in Article 50(2) of the EU AI Act, the rule that requires watermarking of synthetic audio, image, video and text, applies from August 2, 2026, for newly placed systems. That change was locked in through the Digital Omnibus on AI, signed on July 8.


Why does that matter for RegTech? Because financial crime compliance is now firmly on the AI Act's high-risk list. The Act classifies AI systems used in AML, sanctions screening and fraud detection as high-risk, imposing specific obligations around transparency, human oversight, data quality, model documentation and bias testing.


In other words: if your KYC vendor is running black-box models in Europe, you have a paperwork problem by August. And if your synthetic-media detection tooling doesn't recognize the new watermark standard, you also have a detection problem.


Agentic AI Meets The Compliance Stack


The regulatory calendar is only half the story. The other half is what compliance teams are actually deploying to keep up.


RegTech Analyst's July outlook is emphatic on this: the industry is in the middle of a decisive shift from periodic KYC refreshes toward perpetual KYC, continuous, trigger-based monitoring that reacts to an ownership change, a new sanctioned counterparty, a sudden transaction pattern or a behavioural anomaly the moment it happens.


The reason isn't fashion. It's arithmetic. Ownership structures, sanctions lists and politically-exposed-person registers are now changing daily. A once-a-year customer refresh in that environment is theatre.


The Adversary Uses AI Too

The uncomfortable subtext of every 2026 compliance conversation is that criminals have the same tools. As Moody's noted in its 2026 outlook, AI is accelerating activity on both sides of financial crime. Automated deception, synthetic identities, deepfake KYC videos, mule-network coordination, scales just as well as automated detection.


That's the arms race regulators are now, explicitly, pricing in. When AMLA's incoming transaction-monitoring guidelines land, they will not just describe what monitoring looks like. They will describe what "effective" monitoring looks like against an adversary that can generate a plausible synthetic customer in under thirty seconds.


The Money Follows


Follow the funding and the picture sharpens. According to RegTech Analyst, Napier AI secured £45 million from Crestline Investors in February 2026 to expand its AI-powered financial crime compliance platform. Novatus Global closed a £30.5 million round led by Silversmith Capital Partners to scale its regulatory reporting technology. And per FinTech Global's July 2026 tally, thirty-two RegTech funding rounds closed in a single month, a level of activity the sector has not seen since the immediate post-DORA scramble.


Recent notable rounds include Compuvi, the LegalTech and RegTech AI company behind compliance platform Confinaid, closing a seed round at a $40 million post-money valuation. And Outpost, an AI-powered payments and compliance infrastructure platform for cross-border commerce, raised $17.5 million in a Series A led by Ribbit.


The market is voting with its cheque book. Yahoo Finance reports that the RegTech market is projected to reach $29.20 billion in 2026 and $93.48 billion by 2032, growing at 21.33% CAGR. Very few sectors in enterprise software post those numbers.


DORA's Enforcement Year


The other regulatory story compliance teams are living through in real time is DORA, the EU's Digital Operational Resilience Act. As Neotas' 2026 guide summarises, the regulatory posture this year is explicitly interventionist: supervisors are examining firms for compliance evidence, not remediation plans.


The stakes are unusually blunt. Financial entities face fines up to 10% of annual global turnover or €10 million for serious breaches. Critical ICT third-party providers face periodic penalty payments up to 1% of average daily worldwide turnover. And individual senior managers face fines up to €1 million, the kind of number that concentrates minds in a way corporate liability sometimes doesn't.


Meanwhile, per UpGuard's 2026 briefing, the European Supervisory Authorities designated their first 19 Critical ICT Third-Party Providers in November 2025, a list that includes Amazon Web Services, Google Cloud, Microsoft, Oracle, SAP and Deutsche Telekom. All are now subject to direct EU oversight, including annual risk assessments and on-site inspections.


That designation matters because it flips a market dynamic. For the first time, the hyperscalers your bank runs on are themselves inside the regulatory perimeter of your bank's regulator. Third-party risk management is no longer a documentation exercise. It's a supervisory relationship.


What The Machine-Readable Future Actually Looks Like


Underneath the deadlines is a quieter architectural shift. As Aptus.AI has argued for some time, RegTech's long-term direction of travel is machine-readable regulation, rules that are published not just in prose but in structured, executable formats that compliance systems can ingest directly.


The Global RegTech Summit USA framed it well: machine-readable regulations promise faster compliance, clearer expectations and smarter oversight. Regulators, in principle, get real-time visibility into whether firms are actually doing what the rulebook requires.


That vision is still, in July 2026, more aspirational than operational. But the AMLA rulebook, the EU AI Act's structured-data requirements, and DORA's mandated incident-reporting taxonomies are all pushing in one direction: away from prose and toward code.


What The Rest Of 2026 Looks Like


For compliance leaders, three items belong on this week's agenda. First: read the AMLA measures. All 23 of them. They will define the CDD framework you're operating under for the rest of the decade. Second: audit your AI vendors for August 2 AI Act readiness, specifically watermarking recognition and Article 50(2) documentation. Third: pressure-test your third-party risk register against the critical ICT provider list.


For RegTech vendors, the message from the funding data is simpler. The buyer is finally, actually, buying.


The compliance function has spent a decade being the department that says no. In 2026, it's becoming the department that ships infrastructure.

 
 
bottom of page