top of page

EU Backs Bank Fraud Data Sharing Platform for the AMLR Era

6 hours ago
4 min read
EU Backs Bank Fraud Data Sharing Platform for the AMLR Era

German financial-crime software firm spotixx and Dutch cryptography company Roseman Labs have secured funding from the EU's Eurostars programme to expand a bank fraud data sharing platform that lets institutions detect cross-border criminal patterns without exchanging any customer data. The two-year project runs from 1 October 2026. The German side is backed by the Federal Ministry of Research, Technology and Space under grant reference 01QE2653, while Roseman Labs draws parallel Eurostars support in the Netherlands through the Netherlands Enterprise Agency (RVO).


The timing is the real story. The award lands less than a year before the EU's single Anti-Money Laundering Regulation becomes fully applicable on 10 July 2027, a deadline that will reset how banks are permitted, and in payments required, to share fraud intelligence with one another.


What did the EU actually fund?


The grant covers a two-year build-out of the spotixx Information Sharing Platform, a system that already gives participating banks a shared view of suspicious activity crossing institutional lines. The stated work programme is broader coverage: additional use cases, deeper pattern detection across the network, and enough operational hardening to serve as long-term infrastructure rather than a pilot.


The specific euro allocation for this project has not been disclosed. What is on the record is the wider round: RVO confirmed that Dutch participants in this Eurostars cut-off shared more than 10.5 million euros across 23 approved projects spanning partners in 14 countries, with the spotixx and Roseman Labs collaboration named among the winners. That figure is the aggregate for the Dutch cohort, not the budget for this single project, a distinction worth holding onto given how easily round totals get attached to individual awards.


Eurostars is the SME arm of the intergovernmental Eureka network, co-funded by the European Commission and national governments, with member states typically covering the larger share of each grant. That structure explains the split funding here: German public money for spotixx, Dutch public money for Roseman Labs, one shared roadmap.


Why does the architecture matter more than the money?


The platform runs on secure multi-party computation (MPC), the privacy-enhancing cryptography Roseman Labs was founded on in 2020 and has since deployed with Dutch government bodies including the national cyber security agency. Under MPC, the data behind a suspicious pattern is encrypted before it is processed and stays encrypted throughout, so participating banks compute jointly on shared signals while raw customer records remain inside each institution.


That design choice is the point, and it is best understood against a cautionary precedent most of the market watched unfold. Transaction Monitoring Netherlands (TMNL), set up in 2020 by ABN AMRO, ING, Rabobank, Triodos Bank and de Volksbank, tried to fight the same problem by pooling transaction data into a single shared entity. It was wound down in 2024 after sustained legal and privacy challenges and a recognition that broad centralised pooling would not survive the incoming EU framework. The architectural lesson was blunt: shared intelligence is viable, shared raw data is not. MPC is the answer to exactly that constraint, delivering the cross-bank view without the central honeypot that sank the previous model.


What regulation is really driving this?


Regulation (EU) 2024/1624, the AML Regulation, has been in force since July 2024 and becomes fully applicable on 10 July 2027. Its Article 75 creates a legal basis for formal partnerships in which obliged entities can exchange money-laundering and terrorist-financing intelligence, within a defined and audited framework. The EU's new Anti-Money Laundering Authority (AMLA) and the European Data Protection Board confirmed on 1 July 2026 that they are jointly drafting guidelines on how such partnerships can operate without breaching data protection rules, with a public consultation planned for the first half of 2027.


Payments faces a firmer instruction still. Provisions in the EU's proposed Payment Services Regulation would move beyond permitting fraud-data sharing between payment service providers toward requiring them to connect to shared infrastructure and exchange fraud signals. For a platform that keeps raw data encrypted and inside each bank, that regulatory direction reads less like a compliance burden and more like a market being created on schedule.


How far along is the platform?


The system is not a slide deck. The partners describe a live interbank fraud network already running between three major German banks, drawing on the German Savings Banks Association's approach to data sharing. Two use cases are in practice today: blocking an account flagged as suspicious by one bank before it can be opened or used at another, and cutting false positives by scoring a pattern across the whole network rather than at a single institution in isolation.


The cryptography is designed to be quantum-safe and GDPR-compliant, and the platform supports the audit trails and explainability that compliance teams need before they can act on what it surfaces. Those are not incidental features. Under Article 75, recording every instance of information sharing is a condition of the regime, which makes auditability a gating requirement rather than a nice-to-have.


Why This Matters to FinanceX Readers


Financial crime moves between institutions in hours; the intelligence to stop it has historically stayed locked inside whichever bank saw it first. The EU is now legislating that gap closed, and the compliance clock runs to July 2027. For banks, the question is shifting from whether to join a sharing network to which architecture will still be legal once the rules bite, and TMNL's collapse is a live warning that the wrong answer is expensive. Privacy-preserving cryptography has moved from research curiosity to procurement criterion. For investors, this is a regtech category with a regulator-mandated demand curve and a small field of credible technical providers, which is a rare combination worth tracking as the 2027 deadline approaches.

 
 
bottom of page