top of page

Visa Pays $2.4bn for Behavioural Biometrics, AMLA Sets Its First Rulebook, and DORA Enforcement Grows Teeth

Visa Pays $2.4bn for Behavioural Biometrics, AMLA Sets Its First Rulebook, and DORA Enforcement Grows Teeth

A week that saw a payment giant swallow a fraud specialist, Europe's new financial crime supervisor publish its harmonisation blueprint, and half of Europe's banks still catching up on operational resilience shows why RegTech is no longer a nice-to-have line item.

If anyone still needed convincing that regulatory technology has moved from cost centre to strategic asset, the past week has done the job for them. As of this week, Visa has agreed to buy a behavioural biometrics specialist for $2.4bn in cash. The European Anti-Money Laundering Authority has published its first proper enforcement rulebook. And a fresh round of surveys shows that European banks are still uncomfortably behind on the Digital Operational Resilience Act, which is now supposed to be enforced rather than negotiated. Put together, this is the sort of week that reprices the entire compliance stack.


Visa's $2.4bn bet on watching how you type


The headline deal came from Visa, which announced on 3 August 2026 that it had agreed to acquire BioCatch, an AI-driven behavioural biometrics and fraud intelligence specialist, in an all-cash transaction valued at $2.4bn. According to CNBC, Bloomberg and FinTech Global, the target is being sold by funds advised by Permira alongside other shareholders. Closing is expected by the end of Visa's second fiscal quarter in 2027, subject to regulatory approvals.


BioCatch is not just any RegTech acquisition target. The company's platform draws on machine learning to examine thousands of signals across applications, behaviour, devices and networks, from typing patterns and touch gestures to the way a phone is held, in order to separate genuine customers from criminals as activity happens. According to the joint press release, BioCatch's customer base spans more than 350 banks in 21 countries, including over 100 of the world's largest financial institutions. Coverage reaches 1.8 billion devices and 760 million individual users.


Why Visa is willing to pay this much

The strategic logic is not hard to see. Payment fraud losses are climbing at a time when generative AI is making synthetic identity attacks, deepfake voice scams and account takeovers cheaper to run at scale. Visa already sits at the centre of card authorisation flows for a huge share of global payments. By folding BioCatch into its existing cyber, fraud, risk and security offering, Visa can push fraud detection upstream, out of the transaction moment and into the enrolment, session and behavioural layers where the loss actually gets set up. As Payments Industry Intelligence put it, the deal strengthens Visa's fraud defences at a moment when scam volumes are outpacing everyone's control library.

The deal also puts pressure on Mastercard, PayPal and every payments network that has been building rather than buying. When your competitor announces a $2.4bn cheque for behavioural intelligence, 'we are working on it internally' is no longer a satisfying quarterly earnings answer.


AMLA fills in the enforcement blueprint


Away from the boardroom drama, the Anti-Money Laundering Authority has been busy publishing the rules that will define its own supervisory reach. Late in July 2026, AMLA released final Regulatory Technical Standards establishing a harmonised EU framework for assessing and enforcing breaches of anti-money laundering and counter-terrorist financing obligations. The RTS introduce a common methodology for supervisors to evaluate the seriousness of breaches based on duration, repetition and impact. Breaches are classified into four gravity levels, with proportionate enforcement outcomes attached to each.


According to AMLA's own press release, once the European Commission adopts the standards they will apply directly across all EU Member States and all sectors subject to AML/CFT requirements. That is a big deal. It means the days of a Belgian firm getting a slap on the wrist for the same infraction that draws a heavy fine in Germany are numbered.

AMLA has also published final draft technical standards governing cooperation with national financial supervisors. These cover the selection of institutions for AMLA's direct supervision, the transfer of supervisory responsibilities and continuing cooperation with national authorities. Meanwhile, the European Banking Authority issued a public working draft of the data model and taxonomy that will support the collection of data on eligibility for direct AMLA supervision, as part of release 4.4 of its reporting framework.


What this means for compliance teams

Read together, the pieces amount to a live user manual for how European banks and non-bank obliged entities will be judged from 2027 onwards. Perpetual KYC, real-time transaction monitoring and machine-readable reporting are no longer talking points. They are the shape of the pipe supervisors are building. Which brings the story neatly to the technology stack scrambling to meet them.


Perpetual KYC and AI-native platforms move in


The vendor side of the market is not standing still. Alloy has launched an AI-powered perpetual KYC solution designed to give FinTechs and banks continuous customer monitoring rather than point-in-time reviews, according to RegTech Analyst. The pitch is straightforward: static KYC is dead, dynamic monitoring is standard, and risk assessments should evolve automatically as customer behaviour changes.


ComplyAdvantage, meanwhile, has completed the full integration of its payment screening capabilities into its AI-native Mesh platform, per Crowdfund Insider. Customer screening, transaction monitoring, payments screening and ongoing monitoring now live in a single experience, with the vendor reporting significant reductions in alert volumes and faster onboarding. It is the kind of consolidation move that regulated firms have been asking for after years of stitching together point solutions with elastic and hope.


According to a July 2026 GlobeNewswire release cited in industry coverage, the RegTech market is projected to reach $29.20bn in 2026 and grow at a compound annual growth rate of 21.33% to $93.48bn by 2032. That is the kind of number that turns compliance from a cost line into a boardroom priority.


Cash keeps landing in the sector


The funding side of the ledger backs up the strategic picture. According to FinTech Global, the second quarter of 2026 saw more than $2bn raised across RegTech, on the back of a first quarter that had already delivered close to $3bn. That comes after $5bn was raised across the sector in 2025, with US-headquartered RegTechs pulling in a combined $3.17bn.


Recent named rounds include Horizon3, which closed a $250m Series E at a valuation of more than $2bn, effectively tripling the $650m valuation it commanded at Series D. Zenity, an AI security and governance platform aimed specifically at AI agents, closed a $125m Series C. And Compuvi, a LegalTech and RegTech artificial intelligence business behind the compliance platform Confinaid, closed seed funding at a $40m post-money valuation, led by Evolution Equity Partners with participation from Cyberstarts, Temasek, Accel, Blackstone, Coatue and Spark Capital.


DORA's grace period is over


Cheque-signing at the vendor level is not going to save financial institutions still lagging on the Digital Operational Resilience Act. According to Regulation-DORA and Nemko Digital, 2026 marks the start of active enforcement across Europe, and supervisors have signalled that enforcement for serious incident reporting failures and persistent Register of Information deficiencies is expected to begin in the current supervisory cycle. Deloitte's Wave 3 survey found that only half of financial institutions expected to reach full compliance by the end of 2025, with 38% pushing their target into 2026. A subsequent Deloitte Luxembourg survey put confidence in compliance at just 25%.


That is a large exposure surface. As Regulation-DORA notes, regulators have deployed automated tools that cross-reference ICT registers across the EU. Inconsistencies, technical gaps or late updates are flagged immediately by the same systems that supervisors will lean on when they issue findings.


MiCA leaves a door closing behind it


While the operational resilience clock has moved on, the crypto regulatory perimeter is also tightening. According to Sumsub and Cyfrin, the Markets in Crypto-Assets Regulation transitional period ended on 1 July 2026, so any provider still relying on grandfathering has run out of runway. Fines since MiCA enforcement began have surpassed €540m, per Zitadelle AG, with maximum penalties reaching 12.5% of annual turnover for the most serious violations. More than 18% of European crypto platforms have already exited the market or shut down rather than absorb the compliance cost. Separately, the European Commission's targeted consultation on the review of MiCA, opened on 20 May 2026, closes for responses on 31 August 2026.


The takeaway


It is a rare week when the regulatory technology story is the story. This one belonged to it. A payments incumbent bought its way into behavioural intelligence at a price point that will discipline the next twelve months of RegTech M&A. AMLA delivered the enforcement grammar the industry has been waiting for. Perpetual KYC and integrated AI monitoring platforms moved from pitch decks into rollouts. And every institution that assumed DORA was a paper exercise now knows the paper is being read by an automated cross-referencing engine. If your compliance stack still looks like a 2023 org chart, next week is a good time to reprice it.

 
 
bottom of page