New EU AML Regulations: What AMLA Means for Compliance Data
AMLA enforces new EU AML regulations from July 2027, creating a single rulebook that reshapes compliance data across Europe.
Quantifind raised $200 million in June 2026. Citi Ventures, S&P Global and Deloitte all backed the round. The pitch: legacy AML systems drown compliance teams in false positives, and the new EU AML regulations arriving in July 2027 will turn that operational drag into a regulatory violation. Quantifind was not alone. Regtech firms pulled in more than $2 billion in the second quarter of 2026 alone.
The money is chasing a deadline. On 10 July 2027, the Anti-Money Laundering Regulation takes direct effect across all 27 EU member states. Not as a directive requiring national transposition. As a regulation. Same rules in Tallinn as in Dublin. Same rules in Lisbon as in Helsinki. Enforced by AMLA, the Anti-Money Laundering Authority, a Frankfurt-based agency that did not exist two years ago and now intends to supervise the continent’s highest-risk banks directly.
AMLA exists because the old system broke. Badly. Between 2007 and 2015, more than $230 billion in suspicious transactions flowed through Danske Bank’s Estonian branch. National supervisors in Denmark and Estonia each assumed the other was watching. Neither was. Danske paid $2 billion to settle with US and Danish authorities. ING paid €775 million to Dutch prosecutors for separate failures. The EU’s answer was not another set of guidelines for member states to interpret as they pleased. It was a single rulebook with a supranational enforcer carrying a chequebook of fines.
The new EU AML regulations end the era of national opt-outs
Under previous directives, Germany could set its own simplified due diligence thresholds. So could France. So could every other member state. A bank operating across borders had to reconcile dozens of overlapping regimes, and a compliance gap in one jurisdiction did not necessarily trigger consequences in another.
That is over. The AMLR strips member states of the discretion that made regulatory arbitrage possible. Customer identity requirements now demand place of birth, multiple nationalities and digital identity credentials as standard. Beneficial ownership verification sits at 25%, with a mechanism for the European Commission to lower it to 15% after 2029. An EU-wide €10,000 cap on commercial cash payments takes effect on the same date. FIUs get a binding five-day response window on data requests.
The practical consequence for a mid-market bank running AML operations across, say, Germany, the Netherlands and Poland is that three sets of national workflows collapse into one. That sounds like simplification. It is not. The new EU AML regulations set a standard that may be stricter than any of the three national regimes they replace. It is a wholesale rebuild, not a merger.
AMLA takes direct control, and it is already choosing targets
From January 2028, AMLA will directly supervise 40 of the highest-risk financial institutions operating across the bloc. Around 200 of its projected 430 staff will work in joint supervisory teams alongside national regulators. The agency launched a recruitment drive in May 2026 to add 130 supervisors, more than doubling its headcount from 119.
The selection process is not theoretical. Executive board member Rikke-Louise Petersen told attendees at AMLA’s inaugural conference in Frankfurt in June 2026:
“The selection process is already underway. This is not a project for the future.”
AMLA published a reporting package in May for national supervisors to identify provisionally eligible entities, with data collection due by August 2026 and a provisional list expected by September. Formal selection begins in July 2027.
The new EU AML regulations give AMLA the power to impose fines of up to 10% of annual turnover or €10 million for serious breaches. Global AML enforcement fines hit $4.6 billion in 2024, with TD Bank’s $3.1 billion settlement accounting for two thirds of that total. Whether AMLA can match that enforcement intensity with 430 staff and a brand-new operational infrastructure is the open question the new EU AML regulations leave unanswered. The fine ceiling is aggressive. The institutional capacity to use it is unproven.
New EU AML regulations pull crypto and football into scope
The AMLR extends obligations well beyond traditional banking. Crypto-asset service providers, professional football clubs and agents, crowdfunding platforms and luxury goods dealers are all now obliged entities.
CASPs face a deliberately low bar. Full customer due diligence kicks in at €1,000 for occasional crypto transactions, well below the €3,000 general cash threshold. Anonymous accounts are banned outright. Regulated platforms cannot list or custody privacy-enhancing coins.
Each new category creates a compliance procurement cycle. Football clubs that have never run transaction monitoring will need to buy it. Luxury dealers built on high-value cash transactions will need identity verification infrastructure from scratch. The global RegTech market is pricing the new EU AML regulations into current valuations. Quantifind’s CEO Ari Tuchman framed the opportunity in blunt terms at the fundraise announcement:
“There is no acceptable tradeoff among them in regulated environments.”
He was talking about accuracy, speed, scale and explainability. The AMLR demands all four simultaneously.
The data rebuild is where the money burns
Forget the regulatory language. The real cost of the new EU AML regulations sits in the data layer. Supervisory convergence under AMLA requires standardised reporting and cross-border connectivity between systems that were never designed to interoperate. An EY survey published alongside AMLA’s June 2026 conference found that 66% of financial institutions expected to amend customer due diligence and transaction monitoring processes. That means a third, apparently, did not. Whether that reflects confidence or denial is unclear.
Mid-market banks already spend $15 million to $40 million annually on AML compliance. The AMLR will push those figures higher before it produces any savings. Beneficial ownership records need cleansing. PEP screening databases need updating for expanded definitions covering sub-national officials and state-owned enterprise executives. Transaction monitoring thresholds need recalibrating. None of this is incremental. It is migration-scale work on a fixed deadline.
The new EU AML regulations formally recognise AI as a legitimate compliance tool under EU law for the first time. That is significant. But AMLA has drawn hard lines around explainability and auditability. An algorithm that flags a transaction as suspicious but cannot articulate why will not pass muster. For institutions that have spent years deploying opaque machine learning models, that requirement alone could force a rebuild.
AMLA has released six consultations on binding technical standards that will define what the new EU AML regulations require in practice. These are not guidance documents. They are the rules compliance teams will be measured against from day one. The deadline is less than 12 months away. AMLA’s executive board includes former senior officials from Banca d’Italia, De Nederlandsche Bank and the Central Bank of Ireland. It staged its first public hearing within nine months of becoming operational. Its first full conference at the Alte Oper in Frankfurt drew national supervisors, compliance officers and intelligence units from across the bloc.
Nobody in that room was under the impression this agency plans to be patient. The new EU AML regulations gave it the mandate. The question now is execution.

The go to weekly newsletter for compliance, risk, and governance professionals.
Trusted by 10,000+ industry leaders for authoritative RegTech intelligence, delivered weekly.
Join them today.
