AI in anti-money laundering is often framed as a model-performance problem: better detection, fewer false positives, faster case closure. Those goals are real, and the tools aimed at them are becoming more capable. In Europe, however, the frontier is shaped at least as much by law, institutional architecture, and governance as by model quality. The key questions come before the model: what data it may lawfully access, what infrastructure it operates within, and what oversight applies to its outputs. As the technology improves, those questions become more important, not less.
Three recent European events show what that frontier looks like. Read together, they define the operating space in which AI-assisted AML is being built.
1. TMNL and the privacy ceiling
Transaction Monitoring Netherlands (TMNL) was Europe’s most ambitious cross-institution monitoring initiative. Five banks – ING, Rabobank, ABN AMRO, de Volksbank, and Triodos – pooled transaction data from around 2020 onward, roughly 10 billion records over about three years. The reasoning was sound: laundering networks operate across accounts, banks, and borders, and a transaction that looks ordinary inside one institution can resolve into a clear pattern when seen alongside activity at three others. A single bank sees only its own fragment.
The initiative did not clear the legal bar. In July 2024, TMNL was wound down. The decisive intervention was not a court ruling striking down a running system; it was scrutiny of the legal foundation that would have supported that system. The Dutch Council of State (Raad van State) Advisory Division, in advisory opinion W16.24.0076/II (2024) on the draft law that would have established a legal basis for joint transaction monitoring, found that the necessity and proportionality of that monitoring had not been sufficiently demonstrated and advised removing the joint legal basis from the proposal. In its words: “It has not been sufficiently substantiated that the necessity and proportionality of joint transaction monitoring have been demonstrated.” The Dutch Data Protection Authority had separately raised concerns about the processing.
The consequence reaches beyond one initiative. Broad private pooling of personal transaction data across institutions faces a high bar in the EU, and that bar follows from fundamental-rights protection – the right to data protection under the Charter and the requirements of the GDPR – not from a gap that better models will close. The necessity and data-minimisation tests apply regardless of how capable the technology becomes.
A narrower, lawful path is being formalised. Article 75 of the EU Anti-Money Laundering Regulation creates a framework for information-sharing partnerships between obliged entities, applicable from 10 July 2027. It is deliberately tighter than TMNL’s model: targeted exchange under defined conditions, not broad pooling.
For any team building AI-assisted monitoring in Europe, the practical implication is to treat legal basis and data minimisation as design inputs, settled before the technical architecture is fixed, rather than as compliance checks applied afterward. Better models inside one institution can improve what that institution lawfully sees; they do not lift the ceiling above it.

TMNL and the privacy ceiling: from operational pooling (2020) to wind-down (July 2024) to the narrower AMLR Article 75 pathway (10 July 2027).
2. The Digital Euro: a different institutional architecture
While TMNL tested the limits of private pooling, the European Central Bank advanced a different model through the digital euro preparation phase. The design incorporates a centralised fraud and AML risk-scoring function within the payment infrastructure itself: a central layer produces a per-transaction risk score, each payment service provider receives that score, and the PSPs retain authority over how to act on it. The scoring sits where it has visibility across the system, rather than inside a single institution.
In October 2025, the ECB concluded framework agreements for the Risk-and-fraud-management lot. Feedzai S.A. ranked first and Capgemini Deutschland GmbH ranked second – both are on the framework, with Feedzai as the primary contractor. EU public-procurement frameworks award multiple ranked vendors; ranking governs how work is allocated, not who is excluded. The framework envelope across both vendors is a maximum of EUR 237.3 million (the framework ceiling), re-estimated at EUR 79.1 million, over a term of up to 15 years. The digital euro remains in its preparation phase, not live.
This is architecturally distinct from cross-bank pooling. TMNL was a private consortium sharing independently held data without a statutory mandate for that sharing or a purpose-built public infrastructure to house it. Digital euro monitoring is central scoring embedded in public payment infrastructure, under a mandate set through the EU legislative process and governance designed for that purpose. The legal foundation, the accountability, and the data-governance model are different, and those differences define what the architecture can do that institution-level controls cannot: provide a network-level view, within defined limits, that helps a PSP act on signals it could not generate from its own data alone.
For institutions participating as PSPs, this points to a layered environment rather than a replacement of existing controls. Customer due diligence, transaction monitoring, case management, and reporting remain obligations of the individual obliged entity and cannot be delegated to a central scoring layer. Those controls will operate alongside, and can be informed by, a layer with broader visibility. The direction is consistent with the wider AML package, which establishes new supranational structures including the EU Anti-Money Laundering Authority. Institution-level programmes increasingly need to be coherent with that environment, not designed in isolation from it.

Two monitoring architectures: private cross-institution pooling (TMNL) versus central infrastructure scoring (the digital euro model).
3. The Central Bank of Ireland Innovation Sandbox
The Central Bank of Ireland ran its first Innovation Sandbox cohort, themed Combatting Financial Crime, across December 2024 – June 2025, with direct engagement from CBI staff throughout. The format is a structured, regulator-supervised space where emerging tools are tested and evaluated with regulatory input before wider deployment.
The seven participants map the problems under active development. Several worked on privacy-preserving information sharing, including secure multi-party computation, federated approaches, and differential privacy, exploring whether institutions can detect shared networks without the broad pooling that failed legal scrutiny in the Netherlands; whether those methods deliver both detection value and legal robustness remains an open question. Others addressed identity verification and onboarding, where the quality of data entering AML systems depends on the identity infrastructure at the front end. Fraud-prevention tooling featured as well, reflecting the operational overlap between fraud and AML.
Structured AML/CFT knowledge was another strand, and the category in which AMLYZE participated with AMLTRIX. AMLTRIX is an openly licensed AML/CFT knowledge base organised as a taxonomy of Tactics, Techniques, Indicators, and Mitigations. In the sandbox, its role was to serve as a shared labelling and structuring reference: a way for institutions to label AML knowledge consistently, train models against a common framework, and describe typologies in a standardised vocabulary, without sharing customer or transaction data. AMLTRIX was subsequently selected as a finalist for the BIS Innovation Hub Analytics Challenge 2025 on financial crime.
The sandbox illustrates how progress in this field accumulates: not as single breakthroughs, but through the steady assembly of better infrastructure – privacy-preserving collaboration, structured knowledge references, identity tooling, and evidence of what AI approaches produce under real oversight. It also reflects a pattern across European supervision. The Central Bank of Ireland, the Bank of Lithuania, the Financial Conduct Authority, and other authorities run early-stage engagement programmes, which means the norms that later become formal requirements are being shaped now. Teams that stay out of those processes will inherit requirements they had no hand in shaping.
The Central Bank of Ireland’s first Innovation Sandbox cohort (December 2024 – June 2025), by problem area.
Reading the three together
Each event is instructive on its own; together, they map the terrain. TMNL marks the legal constraint: a structural privacy ceiling around cross-institution pooling that is a feature of EU law, not a temporary gap. The digital euro shows what becomes possible when institutional authority, infrastructure mandate, and governance are aligned: central monitoring under statutory authority operates in a different legal and accountability category than a private consortium. The CBI sandbox shows where open experimentation is happening, with regulators in the room.
For AML and technology teams, the lesson is that AI strategy in financial crime prevention is not only a model-selection exercise. Legal basis, data governance, and institutional architecture are first-order design inputs, on a par with model quality. The models matter; so does the data they can lawfully reach, the infrastructure they run inside, and the oversight their outputs face. In Europe those constraints are still being defined, and they will shape what AI-assisted AML can do more than the next increment of model performance will.
Sources & notes
- Dutch Council of State (Raad van State), Advisory Division opinion 24.0076/II (2024), on the draft law for joint transaction monitoring – raadvanstate.nl. The quoted sentence is translated from the Dutch.
- Dutch Data Protection Authority (Autoriteit Persoonsgegevens) – autoriteitpersoonsgegevens.nl.
- EU Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, Article 75 (information-sharing partnerships; applicable from 10 July 2027) – EUR-Lex.
- European Central Bank, digital euro programme – europa.eu – and the ECB framework-agreement notice for the Risk-and-fraud-management lot published via the EU Tenders Electronic Daily (TED), reported in the ECB’s October 2025 preparation-phase reporting (Feedzai S.A. first, Capgemini Deutschland GmbH second; maximum EUR 237.3 million, re-estimated EUR 79.1 million, up to 15 years).
- EU Anti-Money Laundering Authority, Regulation (EU) 2024/1620 – EUR-Lex.
- Central Bank of Ireland, Innovation Sandbox Programme – Insights Report 2025 (Combatting Financial Crime), cohort December 2024 – June 2025 – centralbank.ie.
- AMLTRIX – framework.amltrix.com; AMLYZE sandbox participation – amlyze.com; BIS Innovation Hub Analytics Challenge 2025 – amltrix.com.
- General data-protection framework: GDPR (Regulation (EU) 2016/679); EU Charter of Fundamental Rights, Article 8.
Analytical framing (the TMNL-vs-digital-euro architectural distinction and the layered-monitoring reading) is AMLYZE’s interpretation of the public record cited above.
This is the first article in a series on AI in AML.
Next up:
- What questions AML teams should actually be asking vendors before buying AI
- Detection improvement vs. alert management in transaction monitoring – and why conflating them leads to the wrong decisions
- How structured knowledge frameworks address the problem that sits before any model is trained






