Regulation has always been written for humans. Lawyers interpret it, compliance teams translate it into policies and controls, and firms spend months implementing new requirements. But as financial services become increasingly digital, that process is starting to look slow, expensive and increasingly out of step with the systems it is designed to govern.
This has given rise to an ambitious idea: what if regulation could be published in a format that computers could understand as well as people? Instead of firms manually interpreting every rule change, compliance systems could consume regulatory requirements directly, helping organisations respond faster and more consistently as rules evolve.
What machine-readable regulation looks like
What would truly machine-readable regulation look like in practice? According to Scott Nice of Label, truly machine-readable regulation would mean regulation being published and maintained in a format that technology can interpret, map and operationalise more easily.
He explained, “It would not simply be a PDF on a regulator’s website that firms then manually translate into policies, controls and procedures. It would involve obligations being structured, tagged and connected to relevant data points, reporting requirements, control expectations and implementation logic.”
In practice, Nice said this could allow a firm to identify which obligations apply to it, understand what data is required, map those obligations to internal controls and assess the operational impact of regulatory change much faster than it can today.
“It would also create a clearer line of sight between regulation, policy, controls, workflows and evidence, which is often missing in current compliance operating models,” Nice said.
Despite this, he stressed that machine readable regulation should not be confused with regulation with requires no interpretation.
He said, “Much of regulation is contextual. It depends on the firm, product, customer, jurisdiction, risk profile and supervisory expectation. The real value would be in making compliance architecture more connected, not in pretending that every regulatory obligation can be reduced to binary logic.”
Meanwhile, Areg Nzsdejan, CEO of Cardamon, stated that in practice, machine-readable regulation would not look like what most people mean when they say it.
He said, “Digitised PDFs or API-delivered updates are a start – not machine-readable in any meaningful sense. Truly machine-readable means structured, versioned obligations: regulatory text decomposed into discrete components with explicit scope, conditions, and a clear link to what a firm must do and how it demonstrates compliance – essentially, a data model.
“At Cardamon, we already do this extraction and structuring work ourselves. In a world of genuinely machine-readable regulation, regulators would do it once, upstream, for everyone.”
Meanwhile, Michael Thirer, CLO at Muinmos, was clear in his view that truly machine-readable regulation in practice would look like the Muinmos platform.
He explained, “Academics and legislative bodies have debated for years the possibility of making regulation machine-readable. While they were debating, two things happened:Machines learnt how to read, and RegTechs like Muinmos stepped in and turned regulation into actionable applications. At Muinmos, this is literally what we do every day – turn legal code into computer code.”
This is why Thirer said, that in its purest form, truly machine-readable regulation in practice would look like the application executing it.
“Because truly machine-readable regulation is machine-executable. As machines execute instantly, in the machine world, there is hardly a difference between the code and its execution. They are basically the same,” he said.
The regulatory balancing act
Can regulatory obligations be translated into executable rules without losing context or judgment?
Not every regulatory obligation can be reduced to code without sacrificing the judgement that underpins effective compliance, according to Nice.
He argues that many rules are well suited to automation. “Requirements such as data fields, filing deadlines, validation rules, thresholds, formats and specific reporting obligations can often be encoded with a high degree of confidence,” he says, adding that doing so can improve consistency while reducing manual errors.
The challenge lies elsewhere. Much of financial regulation depends on interpretation rather than certainty, requiring firms to assess what is reasonable, proportionate or credible in a given context. Financial crime controls, KYC risk assessments, beneficial ownership analysis and tax transparency obligations, for example, often hinge on professional judgement rather than binary decisions.
“These are not always simple yes-or-no questions,” Nice says. “Firms still need to determine whether information is credible, whether a classification makes sense, whether a structure is reasonable or whether a change in behaviour is significant.”
He points to regimes such as FATCA, CRS and CARF as examples of where technology can shoulder much of the operational burden without replacing human accountability. Automated systems can validate data, support workflows, perform reasonableness checks and maintain evidence trails, but they do not remove the firm’s responsibility for the final compliance decision.
“For CRS and CARF, technology can help check whether a customer’s self-classification appears reasonable based on the information available,” Nice explains. “But the customer self-classifies and the firm governs the process around that. That is very different from saying the system makes the entire judgment on its own.”
The answer on this for Nzsdejan is partially. He states that reporting thresholds, deadlines, capital requirements – these translate cleanly. If condition A, action B by date C, he gives as an example.
“The harder part is the language regulators use deliberately: “reasonable steps”, “proportionate”, “material risk”. This isn’t imprecise by accident. Replace that judgment with a checklist and you create an illusion of compliance – firms tick boxes without managing the underlying risk.”
For the Cardamon CEO, the right design target is machine-readable regulation that surfaces context rather than eliminates it.
Whilst Nzsdejan only partially agrees, Thirer fully is on board with this argument. He said that the greatest challenge may be regulations which seem to be intentionally written in obscure “human” terms.
He explained, “In many key jurisdictions, regulation has become “outcome-focused” (like the UK Consumer Duty), and does not prescribe specific steps, but outlines general expectations. It is drafted in what can be called, in this context, “human” terms – like “acting in good faith”, “enabling and supporting customers”, “care” etc.
Thirer states that, ironically, machines may actually be able to help humans comply even better – because they can help humans identify the required standard of care etc.
“In this case, it will be of course humans which will set the initial parameters, guardrails etc., and will also supervise the outcomes; but the machines will actually perform the bulk of the individual tasks,” he said.
Can machine-readable regulation improve outcomes
Would machine-readable regulation improve compliance outcomes or create new risks?
Machine-readable regulation has the potential to strengthen compliance, but only if firms resist the temptation to treat automation as a replacement for judgement, said Nice.
He believes structured, machine-readable rules could make regulatory obligations clearer, more consistent and easier to implement. “It could reduce the friction between regulatory change and implementation,” he says, helping firms understand what has changed, which controls are affected, what data is required and where action is needed.
Beyond implementation, Nice sees significant benefits for governance and auditability. By creating a clear line between regulatory requirements, internal policies, operational controls and compliance outcomes, firms can build a stronger evidential foundation for their compliance programmes.
“If firms can show a clear link between a regulatory obligation, the internal policy position, the control, the workflow, the data used and the outcome produced, compliance becomes more transparent and defensible,” he explains. “That is where machine-readable regulation could be powerful.”
However, he warns that the same technology could introduce new risks if organisations become overly reliant on it. Executable rules are only as effective as the logic behind them, and where that logic is outdated, incomplete or too narrowly interpreted, firms risk automating flawed decisions at scale.
“So I am positive about the direction, but cautious about the framing,” Nice says. “Machine-readable regulation should make compliance more structured and evidence-led; it should not remove accountability from the process.”
Thirer believes that the very exercise of reviewing regulation and trying to see it from a new angle and perhaps more action-oriented will improve the quality of the regulation itself, and hence the quality of compliance.
He commented, “I’m not worried about the introduction of machines – machines are usually more predictable than humans, and are easier to instruct and supervise at scale.”
In the view of Nzsdejan, the answer is both. The upside, he said, is material – consistent interpretation, lower cost of regulatory change, less arbitrage through selective reading.
He said, “At Cardamon, structuring obligations consistently across jurisdictions already transforms what clients can see – comparing their UK, EU, and Singapore footprint from one data model rather than three parallel manual analyses.”
Despite this, the risks are also real. He suggests gaming, as precise rules are more exploitable than ambiguous ones. Brittleness is also one, as coded rules can’t absorb novel circumstances the way text can – and in financial crime, the most dangerous activity often looks superficially compliant. Over-reliance is also key, as teams that treat machine-readable regulation as the complete picture stop applying the judgment that novel risks require.
He concludes, “The answer goes beyond automation – it is automation that creates space for better judgment.”
Removing unnecessary ambiguity
The ambition behind machine-executable regulation is not to eliminate human judgement, but to remove unnecessary ambiguity, according to Ermanno Ciarrocchi, chief growth officer at CleverChain.
He points to the concept of Model-Driven, Machine-Executable Regulation (MDMER), first outlined by the FCA and Bank of England a decade ago, as a vision for expressing regulatory requirements as logical models that systems can execute directly. “The goal,” he says, “was removing ambiguity, not judgement.”
Ciarrocchi believes large language models have significantly lowered the cost of translating natural-language regulation into structured logic, while major regulatory frameworks such as DORA, the EU AI Act and the AMLR are increasing demand for more scalable approaches to compliance.
Even so, he stresses that practical adoption has remained limited to areas where obligations are objective and easily codified. “Live applications making the obligation behind the text executable have remained only within calculable, rules-light domains such as reporting fields, tax thresholds and eligibility conditions,” he says.
The reason, he argues, is that much of financial regulation is intentionally built around principles rather than rigid rules. Whether due diligence has been adequate or a risk rating is defensible often depends on professional judgement, making those obligations inherently resistant to full automation.
“We would treat the principles- and risk-based character of much financial regulation not as a hurdle to be overcome, but as the natural border of the domain,” Ciarrocchi explains. “Where a rule turns on whether due diligence was adequate, or a risk rating defensible, the regime is delegating judgement deliberately.”
Rather than attempting to replace that judgement, he believes technology should make it more transparent. “The useful role for technology is not to remove judgement but to make it traceable,” he says, adding that he favours “an interpretation that is explicit and auditable over one hard-coded by a vendor or mutualised into a single shared answer.”
Ciarrocchi also highlights what he sees as an underappreciated danger: “false precision”. “Automation can lend an output the appearance of authority,” he says, “yet the judgement underneath may have been open to challenge all along.”
Looking ahead, he believes the commercial opportunity in machine-readable regulation will lie less in the underlying infrastructure and more in the layer built on top of it. Pointing to initiatives such as the ISDA Digital Regulatory Reporting framework, which is freely available to firms, he argues that the foundational “rails” are increasingly becoming a public good.
“That is why we believe the next phase of RegTech will be decided less by who can execute a rule, and more by who can defend the judgement around it,” he concludes.
Transformative potential
Machine-readable regulation has the potential to transform anti-money laundering compliance, but only if firms first address the quality and governance of the data underpinning their systems, according to RelyComply.
The company says the growing interest in machine-readable regulation reflects a broader shift towards AI-enabled compliance, where standardised, structured rules can replace much of the ambiguity associated with interpreting legal text.
“The appetite for machine-readable regulation is highly understandable,” it says. “We live in an age where AI development is gaining pace to better AML operations, replacing the subjective legal jargon that once dominated compliance with standardised code to lower any ambiguity.”
RelyComply points to the EU’s Anti-Money Laundering Regulation (AMLR) as an example of the direction regulators are taking, arguing that more structured regulatory requirements could help create consistent compliance processes across Member States. Greater standardisation would improve firms’ ability to trace ownership structures, analyse cross-border transactions and demonstrate how key AML decisions were reached.
“When data trails are detailed, in the correct format, they enable regulated financial institutions to maintain oversight for the end-to-end onboarding, monitoring and reporting capabilities required of them,” the company explains. Better-structured data would also make information easier to share with financial intelligence units, helping create a faster and more coordinated approach to financial crime detection.
However, RelyComply argues that technology alone cannot overcome weak data foundations. “This disparity of data governance and quality will continue to halt any path to machine-readable regulation,” it warns. Incomplete or inaccurate data can undermine identity verification, flood AML systems with false positives and ultimately obscure genuine indicators of financial crime.
The challenge becomes even greater when viewed across the wider financial ecosystem. Banks, fintechs, payment service providers, supervisors and law enforcement agencies all rely on data that must be accurate, interoperable and consistently governed. Without that foundation, RelyComply argues, coordinated, data-led financial crime prevention remains out of reach, while organised criminal networks continue to exploit fragmented systems at scale.
For that reason, the company believes machine-readable regulation should be built around human oversight rather than human replacement. “The answer lies in a human-led approach to managing automated AML systems,” it says. Even the most sophisticated AI models depend on high-quality data, effective governance and clearly defined risk policies to produce reliable outcomes.
RelyComply argues that the success of machine-readable regulation will depend as much on data quality as technology. “Creating a landscape for machine-readable regulation relies on foolproof data and systems that are already flexible to changing risk profiles and criminal typologies,” it concludes, making compliance “simpler, and more effective as deterrents of serious crime.”
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





