Why banks can’t trust AI compliance without guardrails

Why banks can't trust AI compliance without guardrails

As banks race to automate compliance, one problem keeps surfacing: AI does not always give the same answer twice. According to Duna, the RegTech firm building AI-driven compliance infrastructure, the solution is not to make AI predictable but to wrap it inside a system that is.

Duna points to the 2026 Global AI in Financial Services Report, which found that 70% of financial services firms rank model hallucinations and unreliable outputs among their biggest AI risks. Regulators share that concern in equal measure. For compliance leaders, the challenge is reducing that risk without forcing analysts to check every single AI output, which would wipe out much of the efficiency gain.

Duna argues that compliance blends fixed rules with judgement calls, so the supporting technology must handle both. A deterministic system applies identical rules to identical information and produces identical results. AI, by contrast, can reach different conclusions from the same inputs. Pairing the two, Duna says, forms the basis of bank-grade AI: the deterministic layer guarantees procedures are followed in a repeatable and auditable way, while AI handles tasks such as weighing the relevance of adverse media.

Duna’s own deterministic policy engine translates a bank’s policies into code and orchestrates specialised AI agents across onboarding, due diligence, screening, monitoring and perpetual Know Your Customer (KYC). When more evidence is needed, the engine calls on an agent, then decides whether policy requirements have been satisfied and what action follows.

A practical example involves value-added tax (VAT) checks. If a registered address differs from the one a customer provided, the engine asks AI to assess the mismatch. The company may have relocated from Belgium to the Netherlands without updating its VAT record, or it may run two headquarters listed in separate sources. Such scenarios are often too rare to merit dedicated rules, so AI evaluates the context and escalates genuinely ambiguous cases to a human.

Before AI outputs can bypass human review, Duna says agents must meet the standards banks already apply to staff. That means running agents and analysts on the same cases, comparing outcomes and identifying where instructions need refining or where analysts themselves disagree. Teams must also rerun identical cases to measure consistency, establishing whether any change stems from new information or model variation.

Once an agent performs reliably within agreed tolerances for a specific task, review can be reduced task by task. At SeQura, Duna runs screening and verification checks, including adverse media, politically exposed person (PEP) checks, ID verification and watchlist hits, before a case reaches an analyst. Average analyst time per case dropped from 243 minutes to 14.9 minutes, making reviews 16.3 times faster.

Duna also stresses designing for reassessment. Because it records the evidence behind each case, its system can identify work affected by an outdated instruction and have AI reassess it using the revised approach.

The conclusion, according to Duna, is that AI need not be deterministic for compliance to be dependable. Trust comes from AI operating within a framework built for consistency.

For more, read the full story here.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.