Banks Adopt AI and Stablecoins Faster Than Compliance Can Keep Up

Highlights

Agentic AI can expose compliance gaps when agents, vendors and control systems operate under different governance structures.

Stablecoin adoption is testing transaction monitoring systems built around the behavior of fiat payments.

Financial crime teams need clear data lineage, access controls and audit trails as automation assumes more compliance work.

Watch more: What’s Next in Payments With Flagright’s Chris Phillips

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    A little paranoia may be useful when the technology moving money changes faster than the controls designed to police it.

    That is the premise Chris Phillips, director of Financial Crime Industry Engagement at Flagright, brought to a PYMNTSWhat’s Next in Payments” interview centered on a maxim associated with former Intel CEO Andy Grove: Only the paranoid survive.

    Grove used the idea to describe strategic inflection points, when changes in technology, regulation, competition or customer behavior can undermine assumptions that businesses have relied upon.

    For financial institutions, several of those forces are converging, Phillips said.

    “I think a little bit of paranoia is healthy,” he said, adding, “You want to keep on your toes and understand what’s going on.”

    Artificial intelligence has moved from specialized experimentation into routine financial services discussions, while stablecoins have traveled from the edge of banking strategy to conversations at institutions that would scarcely have considered them several years ago.

    Phillips said he views threats and opportunities as closely connected, where a threat offers what he termed “an opportunity to do something a little bit better.” That means examining a technology stack for places where systems can break and where governance can diverge across technologies, vendors and business functions.

    AI complicates that work because agentic systems do not resemble another conventional software upgrade. Banks may deploy separate agents for sanctions, know your customer, transaction monitoring and other functions, sometimes supplied by different vendors. Those agents can operate under different controls and model-risk practices even though their decisions intersect.

    That fragmentation is a substantial risk, Phillips said. There needs to be an intentional governance thought process around this, an audit trail that runs from data lineage sources up through decisioning.

    The concern extends to access controls. Each agent introduces questions about what it can reach, what it is permitted to do, and whether investigators and regulators can reconstruct its decisions. Phillips pointed to a need to maintain a clear audit trail. Financial institutions increasingly need to be able to explain how data inputs, models and automated steps contributed to a final decision.

    Stablecoins Put Legacy Controls Under Pressure

    Stablecoins present a related problem because their place within U.S. financial services is changing.

    The GENIUS Act is a pivotal development, Phillips said, adding it “laid the bridge across that chasm” where stablecoins and cryptocurrency had largely occupied a separate category from conventional banking. Stablecoin-native models are emerging now. Books may be denominated in dollars while customers transact in stablecoins, and transactions ultimately settle in dollars.

    The compliance problem is architectural. Transaction monitoring systems designed around fiat payments cannot assume that stablecoins behave identically. Chain hopping, in which funds move across blockchains, is an example of information failing to accompany a transaction in the manner traditional monitoring systems expect, Phillips said.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    “You can’t just tack on crypto on top of a typical rules-based system, and say, ‘Hey, hopefully it works,’” Phillips said.

    Adoption has moved faster than the industry’s understanding of some of those monitoring problems, he said.

    AI presents much the same governance test. Financial institutions can attach agents to legacy infrastructure, but adding capability does not create coherent oversight. The institution still must know how a decision was reached, which information produced it, and whether controls remain intact as data passes among systems.

    For Flagright, those issues help define the need for what Phillips described as an AI operating system for financial crime compliance, a unified platform in which agents operate under common governance structures and audit trails. Across any such architecture, the rules layer and data pipeline are critical control points. Without strong access controls and data governance, tampered inputs can undermine alert quality.

    The broader question for compliance departments is where automation should end and human judgment should begin.

    Phillips used transaction structuring alerts to illustrate the distinction. A straightforward alert may be something an agent can assess and move through the process, including preparation of a suspicious activity report narrative. Repeated structuring over weeks by somebody with no known source of income presents a different risk and warrants deeper scrutiny.

    Automation, however, does not transfer accountability to the machine. Compliance officers still need to understand the financial crime typologies underlying their systems rather than assuming that installing another product or agent resolves the problem.

    Phillips distilled his advice to two words: “Stay curious.”

    Financial crime professionals do not need to become IT specialists, he said, but they do need to understand what their technology is doing and remain deliberate about its use.

    Watch the full interview with Flagright’s Chris Phillips to learn more about:

    • Why access control may pose a different AI risk than conventional model governance.
    • How financial crime teams can determine which alerts warrant human investigation and which can be handled by agents.
    • Why compliance systems may require continual adjustment as criminal methods and financial technology change.

    For all PYMNTS digital transformation coverage, subscribe to the daily Digital Transformation Newsletter.

    Chris Phillips is director of Financial Crime Industry Engagement at Flagright.