Published on: 6th October 2026
Authored by: Khiara Beryl Cardozo
University College, Dublin
Abstract
Traditional anti-money laundering (AML) legal frameworks were constructed upon the static assumption that criminal proceeds must enter, pass through, or conceal themselves within the physical or digital financial system via identifiable human actors.[1] Today, this foundation is severely challenged by the emergence of algorithmic financial crime, where Generative Artificial Intelligence (AI) enables mass-scale fraud, automated layering, synthetic identity fabrication, and deepfake deception.[2] This article examines whether existing AML laws are fit for purpose when compliance data can be algorithmically fabricated.[3] Focusing on the Irish legal framework under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (CJA 2010) and the EU AML Reform Package—including Regulation (EU) 2024/1620 (AMLA) and Regulation (EU) 2024/1624 (AMLR)—it argues that while current AML law is technology-neutral enough to capture AI-assisted financial crime in principle, its preventive architecture remains operationally ill-equipped for the velocity, scale, and evidential uncertainty generated by modern AI tools.[4]
I. Introduction
In the past, anti-money laundering regulation was founded on a relatively static assumption: criminal proceeds must enter, pass through, or conceal themselves within the financial system through observable physical or digital transactions.[5] As a result, legal and regulatory frameworks historically focused on four primary pillars: customer identification, beneficial ownership tracking, ongoing transaction monitoring, and the reporting of suspicious transactions to competent Financial Intelligence Units (FIUs).[6]
Presently, this traditional framework is facing rapidly shifting technological realities.[7] Fraud at a mass scale is now entirely achievable using Generative AI technologies capable of creating highly convincing synthetic identities, forging official identity documents, and automating complex fraudulent workflows.[8] The issue, in essence, poses a fundamental legal question: are existing AML laws sufficient when the foundational verification data required for statutory compliance can simply be algorithmically fabricated, manipulated, or simulated?[9]
In the context of the European Union (EU), analyzing this question is particularly urgent.[10] The EU anti-money laundering regime is currently undergoing its most comprehensive structural reform in decades.[11] The establishment of the Anti-Money Laundering Authority (AMLA) under Regulation (EU) 2024/1620, combined with the directly applicable Anti-Money Laundering Regulation (AMLR) under Regulation (EU) 2024/1624, represents a major shift toward harmonized, centralized supervision.[12] The AMLR will apply generally across all Member States from 10 July 2027, while AMLA is actively preparing for its first selection of obliged entities for direct EU-level supervision starting in 2027, leading to the formal commencement of direct supervisory operations in 2028.[13]
This article argues that existing AML law is sufficiently technology-neutral to capture most AI-assisted money laundering in principle, but its preventive architecture is not yet operationally adapted to the scale, speed, and evidential uncertainty produced by modern AI tools.[14] Hence, the core flaw in current AML governance is not legislative under-criminalisation; instead, it lies in the operational assumptions underpinning customer due diligence (CDD), identity verification mechanisms, automated transaction monitoring systems, and supervisory risk assessments.[15] Artificial intelligence can simultaneously erode these preventive systems while also fortifying compliance capabilities.[16] For this reason, the primary regulatory objective should not be to construct a standalone criminal offence of “AI money laundering,” but rather to develop a technologically informed, risk-based approach capable of adapting existing statutory obligations to new, automated forms of financial crime.[17]
II. From Traditional Money Laundering to Algorithmic Financial Crime
Classically, money laundering is conceptualized as a three-stage process: placement (introducing illicit, dirty money into the legitimate financial system), layering (distorting the audit trail and hiding the true source of funds through complex series of financial transactions), and integration (re-investing the laundered funds into the economy to make them appear entirely legitimate).[18] While this analytical taxonomy remains useful for legal classification, artificial intelligence now enables criminal networks to manipulate and automate this entire financial infrastructure simultaneously.[19]
The primary significance of AI lies in its unprecedented capacity for automation, speed, and scale.[20] Generative AI applications can create synthetic corporate structures, produce flawless forged documentation, and generate highly naturalistic correspondence.[21] Furthermore, deepfake technology can manipulate voice and video feeds in real-time to bypass biometric identity checks.[22] According to the Financial Action Task Force (FATF) 2025 Horizon Scan, these technologies constitute emerging AML/CFT risks that significantly enhance the ability of illicit actors to evade standard preventive controls.[23]
Importantly, AI does not alter the fundamental legal definition of money laundering.[24] Under international and European legal standards, any transaction involving property known to be derived from criminal activity remains unlawful, regardless of whether the transaction is executed manually by a human actor or autonomously via a software algorithm.[25] Rather, AI fundamentally alters the operational environment in which regulated institutions must detect, investigate, and report illicit behaviour.[26]
Consider the practical realities of remote customer onboarding.[27] Under standard Customer Due Diligence (CDD) practices, a regulated financial institution must collect identifying data and verify the customer’s identity using reliable documents, data, or information obtained from a dependable, independent source.[28] The new EU AMLR establishes strict mandatory requirements for obliged entities to obtain and verify identification information for both natural customers and beneficial owners, incorporating the use of electronic identification tools that comply with Regulation (EU) No 910/2014 (eIDAS assurance standards).[29] However, strict adherence to formal verification procedures can create a dangerous and misleading sense of regulatory assurance when a perpetrator can generate perfectly credible corroborating evidence, manipulate live video verification feeds, or simulate realistic digital footprints using AI.[30]
This creates a critical distinction between legal verification and substantive authenticity.[31] An institution might fully satisfy its procedural regulatory obligations by collecting a valid-appearing passport image, utility bill, and facial scan, while in reality dealing with a completely synthetic identity engineered by a generative model.[32] The legal obligation that identity must be verified has not failed in the abstract sense; rather, the underlying evidential material relied upon to satisfy that statutory requirement has become fundamentally less reliable.[33]
Similar challenges arise in automated transaction monitoring.[34] Under domestic statutory regimes, such as Irish law, designated persons are required to monitor ongoing customer dealings, scrutinizing transactions, source of wealth, and origin of funds to ensure that observed activity aligns with the customer’s known business profile.[35] However, AI-assisted criminals can deploy machine learning algorithms to distribute micro-transactions across thousands of accounts, vary transaction timing and amounts dynamically, and mimic normal consumer habits to deliberately bypass rule-based compliance thresholds and red flags.[36]
The result is an escalating regulatory contest between criminal automation and compliance automation.[37] On one side, financial institutions deploy machine learning models to analyze vast datasets and detect subtle anomalies.[38] On the other side, criminal actors utilize sophisticated generative models to render illicit activity indistinguishable from legitimate financial noise.[39] Consequently, the legal effectiveness of modern AML regulation depends on whether institutions can accurately distinguish genuine behavioral signals from artificially generated financial normality.[40]
III. The Irish AML Framework: Flexible but Not AI-Specific
Ireland’s primary anti-money laundering statute is the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (CJA 2010), as amended.[41] The statutory architecture of the CJA 2010 requires designated persons—including credit institutions, financial providers, legal professionals, and accountants—to execute customer due diligence, verify customer and beneficial ownership identities, assess the purpose of business relationships, perform ongoing transaction monitoring, and submit Suspicious Transaction Reports (STRs) to the Financial Intelligence Unit (FIU Ireland) and the Revenue Commissioners.[42]
A central strength of the Irish framework is its deliberate technology neutrality.[43] The CJA 2010 does not restrict its definitions of money laundering or predicate offences to specific technological mechanisms, nor does it limit CDD compliance to physical paperwork.[44] This technology-neutral design ensures that as new financial technologies emerge, they automatically fall within the scope of existing statutory obligations, eliminating the need for Parliament to pass new criminal statutes for every technological innovation.[45]
Furthermore, the European Union (Anti-Money Laundering: Protection of Whistleblowers) Regulations 2018 and subsequent statutory amendments reinforced the risk-based approach within Irish law.[46] Section 30A of the CJA 2010 mandates that designated persons conduct comprehensive business-wide risk assessments, explicitly evaluating risk factors such as customer demographics, product features, geographical risks, transaction types, and delivery channels.[47] Section 30B requires institutions to apply these insights to individual customer-level risk assessments, tailoring the intensity of CDD measures accordingly.[48] Thus, the Irish framework already possesses the legal mechanics necessary to incorporate technological risk into compliance assessments.[49]
However, technology neutrality must not be conflated with technological adequacy.[50] While the law is broad enough to criminalize AI-assisted illicit conduct, the practical compliance systems implemented by private institutions often remain profoundly ill-equipped to combat algorithmically generated deception.[51] Because AML statutes operate through a model of delegated preventive responsibility—where private institutions act as the primary frontline gatekeepers—this distinction is critical.[52] Although the state establishes the legal standard, the actual efficacy of the regime depends entirely on private compliance software and operational procedures.[53]
This operational challenge is clearly illustrated within Sections 33 and 35 of the CJA 2010.[54] While these provisions mandate customer identification, beneficial ownership verification, and ongoing transaction monitoring, they provide no specific legal guidance regarding how institutions should evaluate synthetic identity documents, detect deepfake video feeds during digital onboarding, or identify algorithmically obfuscated transaction networks.[55]
This is not necessarily a defect in the statute itself, as prescribing rigid technological standards in primary legislation would lead to rapid obsolescence.[56] Rather, it highlights that a technology-neutral statutory framework requires robust regulatory guidance, rigorous supervisory interpretation, and updated enforcement expectations from regulatory bodies such as the Central Bank of Ireland.[57]
IV. The EU AML Reform: A Stronger Foundation
The operational implementation gap highlighted above is a central target of the EU’s new Anti-Money Laundering Package.[58] By replacing fragmented national transposition with a directly applicable Single Rulebook, Regulation (EU) 2024/1624 (AMLR) establishes uniform, binding rules across all EU Member States.[59] Under the AMLR, obliged entities must execute Customer Due Diligence when establishing business relationships, carrying out occasional high-value transactions, detecting suspicious activity, or when doubts arise regarding the truthfulness or adequacy of previously obtained customer identification data.[60]
This explicit statutory requirement to re-evaluate customer data whenever doubts arise regarding its veracity becomes particularly vital in an AI-driven environment.[61] It establishes that customer verification cannot be treated as a static, one-off onboarding exercise.[62] Instead, it imposes an ongoing legal duty on financial institutions to re-verify customer identities whenever new behavioral data, anomaly reports, or intelligence suggest that a profile may have been artificially fabricated or compromised.[63]
The AMLR also significantly strengthens beneficial ownership transparency requirements.[64] Obliged entities must identify all beneficial owners, verify their identities using reliable independent sources, and trace complex control structures to prevent criminal networks from hiding behind multi-layered corporate entities, nominee directors, and synthetic personas.[65] This focus is essential, as AI-enabled financial crime relies not merely on fabricated natural persons, but on the automated management of legal entities designed to obscure the ultimate human beneficiaries.[66]
While the AMLR maintains a flexible, risk-based approach rather than prescribing specific technologies, this flexibility shifts substantial responsibility onto regulatory supervisors and compliance personnel.[67] The critical question remains whether institutions and regulators can identify technology-driven risks quickly enough to ensure a technology-neutral framework remains effective in practice.[68]
To ensure uniform regulatory enforcement, Regulation (EU) 2024/1620 establishes the Anti-Money Laundering Authority (AMLA).[69] Headquartered in Frankfurt, AMLA’s core priorities for its 2026 operational rollout include finalizing the Single Rulebook, fostering supervisory convergence, improving cross-border cooperation between national Financial Intelligence Units (FIUs), and establishing common supervisory risk assessment methodologies.[70] Furthermore, AMLA is refining the selection methodology to identify approximately 40 high-risk, cross-border credit and financial institutions for direct EU-level supervision starting in 2028.[71]
However, institutional centralization alone cannot resolve underlying technological vulnerabilities.[72] While a single European supervisory authority eliminates regulatory arbitrage across Member States, institutions may still struggle equally with AI-generated deception.[73] Therefore, success depends on whether advanced technological competence is embedded directly into AMLA’s supervisory framework by default, rather than treated as an auxiliary compliance option.[74]
V. Where AI Exposes the Limits of Existing AML Law
The primary vulnerability exposed by artificial intelligence is synthetic identity fraud.[75] The core legal purpose of CDD is to ensure that a regulated entity can definitively confirm that a person requesting financial services is precisely who they claim to be.[76] AI tools complicate this by allowing bad actors to combine genuine personal identification information (PII) stolen from real individuals with synthetically generated data, producing hybrid identities backed by valid-looking documentation, facial images, and credit histories.[77]
The EU AMLR attempts to address this by requiring identity verification through official identity documents, dependable independent sources, and qualified electronic identification tools under the eIDAS framework.[78] However, while compliance with formal verification procedures provides procedural protection, it does not guarantee substantive authenticity.[79] Because synthetic identities possess real, verified components, they frequently pass standard verification checks.[80] To counter this, modern legal frameworks must shift from viewing CDD as a static, onboarding-focused event toward a continuous, dynamic verification process.[81]
A second major structural flaw exists in conventional automated transaction monitoring.[82] Existing AML legislation requires institutions to monitor customer transactions and identify unusual or suspicious patterns.[83] However, rule-based monitoring systems rely on historical indicators of illicit behavior.[84] When criminals deploy adaptive machine learning models to restructure transaction flows in real-time, static compliance systems fail to trigger alerts.[85]
Importantly, AI is not solely a threat vector; it also represents a powerful compliance tool.[86] Advanced machine learning algorithms can analyze vast, unstructured datasets to uncover complex money laundering networks that human analysts or legacy systems would miss.[87] The FATF explicitly recognizes this dual role, emphasizing that AI can simultaneously create sophisticated AML vulnerabilities while offering advanced tools to strengthen enforcement capabilities.[88]
Consequently, the proper legal response is not to restrict or mandate specific software tools, but to establish robust regulatory governance over automated compliance systems.[89] Financial institutions must be legally required to document, validate, audit, and explain their automated AML monitoring algorithms.[90] Uncritical reliance on uncalibrated black-box software introduces severe legal and operational risks, leading either to overwhelming false positives or dangerous compliance blind spots.[91]
VI. Attribution and Cross-Border Enforcement
Artificial intelligence introduces complex evidential challenges regarding legal attribution and criminal liability.[92] Criminal law traditionally requires establishing both an actus reus (the prohibited physical act) and a mens rea (the guilty mind) associated with a natural or legal person.[93] In AI-enabled financial crime schemes, operational roles are frequently decentralized: one party develops or fine-tunes the AI model, another acquires stolen identity datasets, a third operates autonomous trading bots, and a fourth receives the laundered funds.[94]
While established principles of accessorial liability, conspiracy, and corporate criminal liability remain applicable, proving specific intent and identifying the ultimate human controller behind dispersed, automated transaction chains presents severe evidential hurdles for law enforcement.[95] An actor in one jurisdiction can deploy autonomous agents hosted on decentralized servers to execute transactions across multiple foreign credit institutions instantly.[96]
Historically, enforcement across the EU suffered from fragmented national supervision, uncoordinated FIU inquiries, and inconsistent cross-border evidence gathering.[97] The creation of AMLA under Regulation (EU) 2024/1620 directly targets these systemic weaknesses.[98] AMLA’s mandate includes establishing joint intelligence analyses, harmonizing FIU reporting templates, and coordinating cross-border investigations.[99]
However, supervisory centralization will only improve enforcement against AI-enabled crime if regulatory authorities possess the technical capacity to analyze complex algorithmic evidence.[100] Without deep technical expertise within AMLA and national FIUs, centralized supervision risks enforcing outdated compliance paradigms across borders more uniformly, rather than addressing the actual mechanics of algorithmic financial crime.[101]
VII. Fundamental Rights and Algorithmic AML
The expansion of automated, AI-driven financial surveillance introduces severe constitutional tensions regarding the protection of fundamental human rights.[102] Advanced AML systems require the collection, aggregation, and processing of massive volumes of personal and financial data.[103] While deploying AI models enhances anomaly detection, it also heightens the risk of disproportionate state and corporate interference with individual privacy and data protection rights.[104]
The legal boundary governing financial transparency was definitively reinforced by the Court of Justice of the European Union (CJEU) in the landmark ruling WM and Sovim SA v Luxembourg Business Registers (Joined Cases C-37/20 and C-601/20).[105] The CJEU invalidated provisions of the 5th EU Anti-Money Laundering Directive that granted unrestricted public access to beneficial ownership registers, ruling that such access constituted a serious and disproportionate breach of Articles 7 (respect for private and family life) and 8 (protection of personal data) of the Charter of Fundamental Rights of the European Union.[106] The Court firmly established that the public objective of combating financial crime cannot override the fundamental principle of proportionality.[107]
This principle applies directly to algorithmic AML surveillance.[108] The deployment of predictive machine learning models to score customer risk profiles must operate within strict legal boundaries.[109] Automated risk scoring can result in severe real-world consequences, including account freezes, delayed transactions, and total exclusion from banking services (“de-risking”).[110] If these algorithms operate as opaque “black boxes” trained on biased or inaccurate datasets, affected individuals are deprived of their right to understand, challenge, or appeal adverse decisions.[111]
Therefore, technological advancement must not transform risk-based AML regulation into a system of automated suspicion by default.[112] Regulatory frameworks must preserve procedural fairness, ensure algorithmic transparency, and embed strict proportionality checks into every automated compliance system.[113]
VIII. Integrating AML and AI Regulation
Addressing algorithmic financial crime requires examining the intersection between specialized AML statutes and broader digital regulations, specifically the EU Artificial Intelligence Act (Regulation (EU) 2024/1689).[114] The AI Act establishes a comprehensive, risk-tiering legal framework, imposing strict transparency and governance requirements on high-risk AI applications and specific generative AI systems, including deepfake generators and synthetic media tools.[115]
While the AI Act is a general regulatory regime without an explicit AML mandate, its provisions are highly relevant to financial crime enforcement.[116] For instance, mandatory technical labeling, digital watermarking, and transparency obligations for synthetic content directly assist financial institutions in identifying algorithmically generated identity documents and fraudulent onboarding media.[117]
These regulatory frameworks must be treated as mutually reinforcing rather than isolated regimes.[118] While AML supervisors should avoid acting as general-purpose AI regulators, they should incorporate standards developed under the AI Act when assessing whether an institution’s compliance infrastructure adequately mitigates AI-specific financial crime risks.[119] Integrating AI governance standards into financial supervisory evaluations ensures a cohesive regulatory defense against technology-enabled fraud.[120]
IX. Reforming AML for the Algorithmic Era
To ensure anti-money laundering laws remain effective in an algorithmic landscape without abandoning their valuable technology-neutral character, regulatory authorities should implement four structural reforms:
1. Mandate AI-Specific Risk Assessments: Business-wide risk assessments under statutory regimes like Section 30A of the Irish CJA 2010 and Article 8 of the EU AMLR must explicitly evaluate exposure to AI-generated threats.[121] Institutions should be required to formally document their operational vulnerabilities to synthetic identities, deepfakes, automated account creation, and algorithmically engineered transaction patterns.[122]
2. Establish Enhanced Digital CDD Standards: Regulators must provide clearer operational standards for digital customer due diligence.[123] Financial institutions should be required to demonstrate that their digital onboarding tools can reliably detect manipulated biometric signals and synthetic identity documentation.[124] Crucially, this guidance must remain vendor- and technology-neutral, specifying required levels of evidential assurance rather than mandating individual commercial software products.[125]
3. Build Specialized Technical Expertise Within Supervisory Bodies: Supervisory authorities—including AMLA, national competent regulators like the Central Bank of Ireland, and FIUs—must recruit specialized personnel proficient in auditing machine learning models, investigating algorithmic fraud, and evaluating automated compliance systems.[126] AMLA’s developing supervisory methodology should integrate technical algorithmic audits directly into its core inspection procedures.[127]
4. Enforce Algorithmic Proportionality and Mandatory Human-in-the-Loop Safeguards: Automated risk scoring and transaction monitoring systems must strictly adhere to the fundamental principles of data minimization, transparency, and human oversight.[128] High-risk automated decisions—such as account closures, transaction freezes, or de-risking actions—must remain subject to meaningful human review, providing customers with clear reasoning and accessible appeal mechanisms.[129]
X. Conclusion
Existing anti-money laundering laws are fit for purpose in principle, but they are not yet operationally fit for the algorithmic environment in which they must be enforced.[130] The foundational technology neutrality of statutes like Ireland’s CJA 2010 and the new EU AML package is a significant legal asset.[131] Broad statutory definitions of money laundering, customer due diligence, beneficial ownership, and suspicious activity reporting possess the legal flexibility required to encompass AI-assisted criminal conduct without necessitating endless legislative amendments.[132] Furthermore, the EU AML Reform Package establishes unprecedented harmonization through the AMLR and provides a powerful mechanism for cross-border supervisory coordination through AMLA.[133]
However, formal legal coverage must not be confused with real-world operational effectiveness.[134] Artificial intelligence directly compromises the evidential reliability of identity verification data, accelerates the velocity and scale of money laundering schemes, and complicates cross-border attribution.[135] Simultaneously, AI provides compliance authorities with powerful new analytical capabilities to detect complex financial crime.[136]
Therefore, the challenge facing modern financial regulation is one of operational adaptation rather than legislative replacement.[137] Enacting a narrow, standalone offence of “AI money laundering” would merely address surface symptoms while leaving systemic compliance vulnerabilities untouched.[138] Instead, the primary regulatory objective must be ensuring that existing, technology-neutral legal duties are enforced through compliance systems and supervisory frameworks capable of identifying, evaluating, and mitigating modern algorithmic threats.[139]
The European Union’s ongoing AML reforms represent a major step in the right direction, but their ultimate success will depend entirely on practical implementation.[140] With the establishment of AMLA and the rollout of direct EU-level supervision, regulators have a unique institutional opportunity to make technical competence a permanent feature of mainstream AML supervision.[141] Current AML laws can successfully meet the challenges of algorithmic financial crime, but only if their technology-neutral foundations are paired with technologically informed supervision, dynamic digital customer due diligence, specialized technical expertise, and robust human oversight over automated decision-making.[142] Without these necessary operational adaptations, statutory frameworks will remain comprehensive on paper while growing increasingly ineffective against the automated financial crime they were created to prevent.[143]
References
[1] Financial Action Task Force [FATF], International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation (Recommendation 1, as amended 2025).
[2] FATF, Targeted Update on FATF Standards on Virtual Assets and Virtual Asset Service Providers (June 2025).
[3] Id.
[4] Regulation (EU) 2024/1620 of the European Parliament and of the Council of 31 May 2024 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, OJ L, 2024/1620, 19.6.2024; Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, OJ L, 2024/1624, 19.6.2024 [hereinafter AMLR].
[5] FATF, International Standards, supra note 1.
[6] Id.
[7] FATF, Horizon Scan Report: Emerging Risks and Technological Developments in AML/CFT (2025).
[8] Id.
[9] Id.
[10] Regulation (EU) 2024/1620 (AMLA Regulation).
[11] AMLR, supra note 4.
[12] Regulation (EU) 2024/1620; AMLR, supra note 4.
[13] Regulation (EU) 2024/1620, art. 5.
[14] Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (Act No. 6 of 2010) (Ir.) [hereinafter CJA 2010].
[15] Id.
[16] FATF, Horizon Scan Report, supra note 7.
[17] Id.
[18] Paul Cassella, The Legal Tools of Anti-Money Laundering Enforcement, 12 J. FIN. CRIME 110, 112 (2021).
[19] Id.
[20] FATF, Horizon Scan Report, supra note 7.
[21] Id.
[22] Id.
[23] Id.
[24] CJA 2010, s. 7.
[25] AMLR, art. 3.
[26] FATF, Horizon Scan Report, supra note 7.
[27] AMLR, art. 15.
[28] CJA 2010, s. 33.
[29] Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS Regulation); AMLR, art. 18.
[30] FATF, Horizon Scan Report, supra note 7.
[31] Id.
[32] Id.
[33] Id.
[34] CJA 2010, s. 35.
[35] Id.
[36] FATF, Horizon Scan Report, supra note 7.
[37] Id.
[38] Id.
[39] Id.
[40] Id.
[41] CJA 2010 (as amended by the Criminal Justice (Money Laundering and Terrorist Financing) (Amendment) Act 2018 and 2021).
[42] CJA 2010, ss. 33, 35, 42.
[43] CJA 2010, s. 2.
[44] Id.
[45] Id.
[46] European Union (Anti-Money Laundering: Protection of Whistleblowers) Regulations 2018 (S.I. No. 487 of 2018) (Ir.).
[47] CJA 2010, s. 30A.
[48] CJA 2010, s. 30B.
[49] Id.
[50] FATF, Horizon Scan Report, supra note 7.
[51] Id.
[52] CJA 2010, s. 25.
[53] Id.
[54] CJA 2010, ss. 33, 35.
[55] Id.
[56] Id.
[57] Central Bank of Ireland, Anti-Money Laundering and Countering Financing of Terrorism Guidelines for the Financial Sector (2023).
[58] AMLR, supra note 4.
[59] AMLR, art. 1.
[60] AMLR, art. 15.
[61] Id.
[62] Id.
[63] Id.
[64] AMLR, art. 42.
[65] AMLR, arts. 42–48.
[66] Id.
[67] AMLR, art. 8.
[68] Id.
[69] Regulation (EU) 2024/1620, art. 1.
[70] Regulation (EU) 2024/1620, art. 5.
[71] Regulation (EU) 2024/1620, art. 12.
[72] Id.
[73] Id.
[74] Id.
[75] FATF, Horizon Scan Report, supra note 7.
[76] CJA 2010, s. 33; AMLR, art. 16.
[77] FATF, Horizon Scan Report, supra note 7.
[78] AMLR, art. 18; eIDAS Regulation, supra note 29.
[79] FATF, Horizon Scan Report, supra note 7.
[80] Id.
[81] Id.
[82] CJA 2010, s. 35; AMLR, art. 21.
[83] Id.
[84] FATF, Opportunities and Challenges of New Technologies for AML/CFT (2021).
[85] Id.
[86] Id.
[87] Id.
[88] Id.
[89] European Data Protection Board [EDPB], Guidelines on the Processing of Personal Data in AML/CFT Frameworks (2024).
[90] Id.
[91] Id.
[92] Lucian Dervan, Corporate Criminal Liability in the Age of Algorithmic Governance, 45 HARV. J. L. & PUB. POL’Y 301, 315 (2022).
[93] Id.
[94] Id.
[95] Id.
[96] FATF, Horizon Scan Report, supra note 7.
[97] Regulation (EU) 2024/1620, recitals 1–5.
[98] Regulation (EU) 2024/1620, art. 1.
[99] Regulation (EU) 2024/1620, arts. 5, 32.
[100] Id.
[101] Id.
[102] Charter of Fundamental Rights of the European Union, arts. 7, 8, 2012 O.J. (C 326) 391.
[103] EDPB, Guidelines, supra note 89.
[104] Id.
[105] Joined Cases C-37/20 and C-601/20, WM and Sovim SA v Luxembourg Business Registers, ECLI:EU:C:2022:912 (Nov. 22, 2022).
[106] Id. at paras. 74–88.
[107] Id. at paras. 85, 86.
[108] EDPB, Guidelines, supra note 89.
[109] Regulation (EU) 2016/679 (General Data Protection Regulation), arts. 5, 22, 2016 O.J. (L 119) 1.
[110] FATF Guidance on Financial Inclusion and AML/CFT Measures (2025).
[111] Id.
[112] EDPB, Guidelines, supra note 89.
[113] Id.
[114] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 2024/1689, 12.7.2024.
[115] Regulation (EU) 2024/1689, arts. 50, 52.
[116] Id.
[117] Regulation (EU) 2024/1689, art. 50.
[118] AMLR, art. 8; Regulation (EU) 2024/1689, art. 2.
[119] Id.
[120] Id.
[121] CJA 2010, s. 30A; AMLR, art. 8.
[122] Id.
[123] AMLR, art. 18.
[124] Id.
[125] Id.
[126] Regulation (EU) 2024/1620, art. 5.
[127] Id.
[128] GDPR, art. 22; EDPB, Guidelines, supra note 89.
[129] Id.
[130] FATF, Horizon Scan Report, supra note 7.
[131] CJA 2010, s. 2; AMLR, art. 1.
[132] Id.
[133] Regulation (EU) 2024/1620; AMLR, supra note 4.
[134] FATF, Horizon Scan Report, supra note 7.
[135] Id.
[136] FATF, Opportunities and Challenges, supra note 84.
[137] Id.
[138] Id.
[139] Id.
[140] Regulation (EU) 2024/1620; AMLR, supra note 4.
[141] Id.
[142] Id.
[143] Id.




