Banks racing to deploy agentic AI in financial crime compliance are running into a familiar trap: treating the new technology as a faster version of the old one, rather than a reason to rethink how the work gets done. Janet Bastiman, Chief Data Scientist at Napier AI, explains what can be a better alternative.

Dr Janet Bastiman is Chief Data Scientist at Napier AI, a financial crime compliance technology provider that has worked directly with the UK’s Financial Conduct Authority (FCA) to test new data and AI models, including through the regulator’s Supercharged Sandbox.
In this interview with PaySpace Magazine Global, Bastiman explains why banks should use AI to do new things rather than automate existing processes, drawing a parallel to the early days of cloud adoption when many firms simply recreated old systems in new environments. She also unpacks why AI success in anti-money laundering (AML) hinges on data readiness and joined-up transaction data, why pilots often stall when they hit the realities of scaling, and why first and second line of defence analysts must remain the humans-in-the-loop for testing, validating, and reviewing agentic decisions, particularly when a transaction or entity is flagged as high risk.
You have been working directly with the Financial Conduct Authority (FCA) on testing new data and artificial intelligence (AI) models. What (if anything) did that collaboration change about how you think regulators should engage with the fintech and AI technology industry?
For years, one of the most persistent myths in technology has been that regulation stifles innovation. But initiatives such as the FCA’s Supercharged Sandbox represent a shift in the role of the regulator from being solely an enforcer to being an enabler of innovation as well. It gives selected participants access to curated datasets, APIs and scalable compute infrastructure, guided by an FCA representative and an industry mentor, making the process collaborative.
When the regulator is so forthcoming in its support, fintech and AI technology companies are encouraged to work with it, which in turn removes hesitancy to develop and test complex technologies within financial services, including agentic AI or automated decisioning. The FCA’s focus on regulating the outcome, rather than the technology used to obtain it, makes the process far more inclusive and collaborative.
One of your arguments is that banks should skip the copilot phase and fast-follow straight to agentic builds. What’s the strongest evidence you’ve seen that copilots are often a detour one can easily omit?
Copilots are quickly becoming obsolete in financial crime compliance. They are context unaware, sit outside of workflows, and are too generic to be useful or compliant. For fincrime compliance, it’s essential to have context-specific information, and the goal is to replace isolated actions with agents. If fincrime teams do not already have a copilot in place, they could skip this entire generation of AI and land directly in agentic.
What internal capabilities does a bank need in place before it can responsibly deploy agentic AI, and where do most institutions fall short today?
I advise teams to use AI technology to do new things, not just to automate existing processes. We should learn from previous generational shifts in technology such as the advent of cloud, where many firms got bogged down recreating their existing technology stacks in new environments, and did not take the opportunity to rethink the approach and drive operational plans.
AI success depends on data readiness as banks need access to clear, joined-up transaction and customer data when it comes to anti-money laundering (AML) use cases. Without that, AI can struggle to connect the dots or even circumvent permissions and poorly-set-up governance frameworks. Where financial institutions and banks often struggle is when they have successful pilots that are designed for a single test case, but they lack the infrastructure underneath to scale the AI system.
Does agentic AI introduce genuinely new compliance risks or just scaling up risks that already existed with earlier automation initiatives in banking?
The new risk for financial institutions is to show the evidence that led to their final decision when it comes to financial crime compliance decisions. Financial institutions are already working on compliance with fincrime regulations and even testing AI use cases, but as it becomes more widely adopted in AML processes, firms are under pressure to show that their outcomes are accurate, risk-based, and explainable under FCA supervision.
In your opinion, which industry offers most opportunities for agentic AI potential: e-commerce, payments, or banking?
From a risk management perspective, they are equally suitable because they all carry the growing regulatory burden of financial crime compliance. Unlike other parts of the financial services ecosystem where agents can operate autonomously, there are specific regulatory requirements for human involvement in financial crime compliance decisions. Some AML typologies are most relevant to specific financial services organisations, but the potential for agents in AML and sanctions programmes should be categorised by risk-type not sector. Low-risk transactions, as defined by a risk based approach, can be auto-closed by agents under current regulatory provisions. For high-risk transactions that require human-in-the-loop investigations, agents can support with collating information via natural-language instructions, and even automation around the creation and filing of Suspicious Activity Reports (SARs). We have developed agents for the testing of AML typologies and screening configurations, that will perform as ‘bad actors’ to try and evade detection.
How should a bank create a solid human oversight policy for an agentic system that’s making decisions faster than a person can review them in real time?
First and second line of defence analysts must understand common money laundering typologies and should be the humans-in-the-loop for any agentic decision making, as well as the testing and validation of agentic builds to confirm they generate alerts as expected.
Human-in-the-loop should be critical for any entity or transaction deemed high risk. AI has use cases for low-risk alerts, but when AI-driven pattern detection generates an alert classified as high risk, a human must be able to actively review the reasoning and be a responsible part of any decision to dismiss or alert.
Which industry initiatives can you particularly single out as those which might solve the issues of explainability of AI agent actions, agentic banking compliance and responsibility dilemmas?
The FCA Supercharged Sandbox is a great example, working with financial institutions to access curated datasets, APIs and scalable compute infrastructure to test specific agentic use cases in a controlled regulatory environment. For explainability, Retrieval-Augmented Generation (RAG) lets compliance teams trace any AI-generated statement back to the original transaction, allowing every agent decision to be checked against real evidence. The EU AI Act also has strong human oversight requirements when it comes to high-risk systems.
You were among the first to productise an idea tested in the regulator’s sandbox. Could you please walk us through what that idea was and what changed between sandbox testing and market launch?
Napier AI used novel frequency-based AI algorithms on large-scale, synthetic financial data sets to detect money laundering typologies more effectively than previous rule-based systems.
Traditional methods rely heavily on broad subgraph analysis and post-processing to eliminate false positives, which is an expensive and time-consuming process. Instead, we applied information theory and domain knowledge to focus directly on high-risk patterns, reducing noise in the process.
What’s the biggest misconception firms have going into the Supercharged Sandbox about what the FCA will and won’t let them test?
It’s important to be clear that initiatives like the FCA Supercharged Sandbox do not replace regulator scrutiny. They do not certify models or remove the need for firms to validate their own systems. What they do instead is shift the focus to outcomes. The FCA is not dictating how AI should be built, but enabling firms to explore what good looks like, and ask the right questions along the way.
What practical advice would you give a firm preparing its sandbox application, based on what actually moved the needle for you?
Prioritise people. It’s a resource-intensive process and even with the data and infrastructure provided, delivering meaningful outcomes within a fixed timeline requires sustained focus and dedicated expertise. And while the sandbox supports experimentation, entering with a well-defined problem and hypotheses significantly increases the likelihood of success. It’s also important to remember that innovation is iterative. Some of our most valuable insights came late in the process, requiring rapid adaptation and the refinement of our initial ideas.


