
Imagine a compliance team puts an AI agent into its enhanced due diligence workflow. The agent reviews customer information, analyzes relevant data, and prepares a summary for an analyst. It saves time. It works.
Then something changes.
The team wants the agent to operate earlier in the process. Or only for certain customer risk categories. It wants to add a second agent for a different task. A new regulatory requirement changes the information that must be considered. Compliance decides that a human should approve one category of cases before the agent’s output moves downstream.
How hard is it to make those changes? That question may prove more consequential than whether the AI agent worked in the first place.
As financial institutions move from AI experiments toward agents embedded in production AML operations, the architecture surrounding those agents matters enormously. An intelligent agent operating inside a rigid workflow does not make the workflow adaptable. And if every change requires developers, custom integrations, or vendor intervention, AI has not eliminated technical dependency.
In fact, it may have added another layer of it.
The AI may be new. The operating model underneath it isn’t.
Much of the current conversation about AI in FinCrime compliance focuses understandably on capability: Can AI summarize a case? Research an entity? Identify relevant information? Assist an investigator? Recommend a next action?
Those are important questions. But once AI moves into actual AML workflows, another set of questions becomes unavoidable.
Who decides where the agent operates? What information can it use? What happens to its output? When must a human intervene? What happens when requirements change? And who can actually make those changes?
These are not primarily AI questions. They are operating-model questions.
RegTechONE, AML Partners’ no-code configurable AML platform, was designed around the premise that compliance operations must remain adaptable as regulations, risks, business requirements, and technology change. Its configurable workflows can combine business rules, data, automated processes, human decision points, and governed AI agents rather than treating AI as a separate capability bolted onto the compliance operation.
That distinction becomes increasingly important as AI moves from experimentation into execution. An institution shouldn’t merely be able to add an agent. It should be able to determine precisely where that agent belongs, what role it plays, what happens before and after it acts, and how those arrangements change over time.
That shift is already underway. Financial institutions are moving agentic AI into operational workflows, including financial crime compliance. Recent KPMG research with U.S. banking risk leaders describes institutions deploying agents across AML, KYC, and other financial-crime operations while confronting the constraints of legacy systems, human-oversight requirements, and AI governance. The challenge is increasingly not whether AI can perform useful compliance work, but how institutions put it into production without losing control of the process.
Agentic AI changes the question for compliance leaders
The first generation of enterprise AI experimentation naturally centered on what the technology could do.
Agentic AI moves the conversation forward because an agent does not simply produce an answer on request. In AML, agentic AI refers to AI agents that perform defined tasks within compliance workflows—gathering or analyzing information, producing outputs, triggering next steps, or handing work to human reviewers under defined controls. In a regulated environment, that makes context critical.
Consider an agent used during customer onboarding. The institution might permit it to collect or summarize information but require an analyst to make the risk decision. Another agent might operate only when particular risk indicators are present. An institution might allow an agent to initiate one downstream action automatically while requiring approval before another.
Those distinctions are the compliance process. The question for CCOs therefore isn’t simply what an AI agent can do. It is who controls what the agent does, where it operates, how it interacts with human judgment, and how quickly all of that can change.
That is why configurability of workflows becomes more important as AI becomes more capable.
An AI agent is only one part of the AML workflow
No AI agent operates alone. It operates within a larger system of data, rules, risk models, external sources, automated actions, human judgments, approvals, escalations, decisions, and records.
A customer due diligence process, for example, might draw data from multiple sources, apply institution-specific risk rules, invoke an AI agent for a bounded research or analysis task, route the result to an analyst, require additional review above a particular risk threshold, and preserve the resulting decisions and evidence.
The agent is one component of that process. That makes orchestration at least as important as the individual AI capability. Recent banking research has emphasized that institutions need to design agentic processes around people, controls, data, technology, and evidence—not deploy agents first and retrofit governance later.
RegTechONE allows institutions to place governed agents directly into configurable workflows alongside conventional automation and human decision points. An institution can determine where an agent performs a task and how its output affects what happens next.
This matters because AML operations do not remain static.
Suppose compliance decides that an agent currently operating after initial risk scoring should instead operate before scoring for a particular customer population. Or an institution wants to introduce a specialized agent into enhanced due diligence while retaining analyst review. Or experience shows that an existing human checkpoint belongs somewhere else.
Those should be governance decisions followed by controlled configuration and testing—not the beginning of another software-development project. The placement of intelligence inside a regulated workflow should itself be configurable and governed.
Govern the workflow—not just the AI
AI governance understandably receives enormous attention. Institutions need appropriate controls over models, data, access, performance, validation, accountability, and use.
U.S. regulators are wrestling with that distinction as well. In April 2026, the Federal Reserve, OCC, and FDIC revised their longstanding model-risk guidance and explicitly excluded generative and agentic AI from its scope. The agencies nevertheless made clear that banks’ broader risk-management and governance practices should determine appropriate governance and controls for these emerging technologies.
But governing an agent without governing the process surrounding it solves only part of the problem.
A compliant outcome depends on more than the behavior of the model. It depends on the information supplied to it, the task it has been assigned, the rules surrounding that task, what happens to its output, what decisions remain with humans, and what downstream actions the workflow permits.
In other words, institutions need governance at the workflow level. AML workflow orchestration coordinates how data, rules, AI agents, automated actions, and human decisions work together across the compliance process.
For Chief Compliance Officers evaluating agentic AI in AML, the critical requirements include workflow-level governance, configurable human oversight, controlled change, auditability, and the ability to replace or reposition agents without rebuilding the surrounding process.
A CCO should be able to ask:
Can we control exactly where this agent operates?
Can we determine what information it receives and what it is permitted to do?
Can we require human judgment at defined points?
Can we change the routing when our risk appetite or regulatory obligations change?
Can we test those changes before deployment?
Can we reconstruct what happened afterward?
And, increasingly important: Can we replace the agent without rebuilding the process around it?
That last question deserves attention. AI capabilities are evolving extraordinarily quickly. The model or agent that appears best suited to a task today may not be the right choice two years—or six months—from now.
An institution should not have to redesign its compliance operation every time the technology improves.
Don’t turn configuration debt into AI configuration debt
Many financial institutions already know what happens when years of seemingly reasonable technical decisions accumulate.
A customized rule here. A bespoke integration there. A workaround created for one business line. Hard-coded logic added for a regulatory change. Another modification that only a particular development team or vendor understands.
Eventually, change becomes slow and expensive because each new requirement must navigate everything that came before it. That is configuration debt.
Agentic AI creates an opportunity to avoid that history—or repeat it at much greater speed.
Now add agents, models, instructions, permissions, data connections, routing logic, escalation rules, and human checkpoints to an already rigid environment. If each becomes another bespoke technical dependency, institutions can create a new form of configuration debt before they have realized what is happening.
AI configuration debt accumulates when organizations embed AI into processes in ways that become increasingly difficult to understand, govern, modify, or replace.
The answer to this looming risk is not to use less AI. It is to avoid hard-coding today’s AI decisions into tomorrow’s operating model. Agents should remain governed, replaceable components within an architecture designed to change.
The real question is who controls the compliance operating model
There is a larger governance question underneath all of this.
The compliance function is accountable for the compliance program. But how much operational control does it actually have if every meaningful change must first be translated into a technical requirement, placed in a development queue, coded by someone else, tested through a software-release process, and deployed by a vendor or IT team?
Technology expertise will always matter. So will appropriate change controls, testing, segregation of duties, and governance.
But technical dependency and technical governance are not the same thing. A configurable platform can preserve rigorous controls while allowing authorized business users to define and modify the operation they are responsible for running.
That principle sits at the center of RegTechONE. No-code configuration gives institutions the ability to configure workflows and business logic around their own requirements, while governance controls determine how changes are authorized, tested, and deployed.
AI agents extend that operating model rather than replacing it.
An authorized team can determine where an agent belongs in a workflow, how it interacts with other processes, and where human judgment remains necessary. As requirements change, the institution can adapt the operation rather than commission another layer of custom software.
No-code configuration is therefore not simply a convenience. Control of the compliance operating model is the larger value.
Build for the AI you haven’t chosen yet
No institution can know exactly what its AI environment will look like five years from now.
Models will improve. Specialized agents will emerge. Existing capabilities will become commodities. Regulatory expectations will evolve. Institutions will learn from their own deployments and decide that some tasks should become more automated, others should remain human-led, and still others should use combinations that are difficult to predict today.
That uncertainty is not a reason to wait, but it is a reason to build differently.
Financial institutions should not have to predict which AI agent will ultimately win, which model will remain best for a particular task, or exactly how tomorrow’s AML workflow will operate. Rather, they need an architecture that lets them change those answers as needed.
RegTechONE is built for that continuously adaptable operating model: configurable workflows, governed execution, human and automated decision points, and AI agents that can become part of the workflow rather than permanent dependencies around which the workflow must be built.
The durable advantage isn’t choosing the perfect AI agent today. It’s building an AML operating model capable of incorporating what comes next. AI won’t eliminate change from AML. It makes the ability to govern change more important than ever.
See RegTechONE with your requirements in a proof of concept

AML Partners offers a free Proof of Concept that lets financial institutions see RegTechONE configured around their own requirements and use cases—not a generic demonstration built around someone else’s process.
Bring us a workflow, a compliance challenge, or a set of requirements. We’ll show you what a continuously configurable compliance operating model looks like in practice.