Nicosia, Cyprus, July 20th, 2026, FinanceWire
A self-hosted large language model (LLM) integrated with the platform’s ledger, Know Your Customer (KYC), Know Your Business (KYB), Know Your Transaction (KYT), and audit trail assumption has taken on the operational facet of Anti-Money Laundering (AML) investigations. Crucially, all decisions bearing regulatory implications remain firmly in human hands.
FinHarbor, a pioneering provider of technical platforms for launching compliant and modular financial products, has revealed the introduction of its AI Act-compliant module.
This AI co-investigator augments the existing compliance framework and operates wholly within the client’s own infrastructure.
The timing is pivotal. Beginning August 2, 2026, the transparency mandates outlined in the EU AI Act will become applicable to customer-facing AI systems.
Concurrently, a recently adopted simplification package has extended the high-risk requirements to December 2027 — a preparatory phase, not a reprieve.
Thus, FinHarbor’s innovative solution is that of a module crafted in line with the Act’s principles from inception: well-documented, monitored, and inherently unable to function autonomously.
The Quandary: Compliance Teams Overwhelmed by False Alarms
The economic landscape of AML operations has been extensively analyzed. Indeed, data from Google Cloud indicates that upwards of 95% of alerts produced by conventional rules-based AML systems are deemed false positives upon initial evaluation, with approximately 98% failing to culminate in a suspicious activity report.
Compliance teams within burgeoning platforms find themselves overwhelmingly engaged in reconstructing cases from disparate tools rather than probing actual threats.
Industry case studies reflect the efficacy of AI in ameliorating this issue. For instance, HSBC, in collaboration with Google Cloud, successfully diminished alert volumes by more than 60%, simultaneously identifying two to four times the number of truly suspicious activities.
In a Coforge deployment at a prominent U.S. bank, an AI-optimized alert system cut false positives by 70% while enhancing fraud detection rates by 35%.
Module Functionality
FinHarbor’s co-investigator operates across the platform’s integrated ledger, KYC/KYB systems, transaction monitoring, and append-only audit trails. Specifically, it:
- Retrieves client and transaction data on demand. When an analyst poses a query in plain language, the module directly consults the platform’s databases — eliminating the need for SQL or delays from the data team.
- Eliminates the routine layer of AML alerts. Recurring false positives are systematically categorized and resolved with documented justifications, reserving human analysts for cases necessitating discernment.
- Constructs comprehensive investigation profiles. It aggregates transactions, counterparties, KYC/KYB histories, on-chain trails from KYT, alongside sanctions and PEP screening results into a singular profile, in lieu of a laborious manual reconciliation.
- Drafts Suspicious Activity Reports (SAR) and Suspicious Transaction Reports (STR). The module prepares regulatory filings in standardized formats, which are subsequently reviewed, edited, and signed by compliance officers.
- Prioritizes investigations by risk score. This ensures that the highest-risk cases are surfaced and addressed first.
- Responds to regulatory and auditor inquiries. It generates outputs from the unified audit trail as opposed to cumbersome manual evidence compilation.
A Co-Investigator, Not an Autopilot
The fundamental operational principle of this module is embedded in its architecture: AI evaluates; humans decide. It does not independently file SARs, block accounts, or undertake actions with regulatory ramifications.
Each of these steps mandates human authorization. This framework of human oversight, coupled with systematic documentation and model risk management, allows the module to comply with the high-risk parameters dictated by the AI Act, while its built-in disclosure guarantees that users are consistently aware of AI interactions.
This structural integrity also ensures alignment with the Digital Operational Resilience Act (DORA), as the append-only audit log meets third-party oversight specifications and seamlessly integrates into the client’s Security Information and Event Management (SIEM) system.
Deployed Within the Client’s Own Environment
The module functions as a self-hosted LLM, adeptly situated within the client’s infrastructure, interfacing with the platform’s modules and databases via a Managed Control Plane (MCP) server secured behind client authentication layers.
Implementation entails delineating access parameters — specifying which modules and accounts the model can access, alongside assigning API keys and limitations — while also establishing redaction rules for sensitive data fields.
Documentation and human oversight are integrated into the deployment process rather than treated as supplementary steps.
This design philosophy ensures that the module’s applicability transcends EU borders. The core principle — that regulated data remains within the confines of the client’s environment — addresses compliance across various jurisdictions including GDPR, UK GDPR, Switzerland’s revFADP, Brazil’s LGPD, and Saudi Arabia’s PDPL. The AI Act serves as a gateway, not a constraint.
“Compliance teams don’t require an additional dashboard; they need routine responsibilities alleviated without forfeiting control,” asserted Ilya Podoynitsyn, CEO of FinHarbor.
“Our co-investigator engages with the same ledger, KYC files, and on-chain data that our platform already maintains, conducting the groundwork: assembling cases and drafting narratives while documenting each step.
Notably, no regulatory action occurs without human endorsement — a requisite we embraced from the project’s outset, rather than a limitation.”
The module is currently in pilot programs across various client projects. The underlying infrastructure, encompassing MCP and self-hosted LLM deployment within client perimeters, is an established feature of the FinHarbor platform and is publicly documented.
The module is included within the platform, with commercial terms determined for each deployment.
FinHarbor serves as a technical platform provider, adept in the initiation of compliant and modular financial products — from digital wallets and neobanks to cryptocurrency ramps and over-the-counter trading desks.

Rooted in extensive fintech experience, the platform encompasses onboarding, compliance, transaction processing, card services, and reporting, all delivered via a microservices architecture (ISO/PCI DSS-certified) alongside a robust API layer for on-premise or cloud-ready deployments.
FinHarbor facilitates fiat-only, crypto-native, and hybrid business models across markets in Europe, the MENA region, and beyond.
Source link: Tradingview.com.






