Why this subject sits differently
Almost every other topic on this site concerns a police force adopting a technology. Financial crime does not work that way, and understanding why is necessary before anything else about it makes sense.
Banks, payment providers and other regulated firms carry statutory obligations to monitor for suspicious activity and report it. The monitoring systems therefore sit inside those firms, not inside police forces. By the time law enforcement is involved, a suspicious activity report has usually already been generated by a private system operating under financial regulation rather than policing law.
The practical consequence is that the most consequential decisions in this area, what to monitor, what threshold to alert at, what to report, are made commercially and are subject to regulatory rather than police oversight. Anyone assessing AI in financial crime by looking only at what police forces have deployed will conclude, wrongly, that very little is happening.
The false positive problem
Traditional transaction monitoring is rule-based: thresholds, patterns and typologies encoded as explicit conditions. It is well documented that this approach generates very high false positive rates, with the large majority of alerts closing without further action.
The cost of that is usually described as inefficiency, which understates it. The real cost is misallocated attention. Analyst capacity spent clearing alerts that were never going to lead anywhere is capacity not spent on the small proportion that would. A system that produces an enormous number of alerts and a system that produces none can fail in the same way, by failing to direct attention to the right place.
This is the main driver of machine learning adoption here, and it is a notably different motivation from most policing AI. The argument is not that the technology finds more, but that it discards better.
Where models genuinely outperform rules
Financial crime is unusually well suited to machine learning, for reasons that do not apply to most policing applications.
The data is structured, complete and consistent, unlike the free-text and circumstantial material most policing analysis works from. Feedback is comparatively fast and reliable, since whether a case progressed becomes known. And the patterns being sought are genuinely relational: money laundering typically involves layering across many accounts and jurisdictions, and network analysis across that structure is exactly the kind of problem where automated analysis outperforms manual review.
That said, the same caution applies here as elsewhere. A model trained on historic alerts learns which patterns have previously been alerted on and investigated, which is not identical to which patterns constitute crime. Where a firm's historic monitoring was skewed, a model trained on it can inherit and formalise the skew.
Intervening before the loss
The most substantive recent shift is from detecting fraud after the fact to intervening before a payment completes.
Authorised push payment fraud, where a victim is deceived into authorising a payment themselves, is difficult to address after the event: the payment was authorised, the funds move quickly, and recovery is often impossible. Models that identify a transaction pattern consistent with this type of fraud in real time can prompt a warning, a delay or a hold while the payment can still be stopped.
This raises a live tension worth stating. The same intervention that prevents a loss also blocks legitimate payments when it is wrong, and being unable to move your own money is a real harm rather than a minor inconvenience. Where the threshold is set is a genuine trade-off between two kinds of damage, not a technical parameter with a correct answer.
Where the rules sit
Governance here comes primarily from financial regulation rather than policing law. In the UK that means anti-money laundering regulations, Financial Conduct Authority supervision, and reporting obligations to the National Crime Agency. Data protection law applies to the processing, and automated decision-making provisions are directly relevant where a decision materially affects a customer.
The EU AI Act touches this area, though creditworthiness assessment is more squarely addressed than fraud monitoring. There is no single instrument governing automated financial crime detection, which is consistent with the wider pattern described under AI regulation and policy.
Follow the coverage
PoliceAI News tracks AI in financial crime as it develops: detection capability, regulatory findings, major investigations, fraud typologies and the intervention debates around them. The feed refreshes every 30 minutes.
View Financial Crime Stories