How Artificial Intelligence Is Reshaping AML/CFT and KYC in the GIFT IFSC
In the GIFT IFSC, artificial intelligence is already concentrated in the compliance function, and IFSCA’s existing AML/CFT/KYC Guidelines, 2022 already contain the obligations that govern its use. No new AI rulebook is needed to begin. What is needed is a documented pre-deployment risk assessment, retained accountability for vendor models, independent audit, and human decisions that can be articulated and defended.
- Where AI sits: Risk and Compliance, which IFSCA defines to include AML-CFT, KYC and fraud detection, is one of the two strongest fields of AI activity in the centre.
- Adoption driver: Operational efficiency, cited by 82 per cent of entities, up from 64 per cent a year earlier.
- Top concern: Data privacy and protection, cited by 74 per cent of entities, up from 54 per cent.
- Maturity: Generative AI is in production at 17 per cent of entities. Agentic AI, which acts rather than drafts, is the emerging frontier and the real governance test.
- The legal trigger: Chapter III requires the money laundering and terrorist financing risks of new or developing technologies to be assessed before those technologies are used, which captures any AI compliance tool.
- The gap: Formal AI audit tripled in a year to 35 per cent of entities, so roughly two-thirds still have no formal AI audit mechanism.
- The limit: Chapter VI keeps ultimate responsibility for customer due diligence with the Regulated Entity, so buying a vendor model does not transfer accountability.
AML Expert
Get tailored guidance on your compliance obligations, SAR filing, or AML program review.
For years, the conversation about artificial intelligence in financial crime compliance lived in the future tense. It was a matter of pilots, proofs of concept and cautious vendor demonstrations. That conversation has changed. In the GIFT International Financial Services Centre (IFSC), the question is no longer whether AML/CFT teams will use artificial intelligence, but how well they will govern it while they do.
We now have hard evidence for that shift. In July 2026 the International Financial Services Centres Authority (IFSCA) published Artificial Intelligence in the GIFT IFSC: Adoption, Maturity and Governance, the findings of its IFSC AI Survey 2026. It is, to my knowledge, one of the first regulator-led readings of AI adoption across an entire international financial centre, and it deserves close attention from anyone who carries responsibility for anti-money laundering, counter-terrorist financing, and know your customer obligations. The headline is striking in its restraint. IFSCA describes an ecosystem in "confident, accelerating transition", one that moved in a single year from AI exploration to early-stage operationalisation, with the respondent base doubling and Generative AI entering the institutional mainstream.
What makes the survey so relevant to compliance professionals is where the Authority found AI doing its most concentrated work. By business function, IFSCA reports that AI activity is strongest in Risk and Compliance, a category it defines to include AML-CFT, KYC and fraud detection, alongside Internal Operations. In other words, the compliance function is not a laggard waiting to be disrupted. It is one of the two engine rooms of AI adoption in the centre. That single finding reframes the whole discussion. AML/CFT is where much of this technology is being put to work first, and that places a particular duty of care on the people who run those programmes.
- Read the IFSCA survey through a compliance lens and draw out what it tells us about the direction of travel.
- Map artificial intelligence onto the specific obligations that IFSCA's own AML/CFT/KYC framework imposes, obligation by obligation, so the technology is grounded in law rather than hype.
- Be candid about the governance, model risk and explainability tensions that come with the territory, because responsible adoption is the only kind that survives regulatory scrutiny.
Throughout, the anchor is IFSCA's own published position: its AI Survey 2026 and its International Financial Services Centres Authority (Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer) Guidelines, 2022, as most recently updated in February 2026.
What the IFSCA AI Survey 2026 Tells Compliance Teams
Before mapping AI onto obligations, it is worth sitting with the numbers, because they tell a story of pragmatism rather than exuberance.
IFSCA reports that operational efficiency is the standout driver of AI adoption, cited by 82 per cent of entities and widening its lead over every other motive, up from 64 per cent a year earlier. Cost reduction, customer experience and regulatory compliance form a strong second tier. This is an efficiency-first ecosystem, not a moonshot culture, and that matters for AML/CFT. When compliance leaders reach for AI, they are largely reaching for productivity in processes they already run: onboarding, screening, monitoring, investigation and reporting. The use is incremental and operational, which is exactly the pattern one would hope to see in a risk-sensitive domain.
The maturity picture supports this. Generative AI shows the deepest penetration, with close to two-thirds of entities at least exploring it and 17 per cent already running it in production. Agentic AI, systems capable of autonomous decision-making and action, is the emerging frontier, with 45 per cent not yet exploring it but a meaningful cohort already piloting or in production. For a compliance audience, this is the most important sentence in the survey, because agentic systems that can take actions rather than merely draft text raise the governance stakes considerably. An AI that summarises a file is a tool. An AI that decides to clear or escalate an alert is something closer to a delegated decision, and delegated decisions in AML/CFT carry legal consequences.
Three further findings deserve to be flagged for compliance readers. First, IFSCA records that 57 per cent of entities report employees using AI tools, including widely available public platforms, up from 52 per cent, and that entities are actively developing usage policies. Shadow AI, the informal use of consumer tools on work tasks, is a live data-protection and confidentiality risk in any function that handles customer identity data and suspicious-activity intelligence. Second, formal audit of AI has tripled in a year, from 10 per cent to 35 per cent of entities, which is encouraging but still means the clear majority have no formal AI audit mechanism in place. Third, and most tellingly, data privacy and protection is the highest-rated concern across the ecosystem, cited by 74 per cent of entities, up sharply from 54 per cent. IFSCA reads this as evidence of the centre's commitment to data stewardship. I read it as the compliance community's instinct doing exactly what it should, treating the confidentiality of customer data as the first-order risk of any AI deployment.
The survey also captures how AI is being built. Off-the-shelf and customised vendor solutions now dominate, cited by 44 per cent of entities and rising fast, while fully in-house development from scratch sits at 11 per cent. Sourcing capability from parent organisations is significant. This buy-and-adapt posture is sensible for smaller regulated entities, but it pushes a specific risk to the front of the queue, namely third-party and vendor concentration, which IFSCA separately records as a prominent systemic concern. I will return to this, because the Guidelines have a great deal to say about reliance on third parties and about the entity's ownership of outcomes it did not build.
The IFSCA AML/CFT and KYC Obligations That AI Must Serve
Artificial intelligence in AML/CFT is only ever as good as its fit with the underlying legal obligations. So it is worth being precise about what IFSCA actually requires, because every worthwhile AI use case is, in the end, a better way of discharging one of these duties.
IFSCA's AML/CFT/KYC Guidelines, 2022 apply to every Regulated Entity licensed, recognised, registered or authorised by the Authority, and they sit on top of the Prevention of Money-Laundering Act, 2002 and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. Under Clause 1.5, every Regulated Entity must formulate a board-approved AML-CFT policy and a KYC policy, and its senior management must exercise due skill, care and diligence over compliance. That governance spine is important, because it means an AI system used in compliance is not a free-floating IT project. It falls within a policy framework that the governing body has approved and for which senior management is answerable.
The framework is built on a risk-based approach. Chapter II requires the risk-based approach to be objective, proportionate to the risks, based on reasonable grounds, and reviewed and updated at appropriate intervals, at least once every two years or on a material trigger. Chapters III and IV require a business risk assessment and a customer risk assessment, with every customer assigned a risk rating of high, medium or low, driving the depth of due diligence that follows. Notably for our purposes, Chapter III expressly requires entities to assess the money laundering and terrorist financing risks arising from "the use of new or developing technologies", and to do so before those technologies are launched or used. AI is, unambiguously, a new and developing technology, so the very act of deploying an AI tool in compliance triggers a risk-assessment obligation under the Guidelines.
Customer due diligence sits at the heart of the framework in Chapter V. Regulated Entities must identify and verify customers using reliable, independent source documents, data or information, identify and verify beneficial owners down to the controlling-interest thresholds, understand the purpose and nature of the relationship, and conduct ongoing due diligence throughout its life. Enhanced due diligence applies to high-risk customers and politically exposed persons under Clauses 5.5 and 5.6, and simplified measures to low-risk ones. Ongoing monitoring under Clause 5.8 requires entities to scrutinise transactions for consistency with what they know about the customer and to pay particular attention to complex, unusually large or unusual patterns that have no apparent economic or lawful purpose. Ongoing sanctions screening under Clause 5.9 requires customers, their businesses and their transactions to be reviewed against United Nations Security Council lists and any other relevant list.
The obligations extend into payments and reporting. Chapter VII governs correspondent banking and wire transfers, requiring name-screening of originators and beneficiaries, the freezing of terrorist assets, and real-time or post-event monitoring to catch transfers that lack required information. Chapter X governs the identification and reporting of suspicious transactions, setting out a four-step method of detect, ask, review and evaluate, and requiring a Suspicious Transaction Report to the Financial Intelligence Unit-India (FIU-IND) where reasonable grounds of suspicion exist, with no monetary threshold and strict prohibitions on tipping off. Chapter VIII requires a suitably senior and independent Principal Officer, an independent audit function and periodic training. Chapter IX requires records to be kept for at least six years and, crucially, permits them to be maintained in electronic form provided they remain readily accessible.
This is the architecture. Every AI use case worth pursuing maps onto one of these duties, and the credibility of any deployment depends on how faithfully it serves the obligation rather than merely accelerating it.
Where AI Meets Each AML/CFT Obligation
AI in Customer Onboarding and KYC: Chapter V Duties
The most immediate and visible application of AI is at the front door, in customer onboarding and KYC. The IFSCA survey confirms this is already happening, listing document intelligence among the leading use cases: contract and agreement summarisation, intelligent document retrieval, automated statement-of-account processing, PII redaction, and data extraction with verifiable source referencing. Each of these maps directly onto Chapter V. Extracting and cross-checking identity data from officially valid documents, reconciling names across a corporate ownership chain, and surfacing the beneficial owners behind a layered structure are precisely the tasks that consume analyst time and where machine assistance pays off.
It is significant that IFSCA has moved deliberately to enable digital and technology-assisted onboarding within the framework itself. The Guidelines already define Digital KYC and recognise equivalent e-documents and Video-based Customer Identification Procedure, and in February 2026 the Authority amended Annexure-II to add OTP-based Aadhaar e-KYC authentication as an accepted mode for onboarding Indian nationals. The Authority's evolving position on e-notarisation, reflected in its updated FAQs, points the same way. This matters because AI-assisted onboarding does not sit outside the regulatory perimeter as an unregulated efficiency play. It sits inside a framework that IFSCA is actively modernising to accommodate technology-led identity verification, which gives compliance teams a stable footing on which to build.
The opportunity here is real, and so is the discipline it demands. Clause 5.4.3 permits, for customers other than high-risk ones, verification from publicly available official sources and from reputable commercial databases recognised for the purpose. AI can make that research faster and more consistent. But the Guidelines are equally clear that for high-risk customers, identification information must be independently verified using both public and non-public sources, and that the entity remains responsible for the outcome. An AI that assembles a beneficial-ownership picture is an aid to the analyst's judgement, not a replacement for it. The obligation to be satisfied that the entity knows who the beneficial owner is remains a human obligation.
AI in Sanctions, PEP and Adverse-Media Screening: Clauses 5.9 and 7.3 to 7.5
Name screening is, in many ways, the natural home of machine intelligence, because it is a matching problem at scale complicated by transliteration, aliases, fuzzy spelling and context. IFSCA requires ongoing sanctions screening under Clause 5.9 and, in the payments context, requires that positive hits from name-screening checks be escalated to the Principal Officer, with wire transfers to sanctioned parties suspended or rejected and the assets of terrorists or terrorist entities blocked, rejected or frozen immediately under Clauses 7.3 to 7.5. Chapter XI reinforces this through the obligations tied to Section 51A of the Unlawful Activities (Prevention) Act, 1967.
This is where AI has arguably matured furthest in the wider market, and where it is most defensible, because well-designed screening models reduce false positives without lowering the true-positive catch rate. Fewer false positives mean analysts spend their time on genuine risk rather than clearing noise. Adverse-media screening, natural-language classification of negative news across languages, is a second area where the technology adds real value that manual processes struggle to match at scale. Yet screening is also where the discipline of testing bites hardest. A model that quietly narrows its matching logic to cut alert volume can create a dangerous gap, and the consequences of a missed sanctions hit are not commercial but legal. The right posture treats AI screening as a tool that must be tuned, validated and audited against known cases, never as a silent filter that is trusted because it is convenient.
AI in Transaction Monitoring and Suspicious-Transaction Detection: Chapter X
If there is one place where IFSCA has all but invited the use of technology, it is in the detection of suspicious transactions. Chapter X requires Regulated Entities to establish policies, procedures, systems and controls to monitor and detect suspicious transactions. And in its guidance the Authority is explicit: "Robust software to throw alerts when the transactions are inconsistent with risk categorization and updated profile of the customers, shall be put in to use as a part of effective identification and reporting of suspicious transactions." The Authority further contemplates entities adopting "suitable technological tools for extracting STR from their live transaction data". The regulator is not merely tolerating technology-led monitoring. It is signalling an expectation of it.
This is the use case with the greatest upside and the greatest governance weight. Traditional rules-based monitoring generates enormous false-positive volumes and struggles with novel typologies. Machine-learning models that learn the contours of normal behaviour for a given customer and flag genuine anomalies can lift both the efficiency and the effectiveness of monitoring. Behavioural analytics, network analysis to surface hidden relationships, and anomaly detection against a customer's own established profile all map directly onto the Clause 5.8 duty to attend to complex, unusually large or unusual patterns with no apparent economic purpose. This is also where agentic AI, the emerging frontier in the IFSCA survey, will make its presence felt, as systems begin to assemble the evidence around an alert, draft the analytical narrative and propose a disposition.
Here the four-step method of Chapter X, detect, ask, review and evaluate, becomes the governing discipline. AI can materially strengthen the detect and review steps, marshalling the customer's records, transaction history, risk profile and relationships far faster than any analyst. What it cannot do is discharge the evaluate step alone. The Guidelines require the Principal Officer to record the reasons for treating a transaction as suspicious, and the reasonable-grounds standard is a human judgement that must be capable of articulation and defence. An alert generated by a model that cannot explain itself is a starting point for an investigation, not a conclusion of one. And the tipping-off prohibition in Clause 10.4 places a hard boundary around any customer-facing automation: a chatbot or automated communication must never, by word or behaviour, betray that a suspicion has formed or a report has been made.
AI in Dynamic Customer Risk Rating: Chapters III and IV
The risk-based approach is the spine of the whole framework, and it is inherently data-driven, which makes it a natural candidate for machine assistance. Chapters III and IV require business and customer risk assessments and the assignment of a risk rating that determines the depth of due diligence. Clause 5.8 requires entities to periodically review each customer to ensure the assigned rating remains commensurate with the risk, and to refresh due diligence when circumstances change. AI can move risk rating from a periodic, static exercise towards something closer to continuous, recalibrating a customer's risk profile as new transactions, relationships and external signals arrive.
Two cautions apply. First, Clause 4.1 requires that the risk categorisation of a customer, and the specific reasons for it, be kept confidential and not revealed to the customer, so any model-driven rating must sit within controlled systems. Second, a dynamic risk model is only as sound as its inputs and its logic, and a rating that cannot be explained to an examiner is a compliance liability regardless of how sophisticated the mathematics behind it. The Guidelines demand that the risk-based approach be objective and based on reasonable grounds. A black-box risk score that no one can justify fails that test.
AI in STR Reporting and Record-Keeping: FIU-IND and Chapter IX
The final link in the chain is reporting. Every Regulated Entity in the IFSC must register on the FIU-IND FINGate 2.0 portal and furnish suspicious transaction reports, non-profit organisation transaction reports and cross-border wire transfer reports as required. AI can assist in assembling the data, drafting the analytical narrative of a Suspicious Transaction Report and quality-checking submissions for completeness before they are filed. IFSCA's own guidance acknowledges the role of technological tools in extracting reports from live transaction data. On the records side, Chapter IX requires retention for at least six years and expressly permits electronic record-keeping provided the records remain readily accessible and retrievable on demand, which gives entities the latitude to build AI-ready data infrastructure without falling foul of the retention rules.
How to Govern AI in AML/CFT Under the IFSCA Guidelines
Everything above describes opportunity. None of it is safe to pursue without governance, and this is where the IFSCA survey and the Guidelines speak most directly to each other.
The survey shows governance building in step with adoption, but unevenly. IFSCA reports that human-in-the-loop oversight is the most widely adopted production safeguard, which is precisely the right instinct for AML/CFT, where the legal responsibility for a decision cannot be delegated to a model. Where AI governance is formally assigned, it most often sits with a parent group or a Chief Data or Technology Officer, and a growing cohort of entities has stood up dedicated AI Governance Committees or Chief AI Officer roles. Yet the survey also records that a meaningful share of entities have no formal AI governance responsibility assigned at all, and that formal AI audit, though tripling in a year, still reaches only about a third of the ecosystem. The direction is right. The distance still to travel is considerable.
The Guidelines convert these good instincts into obligations. Three connections are worth drawing out explicitly.
First, the new-technology risk assessment. Chapter III requires entities to identify and assess the money laundering and terrorist financing risks arising from new or developing technologies before they are used. Deploying an AI monitoring or screening model is, on a plain reading, exactly the kind of event this clause contemplates. A documented pre-deployment risk assessment of an AI compliance tool is not a nice-to-have. It is the discharge of an existing obligation.
Second, third-party reliance and vendor concentration. With the survey showing a decisive tilt towards vendor and off-the-shelf tools, Chapter VI becomes central. It permits reliance on third parties for certain measures but insists that the Regulated Entity remains ultimately responsible for customer due diligence and enhanced due diligence. Translated to AI, an entity that buys a screening or monitoring model from a vendor owns the outcomes that model produces. It cannot outsource its accountability along with the software. The systemic risk of vendor concentration that entities flagged to IFSCA is real, and the Guidelines' insistence on retained responsibility is the discipline that answers it.
Third, audit and the independent challenge. Chapter VIII requires an adequately resourced, independent audit function able to assess the effectiveness of the entity's controls, and a Principal Officer distinct from business and audit lines. An AI model embedded in AML/CFT falls squarely within that audit remit. Model validation, testing against known cases, monitoring for model drift, and documented human review are the mechanisms by which an entity can demonstrate to IFSCA that its intelligent tools are actually working. The survey's own list of technical risks, led by data privacy but including model drift and the reliability of AI outputs, reads like an audit programme waiting to be written.
Underpinning all of this is data. That 74 per cent of entities rate data privacy as their top concern is the healthiest signal in the entire survey. AML/CFT runs on the most sensitive categories of personal and financial data, and the confidentiality obligations around risk ratings, suspicious-transaction intelligence and the tipping-off prohibition mean that a careless AI deployment is not merely a privacy problem but a financial-crime-control failure. The shadow-AI finding, more than half of entities reporting employee use of public tools, is the sharp end of this. A clear, enforced policy on what customer data may and may not be exposed to which tools is now table stakes for any compliance function.
Three Honest Tensions in AI-Led AML/CFT
Tension One: Explainability Against Performance
The IFSCA survey records, encouragingly, that concern over explainability and black-box behaviour has fallen sharply, from 41 per cent to 21 per cent of entities. I would gently caution against reading that as a solved problem. In most AML/CFT contexts, the more capable model is often the less interpretable one, and the legal standard the Guidelines impose, namely reasonable grounds of suspicion, articulable reasons recorded by the Principal Officer, a risk-based approach that is objective and based on reasonable grounds, is a standard of explanation. Where a decision must be defended to a regulator or a court, an unexplainable model is a weak foundation no matter how accurate. The falling concern may reflect maturity, or it may reflect familiarity breeding a comfort the stakes do not warrant. Vigilance here is a feature, not a flaw.
Tension Two: Efficiency Against Effectiveness
An efficiency-first ecosystem, as IFSCA describes this one, must guard against the quiet substitution of fewer alerts for better detection. Tuning a model to reduce analyst workload is legitimate. Tuning it in a way that suppresses genuine risk to hit a productivity target is not, and the difference is only visible through rigorous, independent testing. This is why audit and validation obligations matter so much, and why silent caps on coverage, undisclosed thresholds, and unexamined suppression rules are what a good compliance leader loses sleep over.
Tension Three: Autonomy Against Accountability
As agentic AI moves from the frontier into production, the temptation to let systems act rather than merely advise will grow. The Guidelines' architecture, senior-management responsibility, a named and empowered Principal Officer, human recording of reasons for suspicion, the non-delegable duty to be satisfied about beneficial ownership, is built around accountable human decision-makers. Agentic systems can prepare, assemble and propose. The decisions that carry legal weight should remain, visibly and traceably, with people. Human-in-the-loop being the most common safeguard in the survey suggests the ecosystem understands this. Keeping it true as autonomy increases will take deliberate design.
What Entities Want from IFSCA, and What Comes Next
One of the most constructive findings in the survey is what entities want from their regulator. Nearly half, 48 per cent, seek clarity on how existing rules apply to AI, and 46 per cent want principles-based guidance on matters such as fairness and explainability. A further third each want harmonisation across Indian and global regulators and specific guidance on third-party risk for AI vendors, and a quarter would welcome an AI regulatory sandbox. This is a mature ask. It is not a plea for deregulation. It is a request for enabling, principled clarity from an authority the survey describes as being in a collaborative relationship with the entities it supervises.
That posture, innovation supported by proportionate guidance, is the right one for a centre that aspires to global standing, and IFSCA's conclusion to its own report commits to exactly that: continuing to develop regulatory frameworks that support innovation while preserving market integrity and consumer trust. For compliance leaders, the practical implication is that the existing AML/CFT/KYC Guidelines already provide most of what is needed to govern AI responsibly, if they are read with attention. The risk-based approach, the new-technology risk assessment, the retained responsibility for outsourced measures, the independent audit function and the articulable-reasons standard together form a serviceable governance framework for artificial intelligence. The gaps that remain are matters of specific application, not first principles.
What This Means for Compliance Leaders in the GIFT IFSC
The GIFT IFSC has crossed a threshold. Artificial intelligence is no longer an experiment at the margins of the compliance function. On IFSCA's own evidence it is one of the two most active fields of AI deployment in the entire centre, and it is being applied to the very obligations, onboarding, screening, monitoring and reporting, that define AML/CFT work. That is a moment of genuine opportunity. Done well, AI lets compliance teams see more, see it sooner, and spend their scarce human judgement where it matters most.
But the opportunity is inseparable from the obligation. The measure of a mature compliance function in this new era will not be how much AI it has bought, but how well it can explain, test, audit and stand behind what that AI does. The regulator has signalled its expectation of technology-led detection and its willingness to guide. The tools are maturing, the vendors are numerous and the data is abundant. What remains scarce, and what will separate the credible programmes from the merely fast ones, is disciplined governance and the seasoned judgement to know where a machine should assist and where a person must decide. Institutions that pair the ambition of adoption with the humility of good governance will not only satisfy IFSCA. They will build the kind of financial-crime defences that a world-class international financial centre deserves.
Frequently Asked Questions
Key findings from the IFSCA AI Survey 2026 for AML/CFT and KYC teams.
It puts compliance at the centre of AI activity. Measured by business function, IFSCA found AI activity strongest in Risk and Compliance, a category the Authority defines to include AML-CFT, KYC and fraud detection, alongside Internal Operations. The survey describes an ecosystem in "confident, accelerating transition" that moved in a single year from exploration to early-stage operationalisation, with the respondent base doubling.
Operational efficiency, and by a widening margin. It was cited by 82 per cent of entities, up from 64 per cent a year earlier, with cost reduction, customer experience and regulatory compliance forming a second tier. For AML/CFT teams this reads as productivity in processes they already run, namely onboarding, screening, monitoring, investigation and reporting, rather than experimental deployment.
Generative AI shows the deepest penetration, with close to two-thirds of entities at least exploring it and 17 per cent already running it in production. Agentic AI, systems capable of autonomous decision-making and action, is the emerging frontier: 45 per cent are not yet exploring it, though a meaningful cohort is already piloting or in production. On sourcing, off-the-shelf and customised vendor solutions dominate at 44 per cent, while fully in-house development sits at 11 per cent.
Data privacy and protection, cited by 74 per cent of entities and up sharply from 54 per cent, making it the highest-rated concern in the survey. Vendor and third-party concentration registers as a prominent systemic concern, and the technical risk list also includes model drift and the reliability of AI outputs. Notably, concern over explainability and black-box behaviour fell from 41 per cent to 21 per cent, which may reflect maturity or may reflect familiarity outpacing the stakes.
Less than the adoption curve would suggest. Human-in-the-loop oversight is the most widely adopted production safeguard, and formal audit of AI tripled in a year from 10 per cent to 35 per cent of entities, which still leaves roughly two-thirds with no formal AI audit mechanism. A meaningful share of entities have no formal AI governance responsibility assigned at all, and 57 per cent report employees using AI tools including public platforms, up from 52 per cent.
Attribution: This article draws on the International Financial Services Centres Authority's report Artificial Intelligence in the GIFT IFSC: Adoption, Maturity and Governance (IFSC AI Survey 2026, July 2026) and on the International Financial Services Centres Authority (Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer) Guidelines, 2022, as updated to February 2026, together with related IFSCA circulars. All survey findings and regulatory provisions cited are those of IFSCA. The views expressed are the author's own.
Work With Pathik Shah Through AML Guild
Pathik Shah and the AML Guild network provide on-demand, CAMS-certified AML/CFT support for regulated businesses, from building and remediating compliance programmes to governing AI-led monitoring, screening and onboarding responsibly.