AI Regulation Tracker / Financial crime and AML
FATF Flags AI and Deepfakes as Rising Money Laundering Risks
On December 22, 2025, the Financial Action Task Force, the global standard-setter for anti-money laundering, published a Horizon Scan on Artificial Intelligence and Deepfakes. It is a non-binding forward look, not a new rule. It warns that synthetic audio, video, and images can defeat identity checks at onboarding, and it signals that supervisors will expect structured AI risk governance. For US firms, that includes banks and the lawyers, accountants, and real estate professionals FATF treats as gatekeepers.
The Financial Action Task Force is the body that sets the rules of the road for anti-money laundering worldwide. Its 40 Recommendations are what national regulators translate into hard law, and its assessments are what put countries on or off the grey and black lists. So when FATF publishes something, even something non-binding, the professionals who have to answer to bank examiners and AML supervisors should read it as a preview of where the questions are going. On December 22, 2025, FATF published a Horizon Scan on Artificial Intelligence and Deepfakes. It is exactly what the name says, a forward look at risks that are emerging rather than a new rule that binds anyone today.
I want to be exact about that status, because it is easy to overstate. A horizon scan sits in FATF's methods and trends work. It is analysis, not a Recommendation, and it does not by itself create a single new obligation for any bank, VASP, law firm, or accounting practice. What it carries is weight of a different kind. It tells supervisors what to look at, it tells assessors what to test, and it tells the private sector what defensive posture the standard-setter expects to see when it comes knocking. Treat it as a signal, a strong one, not as a deadline.
The core risk: deepfakes at the front door
The center of the scan is identity. Onboarding a customer remotely depends on being able to trust that the face on the video, the voice on the call, and the ID document on the screen belong to a real person who is who they claim to be. Deepfake technology attacks precisely that assumption. FATF's point is that the tools have become cheap and easy enough that even unsophisticated actors can produce synthetic video and voice convincing enough to get past facial recognition and biometric onboarding, and that organized networks can automate this at scale to spin up synthetic-identity accounts and move money through them.
The analyses that have unpacked the scan describe deepfakes that can pass through liveness and biometric checks before any alarm is triggered, which is the window criminals exploit to open accounts and divert funds. That is the operational problem in one sentence. Every control built on the premise that a live human on camera equals a verified human is now a control that a determined actor can spoof. The scan does not say those controls are worthless. It says they are no longer sufficient on their own, and that firms need layered verification and the ability to detect manipulated media rather than trusting a single biometric gate.
Dual-use, not just a threat
The scan is careful not to treat AI as purely a criminal weapon. FATF frames it as a dual-use technology, the same capability that helps criminals impersonate a customer also helps institutions detect anomalies, screen transactions, and flag manipulated documents. The message to the private sector is not to fear AI but to govern it. Firms that deploy AI for monitoring and detection are expected to do so with clear ownership, defined risk appetite, testing, and human oversight, not as a black box bolted onto the compliance stack. That is the same governance discipline showing up across every serious AI supervisory document this year, and FATF is now saying it out loud for AML.
Why the DNFBP framing matters, and its US limits
Here is where US professionals need to read carefully. FATF's standards do not stop at banks. They reach what FATF calls designated non-financial businesses and professions, or DNFBPs, and in FATF's own taxonomy that category expressly includes lawyers, accountants, and real estate professionals when they handle certain transactions. So when FATF talks about AI and deepfake risk across the regulated sector, it is, in principle, talking about those gatekeepers too, not only the banks.
But the US implementation is narrower than the FATF standard, and honesty requires saying so. The Bank Secrecy Act applies AML program duties squarely to banks, money services businesses, and a growing list of financial institutions. It has not historically imposed full AML programs on most lawyers and accountants. Real estate is the moving piece. FinCEN has been extending reporting into the residential real estate sector, which narrows the long-standing US gap against the FATF standard for that profession. The practical read for US gatekeepers is this. If you are a bank or a covered financial institution, this scan previews examiner expectations you should already be preparing for. If you are a lawyer, accountant, or real estate professional, you are not directly bound by this document today, but you are exactly the population FATF wants brought further into the AML perimeter, and the direction of travel in US rulemaking has been toward you, not away from you.
What US firms should do now
None of this is a compliance emergency. It is a chance to get ahead of the examiner. For banks and covered institutions, the move is to stress-test your customer identification and onboarding against synthetic media, not just against stolen documents. Assume a convincing deepfake can reach your onboarding flow and ask what second and third layers catch it. Where you already use AI for monitoring, document the governance around it, who owns it, how it is tested, what its error modes are, and where a human stays in the loop, because that is exactly the structured AI risk governance the scan points supervisors toward. For lawyers, accountants, and real estate professionals, the sensible posture is to watch the US rulemaking that is pulling parts of your world into the AML perimeter and to tighten client-identity verification now, while it is a choice rather than a rule. Feeding this into your existing BSA and AML program thinking is cheaper than retrofitting it after a supervisory finding or a synthetic-identity loss.
Questions professionals are asking
Is the FATF Horizon Scan a binding rule?
No. It is a horizon scan under FATF's methods and trends work, published December 22, 2025. It is forward-looking analysis, not a FATF Recommendation or binding standard, and it imposes no new obligation on its own. Its value is as a signal of emerging risk and where AML supervisors and assessors are likely to focus.
What is the main risk it flags?
Deepfakes at onboarding. FATF warns that cheap, easy-to-use synthetic audio, video, and image tools now let criminals impersonate real people well enough to defeat remote identity verification, biometric checks, and liveness detection, enabling synthetic-identity accounts and automated laundering. It also frames AI as a dual-use technology that can strengthen detection when firms govern it well.
Does it apply to lawyers, accountants, and real estate professionals?
In FATF terms, yes in principle. FATF standards cover designated non-financial businesses and professions, which include lawyers, accountants, and real estate professionals handling certain transactions. In the United States the Bank Secrecy Act reaches those professions more narrowly than the FATF standard, though FinCEN has been extending reporting into residential real estate. So the scan is aimed at them as gatekeepers even where US law does not yet bind them directly.
Does it change any US legal obligation today?
No. It creates no new US duty. US AML obligations still flow from the Bank Secrecy Act and FinCEN rules. The scan is best read as a preview of the risk questions bank examiners and AML supervisors are likely to press, and as a prompt to harden identity verification against synthetic media before it becomes a finding.
What should a US bank or covered institution do now?
Stress-test onboarding and customer identification against deepfakes, not just stolen documents, and add layers beyond a single biometric gate. Where you already use AI for monitoring, document its governance, ownership, testing, error modes, and human oversight, which is the structured AI risk governance the scan points toward. Fold this into your existing BSA and AML program rather than treating it as a separate project.
RELATED BRIEFINGS
- Browse the full AI Regulation Tracker
- FATF Horizon Scan: AI and Deepfakes (primary source)
- FSB sound practices for AI at financial institutions
- The FTC impersonation rule and AI voice cloning
- FINRA 2026 generative AI supervision as an exam priority
- US Treasury financial-services AI risk framework and lexicon
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any standard or requirement applies to your situation with qualified AML or compliance counsel in the relevant jurisdiction.