MICKAI®ArticlesAMLA Is Live in 2026: Own Explain…
Article · 11 August 2026

AMLA Is Live in 2026: Own Explainable AML Instead of Renting Transaction Monitoring

The single EU rulebook rewards one owned detection engine, not a stack of per alert subscriptions.

Author
Micky Irons
Published
11 August 2026
Follow Micky Irons
LinkedInX
amlaaml-compliancetransaction-monitoringfinancial-crimeon-premise-ai
AMLA Is Live in 2026: Own Explainable AML Instead of Renting Transaction Monitoring

AMLA became the European Union's anti money laundering supervisor on 1 January 2026, and the cheapest way to meet it is to own an explainable detection engine rather than rent transaction monitoring by the alert. Nemesis runs money laundering, fraud and trade surveillance checks on your own hardware, fully offline, so the meter that drives most of your AML compliance cost, the per alert and per transaction screening fee, simply stops, and a single explainable engine serves every market you operate in under the new single EU rulebook.

AMLA is live in 2026, and your AML compliance cost is about to reset

On 1 January 2026 the Authority for Anti Money Laundering and Countering the Financing of Terrorism, AMLA, took over the EU anti money laundering mandate from the European Banking Authority. Industry tracking of the timetable shows AMLA must publish a large body of technical standards, reported as 23 Level 2 and Level 3 measures, most of them due by 10 July 2026, ahead of the Anti Money Laundering Regulation applying from 10 July 2027. The direction of travel is one harmonised rulebook and closer central supervision of the highest risk obliged entities.

For banks, payment firms, fintechs and other obliged entities this is the moment the ground shifts from national interpretation to a single European standard. In principle that should lower the cost of running one consistent programme across borders. In practice it only does so if the engine underneath is something you own outright, rather than a stack of subscriptions that each bill by data volume, by seat and by alert, and multiply every time you enter another market.

What renting transaction monitoring costs you today

The incumbent transaction monitoring tools, SAS AML, NICE Actimize and Featurespace among them, are licensed per module, per seat and against the volume of transactions they screen. On top of the licence sits the implementation project, the annual tuning to keep detection rules current, and the cloud processing fee for pushing your transaction data out to be scored. The bill grows with your business rather than staying fixed, and none of it leaves you owning the capability at the end.

The larger, quieter cost is the false positive tax. Industry reporting has long put AML alert false positive rates well above 90 percent, which means the overwhelming majority of alerts an outsourced or seat priced engine raises are cleared by hand at cost. Every one of those alerts consumes an analyst hour, and at scale that review labour, often pushed offshore, dwarfs the software line it sits behind.

How Nemesis owns explainable AML on your own hardware

Nemesis is a ready made financial crime detection application inside the Mickai system, a single system that carries a library of these applications for specific business functions. It anomaly scores a batch of transactions and flags money laundering, fraud and trade surveillance concerns with the reasons attached, sealed offline to the Open Audit Record. It is built to replace SAS AML, Actimize and Featurespace, and it runs on the company's own brain, built on its own data, on hardware you own rather than a vendor's cloud.

Because inference runs on device, there is no per alert, per seat or per transaction cloud fee as volume grows, and no transaction data ever leaves the building to be scored. The concrete mechanism is straightforward:

  • Point Nemesis at a transaction batch on your own infrastructure; nothing is sent to an external service.
  • The financial crime brains anomaly score each transaction and rank the population by risk, with the drivers of each score attached in plain terms.
  • An analyst reviews the ranked, reasoned alerts, clears the noise and escalates the genuine concerns, faster because the reasoning is already there.
  • Each detection and each disposition is sealed under post quantum cryptography into a signed Open Audit Record on the machine.
  • The same engine is pointed at the next market's transactions, with no additional licence and no new deployment fee.

The false positive tax, and why reasons attached scoring cuts it

A per alert priced engine has no incentive to reduce the alerts it raises, and a black box score gives an analyst nothing to work with except the alert itself. Nemesis attaches the reasons to every score, so the person triaging can see why a transaction was flagged and reach a decision without reconstructing the case from scratch. That is where the alert triage hours fall: not by hiding alerts, but by making each one faster to resolve, and by keeping the labour in house against a fixed cost engine rather than paying per alert to a vendor and again per hour to clear the vendor's noise.

The saving here is a mechanism, not a headline percentage. What changes is where the money goes. The per transaction screening meter disappears, the review labour attaches to an engine you own, and the analyst spends the hour on judgement rather than on assembling the context that should have arrived with the alert.

One explainable engine, reusable across the single EU rulebook

AMLA's purpose is a single rulebook, and a single rulebook is exactly what makes an owned engine pay off. Instead of licensing separate tooling for each jurisdiction and reconciling their outputs, you run one explainable engine, tuned once, across every market under the harmonised standard. The cost stops multiplying with your footprint.

Supervisors do not only want detection, they want to see the working. Nemesis seals every detection and disposition into the Open Audit Record, a signed, tamper evident trail produced on your own hardware. That evidence supports the record keeping and explainability that AMLA and national supervisors expect, and it is generated as a by product of running the engine rather than commissioned separately. Mickai does not claim to hold any certification on your behalf; it produces the evidence that supports those examinations.

What you replace, and what you save

What you run todayWhat it costs youWith Mickai
SAS AML transaction monitoringAnnual licence plus implementation and tuningNemesis scores the same batches on owned hardware, with no annual monitoring licence
NICE Actimize detection and case modulesPer module and per seat feesOne studio covers detection and triage, with no per seat meter
Featurespace behavioural analyticsSubscription tied to transaction volumeOn device scoring with no per transaction cloud charge
Offshore or in house false positive reviewAnalyst hours per alert at scaleReasons attached scoring clears and escalates faster, fewer hours per alert
Separate audit and case export toolingLogging, storage and export feesEvery detection sealed to the Open Audit Record at no extra meter
Repeated tooling per marketA deployment and licence for each jurisdictionOne explainable engine reusable across the single EU rulebook

Frequently asked questions

Does an on premise AML engine still meet AMLA expectations?

Yes. AMLA's emphasis is on effective detection, explainability and record keeping under the single rulebook, none of which depends on the cloud. Running detection on your own hardware keeps the assessed data in the building and still produces a sealed, regulator ready trail. Mickai does not hold certifications for you; it generates the evidence that supports supervisory review.

What exactly does Nemesis replace?

It is built to replace transaction monitoring licences such as SAS AML, NICE Actimize and Featurespace, and to absorb the false positive review labour they generate. Detection, triage and the audit trail live in one owned studio instead of across several metered subscriptions.

How does keeping detection offline reduce cost and risk?

Offline scoring removes the per transaction and per alert cloud meter, so the bill stops growing with volume, and no customer transaction data leaves your infrastructure to be assessed. You pay for hardware you own rather than a subscription that renews and re prices every year.

Can one engine really cover multiple EU markets?

That is the point of the single EU rulebook. Because the standard is harmonised, one explainable engine can be tuned once and pointed at each market's transactions, rather than licensing and reconciling separate tools per jurisdiction, so the cost does not multiply with your footprint.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/amla-2026-explainable-aml-on-premise. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
18 Aug 2026
How Telecoms Operators Meet the Telecommunications Security Act With AI That Never Leaves the Network
Telecoms operators meet the Telecommunications Security Act code of practice with AI that runs inside the security-critical boundary on operator-owned hardware. A zero-egress perimeter keeps network configuration and signalling data within operator control, so nothing sensitive crosses out to a public cloud service.
18 Aug 2026
Can energy operators run AI on grid and OT data on-premise to satisfy the Cyber Assessment Framework?
Yes. Energy operators can run forecasting and anomaly detection on grid and OT data entirely on their own hardware, and this satisfies the Cyber Assessment Framework more cleanly than cloud analytics, because telemetry never leaves the audited perimeter and no third-party processor exists to assess.
18 Aug 2026
How Airports Meet EASA Part-IS from February 2026 with On-Site AI
Part-IS applies to aerodrome operators from 22 February 2026 and makes the airport, not its vendor, accountable for information-security risk. Running AI on operator-owned hardware behind a zero-egress perimeter keeps passenger and operational data inside that boundary, so a supplier's SOC 2 cannot discharge it.
18 Aug 2026
Can Automotive Suppliers Use AI on OEM Design Data While Keeping TISAX Prototype Protection?
Automotive suppliers can run AI on OEM design and prototype data and keep TISAX prototype protection, but only when the model runs on their own hardware inside the protected zone. Public cloud AI transmits the data outward, which prototype protection forbids.