How Luno is moving faster with AI – and staying compliant while doing it

post-title

Everyone is talking about AI, but few are talking about what it actually takes to deploy it safely inside a regulated financial business.

Crypto sits at the sharp end of the “safe adoption” challenge that exists across regulated financial services. For crypto businesses, the regulatory environment is more fragmented, less mature and moves faster than in payments, lending, or insurance. That makes it a useful reference point. If you can get AI governance right in crypto, the same thinking applies almost everywhere in fintech.

Here’s an insider’s account of what it takes to build AI infrastructure inside a regulated financial technology business, and what I think technology leaders in this space need to be thinking about.

The constraint
Every organisation deploying AI at scale is navigating tension between capability and control. In regulated financial services, that tension is structural and non-negotiable.

Fintech businesses operate within multiple anti-financial crime frameworks, consumer protection obligations, data privacy requirements and prudential rules, often across multiple jurisdictions simultaneously, and often in a fragmented way.

At Luno, this means anti-money laundering obligations, KYC requirements, sanctions screening and suspicious activity reporting under different regulatory regimes in the UK, EU, South Africa, Indonesia, Australia and elsewhere.

The specific rules vary, but the common characteristics don’t. A human being must be accountable for the outcome.

This creates a constraint that doesn’t exist in most other industries deploying AI. When an AI system touches a compliance-relevant process in a regulated fintech environment, the regulator isn’t interested in your model’s accuracy metrics. They want to know who reviewed it, who signed off and what the audit trail looks like. That’s as true for a payments business handling disputed transactions as it is for a crypto exchange processing an Enhanced Due Diligence (EDD) case.

It’s not an argument against using AI, but about being precise about where and how you use it.

Quantifying the AI opportunity

The business case is substantial. Regulated financial businesses carry significant operational overheads, mostly in compliance and financial crime functions.

In EDD cases, in-depth reviews are triggered by high-risk customers or transactions, and are extremely time-intensive due to the in-depth nature of the investigations. An analyst manually working through a complex EDD case is often looking at four or more hours of data gathering, cross-referencing, synthesis and write-up.

Early modelling and proof of concept at Luno suggests AI assistance could compress that analytical groundwork down to as little as 15 to 30 minutes, with the analyst’s time now primarily being spent on review, judgement and sign-off. Across meaningful case volumes, that’s a significant change to capacity; not by removing the human accountability layer, but by removing the parts of the work that don’t require it. In many cases, machines are going to be better and more consistent at much of this non-decision-making work because they are not prone to fatigue, distraction, or boredom.

Anti-financial crime orchestration workflows, the coordination layer that manages alerts, escalations and reporting across financial crime controls, show similar potential. Processes that currently run in hours could run in minutes. Regulatory reporting that requires tedious manual collation across multiple data sources becomes automatable.

This isn’t unique to crypto. Any regulated fintech with a significant compliance operations volume, such as payments, fraud review, credit risk assessment, regulatory reporting and customer due diligence, is sitting on a comparable opportunity. The shape of the problem is the same even when the specific regulation differs.

The efficiency case is incontrovertible, but realising it requires getting the architecture right first.

A framework for where AI actually applies

Not all work in a regulated financial business is equally suitable for AI automation and getting this wrong is costly. You either under-invest and leave real efficiency on the table, or you over-automate and create compliance exposure that costs more to remediate than you saved.
Here’s the framework we’ve developed at Luno and I think it translates broadly across fintech:

Tier 1: High-volume, rules-heavy, auditable: Automate all of this aggressively. Alert triage, standard KYC document processing, regulatory reporting compilation, invoice processing, vendor onboarding documentation and asset tracking. AI as the primary actor, human beings as exception handlers and quality reviewers. These processes are already designed to be repeatable and auditable so AI fits naturally here, and the efficiency gains are the largest.

Tier 2: Process-heavy but exception-rich: AI-assisted, but human-owned. Complex EDD cases, risk assessments, compliance evidence gathering and incident response coordination. AI handles the data gathering, synthesis and initial drafting. A human makes the calls, takes accountability and signs the output. The AI doesn’t replace judgement, it improves the quality of information available to the person exercising it and saves a lot of time in the process.

Tier 3: Relationship and judgement-dependent: AI-informed, human-led. Regulator engagement, people situations, anything where the outcome depends on trust built over time and a genuine reading of the room. AI helps you prepare. It isn’t present for the important conversation.

The reason this framework matters specifically in fintech? A disproportionate share of the highest-value work sits in Tier 2 and 3. Financial crime analysts, compliance officers, risk managers, regulatory relationship owners – these are not roles the intelligence layer replaces. They’re roles where AI can materially improve capacity and quality of output, if the governance is right.

The governance problem most technology leaders underestimate

Here’s what I’ve learnt from developing AI governance infrastructure at Luno: the runway takes longer to build than people expect, and you need it finished before the planes start arriving.

AI governance in a regulated financial business isn’t just an IT problem or a legal problem. It sits with both, plus compliance, information security and vendor management. The questions are genuinely cross-functional. Which AI tools are approved for which categories of work? What data can those tools access? Who owns the audit trail when an AI-assisted process produces a regulatory output? What happens when a model behaves unexpectedly on a compliance-related workflow?

All of these new systems require validation before deployment, ongoing monitoring in production and a process for catching model drift, the gradual degradation of performance that can happen when the inputs a model receives no longer closely match the data it was trained on. From a compliance perspective, model drift is a technical issue, but also a potential risk event, and most governance frameworks fail to account for this.

In most organisations, nobody owns or asks these questions until something goes wrong. In a regulated fintech environment, something going wrong means a potential regulatory incident, not just a bad outcome, and this is not something we can accept.

There’s also the shadow AI problem, which is present in every organisation right now. If you think you don’t have a shadow AI problem, I worry you have your head in the sand. Employees using unapproved AI tools on work data is not a future risk. They already are.

In a regulated financial business, it’s more than a security concern. Depending on what data those tools see and what they do with it, it’s also a potential compliance incident. Most technology leaders I speak to are aware of this problem in the abstract, but underestimate how bad it is in their own organisation.

My recommendation is to get ahead of the problem and build the governance framework before you need it. Specifically, a formal AI tool registry that distinguishes between approved, shadow and prohibited tools; a classification model for what categories of work AI can touch and under what conditions – and clear accountability lines for AI-assisted outputs that touch compliance obligations. None of this is technically complex, but it does require cross-functional ownership and deliberate effort, and it consistently gets deprioritised in favour of the more visible capability work.

The questions you need to ask now

If you're a technology leader in regulated financial services, these are the questions that have shaped my approach:

Where are your Tier 1 automation candidates? If your organisation has significant compliance operations volume and those workflows aren’t on an AI roadmap, that’s a big gap. The efficiency case is strong enough that it should be on someone’s agenda.

What’s your audit trail position? When a regulator asks to see the decision-making record on a complex case, is AI involvement transparent, documented and easily accessible? This needs an answer before deployment, not after.

What’s your shadow AI exposure? Do you have genuine visibility into which AI tools your team is using on work data? If not, that’s the first governance problem to solve.

Who owns the cross-functional questions? AI governance in a regulated environment can’t live solely in IT, Legal, or Compliance in isolation. If nobody owns the intersection, build that ownership structure deliberately, ideally before an incident makes it urgent.

The efficiency opportunity from AI in regulated fintech operations is enormous. The governance challenge is equally large and consistently underestimated, particularly by organisations moving fast on capability without building the infrastructure to govern and support it safely.

The crypto industry sits at the sharp end of this because the regulatory environment is more varied and constantly evolving. But the underlying dynamic of deploying AI inside a compliance-constrained business, at pace, without creating new exposure, is one many technology leaders across financial services are navigating right now.

The organisations that get this right won’t necessarily be the ones that moved fastest. They’ll be the ones who built the runway first and thought clearly about what AI should and shouldn’t be doing in their business, before the planes started landing.

That thinking is available to any technology leader willing to prioritise it. The model won’t do it for you.

Related articles

2026 Executive Day: Diagnosing and fixing corporate friction

During a breakaway session on tackling workplace tension, Zeda CIO Pulana Ngwasheng unpacked her five types of corporate friction. She was joined by Auditor-General CTO Phila Ndarana and AB InBev VP of people Inette Swart.

Top