AI
6 min
Fintech

DORA, MiCA, and AML: what AI automation means for EU compliance in 2026

Written by
Freeday Team
Published on
July 23, 2026

Three regulatory frameworks are running in parallel across European financial services right now, and each has direct implications for organisations that are deploying or planning to deploy AI in their compliance workflows.

DORA (Digital Operational Resilience Act) came into full effect in January 2025. MiCA (Markets in Crypto-Assets Regulation) has been phased in through 2024-2025. The sixth EU Anti-Money Laundering Directive (AMLD6) and the establishment of the new EU AML Authority (AMLA) are reshaping the AML compliance landscape through 2026 and beyond.

For compliance and technology leaders, the question is not whether to engage with these frameworks. It is how to deploy AI in a way that meets their requirements, and where AI can actually help with compliance rather than complicating it.

DORA: operational resilience and AI systems

DORA requires financial entities to manage ICT risk comprehensively, including risks arising from AI systems used in critical or important functions. For organisations using AI in customer service, KYC, or AP processing, this has specific implications.

ICT risk management requirements. AI systems used in customer-facing or compliance-relevant functions must be included in the organisation's ICT risk management framework. This means documenting the AI system's function, its data inputs and outputs, its failure modes, and the controls in place to manage operational risk.

Third-party risk management. DORA's requirements on ICT third-party risk management apply to AI vendors. Financial entities must assess the operational resilience of their AI platform providers, including concentration risk if multiple critical functions depend on the same vendor.

Incident reporting. AI-related incidents that affect critical functions may fall within DORA's major incident reporting requirements. Organisations need to understand what constitutes a reportable incident for their AI deployments.

Business continuity. AI systems that handle significant customer service or compliance workloads need to be included in business continuity planning. What happens when the AI is unavailable? Is the fallback to human processing sufficient to maintain service levels?

The practical implication for AI deployment decisions: DORA compliance is achievable for AI systems but requires upfront documentation and integration into existing ICT risk frameworks. This is not a reason to avoid AI deployment. It is a reason to approach it with the same governance discipline as any other critical ICT system.

MiCA: crypto-assets and AI in compliance workflows

Bitvavo, the Dutch crypto exchange, provides the most relevant case study for MiCA compliance in the context of AI deployment. Bitvavo processed 375,000 customer interactions in 2025 at an 82.9% automation rate, with AI supporting their customer service and KYC-adjacent compliance workflows through MiCA's implementation period.

MiCA requires crypto-asset service providers (CASPs) to implement thorough KYC and AML controls, including customer due diligence that meets standards comparable to those in traditional financial services. AI can support these requirements in several ways:

Automated document collection and validation. MiCA's KYC requirements include verification of customer identity for all account types above defined thresholds. AI can automate the collection and initial validation of identity documents, reducing the manual processing burden while maintaining audit trails.

Suspicious transaction monitoring. AI pattern recognition can flag transaction patterns that warrant AML review more accurately and at lower cost than purely rule-based systems. The key compliance requirement is that the flagging logic is explainable and auditable.

Regulatory reporting support. MiCA introduces new reporting obligations for CASPs. AI can support data extraction and report preparation for these obligations, reducing the manual effort in compliance reporting.

The Freeday fintech industry page covers the Bitvavo deployment and its compliance context in more detail.

AMLA and AMLD6: the evolving AML landscape

The new EU AML Authority (AMLA) became operational in 2025 and will progressively take on direct supervisory responsibility for the highest-risk financial institutions. The sixth Anti-Money Laundering Directive has expanded AML obligations to new sectors and strengthened requirements on beneficial ownership, transaction monitoring, and suspicious activity reporting.

For compliance teams, the AML landscape is moving in one direction: higher expectations, broader scope, and more rigorous enforcement. The organisations that will meet these expectations are those that can process more data, with more consistency, with better audit trails. Those are exactly the capabilities that AI automation provides.

Transaction monitoring. AI-driven transaction monitoring can analyse significantly larger datasets than rule-based systems, with fewer false positives and clearer reasoning chains when suspicious patterns are identified. The EU AML framework's requirements for risk-based monitoring are better met by AI systems that can calibrate risk scores continuously than by static rule sets.

Beneficial ownership verification. AMLD6 strengthens requirements on beneficial ownership identification and verification. AI can automate document extraction and cross-reference against beneficial ownership registers, reducing the manual effort while improving completeness.

SAR quality. Suspicious Activity Reports filed with FIUs (Financial Intelligence Units) must be accurate, timely, and complete. AI can assist in preparing SARs by extracting relevant transaction data, identifying connected parties, and structuring the narrative, while keeping the compliance officer in the decision loop for the filing decision itself.

The explainability requirement across all three frameworks

DORA, MiCA compliance, and AML all share a common requirement: AI decisions in compliance-relevant contexts must be explainable. A compliance officer or regulator must be able to understand why the AI made a specific decision, and that explanation must be documented.

This is where poorly designed AI deployments fail regulatory scrutiny. A system that produces a compliance decision but cannot explain its reasoning is not acceptable in regulated financial services, regardless of how accurate it is on average.

Well-designed AI compliance systems produce explicit reasoning chains: this document was flagged because field X does not match the expected format for documents from issuing country Y, and because the transaction history associated with this customer matches pattern Z that is associated with elevated risk. That reasoning is logged, reviewable, and defensible.

The Freeday security and compliance page covers the explainability architecture for Freeday deployments and how it maps to Dutch and EU regulatory requirements.

What compliance teams should do before deploying AI

The organisations that deploy AI in compliance workflows successfully have typically done three things before go-live:

Regulatory mapping. They have mapped the specific AI use case against the relevant regulatory requirements and documented how the deployment meets each requirement. This is not complex analysis but it needs to be done explicitly, not assumed.

Escalation design with compliance in mind. They have defined the cases that must always involve a human compliance decision, regardless of the AI's assessment. High-risk customer classifications, SARs, and cases above defined thresholds are the minimum. This boundary is documented and enforced in the deployment architecture.

Audit trail validation. They have confirmed that the audit trail the AI produces is complete enough to satisfy a regulatory review. This means testing the logging against real scenarios before go-live, not assuming it will be adequate.

The Freeday KYC solution page walks through the compliance design principles for KYC automation deployments.

FAQ

Is AI automation in financial services compliant with DORA?

Yes, when implemented with appropriate ICT risk management. DORA requires AI systems used in critical functions to be documented, risk-assessed, and included in business continuity plans. Meeting these requirements is achievable but requires the same governance approach as any other critical ICT system.

Does MiCA require specific AI capabilities for KYC?

MiCA requires CASPs to implement KYC controls comparable to traditional financial services. AI can automate document collection, validation, and initial review. The requirement is that the process meets the quality standard, not that AI is or is not used.

Can AI replace human compliance officers in AML decisions?

No, and well-designed AI deployments do not attempt to. AI supports compliance officers by processing higher volumes, flagging anomalies, and preparing case files. The SAR filing decision, the risk classification decision, and the customer relationship decision remain with human compliance professionals.

What audit trail does AI produce for compliance purposes?

A well-designed AI compliance deployment logs every input received, every action taken, the reasoning for each decision, and every escalation. The audit trail is typically more complete than manual processes because it is systematic, not dependent on individual agent documentation habits.

How does AMLA supervision affect AI compliance deployments?

AMLA's direct supervision of the highest-risk institutions raises the bar for documentation and transparency. AI deployments that include complete audit trails and explainable decision reasoning are better positioned for AMLA scrutiny than those that do not.

In this article

Freeday teamlid profiel foto

Stay updated on digital employees

Connect with Freeday on social channels

FAQ

Common questions about AI agents, automation, and enterprise deployment answered.

How do AI agents reduce costs?

AI agents handle repetitive workflows continuously without fatigue or error, eliminating the need for proportional headcount increases. Enterprises using Freeday reduce contact center costs by up to 92% while maintaining industry-leading CSAT scores. The agents process one million monthly calls with consistency that human teams cannot match, handling customer service inquiries, KYC verification, accounts payable processing, and healthcare intake simultaneously across voice, chat, and email channels.

What workflows can be automated?

Any workflow that follows consistent rules and doesn't require complex human judgment can be automated. This includes customer service inquiries, KYC verification, accounts payable processing, patient intake, appointment scheduling, booking modifications, returns management, and insurance verification. The platform connects to over 100 business applications including Salesforce, SAP, and Epic, enabling agents to access the systems your organization already uses.

Is AI deployment secure and compliant?

Freeday maintains ISO 27001 certification with full GDPR and CCPA compliance built into the platform foundation. Security and governance requirements are not afterthoughts but core architectural principles. Your customer data and business processes receive protection that matches the sensitivity of the information involved, with enterprise-grade controls for organization-wide AI deployment.

How does Performance Intelligence work?

Performance Intelligence tracks conversation metrics and auto-scores CSAT in real time, detecting issues before escalation becomes necessary. The system provides visibility into what agents are doing, why they're making decisions, and whether they're complying with regulations. This eliminates manual reporting that consumes time and introduces errors.

What makes the platform model-agnostic?

Freeday's architecture supports any AI model, protecting your investment as technology evolves. You're not locked into a single vendor's approach and can experiment with different models to choose what works best for your specific workflows. This flexibility ensures your platform remains current as the AI landscape changes.

Ready to learn more?

Reach out to our team to discuss your specific needs.