US banks and the compliance vendors that serve them are pointing artificial intelligence at one of banking’s oldest paperwork problems: the volume of false alerts that sanctions screening software throws off before a single genuine match against a government watchlist is found. The push has a new regulatory backdrop. On 16 September 2026, the Conference of State Bank Supervisors (CSBS) published an AI Supervisory Framework that gives state examiners a common set of questions to ask state-chartered banks and state-licensed non-bank financial institutions about how they build, test and monitor AI-based tools, sanctions screening among them.
The screening rules behind that check, the sanctions lists themselves and the near-miss name-matching that trips up automated systems, are covered in Fintechly’s own explainer on how a sanctions match gets flagged. What has changed since that explainer published is what banks are doing about the volume the rules create.
A common yardstick for state-chartered banks
The CSBS framework does not set new rules for banks to follow. It gives state examiners, who CSBS says supervise 79% of all US banks, a structured way to ask an institution what an AI tool does, how it was tested and who is accountable when it gets a call wrong. CSBS president and chief executive Brandon Milhorn said the framework is meant to give financial institutions confidence to explore AI rather than slow them down. It draws on the National Institute of Standards and Technology’s AI risk management framework, the Cyber Risk Institute’s financial-services version of the same, and the US Treasury’s own AI lexicon.
For a sanctions screening system, that means an examiner can now ask a bank to show its model’s false positive and false negative rates, explain how a match score is calculated, and describe what a human reviewer sees before a case is closed. The framework covers any AI tool a state-chartered bank runs, not only screening, but screening is one of the oldest automated decision points in banking, which makes it an obvious place for examiners to start.
The framework lands harder on smaller, state-chartered institutions than on the nationally chartered banks that already run dedicated model-risk teams. Most of the sanctions-screening AI products reaching the market this year are built as an overlay on an existing rules-based system rather than a full platform replacement, which suits a bank that cannot justify ripping out software that has already cleared a regulatory exam.
Why the false positive rate is the target
The reason sanctions screening draws so much AI investment is the scale of the problem it is trying to fix. Cara Wick, a financial crimes executive at Bank of America writing for the analyst firm Datos Insights in February 2025, cites the Federal Reserve’s own model risk guidance, which states plainly that “all models have some degree of uncertainty and inaccuracy”, and notes that anti-money laundering models routinely generate false positive rates of 90% to 95%. Sanctions screening runs worse again: because a bank has almost no tolerance for missing a genuine match, a sanctions model can carry a false positive rate as high as 99.5%, Wick writes, citing the pattern set out in the OCC’s Model Risk Management Handbook.
Every one of those false alerts still needs a human reviewer to clear it before the transaction, account opening or onboarding case can move on. That is the queue the new AI tools are being sold to shrink, not the underlying sanctions lists themselves.
What the vendors are building
SymphonyAI markets an AI Overlay for Screening, branded SensaAI for Sanctions, that sits on top of a bank’s existing name and transaction screening system rather than replacing it. The company says the tool uses generative AI to read the unstructured free text inside a screening alert and predictive models to score how likely a flagged match is genuine, and claims an 80% reduction in false positives with full retention of true positives. SymphonyAI says the product ships pre-trained on synthetic data, so a bank can run a two-week proof of concept against its own historical alerts before committing to a wider rollout.
NICE Actimize, whose wider anti-money laundering suite covers know-your-customer automation, transaction monitoring and case management as well as sanctions work, describes its screening tools in similar terms: entity-centric matching the company says is “infused with AI and machine learning” to raise accuracy without giving up regulatory coverage. Both vendors are selling the same trade to the same buyer: fewer false alerts reaching an investigator’s queue, without a bank quietly missing the one match that mattered. Ripping out a screening system that has already been through model validation and years of regulatory exams is rarely worth the risk to a bank, however strong the new AI’s claims, which is why an overlay that sits on top of the existing stack is the product most vendors are pitching first.
Enforcement keeps the pressure on
The compliance stakes behind that pitch are current, and a screening failure specifically is on OFAC’s own list of causes. On 12 February 2026, OFAC settled with IMG Academy, a Florida school and athletic training facility, for $1,720,000 over 89 apparent violations of counternarcotics sanctions between 2019 and 2025. IMG Academy had entered into annual tuition agreements with two individuals OFAC had designated over their ties to a sanctioned Mexican drug cartel, and received the related payments mostly through third-party wire transfers and credit card charges rather than directly from the sanctioned individuals. OFAC’s enforcement release names IMG Academy’s failure “to conduct sanctions screening checks on its counterparties” as an aggravating factor, and notes that the sanctioned individuals had given their full names, which matched entries on OFAC’s Specially Designated Nationals list, at multiple points during enrolment. The case was not voluntarily disclosed. OFAC had already opened its own investigation before IMG Academy came forward.
The following month, on 17 March 2026, OFAC settled separately with TradeStation Securities for $1,110,661 over 481 apparent violations of sanctions on Iran, Syria and Crimea, arising from brokerage and investment services the firm provided between June 2021 and June 2022. That case was voluntarily self-disclosed and classed as non-egregious, a reminder that cooperation reduces a penalty rather than eliminating it.
Whether the balance shifts because of AI overlay tools, a state examiner’s new checklist under the CSBS framework, or the next OFAC settlement, the direction is the same: sanctions screening is moving from a static rules engine that only gets touched after a regulator complains to a system banks expect to keep tuning. A fuller list of the compliance and regtech providers active in this space is on Fintechly’s regtech sector directory.