August 4, 2026

Coming into force on 10th July 2027, the new EU anti-money laundering regulations will transform how financial institutions, crypto companies, and more approach onboarding, compliance, and risk management. The package aims to reduce fragmentation across member states, mitigate administrative burden, and improve security and UX via electronic identity verification.

Key to the new regulatory package is the Regulatory Technical Standards (RTS), which are currently being drafted. The RTS will set the requirements for how financial institutions operating in the European Union must conduct customer due diligence, risk assessment, and digital onboarding.

This blog explores the drivers for the regulatory changes, what the requirements mean for EU businesses, and the actions organizations can take now to avoid noncompliance risk in the near future.

Drivers for Stricter AML Controls

The changes are in response to the growing sophistication of money laundering and terrorist financing in the EU and beyond. Facilitated by generative AI, deepfake tools, and crime-as-a-service networks, criminals bypass legacy identity controls and open fraudulent accounts. 

Fraudulent identities inside the KYC perimeter can be used for money laundering, terrorist financing, and sanctions evasion. Criminals can scale this — a single individual can open numerous accounts using different stolen or synthetic identities.

The vulnerabilities of weak identity verification were exposed in early 2026, when a single bad actor opened 46 bank accounts with ABM AMRO, using stolen identity information and deepfakes to bypass the ID + Selfie identity controls.

The Shift to eIDAS-compliant Onboarding

Regulators’ response to this is to mandate stronger identity controls at onboarding, anchored to eIDAS. The draft RTS makes eID the default means of verifying user identity, demoting physical documents and video-call identity verification to a fallback option — one that institutions must justify to their supervisors whenever they use it.

The Electronic Identification, Authentication and Trust Services (eIDAS) Regulation sets the framework for using eIDs for remote onboarding. Its Levels of Assurance (LoA) grade the degree of confidence in a claimed identity — AMLR accepts eID at LoA Substantial and High. High is the most stringent identity verification standard in the EU.

With a looming July 2027 deadline, EU businesses are under pressure to modernize their identity stacks to meet the requirements. Certification cycles take months, so adopting identity solutions that are not yet certified to meet eIDAS assurance levels creates a risk of noncompliance and the resulting penalties when the deadline comes.

Partnering with an identity vendor already modular certified to both High and Substantial not only removes this risk, but also allows you to match assurance level with the associated risk of the transaction, identity, or contextual factors — balancing speed, UX, and security.

Resilience Against Identity Threats is Vital

While the draft RTS states that identity verification must comply with eIDAS, it doesn’t yet set specific requirements for anti-spoofing capabilities. The absence of a security baseline risks financial institutions adopting solutions that cannot withstand today’s leading identity threats.  Attacks against remote identity systems come in two forms: 

  • Presentation attack: The attacker buys, steals, or forges a physical identity document to fool the document check, then holds a printout, mask, or deepfake played on a screen in front of the camera.
  • Injection attack: The attacker bypasses the camera entirely, injecting forged document imagery and a synthetic face directly into the data stream, typically using a virtual camera or virtualised environment. 

While presentation attacks remain abundant, they’re well understood, limited in scale, and many solutions are validated for presentation attack detection (PAD). By contrast, injection attacks scale rapidly and are evolving in ways that confound prior defenses. In 2026, iProov Threat Intelligence reported a 1,151% increase in injection attacks targeted at iOS systems, a platform previously considered secure due to Apple’s closed–loop ecosystem.

Combined with AI-generated deepfakes and synthetic identities, injection attacks are proving to be the primary method attackers use to bypass identity defenses — many of which rely on basic PAD — and open fraudulent accounts, undermining AML controls.

Injection Attack Detection

Identity solutions can prove their injection attack detection (IAD) capabilities through independent, standards-aligned testing and validation. CEN TS 18099 is the current technical standard for injection attack detection, grading IAD into Substantial and High. Ingenium, a testing lab, goes further still, setting 5 levels of IAD with Level 2 equating to CEN High.

Though the AMLR RTS has not yet specified injection attack detection as a requirement, the move to demonstrable IAD is the direction of travel for global identity compliance. NIST SP 800-63-4, finalised in 2025, explicitly requires that remote identity proofing systems implement controls against AI-generated content and injection attacks.

So, while IAD may not be an explicit requirement to AML regulations yet, financial institutions can get ahead of the compliance curve by partnering with identity vendors who can demonstrate both IAD and PAD against recognized standards.

How iProov Can Help You Get Ready For Upcoming AML Package

iProov holds eIDAS modular certification at Level of Assurance High (iProov Dynamic Liveness) and Substantial (iProov Express Liveness). Dynamic Liveness is validated against Ingenium Level 4 (CEN TS 18099), the highest independently validated IAD of any biometric vendor at the time of writing. 

Book a demo to understand how we can help.