CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

AI-Enabled Crime in Crypto: AML Best Practices for Firms

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING AI-Enabled Crime in Crypto: AML BestPractices for Firms

AI-powered threats, from deepfakes used to defeat identity checks to illicit AI services sold on dark-web marketplaces, are reaching the cryptoasset ecosystem at a pace that outstrips most firms' existing AML controls. A cross-industry consultation carried out across 2024, drawing on expertise from law enforcement, virtual asset service providers (VASPs), regulators, technology start-ups, and academic researchers, has produced a framework of best practices designed to help the industry get ahead of these risks. For accounting firms, auditors, and CFOs who rely on crypto accounting software to maintain accurate digital-asset records, understanding where AI crime intersects with compliance obligations is no longer optional.

AI-Enabled Crime in Crypto: AML Best Practices for Firms

Why AI Changes the AML Threat Landscape

Traditional financial crime in crypto has relied on obfuscation techniques such as chain-hopping, mixers, and layered wallet structures. AI introduces a qualitatively different problem: it lowers the skill floor for sophisticated attacks while raising the ceiling on what is possible. Deepfake technology can now convincingly impersonate executives or clients during video-based KYC checks. Generative AI can produce synthetic identity documents that pass automated verification layers. Illicit AI services, sometimes sold as "fraud-as-a-service" tools, package these capabilities for non-technical criminals.

The cross-industry consultation identified these as emerging risks, meaning the evidence base is still forming but the trajectory is clear enough that early action is warranted. Firms that wait for a prescriptive regulatory response before updating their controls will find themselves reacting to incidents rather than preventing them.

Deepfakes and Identity Verification

Video and audio deepfakes represent a direct attack on KYC processes that shifted to remote delivery during and after the pandemic. A compliance team relying solely on live video calls to onboard high-value clients now faces a credible impersonation risk. The best-practice response involves layering liveness detection with document forensics and behavioural signals, rather than treating any single check as conclusive.

Illicit AI Services and Synthetic Fraud

Beyond deepfakes, the consultation flagged the proliferation of AI toolkits specifically marketed for financial fraud. These include synthetic identity generators that can create plausible but fictitious customer profiles, automated transaction-structuring tools designed to stay beneath monitoring thresholds, and AI-assisted phishing kits targeting crypto-firm employees. The practical implication is that transaction monitoring rules calibrated to human-speed, human-pattern fraud may systematically miss AI-generated activity.

Who Was Consulted and What They Contributed

The breadth of the consultation is relevant because it signals cross-sector consensus rather than a single vendor's view. Law enforcement agencies contributed intelligence on active AI-crime typologies. VASPs shared operational data on attempted fraud patterns. Regulators provided context on what supervisory expectations are likely to look like as the threat matures. Technology start-ups brought perspective on what AI tools are already accessible, and academic researchers contributed risk-modelling frameworks.

This multi-stakeholder approach matters to accounting firms because it means the resulting best practices are grounded in real incident data, not theoretical scenarios. It also signals that regulators are already engaged with the issue, making it reasonable to expect that supervisory guidance, whether from FinCEN, the Financial Action Task Force (FATF), or other bodies, will eventually formalise some of these practices into hard requirements.

Best Practices: Key Themes for Compliance Functions

The consultation report structures its recommendations by stakeholder group, recognising that a VASP, a custodian bank, and a regulator each face different threat surfaces. For accounting and compliance professionals, several themes stand out.

Early Detection Over Reactive Response

The central argument of the framework is that AI-enabled crime is best countered before it escalates, not after a suspicious activity report has been filed. That means investing in detection capabilities now, even when the volume of confirmed AI-assisted incidents at a given firm remains low. Waiting for a material loss event to justify control upgrades is the wrong decision calculus: by the time the loss occurs, the attack pattern has likely been operating undetected for months.

For firms using digital asset accounting software, this has a direct implication. On-chain records are only as reliable as the identity and transaction-monitoring controls that surround them. If a fraudster has successfully impersonated a client through a deepfake-assisted onboarding, every subsequent transaction attributed to that client in the general ledger carries an integrity risk.

Layered Controls and Red-Flag Indicators

Single-point controls, whether a liveness check or a transaction threshold rule, are insufficient against AI-generated attacks that are designed to defeat specific defences. The best-practice guidance points toward layered architectures: multiple independent checks at onboarding, continuous behavioural monitoring post-onboarding, and anomaly detection that does not rely solely on rule-based triggers.

Specific red-flag indicators highlighted in the consultation include: inconsistencies between a customer's stated profile and their on-chain transaction history; unusual velocity patterns that suggest automated rather than human-initiated activity; and identity documents that pass automated checks but display subtle forensic anomalies detectable through specialist review.

Information Sharing Across the Ecosystem

AI-crime typologies evolve quickly. A fraud pattern defeated at one exchange may reappear at a custodian bank within weeks, slightly modified. The consultation places significant weight on structured information sharing between VASPs, banks, and relevant authorities as a mechanism for distributing threat intelligence faster than criminal actors can iterate. In the US context, existing frameworks such as FinCEN's 314(b) voluntary information-sharing programme provide a channel, though the guidance implicitly calls for more systematic and technology-enabled sharing arrangements.

Accounting firms and auditors serving multiple crypto-sector clients are positioned to observe patterns across client portfolios. While direct client-specific information cannot be shared without consent, firms can contribute to and benefit from sector-level threat intelligence initiatives.

Governance and Board-Level Awareness

The report signals that AI-crime risk should sit on the board agenda, not only within the compliance function. CFOs and audit committee chairs at firms with significant digital-asset exposure need enough fluency in the threat landscape to challenge management on whether controls are adequate. This is consistent with the broader trend toward technology risk being treated as a first-order governance issue, alongside credit and market risk.

For firms reviewing their crypto bookkeeping software stack, this is a prompt to ask vendors directly about their approach to data integrity under AI-assisted fraud scenarios. How does the platform detect anomalous wallet attribution? What controls exist to flag transactions that may originate from compromised identity onboarding?

AML Implications for Accounting Firms and Auditors

Accounting firms that provide AML compliance services to VASPs or that audit digital-asset portfolios face two distinct implications.

Client Risk Assessment Updates

AI-enabled fraud alters the risk profile of clients who were previously categorised as lower risk on the basis of their KYC documentation and transaction history. If a client's identity was established through a process that is now known to be vulnerable to deepfake-assisted impersonation, the historical risk assessment may need to be revisited. This is especially relevant for clients onboarded during the period when fully remote, video-based KYC became standard, roughly 2020 to 2023, before liveness detection and document forensics became widely deployed.

The engineering decisions that define on-chain AML screening are increasingly relevant here: firms should review whether their screening infrastructure can flag the behavioural anomalies associated with AI-generated transaction patterns, not just the wallet addresses on existing sanctions and watchlists. Our earlier analysis of engineering decisions that define on-chain AML screening covers the architectural choices that bear directly on this capability.

Audit Procedures and Evidence Quality

External auditors performing procedures over digital-asset holdings need to consider whether management's controls are sufficient to provide reasonable assurance that recorded transactions reflect genuine economic activity. Where AI-assisted fraud could have resulted in fictitious transactions or misattributed wallet ownership, standard confirmation procedures may not be adequate. Auditors should understand how management detects and responds to AI-crime indicators and reflect that understanding in their risk assessment and the design of substantive procedures.

Stablecoin-Specific Exposure

The broader context of the consultation also touches on stablecoin risk, which is particularly relevant for US-focused firms given the trajectory of domestic stablecoin legislation. Issuers of dollar-denominated stablecoins use transfer screening and continuous monitoring on their own tokens. Firms that hold, custody, or process stablecoins face sanctions exposure risk if those tokens have links to sanctioned jurisdictions.

The intersection with AI crime is direct: if AI-assisted identity fraud enables a sanctioned actor to establish a seemingly clean wallet, subsequent stablecoin flows through that wallet carry undetected sanctions exposure. Under any future federal stablecoin framework, treating a non-permitted stablecoin as permitted because the underlying due diligence was compromised by AI-assisted fraud would constitute a compliance failure, not simply a control weakness. Firms should ensure that their stablecoin exposure monitoring is integrated with, not siloed from, their AI-crime detection controls.

The relationship between stablecoins and illicit finance has already drawn significant regulatory scrutiny. Our coverage of OFAC sanctions and crypto wallet exposure for firms illustrates how quickly a gap between transaction screening and economic reality can create material liability.

Practical Next Steps for Compliance and Finance Teams

The best-practice framework does not prescribe a single implementation path, but the following steps are consistent with its themes and appropriate for firms at various stages of digital-asset maturity.

Review Onboarding Controls for AI Vulnerability

Audit the KYC process end-to-end with specific attention to steps that rely on video, image, or document review. Identify where liveness detection and document forensics are deployed and where they are absent. For higher-risk client categories, consider whether additional verification layers are warranted.

Update Transaction Monitoring Typologies

Work with your compliance technology providers to understand whether current monitoring rules can detect AI-generated transaction patterns, including unusual velocity, synthetic structuring, and behavioural inconsistencies. Request documentation of how the platform addresses these scenarios.

Engage in Sector Information Sharing

Where eligible, participate in FinCEN's 314(b) programme or equivalent information-sharing arrangements in other jurisdictions. Assign responsibility within the compliance function for monitoring published AI-crime typologies from FATF, FinCEN, and relevant law enforcement bodies.

Escalate to Governance

Prepare a board or audit committee briefing that frames AI-enabled crypto crime as an emerging risk category requiring explicit consideration in the firm's risk appetite statement. This is the governance step that converts awareness into accountability.

AI-Enabled Crime in Crypto: AML Best Practices for Firms

Frequently Asked Questions

What types of AI-enabled crime are most relevant to crypto firms right now?

The cross-industry consultation identified deepfakes used to defeat KYC video checks, synthetic identity documents, and illicit AI services that automate fraud patterns as the leading categories. Transaction-structuring tools designed to evade rule-based monitoring are also flagged as an emerging concern.

Does existing AML regulation already cover AI-enabled fraud in crypto?

Current AML frameworks, including FinCEN's Bank Secrecy Act rules and FATF Recommendation 15 on new technologies, impose a general obligation to identify and manage emerging risks. They do not yet prescribe AI-specific controls. However, supervisory expectations are evolving, and firms that proactively implement AI-crime controls will be better positioned when more specific guidance arrives.

How should an accounting firm treat on-chain records that may have been affected by AI-assisted identity fraud?

Where there is reason to believe that the identity underlying a transaction was established through a compromised KYC process, the reliability of that transaction as audit evidence is reduced. Firms should assess the adequacy of management's controls and, where those controls are insufficient, extend substantive procedures accordingly.

What is the connection between AI crime and stablecoin compliance?

If AI-assisted fraud enables a sanctioned party to establish a clean-looking wallet, stablecoin flows through that wallet carry undetected sanctions exposure. This is a compounding risk: the fraud defeats the identity check, and the sanctions screen then clears a wallet it should have flagged. Both layers of control need to be robust.

Where can firms find authoritative guidance on AI and AML in crypto?

FATF publishes guidance on virtual assets and virtual asset service providers, including provisions on new and emerging technologies. FinCEN issues advisories and typologies relevant to the US market. The Financial Stability Board and national supervisors such as the OCC also produce relevant risk assessments. These are the primary sources firms should monitor for developments in this area.

Source: Elliptic

USGLOBAL#stablecoinsGeneralAdoptedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
BDO 2026 Fintech Predictions: What Accounting Firms and CFOs Must Assess Now
AML/KYC & Licensing
Digital Asset Risk Management: What Changes and What Doesn't Under BSA and Global AML Regimes
AML/KYC & Licensing
OFAC Sanctions Tren de Aragua Crypto Laundering Network
AML/KYC & Licensing
OFAC Sanctions Eight Houthi Crypto Addresses: AML Implications for Firms