Do AI-based anti-money laundering (AML) systems violate European fundamental rights?
Notice bibliographique
Résumé
Machine-learning algorithms are increasingly used to predict different forms of criminal behaviour.1 It is therefore natural that such algorithms should be used in transaction monitoring by financial institutions to comply with laws on anti-money laundering and countering financing of terrorism (AML/CFT). The EU’s Fourth AML Directive2 requires banks and other financial institutions to conduct ‘ongoing monitoring of the business relationship including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions being conducted are consistent with the obliged entity's knowledge of the customer, the business and risk profile, including where necessary the source of funds’.3 Monitoring must be sufficient to ‘enable the detection of unusual or suspicious transactions’.4 Most IT systems used for AML/CFT transaction monitoring already include complex rules-based algorithms.5 Regulators and financial institutions are currently studying the introduction of more opaque machine learning (ML) algorithms to supplement the existing rules-based systems. The introduction of ML algorithms in transaction monitoring could permit detection of new criminal activities, but also brings to the forefront data protection risks that so far have been only partially studied.6 A series of recent cases dealing with the collection and processing of personal data for the purpose of combatting crime and terrorism sheds new light on the compatibility of AML/CFT transaction monitoring with the General Data Protection Regulation (GDPR) and the EU Charter of Fundamental Rights (Charter).7 In particular, the Court of Justice of the European Union’s (CJEU) Digital Rights Ireland,8 Tele2 Sverige – Watson,9 Canadian PNR Agreement,10 and Quadrature du Net11 cases raise serious questions regarding the compatibility of current AML/CFT transaction monitoring systems (TMSs) and regulations with the GDPR and the Charter, leading us to the conclusion that current AML/CFT laws imposing transaction monitoring and reporting of suspicious transactions need to be substantially modified, particularly if new ML tools are to be introduced. In this article, we identify the shortfalls of the current legal framework but also make suggestions on how it can be improved in order to facilitate the introduction of ML algorithms while also improving compatibility with fundamental rights. Some of our recommendations for improvement are consistent with those already made in 2011 by the Article 29 Working Party12 and in 2020 by the European Data Protection Supervisor,13 although ours go into considerably more detail, drawing on solutions that have been developed in the field of intelligence gathering and cybersecurity.
Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.
Comment cette classification a été obtenuedéplier
Prédiction machine sur la base complète
Imitation des enseignantsNi prévalence calibrée, ni vérité terrain. Validation humaine à venir. Le volet Gemma est une étiquette directe du modèle pour chaque travail de la base, lue sur la notice réduite au titre. Le volet Codex est un classifieur appris des 10 348 étiquettes directes de Codex et calibré sur les taux pondérés de l'échantillon; les champs sans appui suffisant ne portent aucun appel Codex. Le mode candidate est l'union des deux volets; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont pas des étiquettes humaines.
Scores du classifieur distillé par catégorie (deux têtes)
| Catégorie | Codex | Gemma |
|---|---|---|
| Métarecherche | 0,039 | 0,100 |
| Méta-épidémiologie (sens strict) | 0,000 | 0,000 |
| Méta-épidémiologie (sens large) | 0,001 | 0,001 |
| Bibliométrie | 0,002 | 0,002 |
| Études des sciences et des technologies | 0,005 | 0,013 |
| Communication savante | 0,016 | 0,015 |
| Science ouverte | 0,004 | 0,005 |
| Intégrité de la recherche | 0,014 | 0,008 |
| Charge utile insuffisante (le modèle a refusé de juger) | 0,011 | 0,002 |
Scores machine (provisoires)
Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.
Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.
score_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découleClassification
machine, non validéePrédiction automatique; un appel candidat d’une seule source (Gemma direct ou Codex distillé), pas un consensus.
Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».