It is the one date in the current regulatory set that has not moved. The work it requires is data work, and data work is the slowest kind.

The change most often underestimated is not the content of the rules but the mechanism by which they take effect across member states.
Among the regulatory changes affecting financial services this year, the anti-money-laundering single rulebook is the one worth planning against, for a simple reason. Everything else has moved. This has not.
Regulation (EU) 2024/1624 applies from 10 July 2027. No deferral has been proposed. Set against the deferral of the AI Act Annex III obligations to December 2027 and the rescission of the United States model risk guidance in April, it is the only firm forward date in the current set.
What actually changes
The substantive rules on customer due diligence, beneficial ownership and reporting are, in outline, familiar. The mechanism is not.
Anti-money-laundering obligations in the European Union have until now arrived as directives, which each member state transposes into national law. Transposition permits variation, and variation is what most cross-border compliance functions were built to manage. A group operating in six member states could reasonably run six interpretations, and did.
A regulation applies directly. There is no transposition step and correspondingly little room for national divergence. For a group, that turns six managed interpretations into one required position, and the work of reconciling them lands before the date rather than after it.
Why this is a data problem
The policy work is the visible part and the smaller part. What consumes the time is the state of the underlying customer records.
Most institutions hold customer due diligence data collected under several different regimes over many years, in several systems, to several standards of completeness. A single set of rules applied across that estate surfaces every inconsistency at once: records collected to a lower standard, beneficial ownership captured in free text, verification evidence held in one jurisdiction and not another, refresh cycles that ran on different clocks.
None of that is a compliance failure under the regime it was collected under. All of it becomes visible when one standard is applied across the whole book.
The question worth asking now is not whether your policies will comply. It is how many of your existing customer records could be evidenced to the new standard without going back to the customer. That number determines the size of the remediation, and it takes weeks to establish rather than days.
The sequencing argument
There is a temptation to treat the deferred AI Act work and the AML deadline as competing for the same resource, and to let the closer nominal date win. That reads the calendar correctly and the workload wrong.
The AI Act obligations are largely evidentiary. They require logging, documentation and testing to begin, and they scale with how long you have been recording. Starting them is cheap and deferring them is expensive, but the starting cost is low.
AML remediation is the opposite. It is customer contact, document collection and data repair across an existing book, and it does not compress. A remediation programme that needs twelve months cannot be delivered in four regardless of resourcing, because part of it depends on customers responding.
So the two are not in competition. Begin the AI Act logging now because it costs little to start, and begin the AML data assessment now because the answer determines a programme you cannot shorten later.
What to establish in the next quarter
What proportion of live customer records could be evidenced to the new standard today, without contacting the customer.
Where beneficial ownership is held as structured data and where it is held as text.
Which member state interpretations your group currently relies on that will not survive a directly applicable regulation.
Who owns the remediation, and whether that person has a mandate over customer contact as well as over data.
What your refresh cycle looks like in the jurisdictions with the weakest historic collection standard.
None of those five questions requires a legal opinion. All five determine the size of the programme, and all five are answerable now.
Confirm the operative dates against the regulation itself rather than a summary, and check whether any article numbering has changed since publication. That advice applies to every instrument cited here, and it applies with particular force to a text that will be read directly rather than through a national transposition.
This is reporting on financial technology and operations. It is not investment, legal, accounting or tax advice.
References
Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.
European Union, Regulation (EU) 2024/1624 on the prevention of the use of the financial system for money laundering or terrorist financing, applying from 10 July 2027, 31 May 2024. https://eur-lex.europa.eu/eli/reg/2024/1624/oj
European Union, Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering, 31 May 2024. https://eur-lex.europa.eu/eli/reg/2024/1620/oj
European Union, Regulation (EU) 2026/1744, the Digital Omnibus on AI, for the deferral referenced in the sequencing section, in force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
Board of Governors of the Federal Reserve System, SR 26-2, superseding SR 11-7, for the comparison in the opening, 17 April 2026. https://www.federalreserve.gov/supervisionreg/srletters/srletters.htm
How we work. This article was researched and written by the Financy editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@financyhub.com and tell us what and why.
Filed under RegTech & Compliance · Get The Weekly Brief


