{"id":8093,"date":"2026-07-31T20:41:10","date_gmt":"2026-07-31T20:41:10","guid":{"rendered":"https:\/\/fintech.global\/globalregtechsummit\/?p=8093"},"modified":"2026-07-31T20:41:12","modified_gmt":"2026-07-31T20:41:12","slug":"can-regulation-become-machine-readable","status":"publish","type":"post","link":"https:\/\/fintech.global\/globalregtechsummit\/can-regulation-become-machine-readable\/","title":{"rendered":"Can regulation become machine-readable?"},"content":{"rendered":"<p><strong>Regulation has always been written for humans. Lawyers interpret it, compliance teams translate it into policies and controls, and firms spend months implementing new requirements. But as financial services become increasingly digital, that process is starting to look slow, expensive and increasingly out of step with the systems it is designed to govern.<\/strong><strong>&nbsp;<\/strong><\/p><p>This has given rise to an ambitious idea: what if regulation could be published in a format that computers could understand as well as people? Instead of firms manually interpreting every rule change, compliance systems could consume regulatory requirements directly, helping organisations respond faster and more consistently as rules evolve.<\/p><p><strong>What machine-readable regulation looks like<\/strong><\/p><p>What would truly machine-readable regulation look like in practice? According to Scott Nice of&nbsp;<a href=\"https:\/\/labeltech.io\/\">Label<\/a>, truly machine-readable regulation would mean regulation being published and maintained in a format that technology can interpret, map and operationalise more easily.<\/p><p>He explained, \u201cIt would not simply be a PDF on a regulator\u2019s website that firms then manually translate into policies, controls and procedures. It would involve obligations being structured, tagged and connected to relevant data points, reporting requirements, control expectations and implementation logic.\u201d<\/p><p>In practice, Nice said this could allow a firm to identify which obligations apply to it, understand what data is required, map those obligations to internal controls and assess the operational impact of regulatory change much faster than it can today.<\/p><p>\u201cIt would also create a clearer line of sight between regulation, policy, controls, workflows and evidence, which is often missing in current compliance operating models,\u201d Nice said.<\/p><p>Despite this, he stressed that machine readable regulation should not be confused with regulation with requires no interpretation.<\/p><p>He said, \u201cMuch of regulation is contextual. It depends on the firm, product, customer, jurisdiction, risk profile and supervisory expectation. The real value would be in making compliance architecture more connected, not in pretending that every regulatory obligation can be reduced to binary logic.\u201d<\/p><p>Meanwhile, Areg Nzsdejan, CEO of&nbsp;<a href=\"https:\/\/cardamon.ai\/\">Cardamon<\/a>, stated that in practice, machine-readable regulation would not look like what most people mean when they say it.<\/p><p>He said, \u201cDigitised PDFs or API-delivered updates are a start \u2013 not machine-readable in any meaningful sense. Truly machine-readable means structured, versioned obligations: regulatory text decomposed into discrete components with explicit scope, conditions, and a clear link to what a firm must do and how it demonstrates compliance \u2013 essentially, a data model.<\/p><p>\u201cAt Cardamon, we already do this extraction and structuring work ourselves. In a world of genuinely machine-readable regulation, regulators would do it once, upstream, for everyone.\u201d<\/p><p>Meanwhile, Michael Thirer, CLO at&nbsp;<a href=\"https:\/\/muinmos.com\/\">Muinmos<\/a>, was clear in his view that truly machine-readable regulation in practice would look like the Muinmos platform.<\/p><p>He explained, \u201cAcademics and legislative bodies have debated for years the possibility of making regulation machine-readable. While they were debating, two things happened:Machines learnt how to read, and RegTechs like Muinmos stepped in and turned regulation into actionable applications. At Muinmos, this is literally what we do every day \u2013 turn legal code into computer code.\u201d<\/p><p>This is why Thirer said, that in its purest form, truly machine-readable regulation in practice would look like the application executing it.<\/p><p>\u201cBecause truly machine-readable regulation is machine-executable. As machines execute instantly, in the machine world, there is hardly a difference between the code and its execution. They are basically the same,\u201d he said.<\/p><p><strong>The regulatory balancing act<\/strong><\/p><p>Can regulatory obligations be translated into executable rules without losing context or judgment?<\/p><p>Not every regulatory obligation can be reduced to code without sacrificing the judgement that underpins effective compliance, according to Nice.<\/p><p>He argues that many rules are well suited to automation. \u201cRequirements such as data fields, filing deadlines, validation rules, thresholds, formats and specific reporting obligations can often be encoded with a high degree of confidence,\u201d he says, adding that doing so can improve consistency while reducing manual errors.<\/p><p>The challenge lies elsewhere. Much of financial regulation depends on interpretation rather than certainty, requiring firms to assess what is reasonable, proportionate or credible in a given context. Financial crime controls, KYC risk assessments, beneficial ownership analysis and tax transparency obligations, for example, often hinge on professional judgement rather than binary decisions.<\/p><p>\u201cThese are not always simple yes-or-no questions,\u201d Nice says. \u201cFirms still need to determine whether information is credible, whether a classification makes sense, whether a structure is reasonable or whether a change in behaviour is significant.\u201d<\/p><p>He points to regimes such as FATCA, CRS and CARF as examples of where technology can shoulder much of the operational burden without replacing human accountability. Automated systems can validate data, support workflows, perform reasonableness checks and maintain evidence trails, but they do not remove the firm\u2019s responsibility for the final compliance decision.<\/p><p>\u201cFor CRS and CARF, technology can help check whether a customer\u2019s self-classification appears reasonable based on the information available,\u201d Nice explains. \u201cBut the customer self-classifies and the firm governs the process around that. That is very different from saying the system makes the entire judgment on its own.\u201d<\/p><p>The answer on this for Nzsdejan is partially. He states that reporting thresholds, deadlines, capital requirements \u2013 these translate cleanly. If condition A, action B by date C, he gives as an example.<\/p><p>\u201cThe harder part is the language regulators use deliberately: \u201creasonable steps\u201d, \u201cproportionate\u201d, \u201cmaterial risk\u201d. This isn\u2019t imprecise by accident. Replace that judgment with a checklist and you create an illusion of compliance \u2013 firms tick boxes without managing the underlying risk.\u201d<\/p><p>For the Cardamon CEO, the right design target is machine-readable regulation that surfaces context rather than eliminates it.<\/p><p>Whilst Nzsdejan only partially agrees, Thirer fully is on board with this argument. He said that the greatest challenge may be regulations which seem to be intentionally written in obscure \u201chuman\u201d terms.<\/p><p>He explained, \u201cIn many key jurisdictions, regulation has become \u201coutcome-focused\u201d (like the UK Consumer Duty), and does not prescribe specific steps, but outlines general expectations. It is drafted in what can be called, in this context, \u201chuman\u201d terms \u2013 like \u201cacting in good faith\u201d, \u201cenabling and supporting customers\u201d, \u201ccare\u201d etc.<\/p><p>Thirer states that, ironically, machines may actually be able to help humans comply even better \u2013 because they can help humans identify the required standard of care etc.<\/p><p>\u201cIn this case, it will be of course humans which will set the initial parameters, guardrails etc., and will also supervise the outcomes; but the machines will actually perform the bulk of the individual tasks,\u201d he said.<\/p><p><strong>Can machine-readable regulation improve outcomes<\/strong><\/p><p>Would machine-readable regulation improve compliance outcomes or create new risks?<\/p><p>Machine-readable regulation has the potential to strengthen compliance, but only if firms resist the temptation to treat automation as a replacement for judgement, said Nice.<\/p><p>He believes structured, machine-readable rules could make regulatory obligations clearer, more consistent and easier to implement. \u201cIt could reduce the friction between regulatory change and implementation,\u201d he says, helping firms understand what has changed, which controls are affected, what data is required and where action is needed.<\/p><p>Beyond implementation, Nice sees significant benefits for governance and auditability. By creating a clear line between regulatory requirements, internal policies, operational controls and compliance outcomes, firms can build a stronger evidential foundation for their compliance programmes.<\/p><p>\u201cIf firms can show a clear link between a regulatory obligation, the internal policy position, the control, the workflow, the data used and the outcome produced, compliance becomes more transparent and defensible,\u201d he explains. \u201cThat is where machine-readable regulation could be powerful.\u201d<\/p><p>However, he warns that the same technology could introduce new risks if organisations become overly reliant on it. Executable rules are only as effective as the logic behind them, and where that logic is outdated, incomplete or too narrowly interpreted, firms risk automating flawed decisions at scale.<\/p><p>\u201cSo I am positive about the direction, but cautious about the framing,\u201d Nice says. \u201cMachine-readable regulation should make compliance more structured and evidence-led; it should not remove accountability from the process.\u201d<\/p><p>Thirer believes that the very exercise of reviewing regulation and trying to see it from a new angle and perhaps more action-oriented will improve the quality of the regulation itself, and hence the quality of compliance.<\/p><p>He commented, \u201cI\u2019m not worried about the introduction of machines \u2013 machines are usually more predictable than humans, and are easier to instruct and supervise at scale.\u201d<\/p><p>In the view of Nzsdejan, the answer is both. The upside, he said, is material \u2013 consistent interpretation, lower cost of regulatory change, less arbitrage through selective reading.<\/p><p>He said, \u201cAt Cardamon, structuring obligations consistently across jurisdictions already transforms what clients can see \u2013 comparing their UK, EU, and Singapore footprint from one data model rather than three parallel manual analyses.\u201d<\/p><p>Despite this, the risks are also real. He suggests gaming, as precise rules are more exploitable than ambiguous ones. Brittleness is also one, as coded rules can\u2019t absorb novel circumstances the way text can \u2013 and in financial crime, the most dangerous activity often looks superficially compliant. Over-reliance is also key, as teams that treat machine-readable regulation as the complete picture stop applying the judgment that novel risks require.<\/p><p>He concludes, \u201cThe answer goes beyond automation \u2013 it is automation that creates space for better judgment.\u201d<\/p><p><strong>Removing unnecessary ambiguity<\/strong><\/p><p>The ambition behind machine-executable regulation is not to eliminate human judgement, but to remove unnecessary ambiguity, according to Ermanno Ciarrocchi, chief growth officer at&nbsp;<a href=\"https:\/\/cleverchain.ai\/\">CleverChain<\/a>.<\/p><p>He points to the concept of Model-Driven, Machine-Executable Regulation (MDMER), first outlined by the FCA and Bank of England a decade ago, as a vision for expressing regulatory requirements as logical models that systems can execute directly. \u201cThe goal,\u201d he says, \u201cwas removing ambiguity, not judgement.\u201d<\/p><p>Ciarrocchi believes large language models have significantly lowered the cost of translating natural-language regulation into structured logic, while major regulatory frameworks such as DORA, the EU AI Act and the AMLR are increasing demand for more scalable approaches to compliance.<\/p><p>Even so, he stresses that practical adoption has remained limited to areas where obligations are objective and easily codified. \u201cLive applications making the obligation behind the text executable have remained only within calculable, rules-light domains such as reporting fields, tax thresholds and eligibility conditions,\u201d he says.<\/p><p>The reason, he argues, is that much of financial regulation is intentionally built around principles rather than rigid rules. Whether due diligence has been adequate or a risk rating is defensible often depends on professional judgement, making those obligations inherently resistant to full automation.<\/p><p>\u201cWe would treat the principles- and risk-based character of much financial regulation not as a hurdle to be overcome, but as the natural border of the domain,\u201d Ciarrocchi explains. \u201cWhere a rule turns on whether due diligence was adequate, or a risk rating defensible, the regime is delegating judgement deliberately.\u201d<\/p><p>Rather than attempting to replace that judgement, he believes technology should make it more transparent. \u201cThe useful role for technology is not to remove judgement but to make it traceable,\u201d he says, adding that he favours \u201can interpretation that is explicit and auditable over one hard-coded by a vendor or mutualised into a single shared answer.\u201d<\/p><p>Ciarrocchi also highlights what he sees as an underappreciated danger: \u201cfalse precision\u201d. \u201cAutomation can lend an output the appearance of authority,\u201d he says, \u201cyet the judgement underneath may have been open to challenge all along.\u201d<\/p><p>Looking ahead, he believes the commercial opportunity in machine-readable regulation will lie less in the underlying infrastructure and more in the layer built on top of it. Pointing to initiatives such as the ISDA Digital Regulatory Reporting framework, which is freely available to firms, he argues that the foundational \u201crails\u201d are increasingly becoming a public good.<\/p><p>\u201cThat is why we believe the next phase of RegTech will be decided less by who can execute a rule, and more by who can defend the judgement around it,\u201d he concludes.<\/p><p><strong>Transformative potential<\/strong><\/p><p>Machine-readable regulation has the potential to transform anti-money laundering compliance, but only if firms first address the quality and governance of the data underpinning their systems, according to&nbsp;<a href=\"https:\/\/relycomply.com\/\">RelyComply<\/a>.<\/p><p>The company says the growing interest in machine-readable regulation reflects a broader shift towards AI-enabled compliance, where standardised, structured rules can replace much of the ambiguity associated with interpreting legal text.<\/p><p>\u201cThe appetite for machine-readable regulation is highly understandable,\u201d it says. \u201cWe live in an age where AI development is gaining pace to better AML operations, replacing the subjective legal jargon that once dominated compliance with standardised code to lower any ambiguity.\u201d<\/p><p>RelyComply points to the EU\u2019s Anti-Money Laundering Regulation (AMLR) as an example of the direction regulators are taking, arguing that more structured regulatory requirements could help create consistent compliance processes across Member States. Greater standardisation would improve firms\u2019 ability to trace ownership structures, analyse cross-border transactions and demonstrate how key AML decisions were reached.<\/p><p>\u201cWhen data trails are detailed, in the correct format, they enable regulated financial institutions to maintain oversight for the end-to-end onboarding, monitoring and reporting capabilities required of them,\u201d the company explains. Better-structured data would also make information easier to share with financial intelligence units, helping create a faster and more coordinated approach to financial crime detection.<\/p><p>However, RelyComply argues that technology alone cannot overcome weak data foundations. \u201cThis disparity of data governance and quality will continue to halt any path to machine-readable regulation,\u201d it warns. Incomplete or inaccurate data can undermine identity verification, flood AML systems with false positives and ultimately obscure genuine indicators of financial crime.<\/p><p>The challenge becomes even greater when viewed across the wider financial ecosystem. Banks, fintechs, payment service providers, supervisors and law enforcement agencies all rely on data that must be accurate, interoperable and consistently governed. Without that foundation, RelyComply argues, coordinated, data-led financial crime prevention remains out of reach, while organised criminal networks continue to exploit fragmented systems at scale.<\/p><p>For that reason, the company believes machine-readable regulation should be built around human oversight rather than human replacement. \u201cThe answer lies in a human-led approach to managing automated AML systems,\u201d it says. Even the most sophisticated AI models depend on high-quality data, effective governance and clearly defined risk policies to produce reliable outcomes.<\/p><p>RelyComply argues that the success of machine-readable regulation will depend as much on data quality as technology. \u201cCreating a landscape for machine-readable regulation relies on foolproof data and systems that are already flexible to changing risk profiles and criminal typologies,\u201d it concludes, making compliance \u201csimpler, and more effective as deterrents of serious crime.\u201d<\/p><p><a href=\"https:\/\/regtechanalyst.com\/\">Read the daily RegTech news<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Regulation has always been written for humans. Lawyers interpret it, compliance teams translate it into policies and controls, and firms spend months implementing new requirements. But as financial services become increasingly digital, that process is starting to look slow, expensive [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":8095,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[],"class_list":["post-8093","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/posts\/8093","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/comments?post=8093"}],"version-history":[{"count":1,"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/posts\/8093\/revisions"}],"predecessor-version":[{"id":8096,"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/posts\/8093\/revisions\/8096"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/media\/8095"}],"wp:attachment":[{"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/media?parent=8093"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/categories?post=8093"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fintech.global\/globalregtechsummit\/wp-json\/wp\/v2\/tags?post=8093"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}