Expertise

Blog
EU Sanctions Are Moving Faster Than Screening: What Banks Need to Know in Q4 2026
A near-miss on the EU's asset-freeze renewal and a fast-moving sanctions rollout this autumn show why name screening alone no longer captures the full picture.
European Union (EU) sanctions no longer sit still long enough for name screening to keep up.
Behaviour-based surveillance – reading transaction, trade, and ownership patterns rather than matching names – can help institutions identify the evasion patterns a list alone misses.
With EU sanctions continuing to evolve this year, an underlying list nearly lapsing in September, and oversight shifting to a single new EU authority, banks that still screen on names alone risk missing how sanctions exposure develops beyond the list itself.
Why Sanctions List Screening Alone Is No Longer Enough
In September 2026, the EU's Russia asset-freeze regime came within days of lapsing. Slovakia had demanded the removal of two Russian-linked businessmen as the price of its support for the routine six-monthly renewal, which needs unanimous approval from all 27 Member States [1]. Member States bought a one-week extension to keep negotiating.
Days later, Commission President Ursula von der Leyen told Parliament that pressure on Russia "does not always require new sanctions, but above all the enforcement of existing ones," with no timeline given for the next sanctions package.
The rest of the year has been just as fluid. July's 21st sanctions package – the largest round of EU listings in four years, adding 218 individuals and entities – extended the transaction ban to 33 additional Russian credit and financial institutions and 14 crypto-related service platforms, alongside measures targeting energy, trade, and circumvention [2].
Separately, a Financial Times investigation reported this August that directors at a privately owned Russian bank’s Luxembourg arm used personal loans to buy discounted bonds and swap them for full-value rouble replacements – a circumvention route built from ordinary banking mechanics, with no sanctioned counterparty involved [3].
None of this changes what a name screen does. It changes how much an institution has to track, how quickly it has to respond, and how much additional context it needs to understand the risk behind a match.
What Does Behaviour-Based Surveillance Actually Look For?
EU sanctions increasingly target sectors, activities, and ownership structures rather than only named individuals.
The EU's own ownership and control test requires institutions to look past formal shareholding percentages to de facto influence – which means a transaction may involve no direct listed-party match and still create exposure under a sectoral or facilitation rule.
Behaviour-based surveillance looks for the patterns that may indicate this kind of structural exposure:
Rapid growth in trade with specific third countries right after new restrictions take effect
Entities with little operating history repeatedly involved in high-risk commodity flows
A mismatch between a customer's declared business and the goods or funds actually financed
Circular ownership or control concentrated among a small group of individuals
Payment corridors that bypass normal trade routes without clear commercial reason
No single signal proves evasion. Russia's shadow LNG fleet, reportedly expanded to around 25 vessels this summer ahead of the EU's 2027 LNG import ban [3], is a reminder that evasion capacity can build quietly ahead of a restriction – which is exactly why these signals need to be assessed together, not treated individually.
The challenge is therefore not simply generating more alerts. It is connecting these signals with customer, transaction, ownership, and external risk context quickly enough to determine whether they form a meaningful pattern.
How Is EU Supervision Changing?
The EU's Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt, took over the European Banking Authority's AML/CFT mandates on 1 January 2026 and published its first multiannual work programme the following month [4].
Its remit also extends directly to sanctions implementation: as a direct supervisor, AMLA will check compliance with sanctions-related measures among the highest-risk cross-border financial groups and contribute to a common EU supervisory approach to sanctions compliance.
Direct supervision of up to 40 of some of the most complex, high-risk financial institutions or groups begins in 2028, with the first selection set to take place in 2027.
This raises the bar for governance and explainability. Any behavioural model deployed now needs to show its reasoning in terms a supervisor can test: which data informed a decision, how thresholds were set, and where a human reviewed or overrode the outcome.
For sanctions teams, expanding detection beyond names cannot come at the expense of defensibility. Broader behavioural insight needs to be accompanied by a clear record of what was identified, why it mattered and how the institution responded.
Where Agentic AI Fits
Agentic AI offers a way to make this broader, behaviour-aware approach operational at scale.
Rather than scoring a transaction once against a fixed rule, an AI Agent can investigate an alert the way an analyst would – pulling ownership data, trade history, and enforcement records together, then assessing that evidence against defined risk indicators and producing a documented rationale for human review.
Where conventional analytics can identify that something looks unusual, an AI Agent can bring the surrounding evidence together, investigate why it looks unusual, and document how that context informed the resulting decision.
Silent Eight's Iris 7 AI Agents work this way across customer and payment screening, applying institutional policy consistently while maintaining an auditable record of the evidence and reasoning behind each decision.
What Comes Next for EU Sanctions Compliance
No date has been set for a 22nd sanctions package, though EU foreign ministers have signalled support for one.
Early reporting points to further shadow fleet enablers, more crypto platforms facing scrutiny, and closer attention to third-country banks and companies shown to facilitate circumvention [5].
However, none of this is confirmed, and September's near-miss is a reminder that unanimity among 27 Member States isn't guaranteed even for measures already in force.
That unpredictability is itself the case for behaviour-based surveillance. Institutions that only react once a name lands on a list will always be a step behind a process that is, by this year's own record, uneven in timing and increasingly complex in implementation.
List screening remains fundamental. But the lesson from this year's EU sanctions activity is that the risk institutions need to identify increasingly extends beyond the list itself.
Behaviour-based surveillance complements established screening by adding the context needed to identify how sanctions exposure is developing across transactions, ownership structures, counterparties, and corridors – before every risk is reduced to a name on a list.
A control framework built around that reality needs to look for the pattern, not wait for the paperwork.
Silent Eight's Iris 7 AI Agents for financial crime compliance help institutions put these principles into practice.
Across customer and payment screening, AI Agents investigate sanctions alerts using wider context, apply institutional policy consistently, and produce explainable, auditable decisions – helping teams look beyond isolated list matches while keeping human expertise focused on genuine risk.
Share article









