Back to Articles
Thought Leadership6 min read

The $5bn RegTech Market Was Built for the Wrong Regulator

The Global State of RegTech 2026 report shows $5bn raised in 2025, with 63% going to US companies. This article argues that EU compliance teams are selecting from a vendor landscape optimized for US regulatory architecture, and that the evidence standard AMLR requires is architecturally different from what most platforms were built to produce.

Fredrik Gröndahl
The $5bn RegTech Market Was Built for the Wrong Regulator

The numbers in last week's Global State of RegTech 2026 report are genuinely large. $5bn raised by RegTech companies in 2025, spread across 1,300-plus vendors offering over 4,000 products. The investment into the sector in the first half of 2026 alone, combining Q1's roughly $3bn and Q2's $2bn-plus, suggests a level of capital confidence that has not slowed since AMLR passed.

The problem is where that capital is going. For a fund administrator or TCSP in Luxembourg preparing for AMLR's July 2027 application date, the geography of RegTech investment is not a background fact. It is a procurement risk.

The Report Behind the Number

On August 5, 2026, RegTech Analyst and Parker & Lawrence Research published The Global State of RegTech 2026, their annual assessment of the sector's funding, vendor landscape, and adoption dynamics.

The headline number is $5bn raised in 2025. The more relevant figure sits a few lines deeper: $3.17bn of that total, 63%, went to US-based companies. The second-largest market was Israel, at $566m. The UK came in third at $412m. France and Portugal combined for $225m. Italy accounted for $200m. Luxembourg-headquartered RegTech companies are not individually cited.

This is not primarily a story about European ambition. It reflects where regulatory pressure has been most commercially legible: the US BSA/FinCEN framework has driven demand for specific compliance capabilities at scale for decades, and capital followed that demand. The question is whether the platforms that capital funded are the right architecture for what AMLA is about to require.

The US Framework and AMLR Produce Different Evidence

Every compliance platform has an architecture shaped by the regulatory context it was built to satisfy. For US-originating RegTechs, that context is the Bank Secrecy Act and FinCEN's Customer Identification Program requirements. CIP demands that institutions verify customer identity at account opening: name, address, date of birth, identification number. The evidence is a captured record at a single moment in time.

AMLA's CDD standards under the AMLR, as articulated in the draft RTS under Article 28 published for consultation in April 2026, demand something structurally different. They require not just identity verification at onboarding but continuous, evidence-generating processes across the full customer lifecycle. The risk assessment must be updated when risk-relevant information changes. The documentation must support a supervisor's ability to reconstruct the rationale for any risk classification at any point in the relationship.

A platform built to satisfy CIP produces a record of what you knew at onboarding. A platform built for AMLR must produce a record of what you knew, when you knew it, why it triggered or did not trigger a risk reassessment, and what the decision chain looked like. These are different data architectures, not different UIs sitting on the same underlying logic.

Quantifind, one of the larger recipients of recent RegTech capital at $200m in June 2026, specifically serves financial crime AI and risk intelligence, with plans to expand into Europe. The question for a Luxembourg fund administrator evaluating such a platform is not whether it is sophisticated. The question is whether the evidence it generates maps onto the examination criteria CSSF will apply under AMLR.

The 4,000-Product Landscape Is Not Neutral

The Global State of RegTech 2026 report notes that while consolidation has been the sector's defining trend in recent years, the vendor landscape is now fragmenting again, driven by AI-first entrants that look very different from established players. Early-stage deals represented the largest volume in 2025: 145 deals raising $1.85bn, versus 17 private equity deals raising $1.1bn. General Catalyst was the most active large-ticket investor, deploying $751m across four deals.

For a compliance buyer in Luxembourg or Mauritius, this fragmentation creates a specific selection problem. Established platform players have built connectors to data sources, workflows for screening exceptions, and audit trail outputs that map onto known supervisor expectations. Most of those expectations are US, UK, or broadly financial-crime oriented. Few are calibrated to Luxembourg CSSF circular structures, FSC risk-based approach guidelines, or AMLR group-wide policy requirements under Article 16.

The AI-first point solutions entering the market compete on detection accuracy, processing speed, and reduced false positives. Those are legitimate value propositions. They do not address the question a CSSF examiner will ask in 2028: show me the documentation trail for this beneficial ownership classification and the risk weighting applied to this client.

Where Q2 2026 Money Actually Went

Looking at the Q2 2026 investment data, the dominant theme is AI security and real-time threat detection. Cyera's $600m round, Quantifind's $200m, Behavox's $175m. Behavox directly serves AML monitoring for banks and asset managers, and its recent investment is tied to international expansion including Europe.

These are capable platforms. They are also built around a model of financial crime compliance that prioritizes catching bad actors through pattern recognition. That is a necessary function. It is not the same as producing the structured evidence trail that AMLA's ongoing monitoring guidelines, currently in consultation with a September 3 closing date, require for every business relationship under the AMLR.

The compliance problem for a TCSP is not primarily whether it catches the suspicious transaction. It is whether it can document, for every client in its portfolio, that the risk-based approach was applied consistently, that the documentation supports the risk classification, and that when the classification changed, the change is traceable. Pattern detection solves one problem. Evidence architecture solves a different one.

What This Means for Management Companies, TCSPs, and Fund Administrators

A management company or fund administrator evaluating compliance platforms in the second half of 2026 needs to ask a specific question: is this platform's evidence output designed for the regulatory framework I am subject to, or for the regulatory framework where the capital behind this product originally came from?

The test is operational. Ask the vendor for a sample audit trail output for a CDD review triggered by a beneficial ownership change. Ask where in that output the risk reassessment rationale is documented, how it maps to specific AMLR articles, and what a CSSF examiner or FSC examiner would find. If the vendor has never answered that question for a Luxembourg or Mauritius context, the platform architecture was not built for that context.

This does not mean US-originating platforms are unsuitable. It means the compatibility question requires an explicit answer, not a vendor-supplied assumption that compliance is compliance regardless of jurisdiction.

The Position

The RegTech market raised $5bn in 2025 and is on track for a comparable total in 2026. Most of that capital is solving real problems. The problems being solved are not always the ones AMLR's compliance evidence standard is going to test.

A compliance platform is an evidence-production system with a risk detection layer on top. When the regulator that matters to you operates a different evidence standard from the one that shaped the platform's architecture, the gap between what the platform produces and what the examination requires is an operational risk, not a configuration setting.

EU obliged entities have twelve months before AMLR applies. That is long enough to ask the right vendor questions. It is not long enough to discover at the point of examination that the platform was built for the wrong framework.

If you want to understand how Fidify's evidence architecture is designed specifically for AMLR and CSSF compliance requirements, we can walk you through it.