Can AI write SAR narratives FinCEN will accept? What US, UK and EU regulators say about AI in BSA reporting, and how AI SAR drafting grounds every claim.
Table of contents
Key highlights
- Financial institutions filed about 4.7 million Suspicious Activity Reports in fiscal year 2024, so the narrative-writing workload behind BSA reporting is enormous and growing harder to staff.
- AI SAR drafting uses reasoning models to produce the narrative, key facts, and typology classification of a report from underlying case data. The model drafts and cites; a human attests and files.
- US authorities have signalled openness, not a rulebook. Treasury's June 2024 Request for Information on AI and its 2024 National Illicit Finance Strategy both frame AI as having significant potential to strengthen AML and CFT compliance, while expecting it to be governed.
- A defensible SAR narrative answers who, what, when, where, why, and how, names the typology, and cites the source systems. That structure is exactly what a grounded reasoning agent can produce.
- First-generation auto-SAR tools failed because they hallucinated counterparties and could not cite a claim back to its alert source. Grounding through retrieval over the case file with per-claim citation is the fix.
- The signature stays human. In the US the institution and its BSA officer remain accountable, and in the UK the nominated officer files to the NCA, so the durable pattern is agent-drafted, human-attested.
AI SAR drafting is the use of large reasoning models to produce the narrative, key facts, and typology classification of a Suspicious Activity Report from underlying case data. The model assembles and cites the evidence; a human reviews, attests, and files, because accountability for the report remains with the institution and its nominated officer, not the model.
TL;DR
AI SAR drafting is the use of large reasoning models to produce the narrative, key facts, and typology classification of a Suspicious Activity Report from underlying case data. With about 4.7 million SARs filed in the US in fiscal year 2024, the narrative workload is one of the heaviest manual burdens in compliance, and it is exactly the kind of structured-writing task a grounded reasoning model does well.
The regulatory position in 2026 is openness with conditions, not a green light. US authorities have framed AI as a tool with significant potential to strengthen AML and CFT compliance, while expecting model governance and human accountability. The narrative still has to be defensible: who, what, when, where, why, and how, named typologies, and citations to source systems. The failure mode to avoid is the first-generation auto-SAR tool that hallucinated counterparties and cited nothing. The fix is grounding: retrieval over the case file, a citation behind every claim, and a human who attests and files.
12 min read. Last updated 1 July 2026.
What is AI SAR drafting?
AI SAR drafting is the use of a reasoning model to turn a worked case into the written report a regulator reads. Given the alert, the investigation file, the transactions, and the customer record, the model produces the narrative, extracts the key facts, and classifies the typology, in the structure the filing form expects. It does not decide whether to file, and it does not sign. It drafts, and it cites.
This sits at the end of the AI compliance agents workflow, downstream of L1 alert triage and case completion. By the time a case reaches SAR drafting, the evidence has been assembled, and the task is to render it into a defensible narrative quickly and consistently, which is where human teams lose the most hours and where quality varies most between analysts.
What have US authorities actually said about AI in BSA programs?
It is important to be precise here, because the regulatory record is often misquoted. There is no FinCEN rule that authorises or prohibits AI-drafted SAR narratives in those words. What exists is a clear direction of travel.
In June 2024, the US Treasury issued a Request for Information on the uses, opportunities, and risks of artificial intelligence in financial services, drawing more than 100 comment letters and a follow-up report. In its 2024 National Strategy for Combatting Terrorist and Other Illicit Financing, Treasury stated that innovations in AI, including machine learning and large language models such as generative AI, have significant potential to strengthen AML and CFT compliance by helping institutions analyse large volumes of data and identify illicit-finance patterns. FinCEN has separately engaged the industry on AI through its BSA Advisory Group subcommittees and a FinCEN Exchange on AI in monitoring. The consistent message is encouragement paired with an expectation of governance and accountability, not a blanket authorisation. So the right reading for 2026 is that AI-assisted drafting is permissible where it is governed as a model and a human remains accountable, which is the same posture set out in the AI compliance agents pillar.
What makes a SAR narrative defensible?
A SAR narrative is defensible when it tells a complete, evidenced story. FinCEN guidance has long held that the narrative should answer who, what, when, where, why, and how: who is conducting the activity, what instruments and amounts are involved, when and where it occurred, why it is suspicious, and how the mechanism worked. On top of that, a strong narrative names the specific typology, structuring, layering, trade-based laundering, and ties each material fact to the source system it came from.
That structure is precisely what a grounded reasoning model can produce consistently. Here is a redacted human draft beside an agent draft of the same case.
Human draft: "Customer made several large cash deposits over two weeks that appear structured to avoid reporting thresholds, followed by wires to a high-risk jurisdiction."
Agent draft: "Between 2026-05-03 and 2026-05-16, customer ref 4471 made 9 cash deposits of $9,200 to $9,700 (source: ledger entries 5567-5575), each below the $10,000 CTR threshold, consistent with structuring. On 2026-05-17 the aggregated balance was wired to a beneficiary in a FATF-listed high-risk jurisdiction (source: wire 8841). Typology: structuring followed by layering."
The agent draft is not more eloquent. It is more defensible, because every claim carries a citation a reviewer can verify.
Why did first-generation auto-SAR tools fail?
The first wave of automated SAR tools earned a bad reputation for two reasons. They hallucinated, inventing counterparties, amounts, or dates that were not in the case file, because they generated fluent text without being anchored to the underlying records. And they could not cite, so a reviewer had no way to check a claim short of rebuilding the case by hand, which defeated the time saving and introduced filing risk.
A SAR with a fabricated detail is worse than a slow SAR. It exposes the institution to a false filing and to an examiner's finding that the control cannot be trusted. That is why fluency was never the goal and grounding always was. The lesson carried into 2026 is that a SAR-drafting tool must be evaluated on whether it can prove every statement, not on how natural it reads.
How does a reasoning agent ground the narrative?
Grounding is the engineering that separates usable AI SAR drafting from a liability. A grounded SAR agent works in three moves.
It retrieves over the case file, pulling the specific transactions, records, and alert details rather than relying on its training, so the narrative is built from your data. It cites per claim, attaching each statement in the narrative to the source record and identifier behind it, so the draft is checkable line by line. And it defers the decision, producing a draft and its evidence for a human to review, amend, and attest, never filing on its own.
Underneath, the quality of the narrative depends on the quality of the underlying identity and ownership data. Ownership resolution that traces control through multiple tiers, as covered in UBO mapping with AI, is what lets the narrative name the real parties rather than a shell. And keeping that data on an architecture that is not a single breachable store, as we discuss in why your KYC vendor is your biggest data breach risk, is part of governing the data the model reasons over.
How do the rules differ across the US, UK, EU and Singapore?
SAR and STR regimes share a logic but differ in mechanics, and an agent has to respect each.
In the United States, institutions file SARs to FinCEN, and the institution and its designated BSA officer carry accountability for the filing. In the United Kingdom, suspicious activity reports go to the National Crime Agency under the Proceeds of Crime Act 2002, the nominated officer submits them, and the tipping-off provisions mean you must not disclose that a report has been or may be made, which constrains how any tool surfaces SAR status. In the European Union, reporting runs to national financial intelligence units, and the European Banking Authority sets guidelines on money-laundering and terrorist-financing risk that shape expectations, with the new single rulebook harmonising obligations from July 2027. In Singapore, suspicious transaction reports go to the Suspicious Transaction Reporting Office under the relevant MAS and CDSA requirements.
The common thread for an AI agent is that it can draft to each template and jurisdiction, but the human accountability and the confidentiality rules, especially tipping-off, are non-negotiable and must be built into the workflow. For the cross-border crypto angle, see our FATF Travel Rule guide.
What audit trail do regulators inspect, and who signs the SAR?
When an examiner reviews an AI-assisted SAR, they want to reconstruct how it was made. That means a record of the model version and prompt that produced the draft, the source documents the agent retrieved and cited, the changes the human reviewer made, and the identity of the person who attested and filed. If you can produce that chain, the use of AI strengthens your file rather than weakening it, because it shows a consistent, evidenced process.
On signing, the answer is unambiguous: a human signs. In the US the SAR is filed under the institution's responsibility, with a BSA or compliance officer accountable. In the UK the nominated officer files to the NCA. The agent's role ends at a reviewed, cited draft. This is the same agent-drafted, human-attested boundary that governs filings across the AI compliance agents framework, and it is what keeps accountability where regulators require it.
When should AI not touch your SAR process?
There are parts of the SAR process AI should stay out of, and naming them is part of using it well. AI should not make the decision to file or not file. That judgement, whether activity is genuinely suspicious, belongs to the investigator and the nominated officer, because it is the decision the law holds them to.
AI should not operate where you cannot ground it. If the case data is not retrievable and citable, an agent will be guessing, and a guessed narrative is the first-generation failure all over again. And AI should not be used in a way that risks tipping off, so any tool must be designed so that SAR status is not exposed to the customer or to unauthorised staff. Used inside those limits, drafting from grounded evidence with a human decision and signature, AI removes the writing burden without touching the accountability. Used outside them, it manufactures risk.
The bottom line
Yes, AI can draft SAR narratives, and at 4.7 million filings a year the case for help is obvious. But the question that matters with AI SAR drafting is not whether AI can write, it is whether it can prove what it writes. Done right, AI SAR drafting strengthens the file: US authorities have opened the door to AI that improves AML compliance, while keeping it shut on anything that erodes accountability or governance.
Draft from grounded evidence, cite every claim to a source record, respect tipping-off and the jurisdictional template, and keep the decision and the signature human. Inside those lines, AI turns the heaviest writing task in compliance into a fast, consistent, defensible one.
See a SAR drafted end to end, book a SAR demo, or read how it works.
Related resources
- AI compliance agents: the 2026 operator guide
- L1 alert triage with AI
- UBO mapping with AI
- AML transaction monitoring in 2026
- AML compliance software in 2026
- FATF Travel Rule compliance for VASPs in 2026
- Why your KYC vendor is your biggest data breach risk
Cited sources
- FinCEN, SAR Stats and Year in Review: fincen.gov
- US Department of the Treasury, Treasury and Artificial Intelligence (2024 RFI and report): treasury.gov
- UK National Crime Agency, Suspicious Activity Reports: nationalcrimeagency.gov.uk
- European Banking Authority, AML and CFT: eba.europa.eu
- FATF Recommendations: fatf-gafi.org
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.