A plain definition of sanctions plus the mechanics a compliance team is legally accountable for: the types, the lists, screening, and the ownership rule that catches firms.
Sanctions are restrictive measures that a government or international body imposes on a country, entity, vessel or individual to change behaviour or protect security, without going to war. For a regulated business, complying means screening every customer, counterparty and payment against constantly changing government lists, then blocking, freezing and reporting any match.
A sanction is a restrictive measure that a state or a group of states adopts to influence the conduct of a target judged to threaten international peace, security, human rights or a specific foreign-policy objective. The UN Security Council frames sanctions as a tool to maintain or restore international peace and security, sitting between diplomacy and the use of force. The US Treasury's Office of Foreign Assets Control (OFAC) describes its programmes as economic and trade restrictions used to accomplish foreign policy and national security goals. The EU calls them restrictive measures.
In everyday examples, a sanction might freeze the assets of a designated oligarch, ban the export of dual-use technology to a specific country, or prohibit a bank from processing payments for a listed vessel. For a compliance, banking, payments or trade professional, though, sanctions rarely mean the abstract policy. They mean the practical, legally enforced obligation to screen everyone you deal with against government lists, and to block anything that matches.
Breaching sanctions is generally a strict-liability offence, which means you can be penalised even if you did not intend to break the rules and did not know the counterparty was sanctioned. That is why sanctions screening is not optional housekeeping. It is a core control that banks, payment firms, insurers, crypto businesses and exporters are expected to run continuously, and it is inspected by regulators.
The stakes are rising. Global money laundering is estimated at 800 billion to 2 trillion US dollars a year, roughly 2% to 5% of global GDP (UNODC), yet less than 1% of the proceeds are ever seized or frozen. Sanctions are one of the main levers used to attack that flow, so the pressure on firms to screen well, and the penalties for failing, keep growing.
The word sanction covers several distinct instruments. The categories that matter most for compliance are financial, trade and sectoral measures. The table below sets out the practical taxonomy rather than the loose lists sometimes seen elsewhere.
Sanctions are imposed by international bodies and by individual states, and a firm usually has to screen against several regimes at once because they do not always align. These are the four bodies to know.
One distinction explains why a European bank with no US operations still cares intensely about American lists.
Primary sanctions bind persons under the imposing state's own jurisdiction. US primary sanctions apply to US persons: US citizens and permanent residents wherever they are located, entities organised under US law and their foreign branches, and anyone physically present in the US.
Secondary sanctions reach non-US parties that transact with a sanctioned target, by threatening to cut them off from the US market or financial system. They are extraterritorial by design. A firm outside the US cannot ignore OFAC lists, because dealing with a target can trigger its own loss of access to dollar clearing and US counterparties.
For a regulated business, complying with sanctions is an operational process, not a legal abstraction. It runs as a pipeline, and each step introduces the false positives that dominate the workload.
The trap that catches firms is that a company can be sanctioned without appearing on any list. Under OFAC's 50 Percent Rule, any entity owned 50% or more, directly or indirectly, in aggregate, by one or more blocked persons is itself blocked, even though OFAC never names it. The EU and UK operate similar ownership and control tests.
So a clean-looking counterparty can be effectively sanctioned through its ownership chain. Beneficial-ownership and UBO analysis is therefore inseparable from sanctions screening. Ownership is also dynamic: a clean entity today can become blocked tomorrow if a designated person raises their stake above the threshold. Building that ownership picture is where due diligence and sanctions work meet.
Fuzzy matching is deliberately generous. It has to be, because a listed person may appear in a payment under a transliterated, misspelt or partial name, and missing a real match is a breach. The cost of that caution is volume: the industry's false-positive rate on screening and monitoring alerts is widely cited at around 95% (Accenture, McKinsey, ACAMS). Analysts spend most of their time clearing alerts that were never genuine hits.
This is the pain that AI is now attacking directly. A 2025 Federal Reserve working paper (Allen and Hatfield) benchmarked four large language model families against traditional fuzzy matching on sanctions name and address screening. The models cut false positives by roughly 92% on average and improved detection rates by around 11%. The catch was latency: the models ran roughly four orders of magnitude slower, so the authors recommend a model cascade, running fast fuzzy or exact matching first and reserving the models for the uncertain cases.
Regulatory tempo is at a record high, driven largely by Russia's war on Ukraine, and enforcement is turning criminal. The timeline below sets out the load-bearing developments.
Analysts price the dedicated sanctions-screening-software market at roughly 1.5 billion to 2.5 billion US dollars in 2024 to 2025, growing at a compound annual rate of about 6% to 15% depending on the report (Verified Market Research, Market Research Intellect, Business Research Insights). These are vendor forecasts that disagree with each other, so treat them as a range, not a single verified number.
AI is now a genuine defensive tool in sanctions compliance, and the evidence is concrete rather than promotional. The Federal Reserve study above is the strongest case: large language models cut false positives by roughly 92% and improved detection by around 11% versus the best fuzzy baseline, with a model cascade recommended so the slow models only handle the hard cases. Beyond matching, AI can pre-classify a large share of screening alerts so analysts focus on genuine hits, and it can draft the auditable disposition notes that every sanctions decision needs.
The defensive gains are real when AI is applied to the workflow around screening rather than to policy itself: cutting false positives through better matching and threshold tuning, triaging alerts so analysts see the ones that matter, drafting disposition notes so decisions stay defensible, and mapping ownership so the 50 Percent Rule can actually be applied to layered structures. Each of these attacks the roughly 95% false-positive burden without replacing the underlying screening data.
The same capabilities are being weaponised to evade sanctions, and 2025 to 2026 produced named incidents. Anthropic's August 2025 threat report documented North Korean operatives using Claude to fabricate identities, pass technical interviews and hold remote jobs at US technology firms, funnelling salaries to a sanctioned regime, and noted that AI removed the training bottleneck that once limited such operations. A related cluster used AI-generated CVs, synthetic identities and deepfake video in interviews. The US Department of Justice searched 29 suspected laptop farms across 16 states in June 2025, and CrowdStrike reported a 220% year-on-year rise in such infiltrations.
The Royal United Services Institute (RUSI), in its report Algorithms of Evasion, warns that generative AI can mass-produce high-quality fraudulent documents such as passports, bank statements, vessel registrations and invoices, authentic enough to defeat traditional compliance checks. Crypto remains the evasion rail: the Lazarus Group's 1.5 billion dollar Bybit theft in February 2025 shows sanctioned states already operate at scale in digital assets. FATF's AI and Deepfakes Horizon Scan, published in December 2025, warns that synthetic audio, video and images can defeat KYC, remote onboarding and liveness checks that many AML systems have not yet upgraded to detect.
Attackers now use AI to fabricate identities and pass interviews for sanctioned regimes, forge documents at scale, and defeat biometric checks with deepfakes. As one RUSI researcher put it, static biometric checks such as a selfie or voice print are no longer sufficient proof of identity against AI-enabled adversaries. The defenders' AI advantage and the attackers' AI advantage now centre on the same layer: identity and ownership, which is exactly what sanctions compliance depends on. See synthetic identity fraud and deepfake detection in KYC.
If you run a regulated business, these are the essentials a sanctions programme has to cover.
Several credible, attributed directions are already visible. Criminal liability is becoming the norm rather than the exception, with the EU directive and OFSI's doubled penalties pointing to prosecution rather than administrative fines, and first criminal cases expected across 2026 to 2027. Beneficial-ownership screening is becoming table stakes as the 50 Percent Rule and its analogues bite, so continuous UBO monitoring stops being a nice-to-have.
FATF frames the future explicitly as AI versus AI: firms will need to ramp up AI detection, scale human review, and invest in cross-industry collaboration, while supervisors intensify scrutiny of AI-specific controls. RUSI goes further, recommending deepfake-aware KYC and even compute-KYC obligations that monitor GPU-rental patterns, an early sign that AI infrastructure itself may become sanctions-relevant. And the Federal Reserve's cascade finding, fast matching first with models reserved for the hard cases, is likely to shape how screening stacks are architected, favouring orchestration over any single monolithic engine.
The honest frame is your sanctions vendors plus Zenoo, never Zenoo replaces sanctions screening. Zenoo does not publish or maintain government lists, and it is not the name-matching engine that decides whether a payment name equals a listed person. Those functions belong to specialist screening providers, the kind found in Zenoo's Marketplace. Where Zenoo genuinely helps is the workflow around those vendors.
Institutions typically run several providers at once. Zenoo orchestrates across them: it routes checks, handles failover if one is down, runs checks in parallel, and keeps one immutable audit trail (32 event types across 8 categories) so every screening hit, disposition and override is traceable, which matters more as enforcement turns criminal. Its 10 specialised AI agents work on that output, not the list. The Alert Investigator agent can pre-classify up to 80% of screening alerts, resolution notes are drafted in about 10 seconds, and threshold tuning typically cuts false positives by 15% to 30%. For the 50 Percent Rule, the KYB Researcher and Full KYB Pipeline build the beneficial-ownership picture, discovering 2 to 4 times more related persons than manual processes.
Zenoo does not decide sanctions policy or guarantee that a match is legally correct; the firm remains liable. It does not detect deepfakes or forged documents itself; it orchestrates the biometric and document-verification vendors that do. And it does not maintain sanctions lists or replace a screening provider's matching engine. Every Zenoo figure here comes from our internal metrics registry.
Zenoo does not replace your sanctions screening vendor. It orchestrates the vendors you already use, routes and runs checks in parallel with failover, keeps one immutable audit trail, and puts 10 specialised AI agents on the workflow around screening: triage, disposition notes, threshold tuning and ownership research.