Strict Liability, Sanctions, and Agentic AI
This episode explores how strict liability under IEEPA can leave institutions exposed even without intent, using real-world enforcement examples and the challenge of detecting hidden sanctions violations. It then makes the case for agentic AI as a defensible, audit-ready way to investigate complex transaction networks and reduce alert fatigue.
Chapter 1
The Invisible Strike and the Fallacy of Strict Liability
Lachlan Reed
So, picture this. It's February 2026. You are running admissions or finance at IMG Academy, this massive, high-profile sports training school over in Florida. Some international students sign up, the tuition fees clear, everything looks completely standard. But behind the scenes, that money was routed through a complex web of third-party shell companies tied directly to a Mexican drug cartel. And even though nobody at the school had a clue, OFAC—the Office of Foreign Assets Control—hits them with a $1.7 million settlement. Gone. Just like that.
Jack Burns
It is the brutal reality of strict liability under the International Emergency Economic Powers Act. Under IEEPA, the government does not need to prove you intended to bypass sanctions, or even that you knew. If the transaction occurred, you are liable. We saw the exact same mechanism play out with GVA Capital, hit with a massive $215 million penalty for managing proxy assets of a sanctioned Russian oligarch. The system does not care about your good intentions.
Simon Carver
Wow. I mean, my head is already spinning with all these acronyms. OFAC, IEE-- IEEPA. I told you guys, if we started with the heavy legal stuff, my brain would just melt. But, uh, welcome to the show, everyone! I'm Simon Carver, and with me as always is the brilliant Lachlan Reed, and of course, our resident force of nature, the expert on all things structure and systems, Dr. Jack Burns. Before we dive deeper into this regulatory minefield, do us a quick favor—if you're enjoying this, hit that subscribe button, share it with a colleague, and please make sure to join us for the next topic, see you in our next episode! Alright, Jack, help me out here. How does a school in Florida, or a VC firm, even begin to defend themselves against this?
Jack Burns
Think of it through the lens of physics, or even leverage in Brazilian Jiu-Jitsu. In BJJ, you do not oppose force with raw strength; you find the point of maximum leverage where a small effort yields a massive structural failure. The adversarial network does exactly this to our global financial infrastructure. Take the launch of the FinCEN whistleblower portal just this past February. It targeted these highly structured wire transfers disguised as, of all things, "timeshare fees" for holiday resorts.
Lachlan Reed
Timeshares. Of course. It's always something mundane, isn't it?
Jack Burns
Exactly. Because a mundane transaction blends into the background noise. Traditional compliance monitoring relies on static, rule-based checklists. If a name matches 70% of a watch list, it triggers an alert. The result? A crushing 99% false positive rate. You have twenty-four-year-old analysts staring at thousands of alerts a day. Psychologically, their brains simply stop registering danger. It is alert fatigue paralysis. The human mind is not built to find a needle in a haystack when 99% of the needles are just shiny pieces of straw.
Lachlan Reed
Oh, absolutely. It's like, uh, back in my shed, right? Trying to fix up an old trail bike. You get these guys who buy them and they, they want to bypass the emissions or whatever, so they strip out the metadata of the bike, right? They, they scratch off the serial numbers, paint over the logos, modify the exhaust. If you're just standing on the side of the road in a massive dust storm, trying to spot whether that bike passing you at eighty KPH has a modified exhaust... I mean, on paper, it's just a bike. But underneath, the whole thing is designed to cheat the system. Honestly, trying to parse these multi-layered transaction trails with just a basic spreadsheet and an exhausted analyst? I mean, even a kangaroo could trip over this. It's just too much clutter.
Chapter 2
Defensive Leverage: Deploying Agentic AI to Level the Field
Simon Carver
So, if the manual checklist is dead, what's the alternative? I keep hearing about AI, but we've all seen how chatbots can just, you know, hallucinate things out of thin air. How does that help a bank avoid a $200 million fine?
Jack Burns
Because we are not talking about generative AI as a passive tool. A standard language model is like a very fast librarian. You ask it for a document, it runs to the back, and it hands it to you. Agentic AI is fundamentally different. It is an autonomous, forward-deployed intelligence team. When an alert triggers, you do not wait for a human to prompt it. A swarm of specialized agents collaborates in real time. One agent scrapes corporate registries in Cyprus or Delaware. Another verifies the ultimate beneficial owners. A third maps the entire transaction routing network. Within seconds, they compile a highly contextualized, human-readable dossier before an investigator even opens the file.
Simon Carver
Wait, so the machine is doing the actual investigating? But what about the regulators? I mean, in 2026, the SEC shifted its entire focus away from crypto and straight toward AI governance and operational resilience. If a bank just points to a machine and says, "Uh, the robot said it was fine," won't the SEC just laugh them out of the room?
Jack Burns
Absolutely. Which is why the core principle of this technology must be what we call "defensibility by design." You cannot have a black box making black box decisions. The agentic system must generate an immutable, step-by-step audit trail. It has to explain *why* it connected that Delaware shell company to the sanctioned entity in Russia. It does not replace human judgment; it clears the operational brush so the human can exercise actual strategic command. It moves the analyst from a data-entry clerk to an intelligence officer.
Lachlan Reed
Yeah, that makes total sense. It's like, uh, when I was working on the carburetor on my old dirt bike last weekend. I bought this fancy, automated ultrasonic cleaner. I thought, great, I'll just throw the whole carburetor in there, press a button, and it'll fix everything. But I didn't clean out the actual physical rust and gunk first. I just turned it on. And, uh, let's just say it consolidated the dirt into places it should never go. Ruined the whole housing. If you just throw these incredibly powerful autonomous AI agents onto a complete mess of fragmented, dirty corporate data silos... mate, it's like putting a jet engine on a rusty billy cart. You're just going to crash faster.
Jack Burns
A very apt analogy, Lachlan. You must start with the data architecture cleanse. And then, you deploy in a secure sandbox. You let the agents run parallel to your legacy systems, observing how your best human investigators handle the nuances. It is a psychological integration. The workforce has to learn to trust the machine's reasoning, and the machine has to learn the organization's specific risk appetite.
Simon Carver
It really is about redefining how we work alongside these machines. It's not about being replaced; it's about reclaiming our time for the actual hard, critical thinking. Well, that is all the time we have for today's quick take! A huge thank you to Jack and Lachlan for breaking down a incredibly complex topic. Make sure to hit that subscribe button, leave us a review, and share this episode with anyone in your network who is currently drowning in compliance theater. We'll see you in the next episode!
Lachlan Reed
Too right. Keep those carburetors clean, everyone. Catch you next time!