
How Compliance Actually Scales with Hamza Siddiqui, Director of Compliance at Chime
July 8, 2026
51
min
TL;DR: Hamza Siddiqui has spent his career translating between machine learning engineers and regulators — first at Upstart, where he helped secure a CFPB no-action letter for ML-driven credit underwriting, and now at Chime, where he runs compliance for one of the largest neobanks in the US. He explains why compliance must be embedded in product design from day one, why he prefers "augmented intelligence" over "artificial intelligence," and how the right tooling turns a compliance team of 10 into one that operates at 10x output without adding headcount.
What This Episode Covers
Hamza Siddiqui has operated at the intersection of compliance and machine learning since before the 2022 AI hype cycle made everyone a LinkedIn thought leader on the topic. He joined Upstart ahead of its IPO, served as the translator between ML engineers building novel credit models and the CFPB regulators evaluating them, and now leads compliance at Chime across BSA/AML, consumer protection, and product risk. This conversation maps his experience onto the questions compliance leaders and RegTech builders face today: how to embed compliance into product development, how to evaluate build-versus-buy decisions for AML tooling, and what RegTech startups need to demonstrate to earn trust at scale.
Hamza also talks about growing up in post-9/11 America after moving from Pakistan at age eight — an experience that fundamentally shaped how he thinks about trust, risk, and who gets to earn it. He lost 82 bitcoins to a corrupted hard drive. He tests every product he works on by asking whether it would help or harm his 11-year-old nephew and 18-month-old daughter.
Who Is Hamza Siddiqui
Hamza Siddiqui is the Director of Compliance at Chime, one of the largest neobanks in the United States. Before Chime, Hamza joined Upstart just before its IPO, where he bridged machine learning engineering and regulatory compliance — helping the company secure a second CFPB no-action letter and launch its first non-personal loan product built on ML credit models. His career spans two IPOs and a trajectory from Pakistan to Washington, DC, through the post-9/11 era that shaped his thinking on digital trust, systemic risk, and the role compliance plays in financial inclusion. Hamza advises several early-stage companies on AI governance and regulatory strategy, and he advocates for a compliance mindset that enables growth rather than constraining it.
What It Actually Sounds Like to Translate ML for Regulators
The best compliance practitioners take esoteric regulations and restate them in terms an engineer or PM can act on. Hamza did this at Upstart before most companies had shipped a single ML model into production. The challenge was specific: Upstart's credit underwriting replaced FICO-based rules with machine learning features — hundreds of variables that determined whether someone received a loan and at what price. Hamza worked with the ML team in what he describes as a safe space, asking them to distill technical concepts until he could map each feature back to credit reasoning a regulator would recognize. That translation flowed both directions. He took the output back to CFPB examiners, bank partners, and internal stakeholders, framing the model not as a black box but as something functionally equivalent to human judgment — just faster, more consistent, and auditable at every step. Nick Passarelli from Melio covers the operational side of running AI in compliance workflows.
Why Build Versus Buy Keeps Breaking BSA/AML Programs
Compliance leaders who default to building in-house tooling rarely ship fast enough to match the growth they are supposed to support. Hamza frames the problem in terms of velocity: a fintech in hypergrowth cannot spend 15 to 18 months engineering a sophisticated transaction monitoring platform when the business needs coverage in month zero. That gap is where buy decisions happen. The evaluation criteria Hamza applies are direct — speed to implementation, trustworthiness of the solution, and cost relative to the growth the company is pursuing. Legacy systems like Actimize take quarters just to learn a business. Newer RegTech platforms built on AI can onboard faster, adapt to shifting risk profiles, and deliver auditable outputs that reduce false positives at scale. Hamza notes that BSA/AML has never produced a runaway winner the way Vanta did for SOC 2 — largely because the stakes are personal. Consent orders carry individual fines, and compliance officers will not outsource trust to a vendor they cannot verify.
The 10x Compliance Officer and the Shift from Processing to Strategy
Too many compliance professionals operate as processors. Hamza borrows the concept of a 10x engineer and applies it to compliance: the right hire, paired with the right tools, multiplies output without multiplying headcount. When augmented intelligence handles the volume — SAR filings, transaction monitoring alerts, marketing material reviews — the team stops spending 80 to 90 percent of its time on execution and starts asking better questions. Should the transaction monitoring threshold fire 300 alerts, or is it miscalibrated? Does the disclosure approach still make sense? Compliance becomes a growth enabler rather than a cost center. Hamza points to a practical test: a team of 10 that reviews 100 pieces of marketing content per week should reach 400 or 500 with the right tooling, with no artificial increase — just extended capability. That reframing is why he prefers "augmented intelligence." FinCEN's effectiveness-based AML rule reinforces this shift, pushing programs toward measurable outcomes over checkbox compliance. Jennifer Lee from Savvy Labs explores a similar tension between judgment and automation in her episode.
Who This Episode Is For
Frequently Asked Questions
What does a compliance translator between ML engineers and regulators actually do?
A compliance translator takes technically sophisticated concepts — like how a machine learning model uses hundreds of features to make credit decisions — and restates them in terms regulators and bank partners can evaluate. Hamza Siddiqui performed this role at Upstart, working with ML engineers to distill each model feature into recognizable credit reasoning, then presenting that reasoning to CFPB examiners. The translation also flows in reverse: converting regulatory requirements into design constraints that engineers can build against from day one.
Why has BSA/AML compliance never produced a dominant software platform the way SOC 2 compliance did?
BSA/AML carries personal liability. Consent orders come with individual fines for compliance officers, which means practitioners are reluctant to outsource critical functions to vendors they cannot fully verify and audit. Unlike SOC 2 — which operates as a defined checklist — BSA/AML requirements vary by institution type, customer base, geography, and risk profile. That complexity, combined with the personal stakes, has kept compliance leaders reliant on in-house teams and legacy incumbents rather than adopting newer platforms.
What does Hamza Siddiqui mean by "augmented intelligence" instead of "artificial intelligence"?
Hamza reframes AI as an extension of human capability rather than a replacement. Augmented intelligence tools increase the output of an existing compliance team — more SAR filings reviewed, more marketing content cleared, more transaction alerts processed — without creating artificial dependencies outside human oversight. The distinction matters for regulatory conversations because it positions AI as a workflow accelerator with human accountability, not an autonomous decision-maker that replaces the compliance officer.
How should compliance teams evaluate build versus buy for AML tooling?
Hamza applies three criteria: speed to implementation, trustworthiness of the solution, and cost relative to anticipated growth. Building in-house typically takes 15 to 18 months and cannot keep pace with a fintech in hypergrowth that needs transaction monitoring coverage immediately. When evaluating vendors, compliance leaders should look for auditable decision trails, configurable rules, and the ability to onboard quickly without spending additional quarters training the system on their specific business.
How close is the US to passing AI-specific compliance regulations?
State-level legislative activity around AI in financial services is accelerating, with real conversations happening in state chambers about consumer impact and protection. Federal landmark legislation remains unlikely in the near term, though the NIST AI framework provides early signals of what standards may eventually become law. Hamza notes that regulators are signaling openness to new approaches — the surge in bank charter applications reflects a shifting posture — but adoption will be cautious. RegTech companies and fintechs that speak the regulator's language, focusing on audit trails and explainability rather than buzzwords, will navigate the transition more effectively.
Episode Transcript
Alex: Hamza, it's great to have you on the podcast.
Hamza Siddiqui: Delighted to be here.
Alex: You once said it's not artificial intelligence, it's augmented intelligence. And you also lost 82 bitcoins from Pakistan to DC, two IPOs, and now running compliance at one of the biggest neo banks in the world. You've seen the evolution of risk, regulation, and technology from every side. Today, I'd love to unpack what you've learned about AI, fairness, and how to make compliance actually scale. Let's start from the beginning. You were born in Pakistan, moved to the US in the 2000s, which as you mentioned was a very different America a year later. How did that shape the way you think of trust, risk, and systems today?
Hamza Siddiqui: When I first moved to the country, I was 8 years old coming the land of things I've seen on TV. Getting to know everybody and then a year later 9/11 happens and very quickly the reality that you were coming in with this childhood innocence changed very quickly and then to grow up in the post 9/11 era and to experience the world through that lens where trust became a pretty hot commodity and something you had to truly truly earn. It wasn't given anymore. That shaped a lot of my thinking and I think we see that in the world today — are we a high trust society, are we a low trust society. And you see that 9/11 happened, the financial crisis happened, you saw digital money, but I think the underlying context around crypto and the digital money is digital trust, and that was an interesting journey for me to think back to if I was 8 years old what I would be doing in America. I thought I'd be a sports star or a celebrity and now I'm just a hunky dory compliance guy working in digital money.
Alex: That's great. That's super interesting to understand how that initial setting really changed your view on that. But you've also done two IPOs and what actually changes for a CCO going from pre-IPO to public and what becomes a non-negotiable overnight?
Hamza Siddiqui: It's really interesting to see the evolution of a compliance program where you're in a very hypergrowth stage and as you continue to go through your growth phases, as you continue to do big rounds, the target on your back becomes bigger until you get to the IPO stage where you're breathing a sigh of relief as everybody does. Oh, we finally made it. And then you realize, uh-oh, we finally have made it. The target is real tangible whether you're thinking about it from regulators, folks who are very happy to be litigious and so your compliance mindset becomes less indexed on how can we grow, how can we support growth so quickly to how can we do so at a pace that is sustainable and how do we think about our risk appetite in a way that was different when you're in the private markets because your exposure is so limited. But yeah, once you make it, you've made it.
Alex: And it's for all the good and bad, you're thinking through it very differently. It's less of a let's build build. Let's grow grow. It's how do we defend what we have? How do we protect what we're doing? And how do we continue to sustainably think about this? And about thinking differently, there's something really interesting that when we chatted last time, you were at Upstart. You joined there right before the IPO, helped navigate a CFPB second no action letter, and launched their first non-personal loan product. And you said to me that you were a translator between machine learning engineers and regulators. What does that translation actually sound like in practice?
Hamza Siddiqui: When I think about the best compliance people, whether it's very technical people or very innovative products that they're working on, the best compliance people that I look up to that I think are the best practitioners that you see on all the talk circuits, they're the ones that are able to take these very esoteric or antiquated or very confusing laws and regulations and put them into the context for an engineer or a PM. Conversely, when you're working in a space where you are helping develop innovative products, you are taking the very brilliant technical minds or the innovative ideas that are coming through and helping put them in frameworks that the people who are going to ultimately shape your destiny can understand before October of — was it 2022 — when suddenly everyone decided they were an AI influencer and a top leading LinkedIn voice on AI chat with me. We were doing some really sophisticated work at Upstart where we were taking a very novel concept. How do you move away from the FICO and the hard credit rules and give access to people based on their own merit besides just a small box that was created by somebody and that's been part of the industry for centuries. And we had to find the way to fit a very novel concept machine learning models and credit underwriting and help translate it to bank partners to our own internal people and then of course to the CFPB regulators to be able to say this isn't some black box.
It's actually no different than the human brain. We can help you understand how our machine learning models will be making decisions to determine should this person have access to credit based on our risk tolerance or not. How should we price things? And it was the ability to work with the machine learning team who bless their hearts, they were willing to dumb down their very technical concepts to me and I was able to ask all the questions in this very safe space and then take that distill it based on my experience to be able to say here's all the features here's how they map ultimately to what sounds like pretty benign credit reasoning and why we would approve somebody or why we would reject somebody.
I think that was really applying that human element. I love my technical people but sometimes the altitude with which they try to explain their ideas doesn't necessarily translate for nontechnical people.
Alex: And we do AI and we talk to a lot of regulators and it is complicated sometimes to truly make them understand what we're doing and what's going on. And you were doing that as you said pre-2022, a time where AI was even more mystical to some people. How do you actually do it? How do you make that black box legible for regulators without scaring them away because you were able to implement machine learning models at that time which I'm not sure every company managed to do and managed to convince regulators there. How do you do it and how do you think it differs from today with LLMs and maybe more black-boxy models?
Hamza Siddiqui: There's a couple of different ways you can build products and we see that across the industry. You can have a very buttoned up approach where you would think product is leading what ultimately comes to market, but it's somebody in risk or compliance and you have a very watered down version of what could have been a great product.
You also have on the other end a product that once you experience it, you're like, "Wow, this is probably for the average consumer going to be harmful." And I think the best models that I've seen that I've had the ability to work with great leaders and implement on my own are where you're embedding compliance. It's part of the design process. It's part of the development process. And that means for when we were thinking about how do you take a very novel concept? How do you take something that's so technically difficult and ultimately bring it to market?
You embed compliance from day one. You let your technical people do what they have to do. You want to design a machine learning model and you want to develop a new AI, go for it. Here is the sandbox that I think you're going to have to eventually come to play in and laying those things out for your development team and then letting them be creative. Let the folks do what they do best and when they're ready to come to you, sit down, start teasing out what will ultimately matter to your regulators or frankly to the market.
And for us this meant have whatever features you want. Have 500, a thousand. Some of the teams I work with today and some of the folks I advise — don't constrain yourself. Do what you want to do, but keep the end goal in mind where you want to have a flying sophisticated product that's also going to be explainable, that's also going to be something that needs to adhere to these things. And the way to think about it is explainability is going to be at the core of any AI tool or an ML model.
You need to be able to explain what's happening. How can I trust you? How can I trust you to give me an unbiased credit outcome? How can I trust an AI agent to properly execute my BSA AML program? If I don't know what's happening behind it, I cannot account for that unknown risk.
Alex: No, 100%. And the thing is from step now Chime you're dealing with consumer-facing AI and although you might have very understandable decisions, very auditable decisions and understand the reasoning through them, I would imagine that if you do one or two mistakes it's a very risk-averse space and you might not be able to come back from there. Has there been any issues or has there been any blunders that you've seen either at these companies or others that you've seen was not savable?
Hamza Siddiqui: I think of the issues as a spectrum really. Are you going to bring something to market that's going to be so terrible, so overengineered from a safety perspective that the user experience is going to be awful and it's going to polarize people. I think about when Google very early last year released a Gemini update and there were people trying to do certain prompts and they kept experiencing a very strange outcome that you wouldn't expect from what should have been an otherwise easy use innovative product and that was I think a great example where you're overindexing on what you need to do to bring something to market. That was in my opinion a pretty big failure. But on the other end, you had issues with Goldman and Apple Card where they were unable to explain why they had gender discrepancies in their pricing and approving when they first brought the card to market. And I think from that perspective, you lose a lot of trust.
I talked about that at the start. We've entered into this digital world where it's really trust that's digitized. And how do you approach that? And I think the way to do that as consumer-facing AI is when you're ready to launch, you've done thorough testing and you feel really comfortable that the worst actor isn't going to pick out something that you're doing that's incorrect. From an ML model perspective, you want to make sure it's going to be nonbiased.
From a consumer facing, say personal finance tool, you definitely don't want to be encountering a scenario where you're giving me the worst advice. Take out as much credit as you want. Go into debt if you have to. Making sure the underlying training data and ultimately what the output is is going to be something that's palatable.
Alex: But when you're a startup, it's normal for you to try something, fail hard and then go back at it. But in compliance, it's not something you can do. As a startup whether it's a fintech that wants to implement compliance or a regtech startup how do you think you can have this balance between innovation and speed and yet safety and trust.
Hamza Siddiqui: There was a great article the founder of Upstart wrote speed as a habit where you always are trying to move at a very fast pace. But to move very fast, you sometimes have to consider other things in mind. It's no different than when you're say going out for a run. You could sprint your whole marathon and you're probably not going to finish. Pull your hamstring.
Ruin yourself in some horrible idea because you were trying to move too quickly or you could try to walk your marathon, probably get picked up by the last cart and not finish. And as a startup, even as a public company, the way you want to think about speed and the way you want to think about innovation, I think has to come down to how fast can we go at a pace that's going to be comfortable. Should we be shipping LLM models or should we be using untested ML models and credit decisioning? Probably not. Should we wait to train our AI for over the course of a year and eventually bring a product to market that 20 other FinTechs probably already have?
Probably not the right approach either. I think it's finding that right balance of have we done enough testing to have a level of confidence this isn't going to break. This isn't going to harm our members or our consumers. And is it going to detrimentally impact our image?
Alex: And in something that is so important in FinTech as compliance, but that isn't necessarily core to the product as in the product itself. What is your thoughts on build versus buy?
Hamza Siddiqui: That's a challenge I think every leader faces whether you're in compliance, an engineering org. It's more often than not you're thinking I can build it and that's just not going to be scalable and it's not going to be sustainable. When I put on my compliance hat only because I'm not a technical leader, I think about all of the obligations we have in this space, whether it's BSA, AML, whether there's other consumer protection requirements. And the only way to execute at scale is through leveraging technology, is through leveraging tools. And then when you're facing that decision of should I build or should I buy, you have to rely on the fact that you're trying to support innovation. And in the companies that I've been at, speaking about speed, speaking about velocity, you can't take 15 to 18 months to build a really smart, sophisticated tool to support the growth that has to happen in month 0 to two.
And that's where you start looking out into the marketplace. And then when you're looking to buy, you want to look at and understand are these organizations bringing to me the scalable trustworthy solution that's going to help me meet my bank partner requirements, my own internal risk appetite. Is it going to release something? I like to joke about my nephew is the end user of a lot of the products I've been able to build in other family members. Is it going to harm my nephew or is it going to harm my mom?
And that's the decisioning that really goes into it. Cost factor is always a factor, but it's just what has been built. Can I trust the product? And that's where it becomes really incumbent upon the person who's building things to show me, hey, we've built a great solution and you can actually trust us.
Alex: There's been an article, I don't know if it was BCG or McKinsey, that said 95 to 98% of enterprise AI pilots don't go through. Why do you think that is? And I don't know if you've had such pilots at Chime and can talk about why you really think that is?
Hamza Siddiqui: I did read that article. I thought it was hogwash. I was like, I'd love to understand your methodology more. There has to be some disclaimers here. I think there's a lot of exciting things that are happening in just generally enterprise AI space. If you asked me at the end of two quarters ago what tools I think would be able to help me and if you asked me to survey the landscape again and say all right here's is that tool that you selected still something you'd want to use today and the answer is going to be no because something new and better has come to the marketplace so I think pilots are a great opportunity for enterprise companies and companies to really figure out is this going to fit my use case, is this good enough, or is this also future-proof? Pilots are a great way to experience that.
Maybe that's contributing to that high failure rate, but I wouldn't necessarily classify it as a failure as much as discovery. I may test five tools, seven tools and say, I actually really like one. That didn't mean the other five or six were discarded because they were AI and I didn't find use for them. It's just I found the one solution that worked for me. I'm not going to speak to specifically maybe what we do or don't do at Chime, but I will say in a lot of the companies that I've been working with and advising, there is a real energy and a desire to find tools to augment the workflows. How do you bring on something that will make me a 10x compliance person or make me a 10x engineer?
Alex: We'll need to chat after the podcast. But something I'm super curious about is — and we had a chat about this before — we've worked with, we work with a lot of companies and there's an immensely fragmented environment in which compliance teams work in. We talked about the fact that unlike SOC 2 HIPAA compliance with companies like Vanta there's never been a runaway winner for BSA AML compliance. Why do you think that is? And do you think now with the advent of AI this could change?
Hamza Siddiqui: Big big congrats to the team and the backers at Vanta. What an incredible success story. If you could see that replicated anywhere else it'd be a miracle. BSA AML I think is something that has never gone out of flavor. Regardless of say administration change, you've always seen some of the biggest consent orders revolve around this regulatory hurdle and I think when you think about how much exposure banks and fintechs have they want to be really careful and that means if I'm an old school compliance officer I'm going to trust my team to execute my BSA AML program rather than outsourcing it to consultants or even regtech.
I don't know how it works. I'm not going to risk my credibility, my bank's credibility, and for what it's worth, take on the personal fines that accompany these consent orders because I can't trust you. I think that landscape has started shifting a little bit. Regtechs have I think started doing a better job of demonstrating upfront how they are trustworthy vendors and that shift I think will enable a clear winner where you have more and more banks not just FinTech who are leaning into the regtech solutions to be able to say we have a lot of SAR filings we have a lot of things we have to still meet the obligation for regardless of if you agree or disagree with certain FinCEN thresholds you still have to do that job and I do not want to go into yearly budgeting planning and saying I need a 10x increase in my headcount to be able to support whatever merchant activities we're doing or the new correspondent banking activity that we're doing. I would love to be able to bring in a tool and I think having new regtechs that are leveraging AI in a sophisticated way that reduces the need for me to hire more people that come to me and say here's an auditable demonstration of what is actually happening with this human to tech replacement that is going to drive you to feel comfortable to say all of my SAR filings are going out as expected, that all of my transaction monitoring is occurring in the way that I would expect this person with 5 years of experience, and I can audit it if I need to.
Alex: I think it's interesting because when you think about it, SOC 2 compliance is a checklist that you need to hit in order to get that certification. BSA AML is a completely different beast. Every team might have different things that they have to go through for different types of onboardings, for different types of customers, for different types of geos they operate in. It isn't as clear of a checklist to be like, hey, we're compliant and we know we're doing it in a great way. And I feel — I don't know out of your experience — that maybe legacy systems have been very static, rule-based, region focused because of how complicated BSA AML is and now with AI we can get solutions that are much more tailored to an organization. And do you think if your regtech starts today what would you do in order to win the market? What do you think is the top one to three things that would allow a regtech startup to sell to Chime for instance?
Hamza Siddiqui: I think you're hitting it spot on. Speed, trust, and cost. I know every cost is the unspoken elephant in the room, but how much money are you going to save me in the context of how much growth my company's looking for? But it is really that speed to implementation. Certain legacy systems will take months to onboard and then you have additional quarters ahead where you just have to get it to understand your business which is constantly shifting in the fintech or much more tech forward banks with AI tools and some of the regtechs that I'm starting to see — like a certain Sphinx for example — it's having the ability to onboard a potential new agent as I'm considering a new market to be able to say here are some of the things that Singapore cares about which I did not consider if I was a US-based fintech only. As I'm looking to expand, I want to be able to onboard quickly, and I want to have the assurance and the trust that the regtech knows the market, knows the rules, and is going to execute in a way that's going to protect my backside. Really, you got to be able to save my butt.
Alex: Yep. And now there's the other thing that we often see — us being in regtech, you being chief compliance officer — there's always friction with teams as in compliance they're a pain, they're slowing us down, but now I feel on the contrary compliance can become a growth enabler. What do you think about that?
Hamza Siddiqui: I think that's spot on when I think about how the caricature of a compliance officer is and how I try to operate. It could not be more diametrically opposed. I think speed is a good thing. Truly truly believe speed is a good thing and to be able to support the marketplace today and how quickly something say in the influencer world is changing and how your marketing strategy has to shift.
Am I going to sit there and review 50 videos that need to be able to go out in a week? No, absolutely not. There's other tools that can help augment that workflow. Am I going to want to launch a product and limit it to say only a thousand people because I don't quite know what my fraud rules are going to look like or how I can do transaction monitoring? That product is dead on arrival, man.
By the time it's to market and something truly innovative, within a week, somebody else is going to release something that's probably not going to have all the safety constraints I'm worried about and eat all of my market.
Compliance has to enable that growth. I said 10x compliance person. SF loves the concept of a 10x engineer. Having the right compliance hire who's thinking hey how can we manage risk which is a spectrum, it's never black and white, and how do we enable that growth is going to be so key and to be able to do that you need tech tools to augment the work that you're doing. I want to be able to do all of the things a traditional bank would expect me to do but I only have 24 hours a day and I'm a cost center.
And I can't do that with headcount and I'm going to do that with tools and you need a compliance person who is forward thinking who is willing to think through the risk protocols risk processes risk appetite and say you want to go to market and you want to release a very interesting generative AI tool let's release it, here's just high-level concepts, give me an agentic AI tool that's going to do XYZ testing and let's get it out there.
Alex: No 100%. But the thing that I find interesting in compliance is one is the risk appetite that obviously differs based on the organizations but usually when you have a product you have the vendor and the client but here there's a third party, there's a regulator, and what we've seen is sometimes the systems you use in house is as much the use you get from it but also the satisfaction that you get from regulators from them, whether Nice Actimize. They've been there for decades and regulators love the logo. How do you think this can actually — is this necessarily a break for regtech startups? Will it slow them down or is there a way to convince both the end client like Chime and the regulators as well?
Hamza Siddiqui: That's a really good point. Regulators I think for a very long time didn't see innovation — I wouldn't say as a good thing — but certainly not with the same rose tinted glasses that a lot of us in the tech world thought. You saw this in bank charter applications. From the great recession to maybe earlier this year the number of bank applications or trust applications were almost non-existent and we've seen a deluge of them starting this year because the regulators have started signaling there is a favorability towards new products, new banks, new approaches.
And I think regtechs, whether you're new or even if you're still Actimize, this is an opportunity for you to notice that the regulators are signaling their understanding that the world has shifted from when these laws were first written. The world has shifted since maybe even the earliest iterations of the FFIEC exam manuals and that they need to think about a new world and they're welcoming this approach tepidly but they're still welcoming it and it's — I don't blame the regulators, everything moves fast but they're thinking in the long term to really take advantage of I think this shift in tide whether you're an old regtech or a SaaS, depending on how Actimize wants to consider themselves. You have to be willing to speak to the regulator and have them understand your technology. Don't use the latest buzzwords, man. I don't care if it's generative AI.
If I put on my regulatory hat, I need to understand what it is, what it's doing, and how it's going to be compliant with what I'm going to ultimately assess you on. And I think for startups that are trying to get into this very incumbent heavy space, forget the logo, forget the name. Say we're doing the exact same thing that your Actimize is doing. Here's the tech and here's how it's actually the same or potentially better. And it comes down to the boring philosophical things of here's your audit trail.
Here's the rules configuration. And I think when you start speaking that common language of the regulator, they're going to understand, okay, all right, all of the sexy buzzwords and all of the sexy marketing aside, it's all the same on the back end for me. Okay, good. Yes, your community bank can use a smaller regtech rather than needing to pay so much for a much more clunkier solution.
Alex: It's funny because we are an AI startup. We are just over a year old. AI is core to our system. And I hate the word AI. I think that AI is just a tool. It's a way to build. And every startup company is going to become AI. It's as if people are saying, "Oh, we're a code company." Obviously, if you're a software company, there's code in there. Today, if you're a software company, there's most probably going to be AI. And last time we chatted, you said something I really liked. You said you prefer the term augmented intelligence over artificial. What does that mean to you and where does augmentation actually create measurable ROI?
Hamza Siddiqui: I love — I'm hoping if in the next 3 to 6 months it becomes a thing where people are saying yeah we're augmenting our workflows because I would like to think it's because of the podcast and I've done it. I've made it as a cultural influencer. Artificial intelligence is just a scary concept. It's been — think about the earliest movies around AI. It's evil, scary, you can't control it. We don't have that in the marketplace today. We don't have that, I think, potentially for the foreseeable future. And we didn't have that even 3 years ago. What we have had is, I think, a tremendous leap in technology that is truly able to augment the work that I'm doing or augment my way of living.
I love the word augmenting intelligence because I'm not creating an artificial tool or creating a new workflow where it's artificially dependent outside of my constraints. It's an extension of me. As a compliance officer, it's an extension of my brain and for my team, it's an extension of the work that they're trying to do. It augments and makes you faster.
When you think about the number of SAR filings, it's not as if it's artificially increasing the number of SAR filings. It's not as if it's missing things. It's just extending my workflow.
I think the way you measure the success of your augmented intelligence is how much more efficient is it making you and how much your output has increased.
One side of the equation has to remain pretty static. I want my team of 10 to remain say a team of 10 but I want their output increase from a hundred pieces of media reviewed from a marketing compliance perspective to 400, 500 and the only way to be able to do that is to augment their work. There's nothing artificial about it.
Alex: Agree, I really agree. And today compliance teams are overwhelmed by tens of thousands of false positives that they have to manually sift through and it's just the work in which you just click yes, no. And it's not the most gratifying work. And now that we're able to potentially really be an enabler, be an augment there, how do you think this will translate to growth as in what are the teams going to be doing that will actually expand the business?
Hamza Siddiqui: I think too many compliance people, risk people, operations people, even people maybe in the product or technical spaces sometimes see their role as processors. It's been done this way. I have to execute it this way to get this output. And part of that is just because of capacity constraints. You have to get so many things done. You're going to have to devote so much time to reviewing your code to be able to get it to commit. You have to do so much time reviewing your SARS so that you can meet your filing deadlines.
You have to do so much material review so you can get it out the door so you can support the latest influencer campaign. By using augmented intelligence tools, your team is able to get a lot of that processing done faster. They're not devoting 80 to 90% of their time just doing things. Now your team's going to have the chance to stop, think about why they're doing things. Is this enabling my team to think more strategically in how they're approaching a workflow?
Is our transaction monitoring threshold accurate? Should we really be firing off 300 transaction monitoring alerts? Do I really need to flag this much language in a script for an influencer campaign? Can I take a step back at my disclosure approach? You really can't do that if you're under the constraint of it's coming my door. I have an SLA and I got to get it out the door. Now your team can sit back and think, hey, how can we enable this growth? How can somebody whose life depends on shipping code take a step back and think I'm not just executing against whatever my PMs told me the requirements are. I want to be able to iterate and provide suggestions back and say I was building this, everything looks good, but I have a new suggestion. It enables that creativity that you don't otherwise see in these roles that aren't meant to be creative because of the constraints.
Alex: And I don't want to age you, but you've seen regulators evolve over two decades. How close are we to seeing AI specific compliance regulations in the US?
Hamza Siddiqui: I think we're starting to see that at the state level certainly, and they're more model than AI based. I know there's a little distinction but there's real tangible conversations happening now on the hill, in state chambers to say what is the impact to our consumers?
What is the impact to the people that live in my state and how do I protect them against AI? I think the conversation to date has been from a place of fear and I think this is where regtechs, consumer AIs can lean in and help educate the ultimate decision makers to say we are excited about the promise of AI but we also understand some of the risks for the financial services space. It's how do we think about modernizing AOA?
In a way that makes sense for AI and ML tools. How do we think about the way money moves today and how our filing and transaction monitoring system has in some ways failed to keep up? And where can AI help? And where does the guardrail need to exist to say this augmented tool or this machine learning model can be leveraged provided it has these fundamental criteria. There tends to be this desire to be very bullish on the latest technology, which nine out of 10 times I'm right there with everybody else. I'm saying, "Yeah, give me these smart glasses.
Let me use the GPT wrapper and try to augment my workflow." But we also have to think about how it's perceived to I think the more non-technical folks and understand that if they don't have an understanding of how you developed it, they're going to think probably from a place of worse assumptions than you intended and you have to help educate them. I think we're close. I think we're going to start to see some more legislation trickle in across different states over the next 18 to 24 months. I don't think that the US Congress is in a place to get any significant landmark legislation through for quite some time.
Alex: They did crypto. So, it's...
Hamza Siddiqui: The Genius Act was a surprise, I think, a welcome one for a lot of people in many ways. But we're going to start seeing, I think, the industry react to how different regulators are going to set up frameworks. A couple of years ago, NIST came up with their AI framework. And I think that's probably how we're going to start seeing and get at least tea leaves read on what is ultimately going to make its way into legislation.
How are these standards going to be set and what will they translate into?
Alex: And one thing I'm curious — as AI gets better, starts making decisions, not just aiding people, but actually taking on those decisions, who owns the risk, and is that going to be a big question for regulators, the state, and companies like you that need and try to onboard regtechs and AI startups.
Hamza Siddiqui: If you're an investor, if you're a regulator, if you're a boss, you can't really hold a computer accountable. You have to be able to hold somebody accountable. And I think the smartest leaders know that in whatever iteration of where they outsource workflow, low-level decision-making, the accountability lands with the human or the person. And there's that concept of a human in the loop. And I think as we continue to see more sophisticated AI tools that are on that spectrum from just augmenting existing workflows to pushing eventually novel decision-making, you're still going to need, I think, that human element to sign off on whatever constraints are driving a decision, whatever constraints are leveraging the AI decision. And have that accountability exist. From a regulatory point of view, I don't think — I could be wrong.
I don't know how the landscape will change, but I feel pretty confident in saying if you are a bank or a fintech and you say our chief compliance officer is actually this new AI tool, you are probably going to have a very tough life staying above the water. And if you're a company and you say, "We've actually replaced our CEO with this AI tool that's going to drive all of our decisions going forward," your investors are probably not going to be happy because there is that lack of accountability. Accountability remains and for a very long time in the future, I think will remain the key human element. That's going to drive AI adoption, drive AI enablement, and drive AI accountability.
Alex: I think it's interesting. I always compare AI to self-driving cars because even though — and especially for what reading compliance — even though we might make nine out of 10 times better decisions than the humans and find, for instance we've been able at Sphinx to find more true positives that humans can find than whatnot, any single mistake that we will make will be much more dramatic than if a human had done it. Same for a driverless car. It will have the accident rate much lower than human drivers, but when Cruise hit a person in SF, they basically went under. How do you think we're going to be able to change our perception of that so that we understand that, okay, AI does make potentially better decisions than outsourced teams and whatnot. And being able to excuse small errors being made here and there that are less common than with human teams.
Hamza Siddiqui: I love autonomous vehicles. I think they're fantastic. As somebody who walks around the city, bikes around the city, I am grateful to see a Waymo than I am a human driver because of what you mentioned. It's not just at a lower rate. It is at an insanely safe rate that an AV vehicle will operate versus me behind the wheel. And I like to think I'm a careful driver.
I do wonder how much of this is a speed question where we talked a little bit before about the — it's a spectrum. You can either go to market with something totally totally unguarded or you go to the market with something so guarded it's going to be effectively useless. That Waymo could have been something that moves maybe five miles per hour and stops within 20 feet of anything. Totally useless. God-awful experience. Put me on the back of some guy's motorbike at that point.
I do think we as technologists and we as operators and people who are bringing these products to market have an obligation to the consumer, to the marketplace to say, "Here's what we're bringing forward. Here is why we believe it's going to be so much better." And I think continue to prove it out. I don't think we'll ever get to a place where a self-driving car that hits somebody and has zero repercussions. I don't think that's going to happen. And I don't think — we're again back to my whole artificial intelligence CCO or CEO.
This is going to happen. But I do think we need to do a better job of explaining to our fellow consumer of why this is ultimately a better choice and a better experience than what we've had for the last 20 or 30 years. There's a lot of economic anxiety, a lot of the fear of the unknown. And I think when you just start pushing things on people, they're going to default to areas where they've been taught something through a movie or what they've heard in the latest policy paper or have read a study from McKinsey or Bain that says 85% of AI adoption is a failure. Don't even bother checking out those tools.
Alex: No, I love that. Listen, that was really interesting. I do have to zoom out and I do have to talk about this story because it doesn't fit in there but I need to talk about it. We talked about crypto about the Genius Act. You told me last in our last conversation stable coins are useful. Everything else in crypto isn't as much. And then you told me that story about losing 82 bitcoins. And I need to understand, I'll frame it as a question, but what did that experience teach you about UX, custody, and the real world bar for crypto adoption?
Hamza Siddiqui: I have made my peace with losing 82 Bitcoin. Very very early days of crypto. I remember it was a fun little high schooler who had just discovered Tor and I downloaded it just to see what is this dark web thing they talk about and I'm exploring it and I remember going on a forum and somebody's talking about Bitcoin and this stuff and they're like, "Yeah, if you're interested in Bitcoin, I'll send you some. Give me, just give me some gift card or whatever you have." And I said, "All right, I got a gift card that has two bucks on here if you're selling me a transaction." They sent it to me. And I forgot about it. Totally didn't register. You get a new laptop when you go to college.
You get another laptop when it dies 2 years later and you want to fit in with everybody because everybody on college campuses has a Mac and you had an old Windows laptop and you leave it at your mom's house. And then your hard drive corrupts because it hasn't been used and it's a Windows laptop and then you realize in — was it 2015, 2016 — something called Bitcoin is back at I think it touched 20,000 something per bitcoin and you're thinking I know what this is, I had it, I remember exploring it early, let me try to find this wallet of about 82 bitcoins. No luck. Hard drive corrupted.
Alex: That's awful.
Hamza Siddiqui: Didn't write down any of the details in a reasonable place and you make your peace with it until it hits 100K and then you're thinking, "Okay, I really have to try to find this thing." And I did. We were recently helping clean out my childhood home and I found a piece of paper that had five very long mix of numbers and letters. And I thought, "What is this? What could this be?" It was actually just ultimately gibberish.
If it was some kind of — it was 18-year-old Hamza's cipher to protect his data. I don't know what it was.
Alex: So, it's lost twice forever.
Hamza Siddiqui: It's lost twice forever. I was that meme where you look out into the sunset sitting on the swing. That's me. What has it taught me? You achieve a certain amount of zen. No. It highlighted the pros and cons of what the underlying technology is.
There's so much Bitcoin that's essentially lost forever. A lot of people talk about that as a feature. I think about it — I'm a very privileged person. I'm pretty okay with my life. But for some people, Bitcoin in their part of the world is their only way to truly have financial freedom until it's lost somehow.
Somebody hacks it away. You lose access to it for whatever reason. It's gone. It's no different. I know people love to espouse.
Bitcoin is better than cash. It's the same. Once it's gone, it's gone. You burn your dollars. The government isn't going to trust you and say, "Here's another hundred bucks in cash." You lose your Bitcoin, it's gone.
Alex: No, 100%. And the last question about AI. You mentioned your 11-year-old nephew, your 18-month old daughter, and that you're already thinking about how AI fits into your home. Where does AI genuinely help a family today, your family today, and where do you draw the line?
Hamza Siddiqui: That's — I was talking about it earlier. When I design products, I do it with the people in mind. When I'm advising some companies, I'm thinking about what are you building today that's going to make my daughter's life better, easier, safer, sustainable.
For my nephew, it's what are you building that's going to educate him? I think there's a lot of opportunity for how AI can impact education and just the family life. I'm working with a few companies now that are exploring very interesting ideas, so I won't give all of them away, but I think having the ability to leverage AI to be essentially a home manager is going to be pretty exciting for me. My wife kicks butt in addition to all of the things she does at home. I like to think I'm doing okay at my job in addition all the things I should be doing at home.
And we want to have a home that is as efficient as we try to make our workplace in some ways. And I think AI can be a great leverage in that. I would love to have AI be more forward in the education that my nephew is receiving whether it's from traditional sciences to even financial education. AI is going to be such a great companion for that. I also think about the fact that there is an opportunity for AI to truly enable a childhood that looks very different than what the kids have today.
How do you find AI that drives kids to be more physically healthy? I think there's the recent update from ChatGPT around some of the constraints they're introducing and removing. And that is an interesting approach of how do you introduce AI to kids in a way that's going to be safe?
Alex: Cool. Hamza, a quick lightning round before we wrap up. Most overhyped AI use case in fintech right now.
Hamza Siddiqui: Oh, most overhyped. The personal finance assistant.
Alex: All right. Most underrated compliance control that actually moves the needle.
Hamza Siddiqui: Can I say me and my job?
Alex: Perfect. I love it. The hardest part of explaining AI to a regulator in one sentence.
Hamza Siddiqui: The hardest part about explaining AI to regulators is the translation of code into reality. How do you take the software into the physical world?
Alex: One hill you'll die on in compliance.
Hamza Siddiqui: Compliance can be a source of good and I'll leave it there.
Alex: Love it. The one metric you actually trust to prove compliance efficiency.
Hamza Siddiqui: NPS score member or user satisfaction.
Alex: The one thing startups get completely wrong about working with banks.
Hamza Siddiqui: Assuming risk tolerance. That's a question I ask everybody on an interview.
Alex: What could you be when you grow up?
Hamza Siddiqui: If I wasn't in compliance today, I think our old part of me was probably headed off to law school and probably somewhere litigating. I think that's a stereotypical answer, but it's probably the truth.
Alex: Love it. Is there anyone else who should come on our podcast now?
Hamza Siddiqui: Have you met this guy Sam?
Alex: I don't think so.
Hamza Siddiqui: He's running a small company called OpenAI and I think he might have some novel ideas.
Alex: You should give me his number. I'll bring him on next time. But listen, Hamza, it was a pleasure having you here. I really enjoyed the conversation and yeah, let's keep it going and thanks for being on the podcast.
Hamza Siddiqui: Thanks for having me. What a great time.
Alex: Cool. Cheers.
View full transcript
Subscribe to the Podcast


