For years, sanctions screening has operated on a relatively simple premise:
Find the name. Check the list. Decide whether it’s a match.
It’s logical. It’s measurable. And it’s increasingly incomplete.
That model makes sense when the thing you’re looking for stays relatively still.
But sanctions risk doesn’t.
Entities adapt. Relationships change. Payments move through new channels. Ownership structures shift. Digital assets can move across wallets and blockchains in seconds.
The result is a fundamental mismatch:
We’re trying to manage moving risk with systems designed to find stationary targets.
The problem isn’t that sanctions screening can’t find enough matches. It’s that a match is only a snapshot of risk at a moment in time.
That creates an uncomfortable possibility: a screening system can work exactly as designed and still miss how the risk has changed.
Recent events show just how quickly that gap can emerge.
When the target moves
Consider what happened with HTX.
On May 26, 2026, the UK designated Huobi Global S.A., identified on the UK Sanctions List as HTX (formerly Huobi), under its Russia sanctions regime. The designation included an asset freeze and restrictions related to correspondent banking and payment processing.
Then the target started moving.
In the seven weeks following the designation, blockchain intelligence firm TRM Labs reported that HTX restructured its on-chain infrastructure, rotating hot wallets and funding addresses across TRON, Ethereum, BNB Smart Chain, and Solana. According to TRM, some addresses were being retired within hours, making fixed address lists quickly outdated.
Think about what that means for screening.
A static approach can answer:
“Is this wallet on the list?”
But if the same sanctioned entity begins operating through a new wallet, that question is no longer enough. The new address may not appear on the original sanctions list, even though the activity behind it is tied to the same entity.
The more important question becomes:
“Is this new wallet or activity connected to the sanctioned entity?”
That is a fundamentally different problem. Instead of simply matching an identifier against a list, compliance teams need to understand the relationships behind the activity.
The wallet may change. The entity behind it, and the sanctions risk it represents, may not.
That illustrates a much broader challenge for sanctions compliance:
The identifier can change without the risk changing.
The risk doesn’t always sit in the name
The same principle extends well beyond digital assets.
In June, the UK’s Office of Financial Sanctions Implementation announced a penalty of more than £1 million against Sabre Global Technologies Limited, the largest UK penalty for breaches of Russia-related financial sanctions since the 2022 invasion. OFSI found that Sabre continued providing services to designated Russian airline Ural Airlines and tested alternative payment routes to circumvent sanctions restrictions. OFSI also identified weaknesses in staffing, processes, senior oversight, and the company’s ability to assess and mitigate sanctions risk.
This wasn’t simply a question of whether a sanctioned name could be found on a list.
It was about understanding what was happening around that entity.
Who is the customer connected to?
Who owns or controls the entities involved?
What services are being provided?
Where are payments actually flowing?
Are counterparties or payment routes changing?
And perhaps most importantly:
What has changed since the last time we looked?
Those are intelligence questions, not simply matching questions.
Meanwhile, the perimeter is expanding
The challenge is becoming more urgent because sanctions obligations are expanding into parts of the financial ecosystem built for speed and digital-first transactions.
Under the GENIUS Act, permitted payment stablecoin issuers are being brought into a formal AML and sanctions compliance framework. In April, FinCEN and OFAC proposed rules that would treat permitted payment stablecoin issuers as financial institutions for Bank Secrecy Act purposes and require them to adopt and maintain effective sanctions compliance programs.
That means organizations operating some of the financial system’s newest infrastructure are being asked to manage one of its oldest compliance challenges.
At the same time, sanctions regimes themselves continue to evolve.
In June, OFAC and OFSI published joint guidance comparing key elements of the U.S. and UK sanctions regimes. The guidance addresses areas including sanctions lists, licensing, reporting, and recordkeeping requirements, while highlighting similarities and differences between the two regimes.
The direction is clear:
Sanctions compliance can’t be treated as simply a list-management problem.
It increasingly requires intelligence about entities, relationships, activity, and change.
What if matching is the wrong finish line?
If risk is a moving target, the goal of sanctions screening can’t simply be to produce a better match.
It has to help compliance teams understand what that match means.
That requires answering a different set of questions.
Who is this entity, really?
Entity resolution can help distinguish a legitimate customer from another person or organization with a similar name, while accounting for aliases, transliterations, name variations, and other identity signals.
What is this entity connected to?
Ownership and network intelligence can expose relationships that may not be apparent from an individual record alone.
What is happening around this entity?
Contextual intelligence can help analysts understand whether a potential match represents meaningful sanctions exposure.
What has changed?
Continuous monitoring can surface new information and relationships that alter an entity’s risk profile over time.
And when potential risk is identified:
Why does it matter, and what should an analyst investigate next?
This is where AI has the potential to do more than generate another alert. It can help bring together the evidence, relationships, and context analysts need to investigate potential risk more efficiently.
The goal isn’t more sophisticated matching for its own sake.
It’s better intelligence about risk.
You can’t solve a moving-target problem with a static view
There will always be a role for sanctions lists. There will always be a need to screen names, entities, payments, wallets, and other identifiers.
But the HTX example exposes the limitation of treating that as the finish line.
A wallet changes.
An intermediary appears.
An ownership structure shifts.
A payment takes a different route.
A new relationship emerges.
The identifier changes. The underlying risk may not.
That changes what we should expect from sanctions technology.
The question is no longer simply:
“Did we find a match?”
It’s:
“Do we understand the risk?”
Because when risk is a moving target, finding where it was yesterday isn’t enough.
Sanctions screening needs to keep up.