Encrypted, cross-bank fraud detection is coming to Luxembourg well before EU rules make information-sharing mandatory in 2027, DESILO Europe explains.
DESILO Europe has set up shop in Luxembourg and is already racing the clock, with Article 75 of the EU’s AML Regulation taking effect in July 2027.
The company’s FHE technology will let Luxembourg banks compare fraud signals across institutions without ever decrypting each other’s customer data.
Silicon Luxembourg spoke with Myoungbee Sung, General Manager of DESILO Europe, who is currently leading DESILO’s European business and activities in Luxembourg, about the roadmap to a first bank pilot, how the technology actually works, and why the company chose Luxembourg as its European base.
Where do things stand with finding a bank in Luxembourg to test your technology, and when might that partnership become public?
Things are further along than you might expect for a company that set up its European entity only recently, and that says a lot about how Luxembourg works.
Our path to bank testing runs on two tracks that are already in motion. The first is our research collaboration with LIST, Luxembourg’s national research and technology organisation, on an RDI project focused on FHE-based fraud detection across institutions. In plain terms, we are building and validating the technical blueprint that lets banks detect fraud patterns across institutions without any of them exposing customer data. The project is designed as a pilot-ready research demonstrator, using rigorously constructed synthetic financial data before any real data is involved. That staging is deliberate: it means a bank can work with us at zero data risk from day one.
The second track is direct market engagement. On 29 September we launch Beyond Silos, our event series at the LHoFT. It brings compliance leaders, technologists and regulatory voices around one table to work through what collaborative fraud detection under the new EU AML framework will actually look like in practice. Several of the institutions we are in conversation with will be in that room. Article 75 of the AML Regulation gives institutions both the permission and, increasingly, the expectation to build information-sharing partnerships. Beyond Silos is where we intend to turn that regulatory momentum into concrete pilot conversations with Luxembourg’s supervised banks.
As for when a partnership becomes public: the research demonstrator comes first, and bank pilots follow directly on its results. We are building toward pilot engagements as the AML framework phases in, and when we do announce one, it will be backed by validated performance on Luxembourg infrastructure.
“The research demonstrator comes first, and bank pilots follow directly on its results.”
Myoungbee Sung, General Manager, DESILO Europe
In simple terms, how does your technology let banks fight fraud together without ever seeing each other’s data?
Picture a sealed laboratory box with built-in gloves. You can put your hands in and work on what is inside, run tests, combine samples and read results, but you can never take anything out, and you never touch it directly. Fully Homomorphic Encryption, or FHE, is the digital version of that box.
Take a money-mule chain, the backbone of most laundering and fraud schemes. Illicit funds enter at Bank A, hop through a mule account at Bank B, split across two accounts at Bank C, and exit at Bank D, often within hours. Each individual hop looks almost innocent. No single institution sees a crime, because the crime is the chain itself, and the chain only becomes visible when the banks’ views are connected. Fraudsters build their operations across institutional boundaries for exactly this reason.
FHE resolves this at the root. Each bank’s data is encrypted before it leaves the bank and stays encrypted at every moment afterwards: in transit, in storage, and, crucially, during the analysis itself. The computation can trace the full pattern, following the chain from Bank A through B and C to D and scoring the network as a whole, while operating entirely on encrypted data. What comes out is exactly one thing: an answer, such as a fraud risk signal on a specific account or transaction. The chain becomes visible. The customers never do. No bank sees another bank’s clients, no central operator holds readable data, and even we as the technology provider cannot see it.
This flips the fundamental question. For decades, banks had to ask whether they trusted each other, and every intermediary, enough to share data. With FHE the question becomes obsolete: there is no readable data to share, so there is nothing to leak, misuse or breach. The protection is not a contract or a promise. It is mathematics.
“The chain becomes visible. The customers never do.”
Myoungbee Sung, General Manager, DESILO Europe
What’s the biggest hurdle — technical, legal, or just convincing banks — before this kind of data-sharing actually happens?
Five years ago the honest answer would have been “all three.” Today the technical barrier has largely fallen, the legal barrier is falling by legislative design, and what remains is the most understandable hurdle of all: institutional caution. That caution deserves respect rather than complaint.
For decades, the safest sentence a bank’s legal counsel could utter about data sharing was “no.” Every collaboration framework on offer relied ultimately on trust, and the bank always carried the liability. Saying no was not conservatism. It was competence.
Two forces are now dismantling the premise behind that “no.” The first is regulatory: Article 75 of the EU’s AML Regulation gives institutions an explicit legal basis for information-sharing partnerships against financial crime, conditional on strong data protection safeguards. Compliance officers here are no longer asking whether collaboration is permitted — they are asking how to do it defensibly.
The second force is technical. Under conventional approaches, “protected” data still exists somewhere in readable form, reachable by a determined attacker, a compromised insider or a breached intermediary. Under FHE there is nothing to reach. The data is encrypted with lattice-based cryptography, the same family of mathematics chosen for post-quantum security standards, and it is never decrypted at any point in the collaboration, by anyone. The guarantee does not depend on the operator’s integrity or the firewall’s strength. It holds even in the scenario every legal team fears most, a successful hack, because exposure is not just forbidden — it is mathematically impossible.
“Exposure is not just forbidden — it is mathematically impossible.”
Myoungbee Sung, General Manager, DESILO Europe
And once that risk is off the table, the business case surfaces quickly: collaboration is not only safer for banks, it is cheaper, catching real networks earlier while wasting far less effort chasing false positives. But I would not be honest if I stopped at efficiency. Behind every mule chain there is a pensioner whose savings were taken, a family that wired money to a scammer, a small business that never recovered. My own background is in applied ethics, and it is the reason I do this work: technology has to prove its ethics in its architecture, not in its marketing.
Why did you choose Luxembourg for DESILO’s European base, and are you planning to grow your local team?
We evaluated Europe systematically, and Luxembourg won on a criterion most location analyses underweight: density with depth. A technology like ours needs a sophisticated regulator, a banking community concentrated enough that collaboration across institutions is realistic, research partners who can engage with advanced cryptography, and computing infrastructure heavy enough to validate it at scale. Luxembourg is the only place we found where the entire chain sits within a few kilometres of itself: the CSSF, the ABBL and its member banks, the fintech community at the LHoFT, research institutions like LIST, and the national supercomputer MeluXina.
The decision was sealed by how the ecosystem behaved once we engaged. Luxinnovation guided our establishment hands-on and compressed what is normally months of friction for a foreign company into weeks. LIST engaged with us as a research partner, not as a vendor. The LHoFT gave us a platform and a community. One conversation reliably produced three more.
And yes, we are building in the fullest sense. We begin local hiring later this year, I am personally relocating to Luxembourg this autumn, and in September we launch Beyond Silos at the LHoFT. We did not come to open a European office. We came to become a European company, one that helps this financial centre show the world what privacy-preserving collaboration looks like when it is done right.
“We did not come to open a European office. We came to become a European company.”
Myoungbee Sung, General Manager, DESILO Europe
The UK has tried similar approaches to sharing fraud data between banks — what have you learned from that experience?
We have studied those efforts closely, and I would put the Netherlands’ Transaction Monitoring Netherlands (TMNL) in the same family. They are collectively the most valuable market research our field has ever received, and they taught the industry two lessons.
The first is that demand is real and senior. When banks were offered even a partial legal pathway to collaborate against fraud, major institutions stepped forward voluntarily and stayed at the table for years. The appetite exists at board level, because financial crime is a cost every bank shares and no bank can solve alone.
The second lesson is harder: legal permission plus goodwill is still not enough. These initiatives kept colliding with the same wall. The moment collaboration required actually exposing customer data, privacy law, liability exposure and competitive sensitivity reasserted themselves. Anonymisation forces a bad trade: strip enough identifiers to be safe and you lose exactly the linkages fraud detection depends on; keep the linkages and re-identification risk returns.
The natural question is why FHE, which solves this cleanly in principle, was not part of those initiatives. The answer is simple: until recently it could not do the job in practice. FHE has been mathematically sound since 2009, but early implementations ran thousands to millions of times slower than computing on plain data. What changed over the past several years is a compounding of better algorithms, better engineering and hardware acceleration that has closed that gap by orders of magnitude, and DESILO has spent years specialising in exactly that problem — optimising the full stack from cryptographic schemes down to hardware, applying it to financial data through our work in Korea’s financial sector. It is also why access to MeluXina matters to us: we intend to validate that performance at realistic scale, on infrastructure Luxembourg institutions already trust. The earlier initiatives proved the “why.” We believe Luxembourg is where the “how” gets demonstrated first.
“The earlier initiatives proved the ‘why.’ We believe Luxembourg is where the ‘how’ gets demonstrated first.”
Myoungbee Sung, General Manager, DESILO Europe