Case Study – Eightcap
Fast-growing Australian fintech Eightcap is using AI to help manage growing compliance workloads while ensuring customer data complies with privacy, access and data sovereignty requirements across multiple jurisdictions.
Eightcap senior administrator Julius Anuari said operating a global online trading platform meant complying with customer privacy, access governance and data residency requirements that differed across jurisdictions.
That meant engineering, security, and compliance teams all assessed new technology before it was deployed.
“We’re in the fintech business, so we are highly regulated in every jurisdiction,” Anuari said.
“Regulators will have different requirements. In light of that, every tool that we use or try to implement, or feature that comes on … we want to be in a position where it is all above board.
“The compliance team needs to be really across it, the engineering team needs to be really across it, the security team needs to be across it.”
To support that approach, Eightcap has built role-based access controls into its customer relationship management platform, allowing globally distributed sales, onboarding, support, and compliance teams to work from the same customer record while restricting access to sensitive information according to their individual roles.
“We are dealing with teams all over the world that have to speak with the same visibility, so when they are talking to the customer, support knows the same thing that onboarding knows, and sales knows the same thing as well as compliance,” Anuari said.
The company uses Salesforce as the foundation for those operations, with Anuari also serving as its platform lead.
“The security of accessing that information is inherently out-of-the-box with Salesforce, so we are leveraging that,” he said.

Anuari said the company was also focused on meeting privacy obligations that varied between jurisdictions, including customers’ rights to have personal information deleted or provided on request.
“If the customer needs the right to be forgotten, we are able to provide that,” Anuari said. “If the customer asks for information on them, portability information, you have to provide it.”
Those governance foundations have also enabled Eightcap to expand its use of AI, particularly within compliance operations, where staff were required to monitor large volumes of customer interactions across calls, emails, and online chats.
Eightcap is using AI to automate the repetitive work of compliance, including generating call transcripts, summarising conversations, identifying duplicate records, and flagging keywords or customer sentiment for further review.

“(We) let the agentic side deal with volume, and then the human side deal with complexity,” Anuari said.
“Over time, we have actually found that frees up the human agent to just deal with more of the complicated issues.”
This approach has significantly reduced the amount of manual review required by compliance teams, who previously might have to listen to thousands of minutes of recorded calls.
“Now you have the internal AI agent that scavenges through the transcripts … and it generates a summary description’,” Anuari said.
“All of these are flagged on a record, and then depending on who is responsible, the chain of command is followed from there.”
The company was also using AI to analyse customer sentiment, helping distinguish between routine frustration and potentially abusive behaviour that might require escalation.
Anuari said that while the initial focus had been on automating compliance processes, he said Eightcap was now exploring how AI could strengthen internal security by identifying unusual permissions, insider threats, and other anomalous behaviour before incidents occurred. He believed this would be particularly valuable in detecting insider threats.
“While we have been so strong at blocking out the external, most vulnerabilities have happened from within,” he said.
As Eightcap expanded into additional markets, Anuari hoped AI would shift compliance from a reactive process to one that anticipated regulatory requests and automatically assembled the evidence required.
“We are still scaling and reaching global regions that have various compliance requirements,” he said.
“I really want to reduce the time it takes us to provide this evidence. We’re doing the monitoring, but what if we were ahead of it?”

