Burning Question: How often does an AI model need to be retrained?


As a non-expert, I asked Claude:

Let’s assume I am the sanctions officer at a company with a fair number of high-risk segments of my business – not a small number, but nowhere near a majority. And we built an Ai model to evaluate transactions, documents and third party records for sanctions matches, such that the model recommends and presents all its research for a human to evaluate. Based on changes to Russian and Iranian sanctions from July 1, 2024 to June 30, 2026, including changes in designations, guidance, licensing and any other relevant content published by UK, EU and/or U S regulators, how many times would we have likely needed to retrain our model over that 24 month period? Explain when and why, in non-legal language (not a lawyer). check your response against your sources and flag and correct anything that is not well-supported by them. List your sources. Assume that my firm has a pretty full range of exposure, including crypto, securities and maritime shipping.

And the response:

Quick framing before the timeline: your model does two different jobs, and they don’t need retraining at the same rate.

One job is matching against reference data – SDN entries, the EU consolidated list, the UK sanctions list, vessel IMO numbers. That data changes constantly (weekly, sometimes daily) and shouldn’t require retraining at all if the system is built the way most of these tools are – list content lives in a lookup layer, and the model just queries it. That’s a data refresh, not a retrain.

The other job is pattern recognition – reading a bill of lading and recognizing deceptive shipping language, following an ownership chain through three shell layers, flagging a stablecoin flow that looks like sanctions evasion. That’s the part that goes stale when the underlying typology changes – a genuinely new evasion pattern, a new category of prohibited conduct, a new legal test for what counts as “control.” That’s what actually calls for retraining.

I’m assuming your model is architected with that separation (list-matching decoupled from typology-modeling), since that’s how compliance vendors generally build these systems. If yours instead has entity names baked into model weights, the honest answer is “constantly” – so it’s worth confirming that assumption internally.

With that framing, here’s my read of the 24 months.

Bottom line

My estimate: somewhere around 6-7 retrain-worthy events, clustering unevenly rather than spread on a fixed cadence. About three of those are large enough (new prohibition categories, a rebuilt legal architecture, a switch from name-by-name matching to categorical rules) that I’d call them full retrains rather than targeted updates.

The waves, in plain terms

1. October 31, 2024 – OFAC maritime shipping guidance. Treasury published scenario-based guidance describing deceptive shipping patterns – falsified bills of lading, AIS location-spoofing to hide ship-to-ship transfers, SDN proxies buried in trade documents issued to help maritime sector stakeholders identify new or common fact patterns indicative of sanctions evasion and address common counterparty due diligence issues. If your document-review component wasn’t already trained to recognize these fact patterns, this is the kind of thing that needs to go into the model, not just a rulebook update.

2. December 2024 – January 2025 – the shadow fleet buildout. EU package 15 introduced targeted measures against vessels used to circumvent sanctions, the “shadow fleet,” and for the first time imposed full sanctions on third-country actors including Chinese entities. Then, on January 10, 2025, OFAC issued sweeping new sanctions targeting Russia’s energy sector, including a new petroleum services ban, expanded secondary sanctions authority, and designations of Russian oil producers, insurance providers, and more than 180 shadow fleet vessels, done in parallel with the UK, which designated Gazprom Neft and Surgutneftegas the same day, followed by OFAC and OFSI publishing a memorandum of understanding to strengthen cooperation. A brand-new prohibition category (petroleum services) plus expanded secondary-sanctions exposure for foreign banks is a genuine typology addition, not a list update.

3. February 2025 – Iran’s posture flips. National Security Presidential Memorandum 2, issued when Trump took office, formally reinstated the “maximum pressure” strategy against Iran and significantly expanded its scope. In parallel, EU package 16 hit energy, trade, transport, infrastructure and financial services and added listings touching Russian crypto-asset exchanges and the maritime sector for the first time. This is where “Iran risk” stops meaning “drones and human rights” and starts meaning a full petroleum-sector campaign – a different thing for a model to detect.

4. March – May 2025 – the campaign gets teeth, and it’s China-shaped. OFAC’s Iran push became a near-monthly cadence targeting Chinese “teapot” refineries and Iranian shadow-banking exchange-house networks – since February 2025, OFAC sanctioned over 1,000 Iran-related persons, vessels, and aircraft as part of this campaign. Treasury also updated its 2019 maritime evasion guidance on April 16, 2025, as part of implementing NSPM-2. Separately, US and European law enforcement seized Garantex’s web domain and froze over $26 million in cryptocurrency on March 6, 2025. The teapot-refinery and exchange-house patterns are genuinely novel fact patterns for a model that was probably trained mostly on Russia-shaped typologies.

5. July 2025 – the oil price cap stops being a fixed number. EU package 18 introduced an automatic and dynamic mechanism to modify the oil price cap so it stays roughly 15% below the average market price for Russian crude, reviewed every six months, alongside the first-ever full transaction bans on Chinese crypto-asset service providers and on two Chinese financial institutions found to be frustrating EU sanctions. If your model treats “is this deal above the price cap” as a static threshold check, that logic now needs to track a moving, scheduled value – a structural change, not a data point. The UK matched the cap cut and published its first Cryptoassets Threat Assessment on July 21, 2025.

6. August – October 2025 – the densest stretch of the whole window. Four things landed close together: OFAC sanctioned a network tied to the shuttered exchange Garantex and its successor Grinex, along with the ruble-backed stablecoin A7A5, which had been moving roughly a billion dollars a day – a genuinely new evasion typology (sanctioned-bank-backed stablecoin as a settlement rail). Then the E3 invoked the UN “snapback” mechanism on August 28, 2025, resulting in full reimposition of UN sanctions on Iran effective September 27, 2025, and the EU and UK reintroduced autonomous sanctions measures against Iran that had been eased in 2015 – not new listings, but a wholesale rebuild of the Iran sanctions architecture back toward its pre-2015 scope. Days later, EU package 19 introduced specific binding legal definitions of “ownership” and “control” for designated entities – directly relevant to any third-party-ownership-chain logic your model runs. And on October 22, 2025, OFAC designated Rosneft and Lukoil, Russia’s two largest oil companies, under Executive Order 14024 – the first designation by the Trump administration of Russian actors under the war-related sanctions authorities, a sharp reversal after a year in which Russia designations had dropped to 74 total, down from over 3,000 in 2024. Any one of these would justify a retrain; together, this is the strongest single cluster in the 24 months.

7. April 2026 – crypto logic changes shape, not just scope. EU package 20 added a ban on EU operator engagement with the Russian national payment card system Mir or the faster payments system SBP – a payment-rail typology your model may not have needed before – and, more structurally, shifted crypto enforcement away from naming specific platforms or tokens toward a blanket prohibition on transactions with crypto-asset service providers in designated categories. That’s a different kind of rule to encode: a categorical, jurisdiction-based test rather than a name-match.

One thing just outside your window worth flagging for context: EU package 21 landed July 23, 2026 amending Regulation 833 and Regulation 269, entering into force the following day – three weeks after your June 30 cutoff, so I’ve left it out of the count, but it’s the next wave you’d hit almost immediately.

On your specific exposure

  • Maritime: the heaviest thread by far – the October 2024 guidance, the shadow fleet buildout across essentially every EU package, and the UK’s escalation to active tanker interdiction in 2026 all sit here.
  • Crypto: three distinct shape-changes, not just more designations – individual exchange listings (early 2025), first-ever crypto-service-provider transaction bans (mid-2025), then a categorical/jurisdictional ban (2026). Plus the stablecoin typology from Garantex/A7A5, which doesn’t resemble earlier crypto sanctions patterns at all.
  • Securities: thinner, but real – EU’s central-securities-depository protections (package 15), the Russian Direct Investment Fund transaction ban (package 18), and a non-binding CJEU Advocate General opinion from September 25, 2025 advising that “freezing of funds” should be read broadly enough to cover voting rights and participation rights of depository-receipt holders – worth watching since it isn’t yet a final ruling.

Checking this against my sources

What’s solid: every date, designation, and mechanism description above comes directly from primary sources (Consilium, OFAC/Treasury releases, OFSI notices) or law-firm client alerts summarizing them, and I’ve kept the sourcing tight to those.

What’s my judgment layered on top, not something any source states: which of these events “would” trigger a retrain, and the total count of 6-7. No regulator or vendor publishes a “here’s when compliance AI needs retraining” schedule – that’s an inference I’m drawing from the nature of each change (new prohibition category vs. more names on an existing list), and a different model architecture or risk appetite would land on a different number. Treat the count as a reasoned estimate, not a fact.

Two things I want to flag rather than let sit unqualified: the CJEU item is an Advocate General opinion, not a binding judgment – I’ve labeled it that way above. And the “over 1,000 Iran designations” figure is cumulative as reported in an April 2026 source, so it’s close to but not exactly aligned with your June 30, 2026 cutoff – the true count at your exact end date is very likely a bit lower.

One gap: I did not attempt to catalogue every individual OFAC Iran designation round (there were dozens) or every weekly OFSI list update – that would run to hundreds of entries and wouldn’t change the retrain analysis, since after the first round establishes a typology (teapot refinery, shadow banking exchange house), subsequent similar rounds are list updates, not new patterns.

Sources

EU: Consilium timeline of Russia sanctions packages · package 15 (White & Case) · package 16 (FieldfisherBaker McKenzie) · package 17 (White & CaseDLA Piper) · package 18 (White & CaseGide) · package 19 (SkaddenConsilium press release) · package 20 (Morgan LewisMayer Brown) · package 21, for context (Skadden) · CJEU depository-receipt opinion (Sullivan & Cromwell) · EU Iran snapback (Mayer Brown)

US: OFAC maritime guidance, Oct. 2024 · Jan. 10, 2025 Russia energy action (Cleary Gottlieb) · 2025 Trump Russia sanctions pace (CNAS) · Rosneft/Lukoil designations (Steptoe) · NSPM-2 and “Economic Fury” campaign (Treasury) · Iran maritime evasion advisory update (Miller & Chevalier) · Garantex/Grinex/A7A5 (TRM Labs)

UK: OFSI Jan. 2025 Gazprom Neft/Surgutneftegas + OFAC MOU (Covington) · UK “largest ever” shadow fleet package, May 2025 (Mayer Brown) · UK price cap cut + first Cryptoassets Threat Assessment, July 2025 (Skadden) · UK Rosneft/Lukoil, Oct. 2025 (Squire Patton Boggs)

UN/multilateral: Snapback mechanics (Congress.gov CRS) · G7 statement on snapback


Leave a Reply

Discover more from Mr. Sanctions

Subscribe now to keep reading and get access to the full archive.

Continue reading