No idea what you are talking about with AML creating a massive honeypot of data for hackers. If a bank's internal systems were to be widely compromised then stealing a few graph datasets would be the least of their worries. You would have dozens of attack vectors to steal significant amounts of money without the bank finding out quickly.
And compliance issues by HSBC et al is a direct result of a lack of proper AML/KYC systems and processes. So you're making the case that we should roll them out.