Most conversations about “AI compliance” flatten a large market into a single category. In practice, compliance software automates three different kinds of work, each with different buyers, incumbents, data, and technical difficulty:
Regulatory intelligence - know the rules. Ingest, track, and interpret regulations and regulatory change, then turn them into structured, monitored obligations.
Compliance decisioning - decide the case. Apply external regulations, internal policies, and prior decisions to a customer, transaction, document, communication, vendor, or questionnaire.
Compliance operations - execute the workflow. Gather evidence, route cases, capture approvals, file, remediate, and preserve an audit trail.
The three layers also reflect how the market has developed. Regulatory intelligence is the oldest and most mature category; regtech companies have sold regulatory data and change-management software for more than a decade. Decisioning is where many AI-native startups begin because case-level review is bounded, measurable, and well suited to language models. Operations is the current frontier, as agents become capable of handling variable, unstructured, multi-step work across documents and systems.
Autonomous execution is starting to appear in specific, lower-risk workflows, but broad autonomy barely exists. The constraint is partly model reliability and partly whether institutions, regulators, and customers are willing to let a machine make and act on a consequential decision.
I think that value and defensibility generally increase as a product owns more of the decision-to-action loop. A company does not need to begin with regulatory intelligence or move through every layer in order. But products that move from providing information to owning decisions, execution, and governed authority capture more of the workflow, more institutional memory, and more control over how compliance work gets done.
1. Why compliance AI is suddenly investable
a16z ’s Everything, Everywhere Is Compliance, published by James da Costa and Angela Strange in May 2026, makes the macro case. The United States has more than 400,000 compliance officers representing over $40 billion in annual labor spend. The work is also becoming harder to staff, with annual churn above 20% while regulatory complexity continues to grow.
The market was already large. What changed is how much of the work software can perform. Vision-language models can interpret documents that traditional OCR could only extract, while frontier models have improved at reading rules, applying them to facts, and identifying exceptions. Computer-use and longer-horizon agents extend this beyond review, allowing systems to carry context across documents, databases, and legacy applications. Benchmarks are not proof of production reliability, but they show that the addressable workflow is expanding.
The buyer calculus is changing as well. Faster KYC improves onboarding, faster marketing review increases speed to market, and better investigations reduce backlogs. Compliance software is no longer sold only as a way to reduce headcount or avoid fines. YC’s Fall 2026 Requests for Startups reflects that shift, calling for AI-native infrastructure that replaces fragmented tools and manual workflows.
a16z describes compliance as regulation, the software trying to codify it, and the people connecting the two. The three layers in this piece describe which part of that human work a product automates; the autonomy axis describes how much responsibility moves to the system.
2. The three layers of compliance AI
How AI moves from interpreting regulation to executing compliance work
Layer 1 — Regulatory intelligence: know the rules
Regulatory intelligence turns a constantly changing body of regulation into something a compliance team and eventually an agent can act on. The workflow begins with horizon scanning but continues through a consolidated rules inventory, applicability analysis, obligation extraction, and mapping to internal policies, procedures, controls, risks, and owners. Provenance has to remain intact throughout, because the company needs to know where an obligation came from, which version was in force, and what changed.
Regulatory source → obligation → policy → procedure → control
This is the oldest and most mature layer. Regtech companies have collected, classified, and distributed regulatory information for more than a decade, so the market already has established buyers, large incumbents, and recognizable product categories.
It is also consolidating. CUBE acquired Thomson Reuters Regulatory Intelligence and Oden in 2024. The combined company now covers more than 750 jurisdictions and employs close to 250 regulatory subject-matter experts and legal and compliance professionals alongside its AI products. Other established players include Wolters Kluwer, Corlytics, in which Verdane made a majority investment in 2024, and Compliance.ai, which Archer acquired in the same year.
Bloomberg Industry Group’s acquisition of Regology in June 2026 follows the same logic. Bloomberg combined its legal, tax, and government information with software that monitors regulatory change, determines which rules apply to a particular company, and connects those changes to internal policies, risks, and controls.
AI changes this layer by turning regulatory content into company-specific work, moving the product from identifying the rules toward deciding how they apply.
Ascent is a good example. Its platform creates company-specific obligation inventories and maps them to internal policies, procedures, and controls. Its acquisition of Waymark in 2024 combined horizon scanning with obligations management, extending the product from detecting regulatory change to showing where that change matters inside the institution.
Layer 2 — Compliance decisioning: decide the case
Compliance decisioning applies external regulations, internal policies, and prior decisions to a specific customer, transaction, document, communication, vendor, or questionnaire. The system evaluates the facts and produces a determination or draft supported by evidence, rationale, and citations. Where the answer is uncertain or the risk exceeds a defined threshold, it escalates the case to a human reviewer.
Case facts + rules + policy + precedent → determination + rationale + evidence
The distinction from regulatory intelligence is simple. Regulatory intelligence determines what the business must do in general; compliance decisioning determines what it should do in this case. Its central value is replacing hours spent searching policies, source documents, evidence, and prior decisions with a grounded first determination that a reviewer can verify.
This is a natural starting point for AI-native companies because the work can be bounded and evaluated. A buyer can compare the system’s conclusions with those of experienced reviewers, measure reductions in review time, and test whether similar cases produce consistent results. The product does not initially need authority to approve or file anything. It can create value by completing the first pass and sending exceptions to the appropriate reviewer.
I would draw the line here: a decisioning product applies governed rules, company policy, or precedent to a specific set of facts and produces an answer that can be checked against a human reviewer’s. That distinguishes compliance decisioning from generic document generation or retrieval.
This decisioning pattern is appearing across several compliance workflows.
Marketing and communications review. Companies including Norm Ai, Sedric, and Hadrius translate requirements such as UDAAP, SEC and FINRA rules, regulatory guidance, and internal company policy into review criteria that can be applied to financial-services marketing. The systems review advertisements, emails, websites, social posts, and other customer communications for prohibited claims, missing disclosures, unsupported statements, and policy violations.
Life sciences has a specialized version of the same workflow called medical, legal, and regulatory review. Veeva’s acquisition of Copli and launch of Falcon MLR in June 2026 brought agentic review of promotional and medical content into Veeva’s existing life-sciences platform. The acquisition validates marketing review as a decisioning wedge, but it also shows the strategic risk: an incumbent that already owns the content and approval workflow can absorb the review product.
DDQs, RFPs, and security questionnaires. Products such as 1up, Arphie, and Tribble generate answers from approved company materials, policies, prior responses, and supporting evidence. The value is not simply writing prose faster. It is determining which source is authoritative, retrieving previously approved language, attaching evidence to each answer, and routing low-confidence responses to the person qualified to approve them.
Third-party risk. Coverbase analyzes questionnaires, contracts, and third-party evidence against a company’s controls, surfaces exceptions, and produces a risk assessment. Its broader platform also handles vendor intake, evidence collection, follow-ups, continuous monitoring, and remediation. The risk determination sits in decisioning, while the surrounding vendor lifecycle pushes the product into compliance operations.
KYC, KYB, and financial-crime review. Arva AI applies an institution’s policies across customer and business onboarding, sanctions screening, and transaction-monitoring alerts. It assembles the relevant identity, ownership, transaction, and screening data, produces a risk determination supported by evidence, and routes uncertain or higher-risk cases to human investigators.
Parcha initially offered a similar product focused on automating KYC, KYB, and compliance reviews for banks and fintechs. It has since retired that product line and relaunched as Grep AI, applying the agent architecture it developed in financial-services compliance to a broader set of research-intensive, high-stakes workflows.
At the same time, the identity platforms underneath these products are moving into the same decisioning and workflow layer. Persona, which raised $200 million at a $2 billion valuation, has expanded from identity verification into automated decisions, follow-ups, workflows, and case management.
I think this is the more important takeaway from Parcha’s pivot. The KYC and KYB platforms underneath standalone AI reviewers are expanding into decisioning and workflows themselves, leaving less room to build a durable moat at the review layer. The larger opportunity is to own the case, the workflow, or proprietary data or to take the underlying agent architecture into a broader market, as Parcha did.
Product and trade compliance. Trava and Complir use the same underlying architecture: translate a body of regulation into machine-readable logic, map it to product data, and make a product-level compliance determination.
Audit and regulatory submissions. Denki collects evidence, tests controls, and produces traceable workpapers for internal-audit and compliance programs. Ritivel turns clinical data and prior submissions into reproducible, source-linked drafts for life-sciences filings. Both begin with decisioning but move into operations as they assemble the evidence and produce the auditor- or regulator-ready document.
The durable asset in decisioning is not access to the model. It is the system built around it: the mapping between regulations and company policy, the evidence supporting each conclusion, domain-specific evaluations, and the institutional memory created as reviewers accept, reject, or modify recommendations. Capturing why a reviewer overrode the system is especially important, because that is how individual judgments become reusable precedent rather than disappearing into an audit log.
Decisioning is therefore both an attractive entry point and an unstable place to stop. It creates measurable value without requiring the product to act autonomously, but it becomes more embedded when it also gathers evidence, routes exceptions, manages approvals, and records the final outcome. That is the natural path from decisioning into compliance operations.
Layer 3 — Compliance operations: execute the workflow
Compliance operations automates the work that compliance analysts and operations teams perform to move a case from intake to closure. This includes gathering evidence, researching across systems, requesting missing information, routing the case, capturing approvals, preparing filings, managing remediation, and preserving an audit trail. Decisioning provides the judgment within the case; operations carries the case through the governed workflow.
Intake → evidence → decision → approval or action → audit record
Workflow automation is not new. Traditional systems can move a case through a predefined sequence, but they generally depend on structured inputs and explicit rules for every step. When a document is incomplete, an answer is ambiguous, or the next action depends on information scattered across several systems, a person has historically carried the context and determined what to do next.
Agents expand the kind of work software can perform. They can read unstructured documents, retrieve information from multiple systems, determine which evidence is missing, adapt the next step, and operate the applications through which compliance work gets completed. The workflow still needs defined permissions, approval gates, and escalation rules, but it no longer has to anticipate every possible path in advance.
Several companies illustrate how this layer is developing.
Financial-crime operations. Unit21 began as a fraud and AML platform and is adding agents inside the system where alerts, investigations, and regulatory filings already live. Its agents gather evidence, investigate cases against the institution’s procedures, recommend dispositions, draft regulator-ready narratives, and produce a transparent log of the data accessed and steps performed. The institution continues to define its risk appetite, thresholds, approval requirements, and escalation paths.
SOX testing. Petual imports a company’s risk and control matrix, maps evidence to the relevant controls and samples, executes the prescribed testing procedures, and generates audit-ready workpapers. Deviations are surfaced for review and remediation. The determination whether the control operated effectively is decisioning; collecting the evidence, performing the test, documenting the result, and moving exceptions toward resolution are compliance operations.
Financial licensing. Brico manages the operational work surrounding state financial licenses, including applications, renewals, periodic reports, amendments, and status tracking. Licensing is a particularly clear operations workflow because the work extends far beyond determining which licenses are required. Companies must assemble information from across the business, complete forms, track jurisdiction-specific deadlines, respond to deficiencies, and maintain each license after approval.
There are two routes into compliance operations: incumbents can add agents to their existing systems of record, while agent-first companies can absorb the workflow, integrations, and case data around them. a16z frames the buyer’s choice as keeping the incumbent as a backend, rebuilding internally, or buying an AI-native replacement. YC similarly points toward AI-native products that consolidate fragmented compliance tools.
I think the two routes converge. Incumbents will add agents, while agent-first companies will build toward systems of record. Both want to own not only the final decision but how the work was performed: the evidence, policy, exceptions, approvals, and outcome. That execution history becomes institutional memory and makes the product the place where compliance work is executed, governed, and remembered.
3. The trust stack: what gives AI permission to act
The three layers describe what a compliance product does. The trust stack describes what it needs to do that work reliably, safely, and within the institution’s authority. The more judgment, workflow, and consequential action a product assumes, the more of this infrastructure it needs.
Understanding the work
Document competence: Read PDFs, Word documents, spreadsheets, screenshots, IDs, filings, questionnaires, and marketing assets without losing the structure or context that controls the decision.
Company context and master-data mapping: Connect regulations, evidence, and decisions to the company’s legal entities, customers, products, accounts, jurisdictions, controls, owners, and systems. Without that mapping, the system may understand the rule but apply it to the wrong part of the business.
Grounding the decision
Traceability: Tie every material conclusion to the evidence, internal policy, and regulatory language supporting it. The system needs to show not only which sources it retrieved, but why they governed the decision.
Institutional memory: Preserve prior filings, decisions, approved and rejected language, exceptions, reversals, and precedent. That history must remain linked to the policies and rules in effect at the time.
Auditability: Record who or what decided, when, under which policy and model version, and any human review or override.
Governing the system
Permissions and information barriers: Treat access as a first-class control. The system should retrieve information, expose cases, and use tools only within the boundaries of the user, entity, jurisdiction, and task.
Authority: Distinguish between permission to read, recommend, escalate, approve, file, reclassify, contact a customer, and change a system of record. Each action requires its own authorization boundary.
Human control: Support review, correction, rejection, and escalation when evidence is incomplete, policy is ambiguous, risk is high, or human judgment is required by law or internal policy.
Executing the workflow
Workflow orchestration: Sequence the work, route cases, manage handoffs, enforce approval gates, and escalate exceptions from intake through final disposition. Historically, this connective tissue was a person carrying context between documents, inboxes, databases, and applications.
Operational competence: Perform the concrete actions inside the workflow-redline a document, populate a template, preserve formatting, request missing information, upload evidence, submit a filing, export an artifact, and write the outcome back to the correct system.
A regulatory-intelligence product may only need a subset of these capabilities. A decisioning product needs most of them in at least a basic form to produce reliable case-level judgments. An operations product and especially one acting with limited human involvement needs the full trust stack because its mistakes can propagate into customer communications, filings, approvals, and systems of record.
The trust stack converts model capability into operational permission. It is what allows a compliance product to move from advising to doing, and eventually to acting within defined limits.
4. The autonomy frontier
Autonomous compliance closes the loop. The system detects an issue, gathers context, makes a determination, takes an authorized action, records its rationale, and updates the relevant systems of record. Humans define the guardrails and supervise exceptions rather than executing every routine case.
Detect → investigate → decide → act → record → monitor
This is different from rules-based automation, where the trigger, logic, and response are specified in advance. An autonomous agent can navigate a variable path, determine what evidence it needs, choose which tools to use, and resolve ambiguity. The hard part is not giving it the ability to act; it is making sure it stops when it lacks the evidence, confidence, or authority to continue.
Unit21 and Chartis Research’s agentic AI maturity spectrum frames autonomy as a progression:
Rules-based automation: Predefined conditions trigger deterministic workflows.
AI-assisted: The system recommends actions, but humans perform the work and decide.
Agentic with human oversight: Agents execute the workflow, while humans approve material decisions.
Autonomous within governed limits: The system completes permitted decisions and actions, while humans supervise exceptions and quality.
These levels are configured by workflow, jurisdiction, risk tier, and action. A system might close a low-risk false positive, recommend an outcome on a medium-risk case, and require explicit approval before rejecting a customer or submitting a regulatory filing. “Human in the loop” is not one setting; it is a set of controls around individual actions.
The constraint is both technical and institutional. The system has to remain reliable, recognize incomplete evidence, and produce a defensible record of what it did. The institution has to determine what can be delegated, scope the agent’s authority, and assign accountability when it errs. Autonomy will therefore arrive workflow by workflow, and the ability to act safely and prove why the action was appropriate may become one of the deepest moats in compliance.
5. Where founders should start
The best entry point is usually a narrow, expensive workflow with a visible output and a human process against which the product can be evaluated.
Regulatory intelligence works as a starting point when rules change frequently across jurisdictions and the product can propagate those changes into policies, controls, risks, and owners. A better summarizer is not enough in a mature and consolidating market. The product needs to determine applicability and connect regulatory change to company-specific work.
Compliance decisioning works when there is a high-volume review task with a clear human benchmark: marketing review, KYC analysis, alert triage, medical review, product classification, vendor assessment, or due-diligence questionnaires. Decisioning makes it relatively easy to demonstrate value, but it is also easier for an incumbent to bundle if the startup does not capture the surrounding evidence, precedent, or workflow.
Compliance operations works when the process spans multiple systems and produces a durable artifact: an investigation, filing, license, audit workpaper, approval record, or completed onboarding case. This is where a startup has the clearest path to owning the system of record for the work, because the product captures not only the result but the evidence, approvals, exceptions, and execution history behind it.
Autonomy should be a direction, not a day-one claim. A company earns the right to automate consequential actions workflow by workflow, after proving reliability and building the necessary permissions, evaluation systems, escalation paths, and audit controls. The strongest initial use cases are usually routine, high-volume decisions with clear policy boundaries and a safe path for escalation.
The founder test is simple:
Does the product only tell the customer what is compliant, or is it becoming the place where compliant work is executed, governed, and remembered?
The first can be a valuable tool. The second has a stronger path to becoming infrastructure.
6. From compliance answers to compliance actions
Not every company needs to span all three layers. Regulatory-intelligence and decisioning products can remain valuable on their own, but a company selling an agentic future needs to own more of the loop: the workflow, evidence, permissions, decision history, and eventually the authority to act.
The more of that loop a product owns, the harder it becomes to replace. Most compliance AI today helps companies determine what is compliant; the next generation will make the work compliant, and eventually keep it that way.


