In short: as of September 2026, four vendors sell agentic AML operations to financial institutions: Castellum.AI, Bretton, Sphinx and Zyphe. All four deploy AI agents that screen customers, resolve alerts and prepare cases for human approval. The difference is which supervisor they were built for. Castellum.AI, Bretton and Sphinx each frame their compliance posture around United States banking supervision, citing the OCC, the NCUA, the New York Department of Financial Services, the California DFPI, the FDIC and the Federal Reserve on their own websites. None of the three publicly addresses Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation, whose Article 18 governs how an EU obliged entity may outsource AML work from 10 July 2027. Zyphe is built around that Article: every desk states which tasks it will not accept, supports supervisor pre-notification, and ships a written rationale with each case rather than a confidence score.
Sources retrieved and page reviewed 7 September 2026. Written by Michelangelo Frigo, Co-Founder and CEO at Zyphe.
What does each vendor actually sell?
Positioning quoted from each vendor's own homepage, so nothing here is contested.
Castellum.AI
"Agentic Screening and Alert Resolution"
Screening and automated alert resolution built on watchlist data Castellum.AI compiles itself, with a family of agents branded Arbiter covering sanctions and PEP screening, adverse media, transaction monitoring and fraud. Of the four, it has the strongest claim to owning the underlying data rather than renting it.
Bretton
"AI-native operations for the financial back office"
Rebranded from Greenlite AI in February 2026 and scoped wider than AML: a template library, a natural-language agent builder and a shared workbench aimed at back-office operations generally. It publishes the deepest customer roster of the four and offers virtual private cloud deployment.
Sphinx
"Your last compliance hire"
Agents that sign in to the systems you already run and work them the way an analyst would, so no API integration or engineering time is required, alongside an AI-native BPO offering called Frontline and a document fraud detection product.
Zyphe
Operated compliance desks, agent-prepared and human-approved
Desks that work a named queue: sanctions and PEP alerts, adverse media, UBO and EDD, transaction monitoring triage, periodic KYC refresh. Agents prepare the file and your team approves the decision, and every case ships with a written rationale rather than a confidence score.
How do the four compare?
Every cell reflects what the vendor publishes about itself, not what we infer about it.
| Criteria | Castellum.AI | Bretton | Sphinx | Zyphe |
|---|---|---|---|---|
| Supervisory framing on its own site | OCC, NCUA, NY DFS, California DFPI (US) | FDIC, OCC (US) | FDIC, OCC, Federal Reserve (US) | AMLR, AMLA, EU national supervisors |
| Addresses AMLR Article 18 outsourcing | Not stated | Not stated | Not stated | Yes, on every desk |
| Publishes which tasks it will not accept | Not stated | Not stated | Not stated | Yes, against Article 18(3) |
| Written rationale on every case | Not stated | Model validation and audit trail | Not stated | Yes, a Zyphe control |
| Published data-protection posture | SOC 2 | SOC 2 Type II, GDPR, zero-data retention, virtual private clouds | SOC 2 Type II, GDPR | No reconstructable PII at rest |
| Nature of that protection | Contractual | Contractual | Contractual | Architectural |
| Integration model | API and data feeds | Platform with templates, builder and workbench | Agents operate your existing systems, no API needed | Operated desks inside your existing tools |
| Proprietary watchlist data | Yes, compiled in house | Connected third-party sources | Not stated | No, works with your existing data providers |
What "not stated" means
Not stated publicly as of 7 September 2026. It is not a claim that the vendor cannot do the thing, and it is not a claim that it does the thing badly. All three are credible operators, and against a United States supervisor all three are better referenced than we are.
On zero retention
Bretton publishes a zero-data-retention commitment, so we are not claiming to be the only vendor that limits retention. A retention policy is a promise you verify through contract and audit. Our position is narrower and harder to make: a breach of Zyphe is not a breach of your customers' PII, because there is no reconstructable PII sitting in it to take.
Sources, all retrieved 7 September 2026: Castellum.AI, Bretton, Sphinx. Regulation (EU) 2024/1624 quoted from EUR-Lex.
What does AMLR Article 18 require when you outsource AML work?
This is the whole argument for choosing an EU-built vendor, so it is worth stating from the primary text rather than from a summary.
Article 18 of Regulation (EU) 2024/1624 is titled Outsourcing. It permits outsourcing and attaches conditions. Article 18(1) requires you to notify your supervisor before the provider starts work. Article 18(2) treats the provider as part of your organisation, leaves you fully liable for the outcome, and requires you to demonstrate to your supervisor that you understand the rationale behind the outsourced activity. That last requirement is the reason a Zyphe case ships with written reasoning rather than a score: a confidence number is not something an MLRO can explain to a supervisor. The Article applies from 10 July 2027.
Which tasks can never be outsourced?
- The proposal and approval of your business-wide risk assessment
- The approval of your internal policies, procedures and controls
- The decision on the risk profile attributed to a customer
- The decision to enter into a business relationship or carry out an occasional transaction
- Reporting suspicious activity, or threshold-based reports, to your FIU
- The approval of the criteria used to detect suspicious or unusual transactions
Two qualifications belong with that list. Article 18(3)(e) permits FIU reporting to be outsourced to another obliged entity in the same group and established in the same Member State. Article 18(7) lets a collective investment undertaking without legal personality outsource points (c), (d) and (e) to one of its service providers, once it has notified its supervisor and the supervisor has approved. Neither reaches a typical bank, payment institution, electronic money institution or crypto-asset service provider.
Approving an individual alert disposition is not itself an Article 18(3) requirement. The Regulation governs the decisions listed above; how much of the rest your team reviews is set by your own policy. Zyphe returns every case for approval because that is the service boundary we sell, not because a regulation compels it case by case.
When should you choose one of the others?
A comparison page with no losing rows is an advertisement. These are the cases where we are not the right answer.
Castellum.AI
Choose Castellum.AI if your real problem is screening data quality and you want the list and the agent from one vendor.
Bretton
Choose Bretton if you are a large institution automating beyond AML, you need a VPC deployment, and a peer logo wall is what gets the decision approved internally.
Sphinx
Choose Sphinx if you need throughput next week and cannot free up engineering for an integration.
Zyphe
Choose Zyphe if you are an EU obliged entity and your supervisor will ask who did the work and on what basis.
What has Zyphe actually run?
Figures from live deployments. References are available under NDA.
- screening alerts discounted per agent per day
- 600 screening alerts discounted per agent per day
- reviews handled across deployments
- 120,000+ reviews handled across deployments
- operational cost saved across deployments
- $3.3M operational cost saved across deployments
- markets covered
- 52 markets covered
Frequently asked questions
Who are the main alternatives to Castellum.AI, Bretton and Sphinx?
The agentic AML category as of September 2026 includes Castellum.AI, Bretton (formerly Greenlite AI), Sphinx and Zyphe, alongside earlier automation vendors such as WorkFusion and Silent Eight and screening incumbents such as ComplyAdvantage. The four agentic vendors differ less on what the agents do than on which supervisor they were designed for, and on whether the vendor states where its own responsibility stops.
Which AI compliance agent vendors are built for EU AML rules?
On their own public websites as of September 2026, Castellum.AI, Bretton and Sphinx frame their compliance posture around United States banking supervision and do not address Regulation (EU) 2024/1624. Zyphe is built around it: each desk states the tasks it will not accept under Article 18(3), supports the supervisor pre-notification that Article 18(1) requires, and returns a written rationale per case.
What does AMLR Article 18 require when you outsource AML work?
Article 18 of Regulation (EU) 2024/1624 permits outsourcing and attaches conditions. Article 18(1) requires you to notify your supervisor before the provider starts. Article 18(2) treats the provider as part of your organisation, leaves you fully liable, and requires you to demonstrate to your supervisor that you understand the rationale behind the outsourced activity. Article 18(3) lists tasks that cannot be outsourced. The Article applies from 10 July 2027.
Which AML tasks can never be outsourced under AMLR?
Article 18(3) names six: proposing or approving your business-wide risk assessment, approving internal policies and controls, deciding a customer risk profile, deciding whether to enter a business relationship, reporting to your FIU, and approving the criteria used to detect suspicious transactions. Two qualifications belong with that list, in Article 18(3)(e) and Article 18(7), and neither reaches a typical bank, payment institution, EMI or crypto-asset service provider.
Is an AI agent reviewing my alerts an automated decision under GDPR Article 22?
It depends on who decides. GDPR Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects, and the CJEU reading in SCHUFA is broad. An operating model where an agent prepares the file and a named human approves the outcome is the reason Zyphe sells preparation rather than decisions, and it is what your DPO will ask about first.
What is the difference between a zero-retention policy and no reconstructable PII?
A retention policy is a commitment about what a vendor chooses to keep, and you verify it through contracts, audits and trust. An architecture with no reconstructable PII at rest is a statement about what the vendor is able to keep. Bretton publishes a zero-data-retention commitment, so Zyphe is not the only vendor limiting retention. The difference is the kind of promise, not the direction of it.
Related
- The operated desks
What each desk works, what it hands back, and where the Article 18 boundary sits.
- Hiring versus agents versus BPO
The other comparison: cost, delay and coverage of another internal hire against a managed operating model.
- Switching KYC providers
Migration steps, contract timing, and what changes when the new provider never stores PII.
Book a demo
Bring the shortlist. We will take the hardest queue on it.
Book a demo with your real alert backlog. We will run a slice of it, hand back the cases with written rationales, and you can compare the output against anyone else on your list.