Free guide: How to use AI in compliance
Back

Agentic compliance

Updated September 18, 2026

Table of contents

Agentic compliance is the use of AI agents that work a compliance case end to end, gathering evidence, resolving entities, drafting the rationale and proposing or executing a decision, inside limits a human sets and the law reserves. It differs from rules-based automation, which flags activity and leaves the whole investigation to an analyst.

How agentic compliance differs from RegTech automation

Rules engines and screening tools automate detection: a transaction trips a threshold, a name matches a list, an alert is raised. Everything after that, opening the case, pulling the customer file, resolving whether the match is the right person, reading the sources, writing the disposition, is human work, and it is where compliance cost and backlog live.

An agent takes the alert as its input and produces a decision-ready file as its output. It does the assembly and the first-line reasoning, records every step, and hands over a recommendation with the evidence attached. The rules engine does not go away; in a well-built system it is what the agent is allowed to act within.

Rules-based automationAgentic compliance
TriggerA rule fires or a name matchesThe alert, plus the customer file and prior decisions
Work performedDetection and routingEvidence gathering, entity resolution, source review, draft rationale
OutputAn alert in a queueA decision-ready case with the reasoning and sources attached
Human roleInvestigate and decide everythingReview and approve, or act only where a deterministic guard also passes
Audit trailWhich rule firedWhich rule fired, what the agent reviewed, why it recommended what it did

What a compliance agent does, end to end

  1. Receives the case: a screening hit, a monitoring alert, a periodic review falling due, or a KYB with unresolved owners.
  2. Assembles the context: the verified identity, the ownership trace, prior dispositions, the relevant policy and the regulatory basis for it.
  3. Resolves and reviews: decides whether the match is the same person, reads the underlying sources, classifies what it found by category and status.
  4. Drafts the rationale: writes the disposition or the suspicious activity narrative and cites the evidence for each statement.
  5. Proposes or acts: in a suggest mode it hands the file to a named reviewer; in an autopilot mode it enacts the decision only if a deterministic, non-AI guard also passes, and fails closed if configuration is missing.
  6. Records everything: sources reviewed, reasoning applied, action taken, so the decision can be defended in a supervisory examination months later.

Where the law puts the line

Agentic compliance does not move accountability. Under Regulation (EU) 2024/1624, the AML Regulation that applies from 10 July 2027, Article 18(3) reserves a set of decisions to the obliged entity itself, including the customer risk profile, the decision to enter or continue a business relationship and reporting to the financial intelligence unit; an agent can prepare those decisions, not take them. GDPR Article 22 constrains decisions based solely on automated processing that significantly affect a person, which is why a human approval step is structural rather than optional. The six non-delegable tasks are set out on the agents comparison page.

Which providers offer agentic compliance

Several vendors now sell agent-based compliance work, and they frame it differently. Zyphe runs operated review desks for sanctions and PEP alerts, adverse media, UBO and enhanced due diligence, and KYC periodic review, with agents that act only behind a deterministic guard and file drafting that stays with the client’s MLRO; agent triage of transaction-monitoring alerts is planned and not yet shipped. Castellum.AI, Bretton and Sphinx market agentic AML built around US bank supervision, and ComplyAdvantage and Arva market AI agents for screening and investigation. None of these is first or only; the useful comparison is who is accountable for each decision, where the customer data lives, and how the agent plugs into an existing case-management system.

How Zyphe implements it

Every Zyphe agent works against a verified identity rather than a name string, which is what keeps false positives down, and against data that is not pooled in a central store: documents and biometrics sit in the individual’s own encrypted vault, and the agent works from results, logs and proofs. Each desk publishes what it does, what it will not do, and what it hands back. In one deployment around 90 percent of screening cases closed automatically, and one go-live cleared 120 false positives that would otherwise have been analyst hours; both figures relate to screening alert triage, not transaction monitoring.

For the product side, see AML software for the deterministic rules engine the agents work within, and KYC software for the verification layer they start from.

Michelangelo Frigo Written by Michelangelo Frigo (Co-Founder at Zyphe) Reviewed September 18, 2026 Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Agentic compliance is the use of AI agents that work a compliance case from alert to decision-ready file: gathering evidence, resolving whether a match is the right entity, reviewing sources, drafting the rationale, and proposing or executing a decision within limits a human sets and the law reserves. Rules-based automation stops at the alert; an agent does the investigation work that follows.

Traditional compliance automation detects and routes: a rule fires, an alert is raised, an analyst does everything else. Agentic compliance adds the work between the alert and the decision. The agent assembles the case, reasons over it and writes the disposition, and a human approves or a deterministic guard checks before anything is enacted.

Not the ones the law reserves. Under the EU AML Regulation, Article 18(3) keeps decisions such as the customer risk profile, entering a relationship and reporting to the FIU with the obliged entity, and GDPR Article 22 constrains solely automated decisions that significantly affect a person. Agents prepare those decisions; a named person takes them, or a non-AI guard must also pass before an action is enacted.

Zyphe runs operated agent desks for sanctions and PEP alert review, adverse media, UBO and enhanced due diligence, and KYC periodic review. Castellum.AI, Bretton and Sphinx sell agentic AML framed around US bank supervision, and ComplyAdvantage and Arva market AI agents for screening and investigation. They differ on accountability boundaries, data handling and integration model rather than on the word agent.

No. It changes what the team spends its time on. Agents do the assembly and first-line reasoning that filled analyst queues; the team reviews decision-ready files, takes the decisions the law reserves for them, and tunes the rules and guards the agents work within.

Put AI compliance agents to work

Reasoning agents run L1 triage, EDD, UBO and KYB refresh inside your existing tools, with a per-decision audit trail regulators accept.

Book a demo