The Agentic Compliance Stack
Every compliance platform now claims AI agents. The architecture underneath those claims is where the actual differences live.
When did every compliance vendor become an agentic AI company?
Sardine calls itself "the agentic risk platform." Unit21 published a blog post titled "Why We Rebuilt Everything Around AI Agents." Alloy shipped an AI Assistant. Footprint, Taktile, Spektr, Variance, and Baselayer all raised rounds in 2026 with "agentic" somewhere in the pitch. Combined, those five raised over $210 million.
But when eight companies use the same word, the word stops meaning anything. "Agentic compliance" is now a positioning statement, not an architecture. The question worth asking is what's underneath the positioning, because the systems these companies are building look nothing alike.
Four layers, not one product
A compliance investigation at a bank has a shape. A new customer applies for an account. Someone checks their identity against government databases, screens them against sanctions lists, pulls documents, verifies ownership structures, and writes up findings.
If anything looks wrong, someone escalates to enhanced due diligence. More documents, more cross-referencing, more time.
Every step in that chain is a different computational problem. Name matching against an OFAC sanctions list is deterministic. Interpreting a Mandarin-language PDF of corporate filings to map an ownership chain is not. Deciding whether a customer's transaction pattern warrants a suspicious activity report requires judgment. Generating that report requires structured writing.
The companies building agentic compliance are splitting across these problems, not solving all of them. Four architectural layers are emerging.
Investigation agents
Footprint and Variance occupy the deepest layer. Their agents run the entire investigation.
Footprint's Percy takes a compliance team's standard operating procedures and converts them, line by line, into executable agent workflows. You hand it your KYC policy document. Percy builds an agent that follows the policy the way a junior analyst would: pull identity data from LexisNexis and Experian, cross-reference against government registries across 100+ countries, document findings with citations, flag anomalies. The agent backtests against your historical case archive before going live.
The numbers from production: 90% of L1 reviews automated. Enhanced due diligence investigations that took three hours now take 15 minutes with 35% more evidence gathered. Watchlist screening hits that took 30 minutes resolve in under a minute.
Variance does something similar for sanctions specifically. Their agents replicate what a human investigator does when an OFAC screening hit comes back: search company registries, extract names from foreign-language filings, cross-reference aliases, pull photos, check ICIJ leak databases. Multi-hop reasoning across unstructured sources, the kind of work that makes sanctions analysts stare at screens for hours.
Both follow the same boundary: agents propose, humans approve. The agent generates findings and recommendations. A human compliance officer reviews and signs off. The LLM handles evidence gathering and synthesis. The human retains judgment authority.
Orchestration
Spektr and Taktile sit one layer up. They wire together the systems that run investigations.
Spektr is a control plane for compliance operations. It connects your existing tools, Persona for KYC, Middesk for KYB, your sanctions screening vendor, your transaction monitoring system, and orchestrates them into workflows. Their Agent Builder lets compliance teams describe a workflow in plain English ("build an SME onboarding flow for France with ODD triggers on industry changes") and generates the automation with human review steps where needed.
One customer cut ongoing due diligence from 40 minutes per case to 6 minutes, with cost dropping from 21 euros to 2.25.
Taktile is broader. Their Agentic Decision Platform covers compliance but also credit underwriting, claims processing, and fraud detection. The pitch is that AI agents, deterministic rules, and human oversight coexist in a modular system that business owners control without engineering. Goldman Sachs led their $110 million Series C. Production results include 95% automation in B2B underwriting and 75% fewer AML false positives.
The distinction from the investigation layer matters. Spektr and Taktile sit on top of your existing compliance tools. If your sanctions screening vendor adds AI, or your KYC provider ships agentic features, the orchestration layer coordinates them. Building a kitchen versus managing the restaurant.
Identity network
Baselayer occupies a different position entirely. Their problem is data, not workflow.
Their platform verifies business identity across 2,300+ US financial institutions, covering more than 20% of all US FIs. Because they see the same businesses applying across thousands of institutions, they can score cross-network risk. A shell company that looks clean at any single bank develops a pattern when you see it applying at 40 banks in two months.
But the more interesting product is Know Your Agent. As AI agents start transacting on behalf of businesses, someone has to verify the delegation chain: who deployed this agent, who does it represent, what is it authorized to do? Baselayer issues credentials that agents present at transaction time, backed by verified identity of the deploying organization.
That's a different problem from compliance automation. Footprint and Variance make compliance investigations faster. Baselayer makes the identity data that feeds those investigations more reliable, and extends it to a class of entities (AI agents) that didn't exist in compliance frameworks two years ago.
Where the incumbents land
Alloy, Unit21, and Sardine each spent years building rule-based compliance engines. All three have now added agentic AI on top.
Alloy's AI Assistant plugs into its existing identity decisioning platform, used by 900+ financial institutions. Unit21 rebuilt its architecture around AI agents, with Equifax as a partner for what they call "the shift from chatbot to agentic." Sardine branded as an agentic risk platform and claims 90% automation of fraud and compliance checks. They earned a Forrester Wave Leader position in 2026 for financial crime management.
These are not startups experimenting. They have production deployments, regulatory relationships, and institutional data that the newer companies don't.
But their agents inherit the architecture of the platforms they were built on. A rule engine with an AI layer on top is different from a system designed as agentic from the start. Whether that difference matters depends on what you think the bottleneck is.
What's actually new
Investigation agents are faster compliance analysts. Orchestration layers are smarter workflow engines. Identity networks are richer data providers. Dramatic improvements, but not new categories of infrastructure.
The layer that has no precedent is institutional memory. Footprint calls it Trust Fabric. It's the layer that turns the rest of the stack from a set of tools into a system that compounds.
A traditional compliance workflow is stateless. Each investigation starts from zero. An analyst pulls documents, reads policy, gathers evidence, makes a judgment, files a report. The next investigation on a similar entity starts the whole process over. When an analyst leaves, their judgment leaves with them.
Trust Fabric makes the workflow stateful. Every investigation's findings, the evidence gathered, the reasoning applied, the human decision at the end, become retrievable precedent. A Cyrillic transliteration of a sanctioned entity's name that one analyst cleared six months ago is available to every agent and every analyst running future screenings. The system accumulates institutional judgment the way a senior analyst's brain does, except it doesn't resign.
That's the layer where "agentic" becomes more than a speed improvement. An agent that remembers what the organization has learned is categorically different from one that starts fresh every time.
The $210 million question
Over $210 million went into agentic compliance infrastructure in 2026. Footprint, Baselayer, Taktile, Spektr, and Variance all raised major rounds within months of each other. The incumbents rebuilt in parallel.
The capital is flowing because the constraint is real. US financial institutions filed nearly 5 million suspicious activity reports in 2025. Each one represents an investigation a human had to conduct. False positive rates in transaction monitoring routinely exceed 90%, which means analysts spend most of their time investigating activity that turns out to be legitimate. A mid-size bank's compliance staff can be 10-15% of total headcount.
Automating L1 reviews at 90% is the most obvious win. But the deeper question is what happens when the stack matures, when investigation agents, orchestration layers, identity networks, and institutional memory work together. That architecture is still assembling itself. The companies converging on it have very different theories about which layer matters most.
Sources
- Footprint Raises $25M Series B - Funding announcement and product overview
- Footprint Platform - Percy agent architecture and Trust Fabric details
- Baselayer Raises $35M Series A - KYB identity network and Know Your Agent product
- Taktile Raises $110M Series C - Goldman-led round for Agentic Decision Platform
- Spektr Raises $20M Series A - Compliance orchestration platform and Agent Builder
- Variance Raises $21.5M Series A - AI agents for sanctions screening and risk investigations
- Unit21: Why We Rebuilt Everything Around AI Agents - Incumbent platform rebuild around agentic architecture
- Sardine: Agentic Risk Platform - Forrester Wave Leader 2026, 90% automation claims
Frequently Asked Questions
Built by Trio, a fintech-native engineering partner helping teams build the next generation of financial technology and infrastructure.
Subscribe to Ledger Drift for high-signal insights into how modern fintech is built, from systems to code to teams.