RegTech Grows Up: DORA Enforcement Bites, Norm AI Hits Unicorn, Bretton AI Turns Compliance Into Software

As of this week, RegTech is no longer a pilot line item. Fines are being written, unicorns are being minted, and agentic AI is turning compliance from a cost centre into an operating layer. Here is what changed, and what it means for the people paying the bill.
For most of the past decade, RegTech has been the industry that kept promising to arrive. This week it did. Three developments, taken together, mark a turning point: the Digital Operational Resilience Act (DORA) has moved firmly into its active enforcement phase across the European Union, Norm AI has crossed the unicorn threshold on the back of a $120 million Series C led by Khosla Ventures, and Bretton AI (the former Greenlite AI) has raised $75 million from Sapphire Ventures for an agentic compliance platform that has already automated more than a million financial-crime investigations.
The days of RegTech as a demo, a Slack channel and a proof of concept are over. The category is now graded on outcomes.
DORA: the tolerance period is finished
The Digital Operational Resilience Act became fully applicable on 17 January 2025. For most of last year, national competent authorities across the European Union treated 2025 as a soft-landing period, focusing on readiness reviews rather than penalties. That posture has now changed. Per DORA Blog's 2026 analysis, the informal tolerance period is over: authorities are conducting active enforcement reviews, cross-checking Register of Information data automatically, and issuing the first compulsion payments.
Only half of in-scope firms are estimated to be fully compliant, according to the same source. The penalty framework is not gentle. National authorities can impose fines of up to 2% of total annual global turnover or EUR 10 million, whichever is higher, plus individual fines of up to EUR 1 million for responsible persons. DORA sets no EU-wide maximum, so exposure ultimately depends on the supervising Member State.
For chief risk officers, that maths matters. A EUR 10 million floor is a headline, but the turnover-linked ceiling is what should keep boards awake. A mid-sized European asset manager with a EUR 500 million top line is potentially exposed to EUR 10 million per breach. For a global systemically important bank the number is a great deal larger.
Where the pressure lands first
Two areas are absorbing most of the supervisory attention. The first is third-party ICT risk: DORA's requirement to map, contract and monitor critical outsourced providers has produced Register of Information filings that supervisors can now cross-check at scale. The second is incident reporting: the categorisation, notification and post-incident review workflow is one that many firms outsourced to spreadsheets and are now scrambling to systematise.
That is exactly the gap RegTech vendors have spent the year filling. Reports on RegTech operational maturity, published by FCC Times in April 2026, note that AI-powered platforms can now generate reports in FCA, EBA and PRA formats automatically, compressing preparation from weeks to hours. The commercial case for buying rather than building is finally holding up in front of a procurement committee.
Norm AI: a unicorn built on reading regulations
While DORA was concentrating supervisor minds, one American RegTech company was doing something almost unheard of in this segment: hitting unicorn status. TechCrunch reported on 7 July 2026 that Norm AI closed a $120 million Series C at a $1.2 billion valuation, led by Khosla Ventures, with Blackstone, Bain Capital Ventures, Coatue, Vanguard, New York Life, TIAA and Fenwick LLP all participating. LawSites confirmed the valuation and the round composition.
Norm's pitch is unusual in its ambition. The company describes what it does as agentic law: building AI that interprets regulatory rules, monitors compliance in real time, and governs how other AI systems operate in high-stakes environments. Its flagship product, according to Enterprise DNA, is a compliance agent for Microsoft 365 Copilot launched in May 2026. When an employee uses Copilot to draft communications or review a document, Norm's agent works in parallel to flag missing disclosures, identify policy conflicts, check claims against approved sources, and maintain a full audit trail.
The company also runs Norm Law, an AI-native law firm staffed by human attorneys who supervise the agents and offer services to enterprise clients. Norm reports a combined client base representing more than $30 trillion in assets under management, spanning global banks, hedge funds, insurers and asset managers.
Why this valuation makes sense
$1.2 billion for a compliance company is the sort of number that traditionally raises eyebrows. In Norm's case, the multiple reflects a bet that agentic compliance is not a feature inside a legal-tech suite but an operating layer that sits between employees and every AI system they touch. If that bet is right, Norm has quietly staked out one of the most defensible positions in enterprise software.
Bretton AI: the workforce beneath the workflow
The other big RegTech cheque this year went to Bretton AI, which announced a $75 million Series B in February 2026, led by Sapphire Ventures, alongside a rebrand from Greenlite AI. Fintech Futures, AML Intelligence and Fintech Global all covered the round; The Paypers detailed the platform's purpose.
Bretton, founded in 2023, sells an agentic AI platform that supports financial-crime compliance workflows across transaction analysis, KYC and KYB reviews, AML and sanctions investigations, and ongoing transaction monitoring. The technology is already in use at banks regulated by the OCC, FDIC and Federal Reserve, as well as at Robinhood, Mercury, Gusto, Lead Bank and Coastal Community Bank. Average contract values have climbed to $201,000. According to Bretton's own blog, its agents have completed more than 1.2 million L1 and L2 financial-crime investigations, eliminating over 195,000 hours of manual compliance work and saving customers more than $10 million in compliance-related headcount and risk costs.
Sapphire Ventures framed its investment as backing an AI workforce for financial crime operations, which is a candid way of naming what is actually happening: RegTech vendors are no longer selling tools that make analysts faster, they are selling agents that do the analyst work directly, with humans supervising exceptions.
MiCA and AMLA: the regulatory calendar keeps setting the agenda
The Markets in Crypto-Assets Regulation (MiCA) provided the other backdrop for this quarter. According to CheckFile.ai's RegTech guide, MiCA's Article 143 transitional period ended on 1 July 2026, and the European Securities and Markets Authority's (ESMA) knowledge and competence rules apply from 28 July 2026. September has been described as a critical window for crypto-asset service providers (CASPs) to close authorisation conversations with national competent authorities.
In parallel, the incoming Anti-Money Laundering Authority (AMLA) is beginning to shape supervisory practice, with member states preparing for a single-rulebook approach that reduces jurisdictional fragmentation. Together, MiCA, AMLA and DORA form the regulatory backbone that vendors like Norm AI and Bretton AI are effectively productising.
The commercial signal
Two numbers explain why capital is flowing so aggressively into this segment right now. Per Yahoo Finance's syndication of the AI-powered fintech compliance and RegTech platform market outlook, the sector is projected to grow from $16.07 billion in 2025 to $19.91 billion in 2026, with an operational-maturity note that the broader RegTech market reached $23.4 billion in 2026 growing at 20% annually. When regulators write bigger cheques and vendors deliver measurable ROI, the market clears.
What this means for buyers
Three practical takeaways for compliance leaders reading this on Tuesday morning.
First, DORA compliance is now a purchasing decision as much as a policy one. Vendors that can produce Register of Information filings, incident-report packages and third-party risk telemetry in supervisor-ready formats are the ones worth shortlisting. In-house buildouts finished the year uneconomic.
Second, agentic RegTech changes the org chart. If Norm AI's model works, general counsel offices will need fewer document reviewers and more agent supervisors. If Bretton AI's model works, financial-crime teams will look more like exception-handling desks than case-management factories. Either way, headcount plans need rewriting.
Third, the AI Act starts to bite the RegTech vendors themselves. Compliance agents that make decisions inside regulated firms are, under most readings, high-risk AI systems. Vendors that cannot pass their own conformity assessment will not be shortlisted by procurement teams that have to defend the choice to their supervisors.
A category that finally deserves its name
RegTech spent years playing dress-up as a horizontal software category. In 2026 it has become one. The regulatory calendar keeps writing the requirements, the venture cheques keep validating the commercial case, and the agentic-AI stack finally makes it possible to run compliance as software rather than as a hall full of people. That is not hype. It is the sound of a market clearing.
The next twelve months will decide which vendors survive contact with production, and which regulators can keep up with them.



