top of page

The Compliance Officer Now Comes With an API: Inside RegTech's Agentic Summer

Aug 19
5 min read
The Compliance Officer Now Comes With an API: Inside RegTech's Agentic Summer

This week AMLA turned up the pressure on payment firms and property markets, while agentic AI kept devouring the compliance stack. Regulators want effectiveness, investors want automation, and RegTech is quietly having its biggest year yet.

If you spent last summer wondering whether RegTech was a real category or a pitch deck flourish, this week has answered the question. Between fresh moves from the European Union's brand new AML watchdog, a rush of nine-figure funding rounds, and supervisors openly rewriting their expectations of banks, the compliance sector has become one of the most important corners of financial services. It is also becoming one of the most heavily automated.


The shift is not subtle. Agentic AI, until recently a marketing phrase, is now sitting on production compliance workflows. Regulators are asking harder questions, and vendors are producing sharper answers. Here is what changed this week, and why it matters.


AMLA Steps Into the Spotlight


The Authority for Anti-Money Laundering and Countering the Financing of Terrorism, better known as AMLA, has had a busy August. According to AML Intelligence, the Frankfurt based supervisor this month urged member state governments, international organisations and the private sector to intensify efforts against money laundering in the property sector, warning that dirty money in real estate is now a driver of housing crises in major European cities.


That is a striking piece of political framing. AMLA is not just calling out compliance gaps, it is tying AML enforcement to a topic voters actually feel: the cost of housing. Expect national supervisors, estate agents and mortgage originators to feel the follow up.

At the same time, AMLA also launched a survey of payment firms and e-money institutions to gauge how well local watchdog liaison is functioning. The central contact point framework, a technical corner of EU AML law, is being prepared for an update. If you run a payments business with cross-border activity, this is the moment to check whether your internal governance can survive an AMLA questionnaire.


Meanwhile, AMLA has published final Regulatory Technical Standards establishing a harmonised EU framework for assessing and enforcing breaches of AML and CFT obligations. Once adopted by the European Commission, the RTS will apply directly across all EU Member States and all regulated sectors, classifying breaches into four levels of gravity based on duration, repetition and impact. In short, AMLA is building the machinery to grade its future targets.


Direct Supervision Is Coming


According to a February 2026 KPMG analysis, AMLA will begin directly supervising selected high-risk cross-border financial institutions in 2028. Between now and then, the authority is ramping up staffing, IT systems and technical standards.


That timeline sounds distant. It is not. Selection of the first cohort of directly supervised institutions will happen well before go-live, and firms that are borderline are being encouraged, both privately and through the European Banking Authority, to upgrade their AML systems now rather than negotiate later.


Which brings us neatly to the RegTech vendors.


Agentic AI Eats the Compliance Stack


The big story of the summer, and the one banks are actually spending on, is the migration from rule based screening to agentic AI. According to Fintech Global, RegTech captured its strongest quarterly funding haul since 2023 in Q2 2026, with thirty two disclosed rounds in June alone. The headline deal was Norm AI, which closed a 120 million dollar round at a 1.2 billion dollar valuation in early July.


Norm AI's pitch is a good summary of where the money is going: replace compliance memos and manual reviews with agents that read regulation, map it to policy, and monitor transactions in real time. The company is one of several building what looks a lot like a compliance operating system.


Other notable rounds this year, catalogued by RegTech Analyst, include Napier AI raising 45 million pounds from Crestline Investors in February, Novatus Global taking 30.5 million pounds led by Silversmith Capital Partners for regulatory reporting technology, IDfy securing 52 million dollars from Neo Asset Management, and Sphinx picking up 7.1 million dollars in seed funding for AI compliance automation. In August, Compuvi's LegalTech and RegTech platform closed a 40 million dollar seed round backed by Turkish investor Islam Yildiz and Istanbul-based Ozay Law Firm, according to Fintech Global.


Cybersecurity flavoured RegTech is also drawing attention. Horizon3 secured 250 million dollars in Series E funding at a valuation above two billion dollars in early August 2026, and Zenity, an AI security and governance platform for AI agents, closed a 125 million dollar Series C. The subtext is unmistakable. Investors believe AI itself is now a compliance surface.


Regulators Are Watching, and Testing


Vendors are not the only ones building. Supervisors are increasingly running their own tools. In June 2026, the International Organization of Securities Commissions published a Report on Supervisory Technology, summarising a survey of 49 jurisdictions on their current and expected use of SupTech tools for oversight, according to Disruption Banking.


The European Securities and Markets Authority has also stepped up. On 8 July 2026, ESMA launched a Common Supervisory Action focusing on the digital operational resilience of cryptoasset service providers, testing how firms are living up to their obligations under the Digital Operational Resilience Act, better known as DORA. And on 3 August 2026, the three European Supervisory Authorities, together with the European Insurance and Occupational Pensions Authority, published a final report on draft technical standards simplifying bilateral margin requirements for uncleared over-the-counter derivatives under EMIR.


Firms should read these announcements as one message: regulators are moving from tick box compliance to demonstrable effectiveness of controls. That is a much higher bar, and one that traditional GRC platforms struggle to clear on their own.


The EU AI Act Bites


Every RegTech conversation this year eventually lands at the same place, and it is the EU AI Act. Compliance related AI systems, including those used in financial crime prevention, are classified as high risk. That means transparency, human oversight, data quality, model documentation and bias testing are not optional extras. They are audit ready obligations.


For banks buying agentic AI compliance tools, the practical consequence is that vendor due diligence has to move well beyond a demo. Model governance, retraining cadence, explainability and log retention are now board level questions. RegTech firms that cannot answer them are quietly being cut from procurement processes.


What to Watch Next


Three things worth tracking over the next month. First, AMLA's follow up on its property market warning. If national supervisors adopt the tone, expect fresh inspections and a rise in enforcement actions in mortgage originators and estate agent networks. Second, further consolidation among agentic AI compliance vendors. With Norm AI at a 1.2 billion dollar valuation and a wave of nine-figure rounds behind it, M&A is coming. Third, the emerging playbook between AMLA and the ECB Office on how directly supervised institutions will be selected. Get on the wrong list, and 2028 will feel a lot closer than the calendar suggests.


For finance leaders, the story is not that compliance is getting harder. It is that compliance is getting programmable. That changes budgets, org charts and vendor stacks, and it is happening this quarter.

 
 
bottom of page