letter from duna team

On this page

In August 2026, Y Combinator published its requests for startups for its fall batch. One of them is titled "AI-native compliance infrastructure." It describes financial compliance as "still stitched together with spreadsheets, siloed tools, and expensive headcount," with costs that grow faster than revenue as companies expand, and it asks for founders who rethink "what compliance operations look like when AI is the default."

A request for startups is a leading indicator. It reflects what YC's portfolio companies struggle with and where its partners expect the next set of enduring companies to come from. When YC names a category, founders follow, and a wave of startups carrying this label will arrive in 2027.

Duna was founded on this exact thesis in 2023. Three years in, the policy engine runs in production across the full customer lifecycle, AI agents are live with enterprises including Plaid, seQura, Brand New Day, and Bol, and the thesis has survived contact with bank-grade audits. Three lessons from those years seem worth writing down before the category fills up.

The substrate comes first

Agents were the obvious opportunity in 2023, and the first lesson was that you cannot start with them. An agent reasoning over a shared drive of PDFs produces confident answers no auditor can verify. So the unglamorous majority of three years went into the layers underneath: identity data broken into structured, reusable evidence, and compliance policy translated from prose into code. Only then do agents become useful, because they finally have data they can reason over and a policy they can be evaluated against.

The economics explain why most of the market skipped this step. Workflow tools are quick to launch and brittle as requirements change; evidence-based systems demand a heavy upfront build and then handle change without adding complexity. Anyone entering the category now inherits that same sequencing, and there is no shortcut through it.

Regulators are readier than the market assumed

The expected obstacle was supervisory resistance. The opposite happened. The European Banking Authority has criticised financial institutions for failing to embrace AI in anti-money laundering work, and the EU's new AML framework, applying from July 2027, accepts automation on clear conditions: explainable decisions, repeatable results, human oversight where risk is high.

Regulators can count. The industry assigns up to 10 to 15% of its workforce to KYC and AML operations and detects about 2% of global financial-crime flows. Supervisors are not defending that status quo. The conditions they set turned out to be design inputs, and a system built to them clears audits that retrofitted AI features cannot.

The model must not decide

The tempting architecture lets the model make the call. It does not survive an audit, and it should not. In three years we have not found a defensible design in which AI holds decision authority. Agents gather and structure evidence within declared scopes; a deterministic policy engine makes the decision; analysts take the exceptions with the evidence and reasoning attached.

That separation is also where the returns are. McKinsey puts assistive AI at 15 to 20% productivity gains against 200 to 2,000% for agentic systems, and the upper range is only reachable when automation runs by default under coded policy. In production, that looks like screening false positives down by around 70% and analysts working at 4.8x their previous throughput.

YC's request closes with a prediction: the companies that get this right "will become essential infrastructure for any business operating globally." We agree. We started in 2023.

In August 2026, Y Combinator published its requests for startups for its fall batch. One of them is titled "AI-native compliance infrastructure." It describes financial compliance as "still stitched together with spreadsheets, siloed tools, and expensive headcount," with costs that grow faster than revenue as companies expand, and it asks for founders who rethink "what compliance operations look like when AI is the default."

A request for startups is a leading indicator. It reflects what YC's portfolio companies struggle with and where its partners expect the next set of enduring companies to come from. When YC names a category, founders follow, and a wave of startups carrying this label will arrive in 2027.

Duna was founded on this exact thesis in 2023. Three years in, the policy engine runs in production across the full customer lifecycle, AI agents are live with enterprises including Plaid, seQura, Brand New Day, and Bol, and the thesis has survived contact with bank-grade audits. Three lessons from those years seem worth writing down before the category fills up.

The substrate comes first

Agents were the obvious opportunity in 2023, and the first lesson was that you cannot start with them. An agent reasoning over a shared drive of PDFs produces confident answers no auditor can verify. So the unglamorous majority of three years went into the layers underneath: identity data broken into structured, reusable evidence, and compliance policy translated from prose into code. Only then do agents become useful, because they finally have data they can reason over and a policy they can be evaluated against.

The economics explain why most of the market skipped this step. Workflow tools are quick to launch and brittle as requirements change; evidence-based systems demand a heavy upfront build and then handle change without adding complexity. Anyone entering the category now inherits that same sequencing, and there is no shortcut through it.

Regulators are readier than the market assumed

The expected obstacle was supervisory resistance. The opposite happened. The European Banking Authority has criticised financial institutions for failing to embrace AI in anti-money laundering work, and the EU's new AML framework, applying from July 2027, accepts automation on clear conditions: explainable decisions, repeatable results, human oversight where risk is high.

Regulators can count. The industry assigns up to 10 to 15% of its workforce to KYC and AML operations and detects about 2% of global financial-crime flows. Supervisors are not defending that status quo. The conditions they set turned out to be design inputs, and a system built to them clears audits that retrofitted AI features cannot.

The model must not decide

The tempting architecture lets the model make the call. It does not survive an audit, and it should not. In three years we have not found a defensible design in which AI holds decision authority. Agents gather and structure evidence within declared scopes; a deterministic policy engine makes the decision; analysts take the exceptions with the evidence and reasoning attached.

That separation is also where the returns are. McKinsey puts assistive AI at 15 to 20% productivity gains against 200 to 2,000% for agentic systems, and the upper range is only reachable when automation runs by default under coded policy. In production, that looks like screening false positives down by around 70% and analysts working at 4.8x their previous throughput.

YC's request closes with a prediction: the companies that get this right "will become essential infrastructure for any business operating globally." We agree. We started in 2023.