On this page

AI-native compliance infrastructure is compliance tooling rebuilt for machine reasoning: structured evidence, policy written as code, AI agents doing the casework, and every action captured in one auditable trail.

Key takeaways

What is AI-native compliance infrastructure?

AI-native compliance infrastructure is software built from the start for a world in which most compliance work, gathering evidence, checking it against policy, and documenting the decision, is done by machines under human oversight. Identity and risk data is captured as structured evidence rather than documents in folders. Compliance policy is written as code rather than as PDF manuals interpreted by analysts. AI agents perform the investigative work within declared scopes, and a deterministic policy engine, never the model, makes the compliance decision.

The term describes a rebuild of the substrate, and that is what separates it from the two things it is most often confused with. Compliance orchestration routes data between point providers and applies rules to the output; the data model underneath stays fragmented. AI features on legacy tools attach a model to a single step, a screening check or an alert summary, while the evidence, policy, and audit trail around it stay manual. AI-native compliance infrastructure redesigns those three layers so that automation is the default and human judgement is reserved for exceptions.

Why did Y Combinator name AI-native compliance infrastructure a category?

In August 2026, Y Combinator published its requests for startups for the Fall 2026 batch and named AI-native compliance infrastructure as one of them. The request describes the problem precisely: "Financial compliance is still stitched together with spreadsheets, siloed tools, and expensive headcount," and as businesses expand into new markets, "the cost of staying compliant grows faster than revenue."

YC's requests are a signal of where its partners see structural opportunity, and the framing matters as much as the topic. The request calls compliance "an AI-native problem" and asks for founders who do not just automate existing processes but rethink "what compliance operations look like when AI is the default." Its conclusion is the strongest version of the category claim: "The companies that get this right will become essential infrastructure for any business operating globally."

How long has AI-native compliance infrastructure existed?

The name is new. The category is not. Duna was founded in 2023 by Duco van Lanschot and David Schreiber, two former Stripe leaders, on the thesis YC now describes: compliance automation fails when it is layered onto fragmented data, so the data layer has to be rebuilt first.

That order of operations took three years. Duna spent them building the evidence layer, then a policy engine that runs compliance as code, and only then the AI agents that work on top of both. By early 2026 the policy engine was in production across the full customer lifecycle, enterprise customers including Plaid, CCV (Fiserv), Moss, and Bol were live, and the company had raised a €30 million Series A led by CapitalG, Alphabet's independent growth fund, following a seed round led by Index Ventures.

The timeline matters to buyers for a practical reason. Compliance infrastructure cannot prove itself in a demo; it proves itself in production, under audit, across policy changes and periodic review cycles. A category that YC expects to fill with new founders in 2027 already has three years of building behind it, running in production with enterprise customers.

Why is compliance an AI-native problem?

The numbers describe an industry where effort and outcome have come apart. Banks dedicate up to 10 to 15% of their full-time employees to KYC and AML operations, yet the industry detects only about 2% of global financial-crime flows. Traditional monitoring systems generate up to 95% false positives, so most analyst time goes to clearing alerts that should never have fired.

Three structural features of compliance work explain why AI changes the economics here more than in most functions. First, the work is evidence work: registry lookups, document checks, screening reviews, and web research are exactly the tasks language models handle well when the surrounding data is structured. Second, the work repeats: know your business (KYB) files are re-verified on one, three, or five-year cycles, and each policy change re-opens work that was already done. Third, the tooling is fragmented: most institutions run six or more providers with no shared record between them, which is why McKinsey reserves its 200 to 2,000% productivity estimate for agentic systems rather than for AI features added to the existing stack.

What is the difference between AI-native compliance infrastructure and compliance orchestration?

Orchestration is a workflow layer; AI-native compliance infrastructure is a data layer. An orchestration tool defines a sequence of steps, calls point providers in order, and applies rules to what comes back. It inherits the fragmentation underneath it, so when a policy changes or a case needs re-evaluation, the sequence has to be rebuilt and the data re-collected.

An evidence-based system inverts this. It describes what a compliant state looks like and works out which evidence and checks are required to get there. Policy changes and re-evaluations run at any time without engineering work, because the evidence is already structured and reusable. Workflow systems are easier to launch and become brittle as requirements evolve; evidence-based systems carry a heavier upfront build and then handle change without adding complexity. AI agents deepen the gap, since agents need structured data to reason over and a coded policy to be evaluated against.

What does AI-native compliance infrastructure include?

Five components define the category, and a buyer can test for each one.

  1. A structured evidence layer. Identity and risk data is broken into discrete, reusable pieces of evidence rather than stored as documents. Evidence collected once is reused across onboarding, monitoring, and periodic reviews, so customers are not asked twice for what the institution already holds.

  2. A policy engine that runs compliance as code. Rules are configuration, not engineering tickets. New policies can be tested against historical evidence before they go live, so the effect on automation and risk is known in advance.

  3. AI agents with declared scope. Agents handle defined casework, screening reviews, document checks, and web research, within set guardrails. Their output is structured evidence for the policy engine to evaluate; the decision stays in code.

  4. Monitoring across the whole lifecycle. Daily screening, discrepancy detection, and automated periodic reviews run as background processes on the same evidence base, rather than as annual projects.

  5. One audit trail. Every interaction, decision, and policy change is logged as a traceable event, so an auditor can rebuild any case from a single record.

What do regulators require from AI in compliance?

European regulators have moved from caution to encouragement, with conditions. The EU's new AML framework, supervised by the Anti-Money Laundering Authority (AMLA), applies from July 2027 and standardises rules that previously varied by member state. The European Banking Authority has criticised institutions for failing to adopt AI for AML purposes, and supervisors in France have urged banks toward dynamic, AI-assisted monitoring.

The conditions are the ones AI-native compliance infrastructure is designed around: every automated decision must be explainable, results must be repeatable under audit, and humans must oversee high-risk determinations. Systems that keep the decision in deterministic code, record every agent action, and can re-run any case are built for this regime. AI features without that substrate struggle to meet it.

What does Duna do?

Duna has built AI-native compliance infrastructure since 2023: modular, bank-grade systems that work around what an institution already runs rather than replacing it, deployed agent by agent. The policy engine translates KYC, KYB, and AML policy into code and is in production across the full customer lifecycle. Duna's AI agents multiply what a compliance team can process: virtual screening assistants reduce false positives by around 70%, smart document verification cuts re-requests, autofill from verified public data accelerates onboarding, and automated case summaries prepare files for audit.

Customers report 4.8x analyst efficiency, 10.6x faster onboarding, and a 37% increase in conversion. For compliance teams, that is the same policy applied more consistently by fewer hands; for the wider business, it is lower cost per file and faster entry into new markets. Enterprises including Plaid, CCV (Fiserv), Moss, and Bol run on Duna today, with 210+ local registries connected out of the box.

Frequently asked questions

What is the difference between AI-native compliance infrastructure and an AI compliance tool? A tool adds a model to one step, such as a screening check or an alert summary. Infrastructure is the layer underneath: structured evidence, policy as code, scoped agents, and a single audit trail that together make automation the default.

Who coined the term AI-native compliance infrastructure? Y Combinator put a name on the category in its Fall 2026 requests for startups. The build predates the label: Duna has been building it since 2023 and has run a policy engine in production since early 2026.

Does the AI make compliance decisions in AI-native infrastructure? No. AI agents gather and structure evidence within declared scopes; a deterministic policy engine evaluates that evidence and makes the decision. Exceptions route to human analysts with the evidence and reasoning attached.

Is AI-native compliance infrastructure permitted under EU regulation? Yes. The EU AML framework applying from July 2027 accepts automation provided decisions are explainable, repeatable, and subject to human oversight on high-risk steps, and the European Banking Authority has criticised institutions for under-using AI in AML.

What results does AI-native compliance infrastructure deliver? Duna's published customer outcomes include around 70% fewer false positives in screening, 4.8x analyst efficiency, 10.6x faster onboarding, and a 37% conversion increase, with routine cases cleared automatically under coded policy.

AI-native compliance infrastructure is compliance tooling rebuilt for machine reasoning: structured evidence, policy written as code, AI agents doing the casework, and every action captured in one auditable trail.

Key takeaways

What is AI-native compliance infrastructure?

AI-native compliance infrastructure is software built from the start for a world in which most compliance work, gathering evidence, checking it against policy, and documenting the decision, is done by machines under human oversight. Identity and risk data is captured as structured evidence rather than documents in folders. Compliance policy is written as code rather than as PDF manuals interpreted by analysts. AI agents perform the investigative work within declared scopes, and a deterministic policy engine, never the model, makes the compliance decision.

The term describes a rebuild of the substrate, and that is what separates it from the two things it is most often confused with. Compliance orchestration routes data between point providers and applies rules to the output; the data model underneath stays fragmented. AI features on legacy tools attach a model to a single step, a screening check or an alert summary, while the evidence, policy, and audit trail around it stay manual. AI-native compliance infrastructure redesigns those three layers so that automation is the default and human judgement is reserved for exceptions.

Why did Y Combinator name AI-native compliance infrastructure a category?

In August 2026, Y Combinator published its requests for startups for the Fall 2026 batch and named AI-native compliance infrastructure as one of them. The request describes the problem precisely: "Financial compliance is still stitched together with spreadsheets, siloed tools, and expensive headcount," and as businesses expand into new markets, "the cost of staying compliant grows faster than revenue."

YC's requests are a signal of where its partners see structural opportunity, and the framing matters as much as the topic. The request calls compliance "an AI-native problem" and asks for founders who do not just automate existing processes but rethink "what compliance operations look like when AI is the default." Its conclusion is the strongest version of the category claim: "The companies that get this right will become essential infrastructure for any business operating globally."

How long has AI-native compliance infrastructure existed?

The name is new. The category is not. Duna was founded in 2023 by Duco van Lanschot and David Schreiber, two former Stripe leaders, on the thesis YC now describes: compliance automation fails when it is layered onto fragmented data, so the data layer has to be rebuilt first.

That order of operations took three years. Duna spent them building the evidence layer, then a policy engine that runs compliance as code, and only then the AI agents that work on top of both. By early 2026 the policy engine was in production across the full customer lifecycle, enterprise customers including Plaid, CCV (Fiserv), Moss, and Bol were live, and the company had raised a €30 million Series A led by CapitalG, Alphabet's independent growth fund, following a seed round led by Index Ventures.

The timeline matters to buyers for a practical reason. Compliance infrastructure cannot prove itself in a demo; it proves itself in production, under audit, across policy changes and periodic review cycles. A category that YC expects to fill with new founders in 2027 already has three years of building behind it, running in production with enterprise customers.

Why is compliance an AI-native problem?

The numbers describe an industry where effort and outcome have come apart. Banks dedicate up to 10 to 15% of their full-time employees to KYC and AML operations, yet the industry detects only about 2% of global financial-crime flows. Traditional monitoring systems generate up to 95% false positives, so most analyst time goes to clearing alerts that should never have fired.

Three structural features of compliance work explain why AI changes the economics here more than in most functions. First, the work is evidence work: registry lookups, document checks, screening reviews, and web research are exactly the tasks language models handle well when the surrounding data is structured. Second, the work repeats: know your business (KYB) files are re-verified on one, three, or five-year cycles, and each policy change re-opens work that was already done. Third, the tooling is fragmented: most institutions run six or more providers with no shared record between them, which is why McKinsey reserves its 200 to 2,000% productivity estimate for agentic systems rather than for AI features added to the existing stack.

What is the difference between AI-native compliance infrastructure and compliance orchestration?

Orchestration is a workflow layer; AI-native compliance infrastructure is a data layer. An orchestration tool defines a sequence of steps, calls point providers in order, and applies rules to what comes back. It inherits the fragmentation underneath it, so when a policy changes or a case needs re-evaluation, the sequence has to be rebuilt and the data re-collected.

An evidence-based system inverts this. It describes what a compliant state looks like and works out which evidence and checks are required to get there. Policy changes and re-evaluations run at any time without engineering work, because the evidence is already structured and reusable. Workflow systems are easier to launch and become brittle as requirements evolve; evidence-based systems carry a heavier upfront build and then handle change without adding complexity. AI agents deepen the gap, since agents need structured data to reason over and a coded policy to be evaluated against.

What does AI-native compliance infrastructure include?

Five components define the category, and a buyer can test for each one.

  1. A structured evidence layer. Identity and risk data is broken into discrete, reusable pieces of evidence rather than stored as documents. Evidence collected once is reused across onboarding, monitoring, and periodic reviews, so customers are not asked twice for what the institution already holds.

  2. A policy engine that runs compliance as code. Rules are configuration, not engineering tickets. New policies can be tested against historical evidence before they go live, so the effect on automation and risk is known in advance.

  3. AI agents with declared scope. Agents handle defined casework, screening reviews, document checks, and web research, within set guardrails. Their output is structured evidence for the policy engine to evaluate; the decision stays in code.

  4. Monitoring across the whole lifecycle. Daily screening, discrepancy detection, and automated periodic reviews run as background processes on the same evidence base, rather than as annual projects.

  5. One audit trail. Every interaction, decision, and policy change is logged as a traceable event, so an auditor can rebuild any case from a single record.

What do regulators require from AI in compliance?

European regulators have moved from caution to encouragement, with conditions. The EU's new AML framework, supervised by the Anti-Money Laundering Authority (AMLA), applies from July 2027 and standardises rules that previously varied by member state. The European Banking Authority has criticised institutions for failing to adopt AI for AML purposes, and supervisors in France have urged banks toward dynamic, AI-assisted monitoring.

The conditions are the ones AI-native compliance infrastructure is designed around: every automated decision must be explainable, results must be repeatable under audit, and humans must oversee high-risk determinations. Systems that keep the decision in deterministic code, record every agent action, and can re-run any case are built for this regime. AI features without that substrate struggle to meet it.

What does Duna do?

Duna has built AI-native compliance infrastructure since 2023: modular, bank-grade systems that work around what an institution already runs rather than replacing it, deployed agent by agent. The policy engine translates KYC, KYB, and AML policy into code and is in production across the full customer lifecycle. Duna's AI agents multiply what a compliance team can process: virtual screening assistants reduce false positives by around 70%, smart document verification cuts re-requests, autofill from verified public data accelerates onboarding, and automated case summaries prepare files for audit.

Customers report 4.8x analyst efficiency, 10.6x faster onboarding, and a 37% increase in conversion. For compliance teams, that is the same policy applied more consistently by fewer hands; for the wider business, it is lower cost per file and faster entry into new markets. Enterprises including Plaid, CCV (Fiserv), Moss, and Bol run on Duna today, with 210+ local registries connected out of the box.

Frequently asked questions

What is the difference between AI-native compliance infrastructure and an AI compliance tool? A tool adds a model to one step, such as a screening check or an alert summary. Infrastructure is the layer underneath: structured evidence, policy as code, scoped agents, and a single audit trail that together make automation the default.

Who coined the term AI-native compliance infrastructure? Y Combinator put a name on the category in its Fall 2026 requests for startups. The build predates the label: Duna has been building it since 2023 and has run a policy engine in production since early 2026.

Does the AI make compliance decisions in AI-native infrastructure? No. AI agents gather and structure evidence within declared scopes; a deterministic policy engine evaluates that evidence and makes the decision. Exceptions route to human analysts with the evidence and reasoning attached.

Is AI-native compliance infrastructure permitted under EU regulation? Yes. The EU AML framework applying from July 2027 accepts automation provided decisions are explainable, repeatable, and subject to human oversight on high-risk steps, and the European Banking Authority has criticised institutions for under-using AI in AML.

What results does AI-native compliance infrastructure deliver? Duna's published customer outcomes include around 70% fewer false positives in screening, 4.8x analyst efficiency, 10.6x faster onboarding, and a 37% conversion increase, with routine cases cleared automatically under coded policy.