Compliance as code – AI will create a whole new SaaS layer to prevent violations, not just detect them

a16z says AI is finally good enough to run compliance. Europe, with the strictest and fastest-moving GRC rulebook, will build it first

14 Jul 2026

Compliance is one of the most active corners of B2B AI right now, on one promise: the models are finally good enough that the work becomes cheap and fast yet stays reliable. 

Why does this matter?

AI is moving into decisions that shape people’s lives: getting a job, getting paid, getting a visa, getting your shifts, getting a loan or insurance, getting seen by a doctor… There are big questions about how AI earns the trust required to do this, and about how enforcing those guardrails becomes a job where humans are augmented by automation, not replaced. 

The rules are where society writes down who it refuses to harm. We’re backing the companies that make AI work for people, not over them.

What do we see?

Vanta leads the market, doing around $300M in ARR at a $4.15B valuation. But money has started pouring in to disruptors: Norm Ai raised at a $140M+ valuation in 2025, since when we’ve had Sardine’s $70M Series C, Bretton’s $75M Series B, NeuralTrust’s $20M Seed, not to mention a wave of AI-native startups taking off such as Ritivel, Cortea and more. 

We’ve taken calls with more than 30 early-stage startups building in this space. Here’s our take:

  • The 2024-25 cohort was all about certification and workflow automation – compliance-as-checklist, faster paths to validation. 
  • This year’s cohort is all about runtime enforcement – a control layer that enforces policy before actions are processed, not after.

The value is shifting from detection to prevention.

The biggest AI companies of the next decade will do more than help companies pass compliance audits. They will stop violations from happening in the first place. Here’s how.

* * *

Turning schlep into software

Compliance is what happens when rules outside your company have to become real inside it. Data, payroll, recruitment, lending, money laundering, fraud, security, tax, health and safety, marketing, insurance, financial reporting, accessibility, environmental reporting… The list goes on. And being compliant isn’t enough; you have to show it, and keep showing it. It’s less a finish line than a treadmill – adhere, document, prove, repeat. 

Repetitive tasks? Regulated markets? Something that companies can’t sell, partner or operate without? Sounds ripe for a defensible AI breakout!

a16z just made the clearest statement of the bull case for AI’s impact on this category. In ‘Everything, Everywhere is Compliance’, James da Costa and Angela Strange lay out the numbers: more than 400,000 compliance officers in the US, earning more than $40bn in annual wages, doing work that is paper-based, manual and miserable.

Their argument is labour supply: compliance officers are the second-fastest-growing US occupation, yet demand still outstrips supply. The human-intensive model is breaking, so software has to replace it.

Europe’s problem isn’t labour shortage but regulation surplus. Between 2019 and 2024 the EU issued more than 13,000 new regulations (against roughly 5,500 in the US). It now carries around 100 tech-focused laws, with more than 270 active regulators.

Even the rule-makers can’t keep pace. The EU AI Act took force in August 2024 with high-risk obligations set for August 2026, but implementation slipped so badly that last month negotiators deferred them another one to two years. 

And the cost of getting it wrong is rising. Let’s take just one area: GDPR. Cumulative GDPR fines now exceed €7.1bn, with around €1.2bn issued in 2025 alone. Regulators field roughly 443 breach notifications a day, up 22% year-on-year.

Why now

These imminent regulatory deadlines are the ultimate demand catalyst.

But two other key factors are driving urgency in this space:

  1. A liability clock. Insurers have begun carving AI out of standard coverage, so the cost of a violation will keep rising. “We caught it an hour later” is worth less every quarter.
  2. The actor has changed. Compliance was built around humans who could be trained, supervised and held to account. Now AI agents read, decide and transact on their own, and you can’t send an agent on a compliance course (well, not yet). The only place left to bind it is the harness that lets it act.

The old way and the new way

Traditionally, compliance has always been done the same way: read the rules, figure out line-by-line what applies to your organisation, write a policy, publish a framework and check once a year whether anyone followed it. 

Most of that is still manual. Regtech is largely data stores for policies; legacy players cluster on AML/KYC. Incumbents are point solutions for detecting violations: old-school GRC workflow vendors (OneTrust, Drata, Vanta) with distribution and checklist DNA; data governance vendors (BigID, Transcend); and MLOps/model-eval point tools. 

The future of compliance is moving into the runtime itself, sitting between an organisation and its workflows and blocking any non-compliant action before it happens 

Here’s what that shift looks like:

  • The old way was a report certifying that payroll came out correct. 
  • The new way is a pipeline that will not run a payroll that breaks the rule in the first place.

Think about who sits on the other side of these approaches: the warehouse worker whose hours are set by an allocation model, the applicant filtered out before a human reads their CV, the employee a performance review flags for termination. Today they find out something went wrong through an audit a year later, if at all. A compliance layer that blocks the unlawful decision before it takes effect gives everyone the protection that today depends on having a good lawyer.

“I distinguish two roles for AI in this context:

  • Helper AI: This type focuses on tasks like detecting anomalies, writing reports or identifying non-compliance. In this scenario, humans may lose jobs when the AI works effectively because it automates tasks previously handled by people.
  • Gating AI: This serves as a monitoring system to ensure compliance and verify that processes meet specific thresholds. Automation provides certainty that metrics are being met. In this case, humans face risks when the AI fails; if a gating function fails and a non-compliance event occurs, someone is held accountable.

Essentially, for Helper AI, humans lose when it works; for Gating AI, humans lose when it doesn’t.” 


Shay David, Emerge VP, cofounder @ Kaltura and chief of data solutions @ SolarEdge

 

Building compliance as code

We’re calling this category a regulation-aware SaaS layer: software that embeds local and global legal frameworks into an application’s underlying code, governing both humans and AI agents in the flow of work.

Let’s dig one level deeper into what this actually looks like.

This layer does three things: it reads the rules, enforces them and leaves an audit trail.

1: Regulation monitoring 

Regulations are always moving – thousands of pages every month. The more jurisdictions you work across, the more complex it is. This layer ingests all that information and turns it into policy-as-code: machine-readable logic that lives in the software itself, rather than in scattered policy documents or a compliance officer’s head. 

2a: Build-time

Catches violations you can find by reading the plans: where data is set to live, how long it’s kept, who can reach it, whether one client’s records can bleed into another’s. None of this needs a running system; it’s decidable from the code and the configuration, the way a structural engineer can condemn a building from the drawings without waiting for it to fall down. A noncompliant release can’t go live.

2b: Runtime

Catches violations that did not exist until the action happens. Whether a payroll run is legal can turn on what the system actually does that day: an agent sending a payment to an account in the wrong jurisdiction, or pulling a record across a border to answer a query. No blueprint shows that in advance, because the decision is made at inference, not at deploy. The compliance layer becomes the permission logic that agents run on.

3: Auditability

When an agent clears authorisation before it acts, every action is logged with its reasoning so an auditor has a verifiable trail.

Tips for founders building in this space

1: Choose your vertical

The highest risk surfaces have historically been around fintech and banking – think AML/KYC – where incumbents have distribution advantages. But the EU AI Act’s high-risk zone is largely about work systems. Recruitment, candidate selection, performance evaluation, task allocation, worker monitoring, and promotion or termination decisions. All high-risk, with far less mature incumbents. 

2: Sell to whoever owns AI transformation

Compliance software has always been sold to the compliance team. Now the budget is actually being unlocked by AI-transformation programmes, which means the buyer is senior leadership or data privacy officers with a huge new AI governance remit. Buying is still top-down, but purchase power is shifting from the people who document risk to the people who deploy. 

3: Defensibility is built with scale, not a wedge you start with

Policy-as-code means maintaining a codebase that tracks every regulatory update across jurisdictions in near-real-time, but this knowledge layer commoditises fast: regulatory text is public law, LLMs are great at ingestion and the EU is pushing machine-readable legislation. Defensibility accrues instead from an accumulated corpus of resolved edge cases in a specific vertical, which is expensive to rebuild and raises the automatable fraction over time. Moats exist only where the enforced reality is local and doesn’t travel: national supervisory practice, works-council and employment law, sectoral regulators. Outside these zones – with, say, horizontal certification or generic privacy management – distribution wins. (GDPR is the precedent: Europe had the strictest rules first, but the value accrued to US players.)

4: It’s high stakes, but your key metric isn’t accuracy or error rate

Compliance is more complex than security, which pioneered policy-as-code but where a config either matches a policy or it doesn’t – zero judgement, near-100% precision. Yet compliance is also about more than understanding which deterministic rules a system can execute vs which judgement calls you need to route to a human.

We see three classes to build your solution around:

  • What’s provable >> Data residency, retention windows, access scope, etc – some requirements can be reduced to a decidable check over an observable state. This is actually a pretty small set and naming exactly which requirements live here is the most credible thing a founder can put in a deck.
  • What’s statistical >> The honest claim isn’t “we catch violations”. It’s “we catch them at X recall, Y precision, at this threshold, monitored this way”. A stated error bound is a stronger sale than an implied perfect one.
  • What’s judgement >> These are the genuinely ambiguous standards: “fair and not misleading”, legitimate interest, high-risk classification. The deliverable is not a verdict but a calibrated confidence plus an escalation. Value comes from the system being right about when it’s right – a system that’s right 80% of the time and knows which 80% beats one that’s 92% and uniformly confident.

5: Human-in-the-loop provides accountability, not accuracy 

Calibrated judgement routes to a human, but routing isn’t the same as resolving. Automation bias means reviewers often approve what the model proposes and the audit trail then just certifies a rubber stamp, which isn’t a meaningful failure mode. If any part of the system leans on human review, it has to say how the human signal is itself kept reliable (such as disagreement sampling, blind re-review, measured inter-rater agreement).

Final thoughts

Faster violation detection is important, and some good companies will be built on it.

But the companies that will win compliance will build a preventative system: runtime enforcement tied to regulation, inside a vertical, where violations simply cannot occur in the first place.

This is the infrastructure layer of the agentic era. Every action an agent takes in a regulated market has to pass through it, which makes it as fundamental to this software cycle as identity and payments were to the last. It runs on every transaction, and you can’t route around it without breaking the work it guards. Own that layer, and everything regulated gets built on top of you.

And the benefits cut both ways. It holds agents inside the rules, and it takes the compliance load off the humans around them: the specialist is left with only the calls that genuinely need judgement, and everyone else stops carrying the rulebook in their head and just does the job, while compliance takes care of itself.

This is the mission underpinning everything we fund at Emerge: that the gains from AI are shared evenly, so more people get a real chance to make the most of their potential.

About Emerge

Emerge is a global pre-seed fund backed by 100+ of the world’s best human capital development operators. Our vision is to unlock human potential – by being a catalytic partner for early-stage founders, providing first-cheque financial support, ongoing expertise and access to a community who have ‘been there and built it’ with unrivalled market-specific know-how.