Stoyan Mitov is the CEO of Dreamix, a custom software development company helping tech leaders increase capacity without giving up quality.gettyEvery conversation about AI in financial services that I'm hearing right now centers on one technology: agentic AI. Wolters Kluwer projects that 44% of finance teams will use it in 2026, an increase of more than 600% from the year before. KPMG estimates agentic AI could unlock $3 trillion in annual corporate productivity. Compliance, the department long treated as the one that slows everything else down, is under pressure to move first.I think that instinct is backwards. I believe compliance is the worst place in a financial institution to deploy autonomous AI agents before the supporting infrastructure exists. Compliance teams are not short on ambition. The cost of an ungoverned mistake there is categorically different from the cost of one in marketing or operations.The capability is there.The shift from generative AI to agentic AI in compliance is real, and it’s happening fast. Agents now retrieve a customer's transaction history, check it against sanctions and PEP lists, search adverse media and map relationships across networks, compiling all of it before a human investigator opens the case. More than 70% of banking firms are using agentic AI to some degree, according to EY's 2026 Global Financial Services Regulatory Outlook. Adoption across financial services firms generally sits near 52%, according to the Cambridge Centre for Alternative Finance.These numbers describe genuine capability gains. KYC reviews that took days now take minutes. Investigators spend their time on judgment calls instead of data assembly. None of that is hype.Controls are lagging behind.What concerns me is what sits underneath that capability. EY's same research found that governance frameworks have not kept pace with adoption. FINRA's 2026 Annual Regulatory Oversight Report went further, detailing AI agents as a supervisory concern. Four of the risks it flagged refer specifically to the infrastructure problem: • Agents acting without human validation• Agents operating beyond the scope a user intended• Auditability gaps inside multi-step reasoning chains• The risk of agents mishandling sensitive client dataYou’ll notice every item on that list points to infrastructure. The agents are capable. It’s the scaffolding around them that’s lagging; the part that makes their decisions reviewable and reversible. That gap is exactly why I believe compliance is the wrong department to move fast first. A marketing team that deploys an under-governed agent risks an awkward campaign. A compliance team that deploys one risks a regulatory finding or fine, or a transaction that should have been blocked but was not. Oliver Wyman research shows that automating up to 70% of manual compliance work can improve risk detection accuracy by as much as four times, but that number only holds if automation is governed. An ungoverned agent doesn’t multiply detection accuracy; it multiplies exposure. I have watched enough regulatory technology vendors build AI-powered products to recognize the pattern. The model gets built first because it’s the visible, demoable part. The audit trail, the explainability layer and the human checkpoint are usually treated as a later phase. For most software, that sequencing works fine. But for software making decisions about who gets flagged for money laundering, that sequencing is a problem.Here's what has to happen before autonomy expands.Building this properly means a few things need to exist first. Every agent action needs a permission boundary narrow enough that acting beyond scope is not possible by design. Every decision needs a logged, retrievable record of what data the agent used and why it reached its conclusion. A human needs a genuine checkpoint before any agent acts on a flagged case, with real authority to stop it.None of this is exotic. It’s the same discipline compliance teams have applied to human analysts for decades, extended to a new kind of worker. The institutions that build this scaffolding before they scale agent autonomy will be the ones still standing when a regulator asks them to explain a decision an agent made 18 months earlier.The agentic AI wave in compliance will not slow down, nor should it. The capability is real. Speed and governance can coexist without conflict. They simply need the right sequence: infrastructure first, autonomy second. Get that order wrong, and the department built to manage risk might become the one generating it.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Why Compliance Teams Are The Wrong Place To Start Agentic AI Adoption
The cost of an ungoverned mistake in compliance is categorically different from the cost of one in marketing or operations.
44% finance teams adopt agentic AI by 2026 ($3T productivity), but compliance needs governance infrastructure—audit trails, explainability, checkpoints—before scaling autonomy. Ungoverned agents risk regulatory fines and blocked transactions; infrastructure-first sequencing prevents compliance from becoming risk-generator.









