Insights · 28 September 2026 · 16 min read
Banks Have Automated Payments. Now AI Is Taking on Compliance. Freda and Workiva Signal What Comes Next
Banks have spent decades automating transactions, yet compliance still depends heavily on manual reviews, fragmented evidence and time-consuming regulatory workflows. Agentic AI in banking compliance is beginning to change that equation. With 52% of surveyed financial services organizations already

Banks have spent decades automating transactions, yet compliance still depends heavily on manual reviews, fragmented evidence and time-consuming regulatory workflows. Agentic AI in banking compliance is beginning to change that equation. With 52% of surveyed financial services organizations already adopting agentic AI, according to the 2026 Global AI in Financial Services Report, the industry is moving beyond experimentation towards more autonomous operations. The launch of Freda, the agentic compliance platform from Tink's co-founders, and Workiva Agent Studio, which enables organizations to build AI agents for finance, audit and governance, signals a significant shift: AI is moving from answering compliance questions to executing defined compliance workflows. From regulatory change monitoring and evidence collection to control testing and remediation tracking, AI compliance automation could help banks reduce repetitive work, improve operational visibility and scale compliance processes. But the real challenge is not how much AI can automate. It is whether banks can achieve measurable efficiency while preserving regulatory accountability, human oversight and audit-ready evidence.
Banking's next AI shift is happening where mistakes are expensive
Banks have spent years automating payments, fraud detection, customer onboarding and transaction monitoring. Yet one of their most consequential operations still depends heavily on people: compliance.
Regulatory obligations change. Policies need updating. Evidence must be collected, reviewed and retained. Third-party risks need monitoring. Audit findings require remediation. And every decision may need to withstand scrutiny long after the original work was completed.
This creates a difficult operational equation. As banks expand into new markets, introduce products and adopt new technologies, their compliance responsibilities grow. Adding more people and spreadsheets does not necessarily make the process faster or more consistent.
Two September 2026 announcements highlight a potential change in how financial institutions approach this challenge. Freda, founded by Tink's co-founders, introduced an agentic compliance platform designed to discover, build and run compliance programmes. Workiva, meanwhile, unveiled Agent Studio, allowing organizations to create and deploy AI agents for governed business workflows, alongside new regulatory reporting and internal audit capabilities.
These announcements represent different approaches to a common problem. Freda is building an AI-native compliance operating system, while Workiva is extending an established financial reporting, audit and governance platform with customizable agents.
Neither announcement proves that AI can independently run a bank's compliance function. But together, they raise an important question: What happens when AI moves beyond answering compliance questions and starts executing the work itself?
The numbers behind banking's agentic AI opportunity
The momentum behind agentic AI is not based on product announcements alone. Research into financial services adoption indicates that institutions are already exploring the technology, although adoption and implementation maturity vary considerably.
The 2026 Global AI in Financial Services Report, produced by the Cambridge Centre for Alternative Finance with several international partners, draws on 628 respondent organizations across 151 jurisdictions. Its findings offer a useful view of the industry's AI transition.
| Industry indicator | Reported finding | Why it matters |
|---|---|---|
| Organizations surveyed | 628 | Broad international research spanning financial institutions, fintechs, vendors and regulators |
| Geographic coverage | 151 jurisdictions | Captures a range of regulatory environments |
| Financial services AI adoption | 81% | AI is already part of the industry's operating conversation |
| Agentic AI adoption | 52% | Agentic systems are moving beyond theoretical interest |
| Organizations piloting agentic AI | 29% | Many initiatives are still being tested |
| Organizations scaling or transforming with agentic AI | 23% | A smaller group is moving beyond pilots |
| Organizations finding AI value difficult to measure | 55% | Demonstrating business impact remains a significant challenge |
These figures need careful interpretation. The 81% AI adoption figure refers to the broader financial services landscape, not exclusively to banks deploying autonomous compliance agents. Likewise, agentic AI adoption does not mean that every organization has agents operating in production.
Nevertheless, the distinction between experimentation and deployment is becoming increasingly important. A compliance team evaluating a chatbot faces a different implementation challenge from one allowing an agent to retrieve evidence, update a control record and initiate remediation.
For banking leaders, the next question is not simply whether AI can assist compliance professionals. It is whether an institution can safely delegate defined operational tasks to agents while retaining meaningful human accountability.
What is agentic AI in banking compliance?
Agentic AI in banking compliance is the use of AI systems that can interpret defined objectives, plan and execute compliance-related tasks, interact with authorized systems, and report their work within established permissions and oversight mechanisms.
Unlike a conventional chatbot, an agent can do more than generate an answer. Depending on its design and authorization, it may gather evidence, compare information against a control, create a remediation task, update a record or escalate an exception. A traditional compliance workflow often looks like this:
- A regulatory requirement changes or a review is scheduled.
- A compliance professional identifies the affected policy or control.
- The team contacts relevant business owners and requests evidence.
- Evidence is collected from internal systems and reviewed.
- Exceptions are documented and assigned for remediation.
- A reviewer checks the work and retains supporting documentation.
An agentic workflow can coordinate several of these activities. An agent could identify a relevant regulatory change, map it to an existing control, retrieve evidence from connected systems, flag missing documentation and prepare a remediation task for an authorized employee.
The distinction is important: the agent can prepare and execute permitted operational steps without automatically receiving authority to interpret every legal ambiguity or approve every compliance decision.
This is the fundamental shift behind agentic AI in banking compliance. It moves AI from an information interface toward a controlled execution layer.
Freda: Building an AI-native compliance operating system
Freda's September launch is notable because of the experience behind its founding team. Daniel Kjellén and Fredrik Hedberg co-founded Tink in 2012, building financial infrastructure across European markets before Visa acquired the company.
Freda was founded in Stockholm in 2025. Its team includes more than 20 compliance practitioners and engineers. The company describes its offering as an agentic platform for discovering, building and running compliance programmes. Its approach is not limited to generating policy documents or answering regulatory questions. Freda describes four connected components that form the foundation of its platform.
| Component | What it does | Potential compliance value |
|---|---|---|
| Regulatory Engine | Converts legislation, standards and guidance into structured regulatory information | Helps identify applicable obligations and connect them to compliance work |
| Company Graph | Models entities, products, licences, geographies, systems and people | Gives agents business-specific context rather than generic regulatory information |
| Operating Plane | Connects policies, controls, risks, evidence, tasks and projects | Provides a structured environment for managing compliance programmes |
| Agentic Execution | Runs tasks, collects evidence and monitors connected systems | Moves defined compliance activities from manual coordination to controlled execution |
The significance of this architecture lies in the relationship between its components. An AI agent operating without a reliable regulatory foundation may misunderstand an obligation. An agent without organizational context may recommend controls that do not fit the bank's operations. An agent without a structured workflow may identify a problem but fail to ensure that it is resolved.
Freda's model attempts to connect these layers so that regulatory information, business context, compliance records and execution work together.
Its published examples include identity and access evidence collection, cloud configuration evidence, software development control evidence and checks for incomplete employee offboarding. These illustrate the types of recurring, evidence-driven tasks that can be delegated to agents.
However, these are product capabilities and examples, not independent proof of regulatory outcomes or verified reductions in compliance costs.
Workiva Agent Studio: Bringing agents into finance, audit and governance
Workiva's September 15, 2026 announcement takes a different route. Rather than introducing a dedicated compliance platform from a new company, Workiva is adding Agent Studio to its established platform for finance, reporting, audit, sustainability, risk and compliance.
Agent Studio allows users to build, customize and deploy AI agents without writing code. Organizations can combine AI reasoning with Workiva's native capabilities, enterprise knowledge and governed workflows. Agents can also be configured to perform recurring work. The announcement included additional developments that demonstrate how Workiva intends to apply agentic AI to financial and regulatory operations.
| Workiva announcement | Operational focus | What it changes |
|---|---|---|
| Agent Studio | Building and deploying customized AI agents | Allows teams to configure agents around their own processes |
| Regulatory reporting expansion | BEA surveys, US Census surveys and country-by-country reporting | Extends agentic workflows to additional reporting obligations |
| Automated testing for internal audit and GRC | Evidence collection, sample selection, attribute testing and documentation | Coordinates several testing activities within a traceable workflow |
The internal audit announcement is particularly relevant to banking compliance. Audit testing frequently involves collecting evidence, selecting samples, checking attributes, documenting findings and following up on exceptions.
Coordinating these steps through agents could reduce the amount of manual work required to conduct testing. It could also help teams expand their testing coverage without increasing the workload at the same rate.
But automation does not eliminate the need to validate sample selection, test criteria, evidence quality or the treatment of exceptions. An incorrectly configured agent can repeat an error consistently and at scale.
Workiva's approach is therefore closely connected to the idea of governed automation: agents should operate inside processes where permissions, evidence and accountability are part of the workflow rather than added after the work is complete.
Freda vs Workiva: Two approaches to agentic compliance
Freda and Workiva are addressing overlapping operational problems, but their product architectures and starting points differ.
| Dimension | Freda | Workiva |
|---|---|---|
| Core approach | AI-native compliance operating system | Agent-building capabilities within an established enterprise platform |
| Primary emphasis | Regulatory intelligence, compliance programme management and agentic execution | Financial reporting, internal audit, GRC and governed workflows |
| Context model | Regulatory Engine and Company Graph | Enterprise knowledge and Workiva platform capabilities |
| Agent configuration | Compliance-focused agents with configurable scope and permissions | No-code Agent Studio for customized agents |
| Illustrative workflows | Obligation discovery, evidence gathering, access reviews and compliance monitoring | Regulatory reporting, audit testing and financial workflows |
| Key consideration | Accuracy of regulatory interpretation and reliability of execution | Quality of agent configuration, workflow governance and source data |
The distinction matters because buying an agent-building platform and adopting an AI-native compliance system are not identical decisions. A bank seeking to modernize its regulatory obligations and compliance programme may evaluate Freda's connected regulatory and operational model. An organization already using Workiva for financial reporting, audit or GRC may examine how Agent Studio fits its existing workflows.
The two announcements should not be interpreted as a direct performance comparison. They do not establish that one platform is more accurate, less expensive or more effective than the other. The relevant questions are how well each fits the institution's existing architecture, regulatory responsibilities and governance requirements.
Five banking compliance workflows where agents could make a difference
The practical opportunity for agentic AI is easiest to understand at the workflow level. Instead of asking whether an AI system can replace a compliance professional, banks can examine individual activities and determine which steps are suitable for controlled delegation.
1. Regulatory change monitoring
Banks operate across complex regulatory environments. A change to a regulation, technical standard or supervisory expectation can affect multiple policies, controls, business units and reporting obligations.
An agent could monitor defined regulatory sources, identify potentially relevant changes, compare them with an institution's existing obligations and prepare an impact assessment. It could then create review tasks for the relevant compliance owners. The value is not simply faster monitoring. It is the potential to connect a regulatory change with the policies, controls and business processes it may affect.
However, identifying a regulatory change is not the same as determining its legal applicability. Material interpretations should remain subject to appropriate legal and compliance review.
2. Evidence collection and control testing
Evidence collection is one of the clearest candidates for automation because many tasks are recurring, structured and time-consuming. For example, an agent could retrieve approved access records, compare them against a defined review requirement, identify missing approvals and assemble an evidence package. In an audit workflow, agents could also support sample selection, attribute testing and documentation.
The critical requirement is evidence integrity. A bank needs to know where the evidence came from, when it was collected, what criteria were applied and whether the agent altered or omitted any information.
3. Third-party and vendor risk monitoring
Financial institutions rely on cloud providers, payment processors, data vendors and other external service providers. Changes in a vendor's security posture, ownership, certifications or contractual commitments can create new risks.
Agents could monitor authorized sources, compare changes with an institution's vendor records, identify potential control gaps and assign follow-up tasks. For example, a change to a critical service provider's security documentation might trigger a review of the relevant risk assessment and supporting evidence.
An agent should not automatically conclude that a supplier is compliant merely because a document exists. Evidence needs to be assessed against the actual requirements and the institution's risk tolerance.
4. Policy and control maintenance
Policies can become outdated when regulations, products, systems or organizational structures change.
An agent could identify a change that potentially affects a policy, locate related controls, prepare a proposed revision and route it to the policy owner. Once approved, the revised document could be incorporated into the relevant workflow.
This could reduce the administrative burden of keeping related records synchronized. It should not remove the formal approval process for policies that require authorization from designated officers or committees.
5. Remediation tracking and audit preparation
Compliance findings frequently create work across multiple teams. The initial finding may be clear, but the remediation process can involve evidence requests, ownership assignments, progress updates and validation.
Agents could track assigned actions, request missing evidence, identify overdue tasks and prepare status reports. They could also assemble supporting documentation for an audit or regulatory examination.
This is a potentially valuable application because it targets the administrative effort surrounding remediation, while keeping the approval of significant risk decisions with accountable personnel.

Why agentic compliance needs more than a capable AI model
The most consequential question for banks is not whether an AI model can understand regulatory language. It is whether the complete system can operate reliably within a regulated environment. A useful way to evaluate an agent is to separate five capabilities.
| Capability | Key question | What banks should verify |
|---|---|---|
| Regulatory grounding | Is the agent working from relevant and current requirements? | Source traceability, versioning and expert validation |
| Business context | Does it understand the institution's actual processes? | Accurate organizational records and connected systems |
| Execution | Can it complete the assigned workflow correctly? | Testing, error handling and limits on permitted actions |
| Governance | Can the institution control what it does? | Role-based access, approvals, logs and escalation |
| Assurance | Can the institution defend the result? | Reproducible evidence, review records and clear accountability |
This framework also exposes a common weakness in AI procurement. A successful demonstration may show that an agent can complete a task once, but a bank needs to know whether it can do so consistently across changing data, different exceptions and real operating conditions.
For high-impact workflows, testing should include incomplete evidence, contradictory information, outdated policies, unauthorized requests and unexpected system responses. Banks should also test what happens when an agent fails halfway through a task. An agent that updates three systems but fails to record the final approval may create more operational risk than a manual process with a visible backlog.
DORA makes operational resilience part of the AI conversation
For European financial institutions, the Digital Operational Resilience Act (DORA) is an important part of the governance discussion. It has applied since January 17, 2025, establishing requirements relating to ICT risk management, incident reporting, resilience testing and third-party ICT risk.
DORA is not a blanket prohibition on agentic AI. However, deploying agents into compliance and operational workflows creates questions that institutions need to assess within their existing ICT risk and outsourcing frameworks.
For example, banks should understand which systems an agent can access, how its dependencies are managed, what happens when a connected service becomes unavailable and whether the institution can reconstruct the agent's actions during an incident.
If an agent relies on an external model or third-party infrastructure, the institution should also consider relevant contractual arrangements, data handling, service continuity and vendor concentration risks.
The European Union's AI Act adds another layer of consideration. Its high-risk classification depends on the system's intended purpose and the specific activities it performs. Not every compliance agent is automatically a high-risk AI system. Banks must assess the actual function and applicable legal requirements rather than assume that all AI used in finance falls into the same category.
The broader principle is straightforward: deploying an agent does not transfer the institution's regulatory responsibilities to its software provider.
How banks should measure the value of AI compliance automation
AI adoption figures alone cannot establish whether agentic compliance is delivering business value. Banks need operational metrics that compare performance before and after deployment, while accounting for differences in task complexity and risk.
| Metric | What to measure | Why it matters |
|---|---|---|
| Evidence collection time | Median time from request to verified evidence | Shows whether automation reduces administrative delays |
| Control testing throughput | Number of completed, quality-checked tests per review period | Measures the ability to expand testing capacity |
| Exception detection | Relevant exceptions identified and validated | Tests whether agents improve visibility without overwhelming reviewers |
| False-positive rate | Alerts that are reviewed and found not to require action | Indicates whether agents create unnecessary work |
| Remediation cycle time | Time from validated finding to verified closure | Measures the effectiveness of follow-up workflows |
| Human intervention rate | Tasks requiring correction, approval or escalation | Reveals where the agent still depends on people |
| Evidence traceability | Percentage of outputs with complete supporting records | Measures whether work can be independently reconstructed |
| Cost per completed task | Total operating cost divided by verified completed tasks | Helps establish the economic case |
A meaningful pilot should establish a baseline before introducing an agent. Teams should then compare similar tasks, measure the quality of completed work and include the costs of implementation, integration, model usage, monitoring and human review.
For instance, reducing evidence collection time by 40% would be operationally significant only if the evidence remains complete and accurate and the savings are not offset by extensive manual correction.
The Cambridge research finding that 55% of surveyed organizations struggle to measure AI value reinforces why measurement should be part of the implementation plan rather than an afterthought.
For compliance leaders, the relevant return on investment is not the number of tasks an agent claims to complete. It is the number of correctly completed, verifiable tasks delivered at an acceptable level of risk and cost.
The human oversight question: What should AI never decide alone?
As agents gain access to operational systems, the boundary between assistance and authority becomes increasingly important.
Some compliance activities are largely administrative. Retrieving an approved report, checking whether a required field is missing or reminding an owner about an overdue task may be suitable for automation under defined permissions.
Other activities involve material judgment. Determining whether a complex transaction breaches a regulatory obligation, accepting a significant residual risk, approving a major policy exception or making a consequential regulatory representation may require accountable human review. A practical delegation model can divide activities into three categories:
| Delegation level | Suitable activities | Oversight |
|---|---|---|
| Automated execution | Routine retrieval, reconciliation, reminders and predefined checks | Monitoring, logging and exception handling |
| Human-reviewed execution | Drafting regulatory assessments, recommending remediation and preparing policy changes | Review and approval before consequential action |
| Reserved human decisions | Material risk acceptance, significant regulatory interpretation and formal attestations | Decision made by the authorized accountable person |
This is not a universal legal classification. Banks should determine the appropriate level for each workflow based on applicable law, materiality, potential harm and internal governance.
Human oversight must also be meaningful. Reviewers need enough information to understand what the agent did, what evidence it used, which rules it applied and why it reached its conclusion. A generic approval button does not provide effective oversight if the reviewer cannot challenge the underlying reasoning.
What this means for banking leaders and Finov AI Summit Europe
The announcements from Freda and Workiva provide a timely starting point for conversations about agentic AI in banking compliance. For attendees and industry professionals following Finov AI Summit Europe, the broader issue extends beyond the capabilities of any individual platform.
Banks need to decide which workflows should be automated, how much authority agents should receive and how they will verify the quality of the work. They also need to evaluate the operational consequences of connecting AI systems to regulatory records, financial processes and internal controls. Three questions should guide those discussions.
First, which workflows are genuinely ready for agentic execution? Repetitive, evidence-driven processes with clear rules and measurable outcomes provide a more straightforward starting point than complex legal interpretations.
Second, what evidence will demonstrate that an agent is operating safely? Institutions need test results, access controls, complete execution records and clear escalation paths. A compelling product demonstration is not a substitute for operational assurance.
Third, what will happen when an agent makes a mistake? Banks need defined procedures for identifying, containing, correcting and documenting errors. They should know who owns the response and how affected records and downstream decisions will be reviewed.
For the Finov AI Summit Europe conversation, these questions are more useful than treating agentic AI as a race to automate the largest number of tasks. The operational challenge is to establish where automation produces measurable value without compromising accountability.
Conclusion
Freda and Workiva are approaching a shared opportunity from different starting points. Freda is building an AI-native system that connects regulatory knowledge, business context and compliance execution. Workiva is extending its established financial and governance platform with customizable agents and automated workflows.
Both developments reflect a broader shift in enterprise AI: from systems that generate information toward systems that can carry out defined work. That shift could change how banks collect evidence, maintain controls, conduct testing and manage remediation. It could also introduce new risks involving access, data quality, model behavior, system dependencies and accountability.
The institutions that evaluate agentic AI effectively will need to look beyond the promise of automation. They will need to measure verified outcomes, establish clear delegation boundaries and ensure that every consequential action can be explained and reviewed.
The next phase of banking compliance is unlikely to be defined by how many tasks AI can perform. It will be defined by how reliably banks can delegate work while retaining control over the decisions that matter.

Frequently asked questions
1. What is agentic AI in banking compliance?
Agentic AI in banking compliance refers to AI systems that can plan and execute defined compliance tasks, interact with authorized systems, collect evidence and escalate exceptions. Unlike conventional compliance chatbots, agents can carry out parts of a workflow rather than simply provide information.
2. How is agentic AI different from traditional compliance automation?
Traditional automation typically follows predefined rules and fixed workflows. Agentic AI can interpret instructions, plan sequences of tasks and adapt its execution to certain conditions. However, agents require permissions, testing and oversight because their behavior can be less predictable than conventional rule-based automation.
3. What compliance tasks can banking AI agents automate?
Depending on their configuration and authorization, banking AI agents can support regulatory change monitoring, evidence collection, access reviews, control testing, vendor risk monitoring, remediation tracking and audit preparation. The suitability of each task depends on its complexity, risk and need for human judgment.
4. What is Freda's agentic compliance platform?
Freda is an AI-native compliance platform founded by Tink co-founders Daniel Kjellén and Fredrik Hedberg. It combines a Regulatory Engine, Company Graph, Operating Plane and Agentic Execution layer to support regulatory discovery, compliance programme management and the execution of defined compliance workflows.
5. What is Workiva Agent Studio?
Workiva Agent Studio is a no-code capability introduced in September 2026 that enables organizations to build, customize and deploy AI agents within Workiva's platform. It combines AI reasoning with enterprise knowledge, platform capabilities and governed workflows, including applications in financial reporting, internal audit and GRC.
6. Can AI agents replace bank compliance officers?
AI agents can automate selected operational tasks, but they do not automatically replace the accountability of compliance officers. Complex regulatory interpretations, material risk decisions, significant exceptions and formal approvals may require authorized human judgment, depending on the relevant requirements and institutional policies.
7. How does DORA affect the use of agentic AI in European banks?
DORA has applied since January 17, 2025, and establishes requirements for digital operational resilience in the financial sector. Banks deploying AI agents should assess relevant ICT risks, service dependencies, incident response, third-party arrangements and operational resilience obligations. DORA does not automatically prohibit the use of agentic AI.
8. How can banks measure the ROI of AI compliance automation?
Banks can measure evidence collection time, testing throughput, exception quality, remediation cycle time, human intervention, evidence traceability and cost per verified task. Comparisons should use pre-deployment baselines and account for implementation, monitoring and human review costs.
9. What are the biggest risks of using agentic AI for compliance?
Important risks include incorrect regulatory interpretation, poor-quality source data, unauthorized actions, incomplete evidence, unreliable outputs, inadequate audit trails and excessive dependence on external systems. Banks should mitigate these risks through permission controls, testing, monitoring, escalation and appropriate human review.
10. What should banks evaluate before deploying AI compliance agents?
Banks should evaluate regulatory grounding, integration with internal systems, data security, access permissions, evidence traceability, error handling, model reliability, vendor dependencies and measurable business value. They should begin with clearly defined workflows and expand delegation only after testing the system's performance and controls.
More reading
Governance is not the brake. It is the gearbox.
Under the EU AI Act, DORA and GDPR, the institutions that govern AI well are the ones able to move fastest — because they can defend what they deploy.
Insights31% of Consumers Are Already Asking Conversational & Agentic AI About Money. Is Your Bank Losing the First Financial Conversation?
The biggest threat from conversational AI in banking is not that customers will stop using banks. It is that they may stop asking banks first. For decades, financial institutions controlled the most valuable moment in the customer journey: the moment a person had a financial question.
Financial crimeFighting AI-powered fraud with AI
Deepfakes, synthetic identities and automated social engineering are changing the threat model faster than most detection stacks were designed to handle.
Agentic AIHow much authority should an AI agent have in a bank?
Agentic systems are already executing regulated payments in Europe. The design question has moved from capability to authority — who decides, who approves, who is accountable.