Five vendors build agentic AI for regulated financial workflows with the audit depth supervisors expect: DBB Software for custom agent development, Kore.ai for enterprise conversational platforms, NICE Actimize for AML and financial crime monitoring, Salesforce Agentforce for institutions already standardised on Salesforce, and Quantexa for entity resolution beneath a detection layer. One date to settle before evaluating any of them — the EU AI Act’s high-risk obligations did not start in August 2026. The Digital Omnibus moved them to December 2027, turning a missed deadline into a design window.
Most vendor conversations in European financial services are running on a date that no longer applies.
High-risk obligations were due on 2 August 2026. Six days before that, Regulation (EU) 2026/1744 — the Digital Omnibus on AI — entered into force and pushed stand-alone Annex III systems to 2 December 2027, with embedded systems following on 2 August 2028.
A lot of published guidance has not caught up. Check the date on anything telling you the deadline has passed.
The extension is worth more than fifteen months of breathing room, because of what sits inside it. Systems placed on the market before the applicable date escape high-risk requirements unless they undergo substantial modification afterward. An institution that gets a governed deployment live during the window lands in a materially easier position than one arriving at December 2027 with a proof of concept.
What Applies Right Now
Article 50 transparency duties took effect on 2 August 2026 as scheduled. Marking requirements for systems already on the market, plus several new prohibitions, arrive on 2 December 2026.
The classification detail matters more than most summaries admit. Annex III point 5(b) covers AI that evaluates creditworthiness or establishes a credit score — explicitly high-risk. It then carves out an exception for systems used to detect financial fraud. A standalone fraud detection tool generally sits outside the high-risk category. The same tool becomes high-risk the moment its output determines whether a customer gets denied a financial service.
Penalties differ by tier too. The headline €35 million or 7% of global turnover applies to prohibited practices under Article 5. Non-compliance with high-risk obligations carries up to €15 million or 3%.
Institutions that spent 2025 evaluating agents on accuracy are now evaluating them on whether a denied application can be reconstructed and explained eighteen months later. The deferral gave them time to answer that properly. It did not retire the question.
Why Agentic AI Reached Production in Financial Services
Financial institutions run some of the most complex workflows in any industry, and much of that work still depends on manual review, spreadsheet escalation, and compliance teams that surface problems only after they turn expensive.
Industry estimates put global fraud losses above $190 billion annually, with compliance teams spending a large share of their budgets — some analyses suggest around 42% — clearing false positives. Treat both figures as directional rather than precise; methodology varies considerably across sources.
Agentic AI changes the arithmetic because it acts rather than answers. A copilot summarises a flagged transaction. An agent opens the case, cross-references entity risk, screens against sanctions lists, drafts investigation notes, and routes a recommended action with every step logged.
What Separates a Real Vendor From Positioning
Most tools marketed as agents in this sector are language models with a compliance disclaimer attached. Regulated deployment sets a higher bar.
Auditability means immutable, timestamped logs covering every query, record access, and workflow step. Governed execution means acting inside policy frameworks and role-based permissions rather than through open-ended inference. Explainability has to exist at the decision level, so a flagged case can be justified to a supervisor on demand.
Add integration across core banking platforms, AML tooling, and payment rails, plus human-in-the-loop controls with defined escalation thresholds.
Worth understanding what these controls constrain. AI agent architecture describes systems that plan, call tools, retry, and self-correct across many steps — which is precisely why permission boundaries and logging matter more here than in a single-shot model deployment. A vendor who cannot produce the audit log in detail is not production-ready, whatever the demo showed.
How These Five Were Selected
Each firm demonstrates production deployment in regulated financial workflows rather than pilot capability, documented audit and logging architecture rather than a certification badge alone, and integration depth across core banking, AML, or payment infrastructure.
Excluded: vendors whose compliance evidence amounted to a security page, and firms unable to describe escalation and override design concretely.
1. DBB Software

HQ: Kraków, Poland · Founded: 2015 · Team: 50–249
What they do. DBB Software builds custom AI agents, multi-step autonomous workflows, and production AI systems for regulated financial environments. Its agentic AI development services cover agent architecture, tool and API integration, memory, permissions, human approval, evaluation, and production deployment.
The company also builds payment platforms and secure financial workflows for clients across Europe, the US, and Israel. It holds ISO/IEC 27001:2022 certification, with independently audited information security practices that support vendor risk assessment before technical evaluation starts.
Delivery runs on senior architect governance, with explicit controls for agent permissions, tool access, escalation, auditability, and human approval. AI-assisted engineering speeds implementation while DBB architects retain responsibility for system design and production decisions.
Recent delivery. Biolux involved a full HIPAA and GDPR compliance review across AWS infrastructure, IAM, and VPC configuration, producing a remediation roadmap and a certified auditor connection. LegalFly’s multi-jurisdiction scraper runs on AWS Lambda, CloudWatch, and Selenium behind a unified API with a dedicated observability dashboard.
Why companies choose them. The Scope & Design Document arrives in about three weeks from two senior engineers and a solution architect, requiring roughly five hours of client time. It produces technical documentation reviewable against business, security, integration, and governance requirements before implementation begins.
That targets a specific failure pattern: programmes stalling between a proof of concept that performs on sample data and the integration, permission, audit, and escalation work nobody scoped. Delivery then follows a 30-day path to a live MVP with a one-hour incident response target after launch, at $25–$49 per hour.
Best for. Banks, lenders, and insurers whose workflows depend on proprietary methodology and require agent permissions, escalation logic, integration depth, and documentation built for regulated environments.
2. Kore.ai

HQ: Orlando, Florida, USA
What they do. An enterprise agentic AI platform with a dedicated financial services practice, named a Leader by Gartner, Forrester, and Everest Group across conversational and agentic AI categories.
Recent delivery. A ready-to-deploy agentic banking service application, plus agents for financial insight retrieval, corporate research, and customer support.
Why companies choose them. Enterprise governance with audit logging, role-based access, encryption, and configurable guardrails, alongside 300+ pre-built agents and templates. Model-, data-, and cloud-agnostic architecture limits lock-in.
Best for. Mid-to-large institutions building conversational and generative AI across customer service, employee support, and workflow automation.
3. NICE Actimize

HQ: Hoboken, New Jersey, USA
What they do. Among the most established names in financial crime technology, with transaction monitoring, AML, and fraud analytics deployed across major institutions globally.
Recent delivery. A long production history at institutional transaction volumes, using methodology regulators have encountered in prior examinations.
Why companies choose them. Regulator familiarity reduces examination friction in a way benchmark performance does not, and established integration into core banking and payment infrastructure removes a category of implementation risk.
Best for. Banks where AML, financial crime monitoring, and regulatory compliance are the primary automation priority.
4. Salesforce Agentforce

HQ: San Francisco, California, USA
What they do. AI agents for banking, insurance, and wealth management through Agentforce for Financial Services, built on Financial Services Cloud and Data Cloud.
Recent delivery. Agents supporting banking service, advisor assistance, insurance workflows, and CRM-connected engagement, with the Einstein Trust Layer supplying guardrails.
Why companies choose them. Governance inherited from existing Salesforce controls, unified data across CRM, service, and marketing for grounded responses, and prebuilt financial services templates that cut build effort.
Best for. Organisations already standardised on Salesforce Financial Services Cloud.
5. Quantexa

HQ: London, United Kingdom · Founded: 2016
What they do. Applies graph analytics and entity resolution to financial crime detection, surfacing counterparty networks, synthetic identities, and relationships hidden in transaction data.
Recent delivery. The Decision Intelligence Platform assembles fragmented data into a single trusted view before any agent reasons over it.
Why companies choose them. Governance reviews frequently stall on data provenance rather than model behaviour, and resolving entities into a defensible single view addresses that upstream. Modular deployment across cloud, on-premise, or hybrid gives residency control.
Best for. Financial crime analytics teams needing entity resolution beneath their detection and investigation layer.
What to Verify Before Committing
Request the audit documentation rather than the certification badge, and confirm every action lands in an immutable timestamped log the agent cannot alter.
Ask which decisions execute autonomously, which require approval, and how role-based permissions govern each. Expect thresholds and conditions, not principles.
Ask how a specific denied application would be reconstructed eighteen months later. An answer at the model level rather than the decision level indicates a system not built for examination.
Confirm which core banking, AML, payment, and reporting connectors ship pre-built and vendor-maintained, and which require custom implementation priced separately.
Establish whether the vendor’s deployment date puts you inside or outside the grandfathering provision, and what counts as a substantial modification that would reset it.
Where Programmes Go Wrong
Assuming the platform covers governance. Technology supplies permissions, observability, and logging. Role-based autonomy, escalation policy, and accountability structure remain institutional decisions.
Deferring audit design. Retrofitting immutable trails and escalation logic after go-live costs multiples of designing them in, and rarely satisfies an examiner who notices the controls postdate the deployment. The December 2027 date makes this avoidable rather than optional.
Treating build-time controls as sufficient. A governed agent still needs watching once it runs. AI detection and response covers the runtime half, where agents cross systems nobody designed to preserve a single audit narrative.
Deploying probabilistic logic directly into the ledger. Separate reasoning from execution. A hallucinated journal entry is not merely a software bug; it is a material business and compliance exposure.
Optimising on hourly rate alone. Remediation in a regulated environment is rarely just an engineering expense.
Frequently Asked Questions
Q. Did the EU AI Act’s high-risk rules take effect in August 2026?
No. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and deferred Annex III high-risk obligations to 2 December 2027, and Annex I obligations to 2 August 2028. Article 50 transparency requirements did apply from 2 August 2026.
Q. Is AI fraud detection high-risk under the AI Act?
Not automatically. Annex III point 5(b) explicitly excepts systems used to detect financial fraud from the creditworthiness category. The classification changes if the system’s output determines whether someone is denied a financial service.
Q. What are the penalties for high-risk non-compliance?
Up to €15 million or 3% of global annual turnover. The higher €35 million or 7% tier applies to prohibited practices under Article 5, not to high-risk obligations.
Q. Does the deferral mean we can pause AI governance work?
The grandfathering provision argues against it. Systems placed on the market before the applicable date avoid high-risk requirements unless substantially modified, which rewards getting governed deployments live during the window rather than after it.
Q. What should a vendor be able to produce before signing?
A sample audit log at the record level, a written description of escalation thresholds, a decision-level explanation of a specific case, and a list of which connectors are pre-built versus custom.
Bottom Line
The first wave of financial services AI delivered predictive analytics, scoring models, and chatbots. The second is agentic: systems that reason across steps, act within governed boundaries, and produce the audit record supervisors expect.
The regulatory clock moved. The engineering problem did not.
Fixing scope, action boundaries, permissions, and escalation logic before engineering begins removes more regulatory risk than any model choice made afterward — and the institutions that use the next fifteen months for that will be the ones not explaining retrofitted controls to an examiner in 2028.
Related: Custom Apps Are Moving From AI Features to AI Agents
| Guest Contributor Disclosure: This article was contributed by a guest author and reflects the author’s perspective. AI Insights News retains editorial control over all published content and may edit submissions for clarity, accuracy, and readability. |
