Cobo Agentic Wallet

Comp AI Raises $34 Million to Move Compliance from Periodic Audits to Continuous Monitoring

Comp AI has raised a $34 million Series A to develop compliance software that continuously monitors business and security changes and automates follow-up work. The company’s approach reflects a broader shift from audit-time documentation toward ongoing, risk-aware controls, while raising new questions about permissions, evidence quality and human oversight.

Cobo Newsroom
Cobo NewsroomSep 18, 2026
Key takeaways
  • Comp AI announced a $34 million Series A led by Roo Capital and Grand Ventures; TechCrunch reported that the company has raised $37.5 million in total.
  • Its software agents cover customer onboarding, policy and risk generation, evidence collection, control monitoring and vendor assessments.
  • The company argues that conventional compliance often provides a point-in-time view that may not capture changes made after an audit is completed.
  • Comp AI cites the example of an AI agent deployed after a SOC 2 audit that can access customer data or change permissions.
  • Founded in January 2025, Comp AI says it serves more than 1,000 customers and has reported 15-times year-on-year growth in annual recurring revenue; these figures are company disclosures.
  • Continuous monitoring may help high-sensitivity businesses respond faster, but it does not remove the need for least-privilege access, approval controls, audit trails and human accountability.

News illustration

Summary

Comp AI has raised a $34 million Series A to develop compliance software that continuously monitors business and security changes and automates follow-up work. The company’s approach reflects a broader shift from audit-time documentation toward ongoing, risk-aware controls, while raising new questions about permissions, evidence quality and human oversight.

A funding round focused on always-on compliance

Comp AI, a Miami-based security compliance software company, has announced a $34 million Series A led by Roo Capital and Grand Ventures. The company said the new round brings its total funding to $37.5 million, a figure also reported by TechCrunch. Founded in January 2025, Comp AI says it now serves more than 1,000 customers and has seen annual recurring revenue grow 15 times year over year. Those customer and growth figures come from the company and are not further defined in the available source material.

The strategic proposition behind the round is broader than using artificial intelligence to draft compliance documents. Comp AI is trying to shift compliance from a process organized around audit deadlines to a system that continuously observes how a business operates. When applications, vendors, data flows or permissions change, the system is intended to identify whether the change creates a new risk and initiate the relevant work.

Lewis Carhart, Comp AI’s chief executive and co-founder, described the company’s view as a move beyond software that merely tracks completed work. In his formulation, security software should understand the business, perform work and act as risk changes. Chief operating officer and co-founder Claudio Fuentes similarly argued that historical compliance has often been an approximation of security because much of the work could only be performed manually and periodically.

The limits of an audit snapshot

The first generation of compliance software replaced or reduced reliance on spreadsheets, consultants and months of manual preparation. Digital tools can organize policies, map controls and collect evidence more efficiently. Yet a digitized process can still produce a snapshot of the environment at a particular moment. The fact that evidence is stored in software does not necessarily mean that the organization is being monitored between audit cycles.

Carhart gave TechCrunch a scenario that illustrates the gap. A company completes a SOC 2 audit, and two weeks later deploys an AI agent capable of reaching customer data or changing permissions. The earlier audit has not automatically become invalid, he said, but it was not designed to explain in real time what changed afterward.

That distinction matters as companies adopt software that is more interconnected and capable of acting on its own. A new integration, a revised role, a supplier change or a production deployment can alter the organization’s risk profile without waiting for the next formal review. In fast-moving businesses, the question is therefore not only whether controls existed when auditors examined them, but whether the controls remain appropriate as the operating environment changes.

What Comp AI says its agents do

According to the company, its agents handle customer onboarding, policy and risk generation, evidence gathering, control monitoring and vendor assessments. The list covers several stages of the compliance lifecycle: establishing a control framework, producing or updating documentation, collecting proof that controls are operating, checking their status and evaluating external providers.

The important product distinction is the emphasis on monitoring rather than document production alone. A system that generates a policy may save time, but a continuous compliance system must connect changes in the business to the policies and controls that govern them. It must also identify which changes warrant escalation and which are routine operational events.

That requires more than a language model producing plausible text. It requires reliable data sources, an inventory of systems and permissions, a record of changes and rules for determining when an event affects a control. It also requires the company using the software to understand what the system can observe and what it cannot. A dashboard that creates the appearance of constant oversight without complete or current data could provide false confidence rather than stronger security.

Agentic automation creates its own control problem

Continuous automation does not mean that risk can be delegated entirely to software. An agent that can identify a risk and trigger work must operate within clearly defined boundaries. Organizations need to know what data it can access, what settings it can change, how it distinguishes a material event from an ordinary business update, who approves high-impact actions and how the process is recorded for later review.

This is particularly important when an agent can reach customer information or modify permissions. Compared with a tool that only prepares a report, an operational agent has a wider action surface. Misclassification, excessive privileges, compromised credentials, unsafe instructions or an uncontrolled third-party connection could all increase the consequences of an error.

For that reason, the monitoring system itself becomes part of the control environment. Its access should generally be limited to what is necessary for its role, and sensitive actions may require additional approval or a human-in-the-loop process. The most defensible use of automation may be to shorten the time between detecting a change and presenting it to the responsible team, rather than to eliminate human responsibility for consequential decisions.

Relevance for financial and digital-asset operators

The shift toward continuous monitoring is relevant to financial institutions, payment companies, digital-asset platforms and other businesses that handle sensitive data or operate complex permission systems. Their risk posture can change when a new product is launched, an API is connected, a vendor is replaced, employee access is revised or custody and infrastructure arrangements are updated. A periodic review may not capture every change between formal checkpoints.

At the same time, “continuous” monitoring introduces operational challenges. Companies need defined monitoring coverage, dependable data feeds, named control owners and escalation rules. Poorly tuned systems can generate too many low-quality alerts, creating alert fatigue. Incomplete logs can make it difficult to reconstruct why a decision was made, even if the event was technically detected.

Institutional wallet and custody environments illustrate the governance stakes without requiring a particular vendor or product. Key-management procedures, role separation, transaction approvals and external connections all need clear authorization boundaries and verifiable records. An automated platform may help collect evidence or flag changes, but its output cannot by itself establish that access was appropriate or that a high-impact action received the required review.

What to watch after the financing

Comp AI’s financing reflects investor interest in “agentic compliance”: software that aims to connect business changes, risk assessment and control execution instead of merely storing documents or sending deadline reminders. Whether the model can work reliably across industries will depend on the accuracy of its agents, the quality of its integrations and the safeguards around sensitive operations.

The company’s reported customer and revenue growth will also need to be assessed through operational outcomes rather than automation volume alone. Relevant questions include whether risks are identified early, how false positives and missed events are handled, whether evidence is acceptable to auditors and whether customers can reconstruct the decision trail when a system takes action.

The development does not make periodic audits obsolete. A more likely outcome is that audits remain important checkpoints within a broader governance framework, while continuous monitoring fills the information gaps between them. For companies using AI agents, cloud services and complex permission structures, the central challenge will be combining automation speed with explainability, least-privilege access, human accountability and evidence that can withstand review.

Source: link

AIREGULATIONS

About Cobo

Cobo is an institutional digital asset infrastructure provider founded in 2017. The Cobo Agentic Wallet extends Cobo's MPC custody platform to autonomous onchain agents.

Press inquiries: [email protected] · Media kit, executive bios, and additional materials available on request.
Agentic Economy by Cobo

Get this in your inbox every Friday.

The weekly newsletter from the Cobo team — unpacking the most consequential stories in crypto, AI & payments through the lens of institutional custody.