Compliance was built around a game. On one side, the bank's risk officer, compliance head, audit team. The humans who prepare filings and defend the record. On the other side, the regulator's supervisor, inspector, examiner. The humans who read filings and ask the harder questions.

Every part of the compliance function is designed for that game.

The game is changing. Not because either side wants it to. Because both sides are getting agents.

The infrastructure shift underneath this: The On-Prem Awakening and The Open Architecture Illusion.

A game between humans, for a hundred years

Every compliance framework at a regulated enterprise is optimised for three assumptions.

Sampled review. A human regulator can't check every trade, every message, every decision. So compliance systems are built to flag outliers and pass a sample.

Deferred inspection. The review comes on a schedule. Every eighteen months. Every twenty-four. Some intermittent cadence. So compliance can be reconstructed after the fact, from logs, using narrative.

Human context. A human reviewer can be walked through why something looked odd but wasn't. Exceptions get narrative escape hatches. The bank's team briefs the regulator's team. The regulator's team asks follow-ups. The record gets negotiated in a meeting.

That's the game. Slow. Asymmetric. The regulator can't see everything. The bank can't hide everything. Both sides accept the limits. Both sides employ humans who understand each other.

Both sides get agents

The obvious first move is on the bank side. Banks are already building AI into transaction monitoring. Into model risk validation. Into KYC, into fraud detection, into financial-crime screening. Every large bank has a plan for agentic AI in compliance. Some are further than others. None will still be relying on the same human-sampled workflow by 2028.

The equally obvious second move is on the regulator side. Regulators face the same pressure banks do. Supervisory workload growing faster than headcount, for a decade. They have the same technology available. It doesn't matter whether they're technology-forward. They will end up with agents because there's no other way to keep up.

The point isn't a race. Neither side is ahead. What matters is that the game itself is changing.

When both sides are agentic, the compliance conversation stops being a human-drafted narrative and starts being a machine-readable exchange.

Not a race between the bank's humans and the regulator's humans. A negotiation between the bank's agent and the regulator's agent.

What breaks when both sides are agentic

The three assumptions the old game rested on all fall.

Sampled review becomes total review. When the regulator's agent reads at machine speed, there's no sample. Every trade. Every message. Every decision. Every model output. If it happened, it's in the read.

Deferred inspection becomes continuous. The regulator's agent doesn't wait eighteen months. It watches the API today, tomorrow, forever. Compliance shifts from prep-for-audit to prep-for-always.

Human context disappears. The bank's agent has no PowerPoint deck to walk anybody through. The regulator's agent doesn't want one. The exchange happens in structured form or it doesn't happen. There's no meeting in the middle where the two humans reach an understanding. There's just: does the record hold up?

The compliance function that survives is the one that treats every filing not as a document a human will read but as an artefact another agent will parse.

That's a different design.

What survives

Three architectural properties.

Compliance runs inside the decision, not after. Not as a downstream filter that catches violations in the log. As a rule inside the decisioning step itself, so the model cannot fire an action that violates a rule. When the regulator's agent asks "why did you send this message," the bank's agent returns: rules evaluated, timestamp, model version. Structured. Verifiable. No meeting required.

Every decision produces an audit trail as a byproduct, not a project. Compliance stops being something built on top of the platform. It's the platform's natural output. Every decision emits a compliance record automatically. Both agents can read it.

Model versioning becomes the audit unit. Regulators used to ask "why did you do this?" Their agents will ask "which model version made this decision, when did it change, and what data was that version trained on?" The answer needs to be one query away, not a project team away.

Appice Exhibit: Compliance for humans versus compliance for agents on both sides
Exhibit 1. The tussle isn't going away. It's moving to machine speed.

The reframe

The compliance function was designed for a game where humans wrote for humans and negotiated in meetings. That game is not being upgraded. It's being replaced.

The bank's team of compliance humans still exists. So does the regulator's. But the artefacts that pass between them will be built for, and read by, agents on both sides. The compliance human moves from writer of the record to designer of the system that emits the record.

The question stops being "did we prepare well for the exam." It becomes: does our compliance system produce records that another agent can parse.

Different function. Different design. Different budget.

The tussle isn't going away. It's moving to machine speed. The compliance system that survives is the one that reads back as fast as the regulator's agent can read.

The longer body of work, twenty-one essays on what marketing becomes in the agent era, is in A Moment to Think.