Compliance teams running onchain financial services have a problem the rest of the industry is finally catching up to: alert volume is growing faster than headcount, and the hiring market for senior analysts is empty. The tools that drove the first generation of crypto compliance — Chainalysis, TRM, Elliptic, Notabene, the Travel Rule protocols — gave us better signals. They did not give us throughput. The gap between signals and throughput is where AI compliance agents live.
This guide is for MLROs, BSA officers, Heads of Compliance, and the procurement and model-risk teams who buy alongside them. It is the document we hand to compliance leaders evaluating Cogentic — and to those evaluating any vendor in the agentic AI category. It is deliberately vendor-agnostic in framing. The framework holds whether you select Cogentic, build internally, or stay on point tools.
Why now
Three things have changed that make agentic AI in compliance not just feasible but expected. First, frontier reasoning models in 2026 cleared the quality bar for narrative drafting, evidence synthesis, and typology hypothesis ranking — work that took a senior analyst hours, completed in minutes by a model that cites its sources. Second, regulators are explicitly anticipating AI-augmented compliance. AUSTRAC's 1 July 2026 reform, MiCA Title IV's prudential expectations, the US GENIUS Act for stablecoin issuers, and FATF Recommendation 16 all assume institutions are using ML or AI in scope. Third, capacity failures have moved from anecdote to enforcement. Coinbase's NYDFS settlement disclosed 100,000+ unreviewed transaction-monitoring alerts. Robinhood Crypto's settlement disclosed 4,378. The market default — staff your way out of the queue — is no longer working.
What an AI compliance agent actually does
Strip the marketing language and an AI compliance agent does three concrete things:
- Triage L1 alerts. Across alert sources — Chainalysis KYT, TRM Monitoring, Elliptic Navigator, internal rules, ML risk scores — the agent produces a single ranked queue with confidence scores, suggested dispositions, and full evidence citations. Routine false positives auto-close with logged reasoning. Real alerts escalate with pre-assembled investigation context.
- Complete L2 investigations. Resolve entities across customer wallets and KYC records. Trace onchain flows. Pull counterparty context from Sumsub, World-Check, ComplyAdvantage. Compare to peer baselines. Rank typology hypotheses. Output a structured evidence pack with cited sources — not a decision, an evidence pack.
- Draft regulator-ready reports. SAR, SMR, STR. AUSTRAC SMR, FinCEN SAR, goAML XML, UK SAR — drafted from the evidence pack in the regulator's expected register, with page-anchored citations to source data. The MLRO reviews, edits, signs, submits.
Anything else marketed as an agent that does not contribute to one of these three loops is decoration. The validation framework below pressure-tests vendor claims against this concrete shape.
Validation framework
Six questions to ask any vendor in the agentic AI compliance category. Score each from 1 (poor) to 5 (strong). Anything below 3 in audit-defensibility, citation discipline, or reporter-of-record model is a deal-breaker — those are non-negotiable.
1. Audit-defensibility
Can the vendor produce a complete evidence pack for a six-month-old case in one click — including the model version that ran, the inputs it considered, the reasoning trace, the regulatory obligation each decision mapped to, and the MLRO's signature? Bit-identical reconstruction is the floor. Anything less fails an examiner conversation.
2. Citation discipline
Every claim in a drafted SAR narrative must cite source evidence. Ask the vendor to produce a SAR draft, then point at any sentence and ask which Chainalysis trace, Sumsub record, or Snowflake row it derives from. If they cannot answer to the row, the model is fabricating — and fabricated facts in a SAR is a regulatory event.
3. Reporter-of-record model
The MLRO must be the named reporter on every SAR. The cryptographic signature must bind to the SAR content hash so any post-signature edit invalidates the binding. The reasonable-grounds judgement stays human. The AI drafts; the officer decides. A vendor whose product can submit autonomously is not enterprise-ready.
4. Stack integration depth
The agent must work inside the systems your team already runs. Read access to Chainalysis, TRM, Elliptic, Sumsub, World-Check, your customer data warehouse. Write-back to case status, KYC tier, custody policy where you authorise it. A vendor that requires a migration into their case management system fails this question.
5. Model risk documentation
SR 11-7 documentation produced by default. Model versions, training-data disclosures, performance benchmarks, known failure modes. Independent model validation supported. Your model risk team should see the same artefacts the vendor's risk team does — not a marketing one-pager.
6. Jurisdiction coverage and roadmap
Which regimes are live today and which are roadmap. AUSTRAC AML/CTF, MiCA Title IV, FinCEN BSA, FATF Rec 16, MAS, VARA, SFC, FCA. Be honest with yourself about migration plans — if your jurisdictions aren't all covered today, your pilot starts where it is and rolls others as they come live.
Regulatory mapping
Where AI agents map to specific regulatory obligations across the four major regimes onchain financial services operate under in 2026.
AUSTRAC AML/CTF Amendment Act 2024 — effective 1 July 2026
- Tranche 2 entrants: real-estate professionals, lawyers, accountants, trust/company service providers come under supervision. EDD and KYB agents address onboarding-to-operations transition.
- Ongoing CDD: shifts from point-in-time to continuous. Investigation Agent triggers on material facts (sanctions list updates, adverse media, transaction-pattern shifts, counterparty VASP status changes).
- SMR deadlines: 3 business days for ML, 24 hours for terrorism financing. Investigation-to-signed-SMR compression is the only way to hit these consistently.
- Record-keeping: 7-year retention with verifiable integrity. Immutable evidence ledger and cryptographically bound signatures address this directly.
MiCA Title IV (EU) — Crypto-Asset Service Providers
- Travel Rule (TFR 2023/1113): zero threshold; full originator/beneficiary data with verification at EUR 1,000+. Multi-protocol counterparty data normalisation handles ingest. The agent normalises across protocols so workflow is protocol-agnostic.
- Prudential and conduct rules: model risk and operational resilience expectations apply to AI tools used in CDD and transaction monitoring. SR 11-7 documentation is the cleanest mapping for European supervisors.
US GENIUS Act — payment stablecoin issuers
- Reserves and redemption monitoring: redemption-flow monitoring and reserves attestation are workflow problems where custom agents (FDE engagements) ship before the regulation does. Stablecoin issuer monitoring is in the extend the surface for most agentic vendors.
- BSA + sanctions: FinCEN SAR, OFAC 50% rule resolution across UBO cascades. Reporting Agent + counterparty intelligence cover this.
FATF Recommendation 16 — global Travel Rule
- Counterparty due diligence: VASP profiling, registration, licensing. Counterparty intelligence (VASP Track or equivalent) is table stakes.
- Cross-border data transmission: messaging protocols (TRP, TRISA, OpenVASP, Sumsub TR, Notabene) — your team should not care which one a counterparty runs on. Multi-protocol normalisation is infrastructure, not policy.
Vendor-selection checklist
Take to a vendor conversation. Walk it section by section. Demand specificity — vendors who hand-wave on these questions are not ready for production compliance work.
Onchain-native
- Resolve entities across wallets and legal entities as one graph
- Onchain attribution surfacing in evidence packs (Chainalysis or TRM)
- Tokenised-securities transfer logic (or honest roadmap)
Audit infrastructure
- Immutable, append-only evidence ledger
- Signatures cryptographically bound to SAR content hashes
- Bit-identical case reconstruction at six months / one year / two years
- Examiner-ready evidence pack export in one click
Integrations
- Read from Chainalysis, TRM, Elliptic without bespoke ETL
- Read from Sumsub, Persona, Onfido, Middesk, Sayari without manual exports
- Write back to your case management of choice (Salesforce, Zendesk, Unit21, Hummingbird, in-house)
- Slack and Teams handoff for case routing
Model governance
- SR 11-7 model risk documentation produced by default
- Independent model validation supported
- Override rates tracked and surfaced for evaluation
- Eval suite for regression; adversarial fabrication tests
Data handling
- Zero data retention configurable
- Customer data does not train models without explicit opt-in
- Data residency for AU, EU, US (per your operating regions)
- Virtual private cloud deployment available
Deployment playbook
A six-week pilot framework. Adapt to your vendor and your stack. The cadence holds across the agentic AI category.
Week 1 — integration scoping
Vendor's forward-deployed engineering team scopes Chainalysis or TRM ingest, Sumsub reads, your customer data warehouse access, your case management write-back surface. Output: written integration spec with success criteria and acceptance bar.
Weeks 2–3 — agent calibration
Tune policy encoding, jurisdiction rules, risk weights, typology priorities to your SOPs. MLRO reviews recommendations on historical cases. Override rates inform tuning. By end of week 3, agent recommendations align with MLRO judgement on the bulk of representative cases.
Weeks 4–6 — live pilot
Production traffic. MLRO reviews and signs every SAR. Eval scorecards visible weekly. Throughput metrics tracked from day one — cases per analyst-week, time-to-SMR per case. By end of week 6, the metrics commitment for renewal is locked.
Risks to call out
Adoption risk
Senior analysts are the longest-tenured staff in any compliance team. They have habits and pattern recognition that took years to build. The agent threatens neither — it changes what they do, not whether they exist. The right framing in the pilot is throughput multiplier, not headcount substitute. MLROs who lead with the latter face team revolt.
Trust risk
If MLROs don't trust the draft, they rewrite it from scratch and your throughput claim collapses. Citation discipline and evidence-pack quality are the things that earn trust. Vendors that hand-wave on citation are setting their own pilot up to fail.
Procurement risk
Compliance procurement at most institutions is multi-stakeholder — MLRO, CCO, legal, model risk, security, IT. Every stakeholder has a veto. The vendor diligence pack — SR 11-7 docs, security controls, reference architectures, sample evidence packs — runs alongside the pilot conversation, not after. Without it, procurement stalls in week 4.
How to engage Cogentic
Cogentic is the AI agents platform for onchain financial crime. Investigation Agent and Reporting Agent are for AUSTRAC AML/CTF live now. Sanctions / EDD / KYB / regulatory horizon agents on the extend the surface. Custom agents via forward-deployed engineering. Reporter-of-record model baked in. SR 11-7 documentation by default.
If you are an AU VASP hitting the 1 July 2026 deadline, a B2B stablecoin payment platform, a stablecoin issuer, or a tokenisation infrastructure provider — book a twenty-minute readiness conversation. We will walk this checklist with your MLRO, your CCO, and your model risk team. We will tell you honestly whether fits your timeline.