Comp AI Raises $34 Million to Automate Compliance With AI Agents

Comp AI has closed a $34 million Series A led by Roo Capital and Grand Ventures. TechCrunch
The financing was disclosed on Sept. 17, 2026, and brings total funding to $37.5 million. The company was founded by Lewis Carhart, Claudio Fuentes and Mariano Fuentes, who serve as chief executive, chief operating officer and chief technology officer respectively.
Comp AI builds AI agents for security and compliance work. The agents draft security policies and collect evidence for audits. That work usually pulls engineers away from product work and leaves governance, risk and compliance teams with manual follow-up.
The platform also checks continuously whether a company still meets its compliance controls, the specific security rules it has promised to follow. In parallel, Comp AI offers AI-powered penetration testing, or simulated attacks that probe code and infrastructure for weaknesses.
The broader context here is a shift from compliance as exam prep to compliance as an always-on state. Older tools stored documents in one place, assigned an owner to each rule and pulled data from other apps as proof. The agentic approach tries to close the loop, writing drafts, fetching proof, spotting drift and starting checks without someone opening a ticket.
In my view, the real test is not writing policies. That part is cheap. Keeping them current is hard. Policies fall out of date as systems change, vendors change and access habits change. Proof goes stale between audits. Pairing drafting with continuous monitoring targets the right failure, as long as monitoring shows what is actually enforced and not only what a dashboard shows.
Looking at what this means for practitioners, the effects split in two. For security and platform engineers, automatic evidence collection and faster testing could turn audit readiness from a quarterly scramble into background work. For CISOs, auditors and customers, machine-written records still need version histories, approval trails and clear sign-off lines. Accountability does not disappear. It moves to review, configuration and change control.
One part worth flagging is penetration testing. Traditional tests are limited in scope, fixed in time and led by people, with agreed rules about what can be touched. AI agents can cover more ground and test sooner after a code change. The bar will be signal quality. Teams will trust autonomous findings only if duplicates are filtered, exploitability is confirmed, severity is tied to the owning team and runs are safe near production systems. Without that discipline, more findings mean more triage.
Looking further out, the direction points to compliance built into engineering work rather than added just before an audit. Controls, evidence and attack simulation would run continuously, with people setting intent and reviewing exceptions. That outcome is plausible and hopeful, because it could free small security teams from repetitive collection for design and response. It will stand or fall on inspectability. Customers and auditors must be able to see what the agent checked, repeat the check and defend it externally.


