
As 2025 was the year GenAI took hold in RegTech solutions, 2026 is seeing the rise of AI agent adoption raising the upside for compliance automation and creating new risk surfaces. Early GenAI solutions enabled unstructured communications, policies and case files to combine with structured transaction and customer data. Early use-cases focused on productivity enhancements in areas like summarisation, alert review and investigation support.
But automation unlocked a deeper structural benefit as periodic reviews and sampling methods began to give way to continuous monitoring and near-real-time alerts. This created a new challenge as compliance teams found themselves dealing with massive increases in alert volume with false positive percentages well above 90%. One solution was combining GenAI with deterministic machine learning models to reduce false positives to manageable levels.By early 2026, attention had shifted towards agentic AI. Agentic systems raise the automation stakes further by querying external sources and initiating actions via other agents and APIs. But AI agents lack situational awareness and can run amok by initiating inappropriate actions. An agent connected to operational systems can open a case, change a setting, submit a request or pass information into another workflow. An error made at the start can affect each subsequent action. An agent may also retrieve restricted information, use a function outside the user’s authority or act on instructions hidden within a document or external source.
Firms must be able to control which data actions an agent may initiate (read, update, delete), which functions it may access and whose authority it exercises. They must also determine which actions require human review and be able to trace the entire chain of state changes across the workflow.
An Architectural Foundation
Model Context Protocol (MCP) is providing an architectural foundation to help address these constraints and enable agentic AI use-cases for RegTech.
Anthropic introduced MCP in 2024 as an open standard for connecting AI applications with external data and tools. Support subsequently expanded across major technology providers and in December 2025, Anthropic contributed MCP to the Linux Foundation’s Agentic AI Foundation.
MCP introduces a layer between AI models and local or remote tools. An agent communicates only with the MCP layer and no longer needs hardcoded API keys or deep internal knowledge of every downstream tool. This can reduce the bespoke work required to implement controls between agents and external systems and data sources.
Firms can set different permissions according to the user, task and operating environment. An agent may be permitted to read a record but prevented from changing it. It might prepare an action for review but lack permission to execute it. Access to production systems can be separated from access to testing environments and sensitive actions can be held for human approval.MCP-based connections can also support the capture of agent activity by logging who/what initiated the task, which function the agent requested, the relevant source references, any approval and the eventual result. Such a record is ‘table stakes’ for supporting audit, incident investigation and regulatory review.
RegTech Adoption
Several RegTech providers have already deployed MCP for regulated workflows:
- Regnology is using MCP to make regulatory reporting, finance and risk results available to agents through a common interface. An agent can interrogate a completed report, identify an exception and trace the problem into the underlying data. It can then initiate a workflow to investigate or correct the source issue, subject to the firm’s controls. This moves the use case beyond explaining reporting outputs towards linking detection with remediation. The MCP advantage is its ability to give agents defined access across connected reporting processes without granting broad access to the underlying platforms. Firms can decide where the agent may investigate, propose a correction or initiate an approved action.
- Encompass uses MCP to connect bank-controlled agents with its EC360 corporate digital identity platform. Agents can search for legal entities, retrieve corporate documents, run sanctions and politically exposed person checks, and initiate know-your-customer (KYC) workflows. The results are returned with their source provenance and audit history. This addresses a central weakness of generative AI in compliance: an answer is of limited value if the user cannot establish where the information came from. Here, MCP provides a consistent route into current identity data and defined compliance services. The bank retains control of the agent environment, while EC360 supplies the underlying evidence and records how its services were used.
- Comply is applying MCP to employee compliance processes such as trade pre-clearance, policy questions, certifications and annual reviews. Employees can initiate these tasks from collaboration tools such as Microsoft Teams or Slack rather than moving between those applications and a separate compliance platform. The agent interprets the request and calls the relevant function, while the formal decision and supporting record remain within Comply’s system. MCP’s advantage in this case is portability across user interfaces. It allows a governed compliance process to appear wherever employees work without recreating the underlying rules for each channel. This could improve access to compliance controls while preserving central oversight and recordkeeping.
- Sumsub takes MCP beyond information retrieval and workflow initiation into system configuration. An agent can read an AML policy and translate its requirements into verification levels, risk questionnaires and onboarding workflows. It can also help compliance teams update these settings when policies or regulatory requirements change. This use carries greater operational consequence because the agent is shaping controls rather than advising on them. Sumsub says access requires separate permission and sensitive changes are isolated for human review and approval. The MCP advantage is the ability to expose tightly defined configuration functions to different AI models. Compliance teams can automate part of the policy-to-control process while retaining approval before changes enter production.
Controlled Automation
MCP could provide the structure compliance teams need to move agentic AI from isolated pilots into controlled production workflows. Its value will depend on how precisely firms define each agent’s authority, approval points and evidence requirements. As RegTech platforms expose more functions through MCP, agents could take on a larger share of investigation, reporting and control maintenance without receiving unrestricted system access. This would allow firms to increase automation in stages, beginning with retrieval and analysis before progressing towards approved operational actions.
Subscribe to our newsletter


