Engineering agentic compliance with deterministic guardrails and real-time audits
Santhosh Sundar outlines how to build compliance systems that enforce rules at the point of decision using deterministic code for hard limits and agents for interpretation.
Traditional compliance models rely on post-transaction sampling and periodic reviews, a strategy that fails in modern digital environments where changes occur weekly and transactions process in milliseconds. In an essay published on October 2, 2026, Santhosh Sundar argues that agentic AI can close this gap by monitoring activity in real time and taking action within predefined limits. He contends that successful adoption requires treating compliance as a engineered system with clear architecture, interfaces, and ownership rather than simply adding agents to existing workflows.
What happened
Sundar identifies a critical mismatch between legacy control mechanisms and the speed of contemporary software platforms. While batch reports and monthly reviews describe past events, they cannot prevent violations in systems that operate across multiple jurisdictions simultaneously. Agentic AI offers a solution by interpreting objectives and executing tasks such as flagging suspicious transactions or adjusting controls when regulatory thresholds are met. The core argument is that technology is now capable enough for production use, but organizational approach determines success. Teams that design compliance as a holistic system see significant gains, whereas those that merely layer agents onto old processes achieve only modest improvements.
The essay details a shift from inventorying policies to inventorying decision points. Instead of listing every regulation, engineering teams should map where approvals, declines, or changes occur in the workflow. This approach reveals which obligations can be enforced in real time, such as screening payments before release or verifying customers before account creation. By focusing on the moment a decision is made, organizations can embed controls directly into the transaction flow, similar to how card networks currently score fraud risk within milliseconds.
How it works
The proposed architecture separates deterministic rules from probabilistic judgment. Hard constraints like regulatory thresholds, sanctions list matches, and limit checks must remain in deterministic code that is versioned, tested, and reviewed. Agents are reserved for tasks requiring interpretation, such as analyzing regulatory updates, contextualizing unusual activity patterns, or drafting escalation rationales. This three-layer model consists of a deterministic policy layer for enforcement, an agent layer for investigation and prioritization, and a human layer for ambiguous or high-consequence decisions. Guardrails are enforced through code permissions and interface restrictions rather than prompt instructions alone, making the system easier to defend during regulatory audits.
Explainability is built into the decision process rather than reconstructed from logs afterward. For every action, the system records the agent’s objective, retrieved data, applied rules, considered alternatives, and final action. These records include the specific identity and version of the agent and model used. Agents operate with their own identities and policy-based access, ensuring a verifiable history of ownership for data and instructions. This design allows compliance officers and regulators to query evidence directly without engineering support, transforming regulation from a constraint into a system-level enabler.
Key details
- Compliance checks should move from post-transaction sampling to real-time enforcement at the point of decision.
- Deterministic code must handle exact answers like sanctions matches, while agents handle interpretation and context.
- Audit trails must capture the agent’s objective, data, rules, and alternatives at the moment of decision.
- Autonomy levels should start low, with agents observing and recommending before acting on low-risk cases.
- Multi-agent designs should mirror operational specializations, with separate agents for scanning, scoring, and remediation.
- Evaluation suites based on historical cases must run as regression tests whenever models or policies change.
Why it matters
For software engineers and technical leads, this approach shifts compliance from a bureaucratic hurdle to an architectural requirement. By embedding controls into the codebase, teams reduce the latency between regulatory change and implementation. The separation of deterministic rules from agent judgment ensures that critical safety constraints remain predictable and testable, reducing the risk of hallucination-driven compliance failures. This structure also simplifies interactions with regulators, as the binding rules are explicit and the agent’s authority is technically bounded.
Operational efficiency improves as agents handle routine investigations, allowing human experts to focus on complex, high-risk cases. However, this requires careful design of escalation paths. If agents remove simple tasks, human reviewers face a concentrated stream of difficult decisions. Providing clear summaries and proposed actions with each escalation prevents cognitive overload. Furthermore, starting with low autonomy and gradually increasing it based on measured performance ensures that the system remains safe as it scales.
What you can do
- Create an inventory of decision points in your workflow where approvals or changes occur, mapping obligations to each.
- Implement hard regulatory rules as deterministic, version-controlled code separate from agent logic.
- Design audit records that capture the agent’s reasoning, data sources, and model version at decision time.
- Define explicit autonomy levels for each use case, starting with observation-only modes before enabling action.
- Build evaluation suites using historical edge cases to test agent behavior whenever prompts or policies update.
- Plan human escalation capacity and tooling to ensure reviewers can handle complex cases efficiently.



