On September 17, 2026, Comp AI closed a $34 million Series A co-led by Roo Capital and Grand Ventures to scale its agentic AI platform built to automate cybersecurity and regulatory compliance workflows.
🔑 Key takeaways
- Comp AI raised $34M in Series A, bringing total funding to $37.5M since its January 2025 launch.
- The platform automates SOC 2 compliance, security policy drafting, and audit evidence collection via AI agents.
- The human-to-non-human identity ratio jumped from 92:1 to 144:1 in one year, per the Cloud Security Alliance.
- The Coalition for Secure AI and NIST published new guidance in 2026 to frame these emerging risks.
- The 2024 CrowdStrike outage pegged the cost of unmanaged machine identities at $5.4B to $10B.
A Series A to industrialize agentic compliance
Founded in January 2025, Comp AI now counts $37.5 million in total funding. The round was co-led by Roo Capital and Grand Ventures, with allocation between the two undisclosed. The company declined to share its valuation.
The founding trio comprises Lewis Carhart (CEO), Claudio Fuentes (COO), and his brother Mariano Fuentes (CTO). Before Comp AI, the Fuentes brothers co-founded LeapAI, a workflow automation platform that crossed one million users in roughly two years before being shut down for lacking a sticky enough use case to justify continued investment.

That first venture, however, taught them how to ship on top of large language models and showed them firsthand how painful SOC 2 compliance (a U.S. security audit framework) could be. « It’s a very obscure process. It took us a few months to do things manually, and all that time meant pulling our attention away from building the product, » Claudio Fuentes told TechCrunch.
An agentic AI platform for security and compliance
Comp AI pitches itself as an agentic platform (i.e., driven by autonomous AI agents that chain tasks together) to automate the heavy lifting in security and compliance. In practice, its agents draft security policies, gather audit evidence, and continuously monitor whether controls remain in place.
« For many software companies, security and compliance are directly tied to revenue. What Comp AI automates is a big chunk of the work companies traditionally have to do around that process. »
Lewis Carhart, CEO of Comp AI
The software helps firms reach and maintain security requirements but does not replace the actual independent audit. The founders stress that the platform does not replace humans either. « An agent can draft a policy, for example, but a person always reviews and approves. As agents take on more consequential actions over time, we believe the level of human guarantees and approvals should scale accordingly, » Carhart explained.
Comp AI also offers AI-assisted penetration testing, where the platform proactively probes codebases and infrastructure for vulnerabilities. The team plans to use the Series A capital to expand the product surface.
The explosion of non-human identities, the market’s biggest driver
Demand for continuous, autonomous security platforms is accelerating as enterprises roll out agentic AI tools. According to a Cloud Security Alliance analysis published in January 2026, the average ratio of human to non-human identities (software agents, APIs, bots) climbed from 92:1 to 144:1 in a single year. The proliferation widens the attack surface: more identities, more credentials, more access points, more risk.
| Indicator | Early 2025 | Early 2026 |
|---|---|---|
| Human vs. non-human identity ratio | 92:1 | 144:1 |
| Non-human identity categories | Software agents, APIs, bots | Software agents, APIs, bots + agentic AI |
| Credential types | Tokens, keys, service accounts | Tokens, keys, service accounts + agent tokens |
« Imagine a company finishing its SOC 2 audit and then, two weeks later, deploying a new AI agent that can access customer data, change permissions on an internal system, or introduce a new vulnerability through a code deployment. The audit didn’t become invalid; it just wasn’t designed to tell you in real time what changed next, » Carhart said.
Regulatory frameworks and standardization efforts
Several initiatives are working to structure the response. The Coalition for Secure AI (CoSAI), launched at the Aspen Security Forum two years ago, published in its second year a report on the future of agentic security (covering the evolution from chatbots to autonomous swarms), research on Model Context Protocol security, and a shared-responsibility framework. In May 2026, the organization unveiled a new framework addressing accountability when AI gets things wrong.
The National Institute of Standards and Technology (NIST) released in September 2026 an analysis of the identity and authorization challenges facing agentic AI systems. The paper warns that sharing credentials with agents creates accountability gaps that can lead to security, privacy, and legal issues. NIST points to existing standards such as OAuth 2.0 (a standard authorization protocol for APIs) and SPIFFE (a workload identity framework for cloud environments) as mechanisms already equipped to address these challenges.
A risk taxonomy in the making
A study posted on arXiv (an open-access scientific preprint server) in August 2026 highlights that AI agents, service accounts, API tokens, and automated workflows now outnumber human identities by ratios exceeding 80:1. The paper proposes a risk taxonomy and a governance framework dedicated to machine identities.
« The consequences of unmanaged machine identities can be significant, as the 2024 CrowdStrike incident showed, with estimated losses of $5.4 billion to $10 billion. »
arXiv study, August 2026
On the Comp AI side, Mariano Fuentes sums up the roadmap: « We’re building toward a security layer capable of monitoring and validating these kinds of risks more continuously as these systems evolve. » The startup is wading into a market where the race between agentic AI adoption and continuous compliance is just beginning.
Conclusion
Comp AI’s round captures a structural shift: compliance, long treated as a periodic exercise, is becoming a real-time concern as AI agents make decisions and touch sensitive data. If the platform delivers on its automation promises, it could quickly become a standard layer in the security stack of B2B software vendors.
The bullish case sees broad adoption of continuous audits and tighter alignment with NIST and CoSAI frameworks. The bearish case sees fragmentation across vertical tools (one per framework: SOC 2, ISO 27001, HIPAA…) and slow consolidation. Either way, the central question remains: who is responsible when an autonomous agent drifts?
Sources
- TechCrunch – Comp AI sets eyes on a continuously agentic future for security and compliance
- Cloud Security Alliance – Why agentic AI matters for the future of cybersecurity
- Coalition for Secure AI – CoSAI Year 2: The future of agentic security
- NIST – Back to the future: why agentic AI needs a strong identity foundation
- arXiv – Risk taxonomy and governance framework for machine identities
This article is published for informational and educational purposes. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

