Comp AI said Sept. 17, 2026, that it raised $34 million in Series A funding to expand its AI-driven compliance platform into continuous cybersecurity monitoring and testing. Roo Capital and Grand Ventures led the round, which brings the company’s disclosed funding to $37.5 million.

The financing puts new capital behind a growing enterprise problem: annual or periodic audits can confirm that controls existed at one moment, but they do not automatically reveal what changed after a company deployed a new AI agent, altered permissions or connected another data source.

Funding backs a broader security platform

In its funding announcement, Comp AI said it will use the investment to move beyond audit preparation into real-time monitoring, control validation and security testing across applications and infrastructure. The company says its platform combines compliance, risk management, vendor security and security operations.

Comp AI also said it now serves more than 1,000 companies and recorded 15-fold year-over-year growth in annual recurring revenue. Those figures are company-reported and were not independently audited in the announcement.

The company was founded in 2025 by Lewis Carhart, Claudio Fuentes and Mariano Fuentes. TechCrunch reported that its agents can help draft security policies, collect evidence for audits and monitor whether controls remain in place. The platform also offers AI-assisted penetration testing.

Automation does not replace the audit

Comp AI told TechCrunch that people still review and approve agent-drafted policies and that its software does not replace an independent audit. That distinction is important because generating documents and collecting evidence are not the same as determining whether a control is effective or whether an organization has accepted an appropriate level of risk.

The more significant product direction is continuous accountability. Enterprise agents may access customer information, change settings or act across several systems at machine speed. Security teams therefore need records showing what an agent accessed, what it attempted and whether it stayed within its assigned boundaries.

Why the market is moving now

Compliance software has traditionally helped companies prepare for certifications such as SOC 2 by organizing policies and evidence. Agentic software changes the operating environment between those checkpoints. A control that passed review can become less reliable when a new automated process receives broader permissions or touches a previously isolated system.

Comp AI’s round is a bet that compliance will become a live operational layer rather than a project completed before an audit or sales review. For enterprise buyers, the test will be whether automated monitoring produces useful evidence without creating another stream of alerts that still requires extensive manual interpretation.