
For twenty years, manual document processing in financial institutions was a cost problem. Since 2024 it has become a compliance problem, and compliance problems have a different budget. Three European texts are responsible: the Digital Operational Resilience Act, applicable since January 2025; the NIS2 directive, which member states had to transpose by October 2024; and the EU AI Act, in force since August 2024 and phasing in its obligations through 2026 and 2027.
What the three texts have in common
They regulate different things, ICT resilience, cybersecurity and artificial intelligence, but they demand the same kind of evidence: proof that the institution knows and controls what happens to its data, its third-party providers and its automated decisions.
- DORA requires a register of ICT third-party providers, contractual control over them and the ability to demonstrate operational resilience under test.
- NIS2 extends security governance to management level, with personal accountability and reporting duties within tight deadlines.
- The AI Act requires risk classification, documentation, human oversight, logging and transparency for AI systems used in credit, insurance and employment decisions.
Read together, they mean that every process that touches customer data, credit decisions or supervisory reporting must be able to answer: who did what, on which data, with which tool, and where is the record.
Why manual processing fails the test
A team of analysts re-keying values from PDFs into a core system produces no evidence. There is no log of which page a value came from, no confidence score, no way to prove that the same rule was applied to every file. Spot checks find errors after the fact; audits reconstruct decisions from memory. This was acceptable when the regulatory question was cost. It is not acceptable when the regulatory question is control.
The paradox is that generic AI tools do not solve this either. A copilot that produces an answer from a chat prompt is as untraceable as the analyst, with the added problem that the data may have left the institution's perimeter to get there.
The agentic answer
Agents that run on a governed operating system produce compliance evidence as a by-product of doing the work.
- Every extracted value carries a source: the document, the page and the region it came from.
- Every decision is logged with the rule, the model version and the confidence that produced it.
- Knowledge scope is bounded: an agent answers only from the documents and regulations it has been given, so the answer is deterministic and repeatable.
- Human review is inserted where the risk sits, and the reviewer's action becomes part of the record.
- The whole stack, models included, can run on premises or in a private EU cloud, so the third-party register stays short and the data never leaves.

In production: a regulatory assistant for 20,000 employees
One of the largest Italian banking groups runs a regulatory compliance agent used by 20,000 employees. It ingests the group's internal regulations and the external rulebook, models them as an ontology, and answers questions in natural language with the exact clause as evidence. It also produces impact analyses of new regulations, tracks amendments and drafts internal rules with a consistent structure. Compliance officers measure faster resolution of queries; auditors get the trail they need for free.
A checklist for the next twelve months
- Inventory the processes where documents drive decisions: onboarding, credit, claims, collateral, supervisory reporting.
- For each, ask whether you could reconstruct any decision from the last quarter with sources and rules. If not, that process is a liability.
- Prefer tools whose outputs are structured, logged and source-linked over tools that produce prose.
- Keep models and data inside your perimeter where the regulation requires it; make that a procurement criterion, not an afterthought.
- Put human review where risk lives, and record it.
Key takeaways
- DORA, NIS2 and the AI Act all require evidence of control over data, providers and automated decisions.
- Manual processing and generic copilots both fail to produce that evidence.
- Governed agents generate the audit trail as they work: sources, rules, model versions, human actions.
Curious how this would work on your documents?
Related posts
More from the same conversation. All articles
Gartner cites Altilia in the 2026 Magic Quadrant for IDP. Here is how the platform maps to the market it describes.
Four use cases, four mandatory features, sixteen optional ones. Altilia covers them on a knowledge graph, under sovereign deployment, with agents already in production.
Read more →Symbolic AI and LLMs were never rivals. The ontology is where they meet.
Language models are fluent and ungrounded; symbolic systems are rigorous and empty. Altilia lets agents create and populate ontologies, then reason over facts grounded in them, not just extract data or chat over documents.
Read more →
Why the next era of enterprise AI will be won by architecture, not model size
Bigger models do not fix fragmented intelligence, agent-unready data or missing governance. A semantic layer, an orchestration layer and deployment sovereignty do.
Read more →Send us a message.
Start envisioning the platform tailored for your company. An AI consultant will answer within one business day.
