How Are AI Agents Reshaping Europe's Regulated Infrastructure in 2026?

Benjamin Deplus, Partner France

If you look at what we've called "AI agents" over the last two years, most of it has been UI. Clever wrappers sitting on top of someone else's stack: they demo well, they live in the browser, and then they get parked in a side channel because nobody trusts them with real money or real risk. From a capital point of view, we've basically funded thousands of small experiments at the edge.

Why Are AI Agents Moving Beyond "Clever Wrappers"?

That window is closing. In 2024, AI startups pulled in roughly a fifth of all European VC funding, which tells you that investors increasingly see AI as a core infrastructure layer, not an add-on. Regulation is catching up fast: the EU AI Act is live, and by 2026 every Member State has to operate an AI sandbox for "high-risk" systems in areas like finance, employment and critical services. That forces agents out of shadow IT and into governed environments where CROs, CISOs and regulators have an opinion.

In parallel, financial institutions are quietly leaning in. Around three-quarters of UK financial firms already use AI somewhere in their stack and another ~10% plan to within three years. The interesting shift is not another chatbot; it's agents that sit across trading, risk, procurement or finance systems, read the logs and documents, and start proposing or triggering actions. In security specifically, this looks like an autonomous SOC: agents continuously ingesting telemetry across endpoints, cloud, identity and apps, triaging alerts, auto-resolving low-risk incidents, and escalating only the real edge cases to humans, under hard guardrails. Most of the thin, single-skill agents launched in the last 24 months will either be acquired as features or disappear. The ones that matter will look more like infrastructure: deeply integrated, auditable, with proper guardrails and kill switches.

Where Will Demand for AI Agents Be Strongest in 2026?

  • Sector-specific agent platforms in finance, procurement and operations that plug into existing systems but present a single, natural-language interface to the business, instead of ten different dashboards.
  • Autonomous SOC platforms for enterprise security, where agents orchestrate detection, investigation and response across SIEM, EDR, IAM and ticketing tools, with policy-based limits on what can be auto-remediated and full replay of every decision for auditors.
  • Governance and observability layers for agents, logging, policy engines, approval workflows, that a CRO, CISO or regulator can actually sign off, with a clear view of who did what and why.
  • "Agent gateways" for capital markets and core banking, standardising how enterprises route tasks to external models and internal tools, so teams stop wiring up their own bots to legacy systems and hoping for the best.

What Gives AI Agents Lasting Value in Regulated Environments?

In AI & ML, I don't think the lasting value sits with whoever ships the most wrappers. It sits with the teams who own the control plane for agents in regulated environments, and who can make those systems boring, traceable and safe enough to sit directly in the flow of funds and decisions.

Frequently Asked Questions

Q: What is the difference between an AI agent wrapper and an AI agent control plane?
A: An AI agent wrapper is a lightweight layer built on top of an existing model or stack, typically designed for demos or narrow tasks. A control plane, by contrast, is the infrastructure layer that governs how agents are deployed, monitored, audited, and constrained across an organization's core systems.

Q: How does the EU AI Act affect AI agent deployment in financial services?
A: The EU AI Act classifies certain AI applications in finance, employment, and critical services as "high-risk," requiring them to operate within regulated sandboxes by 2026. This effectively moves AI agents out of shadow IT and into environments subject to oversight from CROs, CISOs, and national regulators.

Q: What makes an autonomous SOC different from a traditional security operations center?
A: An autonomous SOC uses AI agents to continuously ingest telemetry across endpoints, cloud, identity, and applications. Unlike traditional SOCs that rely on human analysts for most triage, an autonomous SOC auto-resolves low-risk incidents and escalates only genuine edge cases, all within hard policy-based guardrails and with a full audit trail.

About the author
Benjamin Deplus
Partner
Benjamin Deplus is a serial founder turned VC investor. He built and exited two FinTech ventures, Fred de la Compta and Inqom and pioneered AI-driven bookkeeping automation as early as 2015. A fintech and Saas lover, Benjamin seats at the Board of Trustpair, Dalma, Jump, Dattak