Benjamin Deplus, Partner France
If you look at what we've called "AI agents" over the last two years, most of it has been UI. Clever wrappers sitting on top of someone else's stack: they demo well, they live in the browser, and then they get parked in a side channel because nobody trusts them with real money or real risk. From a capital point of view, we've basically funded thousands of small experiments at the edge.
That window is closing. In 2024, AI startups pulled in roughly a fifth of all European VC funding, which tells you that investors increasingly see AI as a core infrastructure layer, not an add-on. Regulation is catching up fast: the EU AI Act is live, and by 2026 every Member State has to operate an AI sandbox for "high-risk" systems in areas like finance, employment and critical services. That forces agents out of shadow IT and into governed environments where CROs, CISOs and regulators have an opinion.
In parallel, financial institutions are quietly leaning in. Around three-quarters of UK financial firms already use AI somewhere in their stack and another ~10% plan to within three years. The interesting shift is not another chatbot; it's agents that sit across trading, risk, procurement or finance systems, read the logs and documents, and start proposing or triggering actions. In security specifically, this looks like an autonomous SOC: agents continuously ingesting telemetry across endpoints, cloud, identity and apps, triaging alerts, auto-resolving low-risk incidents, and escalating only the real edge cases to humans, under hard guardrails. Most of the thin, single-skill agents launched in the last 24 months will either be acquired as features or disappear. The ones that matter will look more like infrastructure: deeply integrated, auditable, with proper guardrails and kill switches.
In AI & ML, I don't think the lasting value sits with whoever ships the most wrappers. It sits with the teams who own the control plane for agents in regulated environments, and who can make those systems boring, traceable and safe enough to sit directly in the flow of funds and decisions.
Q: What is the difference between an AI agent wrapper and an AI agent control plane?
A: An AI agent wrapper is a lightweight layer built on top of an existing model or stack, typically designed for demos or narrow tasks. A control plane, by contrast, is the infrastructure layer that governs how agents are deployed, monitored, audited, and constrained across an organization's core systems.
Q: How does the EU AI Act affect AI agent deployment in financial services?
A: The EU AI Act classifies certain AI applications in finance, employment, and critical services as "high-risk," requiring them to operate within regulated sandboxes by 2026. This effectively moves AI agents out of shadow IT and into environments subject to oversight from CROs, CISOs, and national regulators.
Q: What makes an autonomous SOC different from a traditional security operations center?
A: An autonomous SOC uses AI agents to continuously ingest telemetry across endpoints, cloud, identity, and applications. Unlike traditional SOCs that rely on human analysts for most triage, an autonomous SOC auto-resolves low-risk incidents and escalates only genuine edge cases, all within hard policy-based guardrails and with a full audit trail.