Introduction
RegTech investment has, for much of the past decade, followed a relatively predictable path: capital flowing toward technologies designed to help financial institutions manage an expanding regulatory burden. That pattern is now shifting. As compliance enters a phase increasingly defined by artificial intelligence, operational resilience, digital identity and real-time supervision, RegTech vendors and the financial institutions that buy their products are showing measurably different investment priorities.
This divergence matters because it signals where RegTech value is likely to concentrate next, and because it affects how financial institutions allocate compliance budgets under growing scrutiny. It is relevant to RegTech vendors positioning product roadmaps, compliance and risk executives at financial institutions, and investors assessing where capital should flow within the sector.
According to findings published in the Global State of RegTech 2026 report, co-authored by RegTech Analyst and Parker Lawrence Research, vendors and institutions were surveyed on where they expect the greatest investment within financial institutions’ risk and compliance environments during 2026. The results show a substantial gap in expectations between the two groups.
What the Data Shows: A Gap Between Vendor and Institution Priorities
The report found that 91.67% of vendors surveyed believe artificial intelligence and automation will attract the greatest level of investment in 2026, compared with only 44.33% of institutions holding the same view. This represents one of the widest expectation gaps identified in the report, and the finding has prompted industry commentary on why vendors and financial institutions appear to be planning around different near-term priorities.
Vendors Focus on Transformation, Institutions on Foundations
Scott Nice, Chief Revenue Officer at Label, said the data illustrates a clear difference in emphasis: vendors are leaning into transformation themes such as AI agents, agentic automation, generative AI and API-based integration, while financial institutions are focused on the underlying foundations required to adopt those technologies safely, including modern data architecture, privacy-enhancing technologies, cryptography, cloud migration and control infrastructure. Nice characterised this as a difference in starting point rather than a fundamental disagreement about the future of RegTech, noting that technology in risk and compliance functions is judged not only on efficiency but on whether outcomes can be governed, evidenced, challenged and explained.
How AI Agents and Agentic Automation Are Driving the Widest Gap
Nice identified AI agents and agentic automation as the area with the largest gap between vendor and institution expectations. He said institution-side caution should not be read as a lack of appetite for AI, but rather as increased precision about where AI can safely operate within a regulated environment, distinguishing between AI that supports a human analyst and AI that acts autonomously within a control framework, with the latter requiring substantially more confidence around governance, explainability, oversight and accountability.
Legacy Infrastructure as a Constraint on AI Adoption
Kevin McGuinness, global head of strategy at Napier AI, said vendors with direct experience delivering RegTech projects at large financial institutions tend to be more attuned to the realities of legacy technology stacks, fragmented data pools and separate business lines. He said Napier’s own position aligns with financial institutions’ emphasis on ensuring underlying anti-money laundering engines are AI-ready before layering advanced capabilities on top, arguing that financial crime compliance teams recognise the risk of applying agentic AI to fragile technical foundations.
Differing Vantage Points: Engine Room Versus End User
Michael Thirer, Chief Legal Officer at Muinmos, offered a different framing, arguing that institutions and vendors are not betting on different futures but viewing the same shift from different vantage points. He compared this to end users of consumer AI tools rarely considering the data centre and infrastructure investment required to operate them, suggesting vendors naturally emphasise the “engine room” of data architecture while institutions focus on the end product.
Key Factors Behind the Sequencing Disagreement
Mike Lubansky, SVP Strategy at Red Oak, described the divergence as being less about disagreement over RegTech’s future direction and more a disagreement over sequencing. He said vendors often market the destination — autonomous compliance, agentic workflows, real-time intelligence and AI-driven decisioning — while financial institutions continue funding the prerequisites: clean and connected data, governed APIs, secure infrastructure, books-and-records integrity, supervisory controls, entitlement models and audit-ready evidence.
What Institutions Require Before Deploying Autonomous Agents
Lubansky said this sequencing caution does not reflect scepticism toward AI itself, but reflects practical requirements for safe deployment in regulated environments. He said a compliance function cannot adopt autonomous agents on the basis of technological capability alone; it must be able to identify what data an agent used, what policy or rule it applied, what action it took, who approved that action, where supporting evidence is retained, and how the resulting decision can later be explained to a regulator.
Costs and Impact: Fragmented Data and Legacy Systems
Nice said many financial institutions continue to operate with fragmented data, legacy systems, inconsistent workflows, manual review processes and heavy reliance on spreadsheets. In this environment, he said, advanced automation risks creating an illusion of progress without addressing underlying structural problems, since poor data quality or inadequately managed exceptions can allow automation to produce weak compliance outcomes more quickly rather than better ones.
Tax Transparency as an Illustrative Case
Nice pointed to tax transparency reporting under FATCA and the Common Reporting Standard (CRS) as an example of firms historically meeting complex regulatory obligations through manual effort, despite that model’s limited sustainability. He said the Crypto-Asset Reporting Framework (CARF) introduces further complexity through digital asset reporting, new data sources, self-classification requirements, reasonableness checks and multi-jurisdiction reporting obligations, making manual, spreadsheet-based compliance models increasingly unsuitable for the next phase of regulatory reporting.
RegTech’s Shift Following the First Wave of Fintech Disruption
The first wave of fintech disruption prioritised customer experience as the primary competitive differentiator, according to RelyComply, pushing incumbent banks toward digital onboarding, intuitive interfaces and streamlined payments, often ahead of modernising compliance functions operating behind those systems. RelyComply said this imbalance between customer-facing innovation and compliance infrastructure is becoming increasingly difficult to sustain as financial crime grows more sophisticated and regulators demand stronger evidence of effective controls.
Anti-Money Laundering as a Growth Enabler, Not Just an Obligation
RelyComply characterised anti-money laundering compliance as a strategic enabler of growth rather than solely a regulatory obligation, noting that real-time cross-border payment capability is now a baseline customer expectation, and that fragmented compliance processes or resource constraints can become barriers to international scaling. RelyComply described AI-powered AML platforms as an increasingly strategic investment rather than a discretionary upgrade, allowing firms to apply consistent due diligence and risk assessment across multiple jurisdictions.
Risks and Limitations
The survey data reflects self-reported expectations from vendors and institutions rather than confirmed investment outcomes, and actual 2026 spending patterns may diverge from what respondents anticipated at the time of the survey. Industry commentary cited throughout this analysis comes primarily from RegTech vendors themselves, including Label, Napier AI, Muinmos, Red Oak and RelyComply, all of which have a commercial interest in characterising institutional caution favourably toward their own product positioning; independent, institution-side verification of these interpretations was not included in the available reporting. Additionally, the report does not quantify actual capital allocation figures, only survey-based expectations, limiting the ability to assess the real financial scale of the divergence described.
Future Outlook
Lubansky said winning RegTech platforms are unlikely to be those that simply layer AI onto disconnected processes, but rather those that connect the broader compliance ecosystem, including data, workflow, policies, disclosures, supervision, reporting, archives and third-party systems. Nice said the next phase of RegTech will likely be shaped by tension between vendor ambition and institutional requirements for trust and governance, suggesting future competitive advantage will depend on embedding AI into controlled, auditable workflows rather than presenting it as a replacement for compliance expertise.
Conclusion
RegTech investment priorities in 2026 show a measurable divergence between vendors, who anticipate AI and automation as the dominant investment area, and financial institutions, which are placing greater near-term emphasis on foundational data architecture, governance and control infrastructure. Industry commentators broadly frame this as a difference in sequencing rather than a disagreement about RegTech’s long-term direction, with institutions positioning current investment in foundational systems as a prerequisite for safely deploying more advanced AI-driven compliance tools in subsequent years.

