Commugen expands native AI GRC agents as 2027 cyber compliance looms
Commugen says enterprises are moving away from spreadsheet-driven compliance as EU AI Act, NIS2 and DORA requirements intensify through 2027. The London-based Cyber GRC provider is pushing native AI agents, no-code workflows and continuous monitoring for more than 150 enterprise customers.
Why it matters: - Security and compliance teams are being pushed toward continuous cyber risk oversight as regulations, audit demands and attack surfaces grow at the same time. - Commugen says organizations that keep relying on manual GRC processes risk more audit findings, more errors and slower responses to changing requirements. - The shift affects regulated industries first, including financial services, where control changes and evidence requests are happening faster than spreadsheet workflows can handle.
What happened: - Commugen said it is expanding use of its native AI GRC agents as enterprises prepare for 2027 cyber compliance requirements. - The London-based company shared observations on how enterprise security and compliance teams are restructuring GRC programs as 2026 ends. - Commugen said the observations are based on its work with more than 150 enterprises, including about a third of Israel's financial institutions. - The company also said it was selected as a national platform for Supply Chain Risk Management and Organizational Cyber Defense in Israel.
The details: - Commugen said three forces are driving change: new obligations under the EU AI Act, NIS2 and DORA; board and auditor demand for continuous visibility into cyber risk; and adoption of AI agents inside GRC workflows. - DORA has applied to EU financial entities since January 2025. - NIS2 enforcement is maturing across member states. - EU AI Act obligations continue to phase in through 2026 and 2027. - ISO 27001 and NIST are also being updated, adding control obligations faster than manual processes can absorb them. - Commugen said the attack surface is expanding as new tools, vendors and cloud environments are added. - The company described manual GRC management as more error-prone and costly in 2026 than in 2018. - Many organizations still split governance, risk management and compliance into separate disciplines with separate owners, tools and reporting cycles. - That setup can create duplicated effort and gaps that show up only during an audit or incident. - Commugen said some organizations that moved from spreadsheets to first-generation GRC platforms now face rigid systems that require heavy IT involvement for minor workflow changes. - Those older platforms also offer limited real-time visibility into actual risk posture. - The company described a common scenario in which a team before an ISO 27001 audit is reconciling five spreadsheets, chasing control owners by email and cross-referencing policy documents last updated eight months earlier. - Commugen said the issue is architecture, not effort. - The company said the cost of getting GRC wrong can include reputational damage, regulatory fines and security incidents. - Commugen said AI-powered GRC tools can continuously monitor controls, identify risks and strengthen compliance management. - The company said effective GRC supports data-driven decisions, responsible operations and shared policy alignment. - Commugen's platform includes native AI GRC agents that work inside existing workflows. - The AI GRC category now includes co-pilots, multi-agent systems, large language models that interpret regulatory text and machine learning models that score risk and flag anomalies. - Commugen said explainability remains essential, and AI-generated compliance outputs still need human review for high-stakes decisions. - The company said AI can help identify what changed when frameworks such as the EU AI Act or an updated NIST profile add new control requirements. - Commugen said organizations are consolidating frameworks including ISO 27001, NIST, SOC 2, GDPR, NIS2 and DORA into a single program so one control can satisfy multiple obligations. - The company said demand is rising for no-code GRC tools that let teams change workflows without IT or developers. - Commugen also said integration with existing security infrastructure, including SIEM tools, is becoming a key requirement. - The company said no-code GRC platforms are typically deployed with time to value measured in weeks, not quarters. - Commugen noted that no-code platforms can face limits in highly customized enterprise environments with complex legacy integrations or deeply bespoke workflows. - The company recommends that buyers evaluate those limits before deployment. - Commugen said customer data in its platform is never used for model training. - The company said processing runs through secure APIs and its AI can be deployed on a customer's own infrastructure. - A CISO of a global financial enterprise said Commugen's AI Agent explanations and justifications made internal risk conversations more credible.
Between the lines: - The market is moving from point-in-time audits to continuous compliance, which favors platforms that can ingest live security data instead of relying on manual re-entry. - Commugen is positioning AI-native GRC as a structural advantage over legacy platforms that are retrofitting AI features onto older architectures. - The strongest demand appears to be coming from teams that need faster evidence collection, easier workflow changes and clearer audit trails without rebuilding their security stack. - The caution on no-code limits suggests buyers still need to test whether the platform fits complex legacy environments before committing.
What's next: - Commugen expects boards to demand cyber risk reporting in business terms, with wider use of cyber risk quantification. - The company also expects AI risk management to become a standard part of GRC programs as EU AI Act requirements take effect. - Commugen plans to expand its AI GRC agents and grow across the UK, Europe, the US and Asia-Pacific. - The company said the organizations best prepared for 2027 will be the ones that can prove their posture continuously rather than scramble before audits.
The bottom line: - Commugen is betting that AI-native, no-code GRC will replace manual compliance workflows as regulation tightens and enterprises demand always-on proof of cyber posture.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Israel Business Currents
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.