The most expensive part of a new regulation is not the fine for breaking it. It’s the consultant’s bill for figuring out how not to. For a European bank staring down the Digital Operational Resilience Act (DORA), that can mean months of manual work: cross-referencing hundreds of pages of legal text against existing internal controls, policy documents, and supplier contracts to find the gaps. ComplyDo, a Berlin startup from Y Combinator’s Fall 2025 batch, is betting that an AI agent can do it for the price of a SaaS subscription [Y Combinator, 2025].
Their engine ingests regulation PDFs, DORA, NIS2, ISO 27001, eIDAS, and a company’s internal documentation. It then attempts to automate the core GRC workflow: extracting requirements, mapping them to controls, identifying discrepancies, and monitoring for regulatory updates [ComplyDo, 2026]. The company claims this can cut the time for such assessments from months to days [ComplyDo, 2026].
The Wedge of the PDF
ComplyDo’s initial surface is deliberately narrow. It is not selling a sprawling GRC platform that manages audits, incidents, and risk registers. It is starting with the foundational, repetitive, and document-heavy task of the initial gap analysis. The input is a set of PDFs; the output is a spreadsheet or a dashboard highlighting missing controls.
The company says it is already trusted by “global leaders and the largest EU enterprises” for use cases like third-party risk assessments and eIDAS audits [ComplyDo, 2026]. Case studies on its site describe anonymous deployments: one firm uses it as a central engine for supplier evidence mapping; external auditors use it for eIDAS compliance checks [ComplyDo, 2026].
The Risks in the Machine
The bet rests on the AI’s accuracy and the customer’s trust. A regulatory gap analysis is not a place for hallucinations or confident mistakes. ComplyDo will need to prove its agents are more reliable and thorough than a human specialist.
- The black box problem. The AI’s reasoning and sourcing must be transparent enough for an auditor to sign off on.
- The integration slog. The tool’s value compounds if it can seamlessly pull data from existing systems like SIEMs, ticketing platforms, and policy repositories.
- The market ceiling. If the product is too good, it could automate the very consulting work that provides its initial beachhead.
The founding team of Moritz Moser, Matthias Schneider, and Leo Schuhmann is operating in stealth regarding their backgrounds. The Y Combinator stamp provides a baseline of operational coaching and network, but the path to enterprise credibility in regulated industries is typically built with public customer logos and seasoned sales leadership [Y Combinator, 2025].
A typical gap assessment for a major regulation like DORA might involve two consultants for three months at a blended rate of $300 an hour. That’s roughly $250,000. If ComplyDo can replace 80% of that labor with a $50,000 annual subscription, the ROI for the customer is clear. For ComplyDo to scale, it must beat the consultant’s spreadsheet, becoming the indispensable tool that makes the consultant both faster and more accountable.
Sources
- [ComplyDo, 2026] ComplyDo, Compliance on Autopilot, Powered by AI Agents | https://www.complydo.io/
- [Y Combinator, 2025] ComplyDo: Global Compliance for Enterprises | https://www.ycombinator.com/companies/complydo
- [SaaSworthy, March 2026] SaaSworthy feature update on pricing/features | https://www.saasworthy.com/product/complydo-io