NoticiasNews

Agentes de IA que preparan el expediente pero no deciden: el modelo que se impone en cumplimientoAI Agents That Prepare the File But Don't Decide: The Model Taking Hold in Compliance

2026-08-26

RadarFirst anunció una capa agéntica sobre su plataforma de privacidad y gobernanza de IA, con agentes construidos para tareas específicas del ciclo de gestión de incidentes. Lo interesante no es la lista de capacidades, sino dónde la empresa decidió trazar la línea.

Qué hacen los agentes y qué no

Según la compañía, los agentes se ocupan de guiar la recepción del incidente, identificar datos faltantes, priorizar los casos de mayor riesgo, formular preguntas de seguimiento, organizar la evidencia, preparar la investigación y redactar borradores de comunicaciones. Capacidades futuras podrían extenderse a reportería, preparación de notificaciones regulatorias, ejecución de flujos de trabajo y coordinación entre áreas.

Lo que explícitamente no hacen es tomar la decisión regulatoria. El sistema entrega orientación estructurada; las personas revisan las recomendaciones y deciden. RadarFirst señala que ese diseño se alinea con las expectativas regulatorias emergentes de intervención humana significativa para sistemas de IA de alto riesgo.

Por qué ese límite es la parte importante

Durante 2025 y 2026 el discurso dominante sobre agentes de IA fue la autonomía: cuánto puede hacer el agente sin que nadie lo supervise. En funciones de riesgo —privacidad, cumplimiento, prevención de lavado de activos, reporte regulatorio— ese planteamiento choca de frente con la realidad legal. La responsabilidad por un reporte mal presentado o una notificación fuera de plazo no se transfiere al proveedor de software ni al modelo: sigue siendo de la institución y de sus oficiales designados.

El marco de la Unión Europea, con obligaciones para sistemas de alto riesgo exigibles desde agosto de 2026, refuerza la misma dirección: supervisión humana documentada, explicabilidad y capacidad de auditar cómo se llegó a una recomendación. La consecuencia práctica es que en cumplimiento el valor de la IA no está en decidir más rápido, sino en eliminar el trabajo de preparación que consume el tiempo de los especialistas escasos.

Dónde está el ahorro real

Cualquiera que haya trabajado en una unidad de cumplimiento sabe cómo se distribuye el esfuerzo en un caso típico. La mayor parte del tiempo no se va en el juicio experto, sino en lo que lo precede:

  • Reunir información dispersa en correos, sistemas centrales y expedientes en papel.
  • Descartar falsos positivos generados por coincidencias de nombres o reglas demasiado amplias.
  • Ordenar evidencia en un formato que resista una revisión posterior.
  • Redactar la versión inicial de un reporte que después se corrige varias veces.

Delegar esas cuatro tareas a agentes libera al analista para lo único que no puede automatizarse: el juicio sobre si un hecho concreto configura o no una obligación regulatoria. Ese es el planteamiento de RadarFirst y es, cada vez más, el planteamiento de la categoría entera.

Cómo evaluar una propuesta de IA en cumplimiento

Para un oficial de cumplimiento en República Dominicana o el resto de LATAM que esté evaluando herramientas, tres preguntas separan lo útil de lo riesgoso:

  • ¿Queda rastro de cómo se llegó a cada recomendación? Si el sistema no puede mostrar qué datos usó y qué regla aplicó, no sirve ante un supervisor.
  • ¿La decisión final está atribuida a una persona identificable? Con fecha, hora y sustento documentado.
  • ¿La herramienta reduce falsos positivos o solo los procesa más rápido? Automatizar el ruido a mayor velocidad no mejora un programa de cumplimiento; lo satura con mejor presentación.

En TEKFENIX diseñamos CumplimientoControl exactamente bajo ese principio de humano en el bucle. La plataforma automatiza el monitoreo de medios adversos, la priorización de alertas y la preparación de expedientes con trazabilidad regulatoria completa, pero la decisión de reportar sigue siendo del oficial de cumplimiento, con el rastro auditable que exigen la UAF y los supervisores sectoriales. La IA que sirve en cumplimiento no es la que decide por usted: es la que llega con el expediente listo para que usted decida bien y pueda demostrarlo.

RadarFirst announced an agentic layer on top of its privacy and AI governance platform, with agents purpose-built for specific stages of the incident management cycle. The interesting part is not the capability list, but where the company chose to draw the line.

What the agents do and don't do

According to the company, the agents guide incident intake, identify missing details, prioritize higher-risk cases, generate follow-up questions, organize evidence, prepare investigations and draft communications. Future capabilities could extend to reporting, regulatory notification preparation, workflow execution and cross-functional coordination.

What they explicitly do not do is make the regulatory decision. The system provides structured guidance; people review the recommendations and decide. RadarFirst notes that this design aligns with emerging regulatory expectations for meaningful human oversight of high-risk AI systems.

Why that boundary is the important part

Through 2025 and 2026 the dominant narrative around AI agents was autonomy: how much the agent can do unsupervised. In risk functions — privacy, compliance, anti-money laundering, regulatory reporting — that framing collides with legal reality. Liability for a misfiled report or a late notification does not transfer to the software vendor or the model: it stays with the institution and its designated officers.

The European Union framework, with obligations for high-risk systems enforceable from August 2026, reinforces the same direction: documented human oversight, explainability and the ability to audit how a recommendation was reached. The practical consequence is that in compliance the value of AI is not deciding faster, but eliminating the preparation work that consumes scarce specialists' time.

Where the real savings are

Anyone who has worked in a compliance unit knows how effort is distributed in a typical case. Most of the time does not go to expert judgment, but to what precedes it:

  • Gathering information scattered across email, core systems and paper files.
  • Discarding false positives generated by name matches or overly broad rules.
  • Organizing evidence in a format that will survive later review.
  • Drafting the first version of a report that gets revised several times.

Delegating those four tasks to agents frees the analyst for the one thing that cannot be automated: judging whether a specific fact does or does not trigger a regulatory obligation. That is RadarFirst's proposition, and increasingly the proposition of the entire category.

How to evaluate an AI compliance proposal

For a compliance officer in the Dominican Republic or elsewhere in LATAM evaluating tools, three questions separate the useful from the risky:

  • Is there a trail of how each recommendation was reached? If the system cannot show what data it used and what rule it applied, it is worthless before a supervisor.
  • Is the final decision attributed to an identifiable person? With date, time and documented rationale.
  • Does the tool reduce false positives or just process them faster? Automating noise at higher speed does not improve a compliance program; it saturates it with better formatting.

At TEKFENIX we designed CumplimientoControl on exactly that human-in-the-loop principle. The platform automates adverse media monitoring, alert prioritization and case file preparation with full regulatory traceability, but the decision to report remains with the compliance officer, backed by the auditable trail that the UAF and sector supervisors require. AI that works in compliance is not the kind that decides for you: it is the kind that arrives with the file ready so you decide well and can prove it.

← Volver al blog← Back to blog