What this is
With the EU DORA (Digital Operational Resilience Act) fully in force from 2025, global banks spend over $200 billion annually on compliance. Deutsche Bank's answer this week: hand all regulatory drills to AI agents.
The partnership details Deutsche Bank disclosed with Google Cloud: they built an "operational resilience platform" on the Gemini Enterprise Agent Platform (Google's enterprise AI agent builder) to handle DORA-mandated compliance drills. These tabletop exercises — simulated scenarios for how to respond when systems fail — used to require dozens of compliance, risk, and IT staff spending weeks on prep. The platform now pulls real signals directly from architecture, data flows, logs, and incident records, auto-generates playbooks, simulates responses, and produces evidence packages regulators can read.
The technically interesting move is the introduction of LangGraph, an open-source framework that makes AI agent workflows traceable. Deutsche Bank split the flow into two lanes: "regulator-aligned execution," where every step is auditable, and "business-flexible execution," which retains elasticity. This dual-orchestration approach is worth borrowing for any company building compliance agents.
Industry view
Supporters see this as a substantive shift in financial-services compliance cost structure. Once agent platforms scale, a single major bank could save millions of hours per year; compliance roles can pivot from "assembling documents" to "designing drill scenarios and assessing risk."
But the skepticism is equally sharp. First, we don't yet know how much EU DORA regulators will accept "AI-generated compliance evidence"; they tend to require human review traces — whether Deutsche Bank's setup can truly replace signed attestations will face its first stress test in 2025. Second, over-reliance on a single cloud vendor's (Google Cloud's) agent toolchain creates vendor lock-in and data-residency risk, especially acute for multinational banks. Third, agent "hallucinations" in compliance — generating plausible but factually wrong compliance documents — are an unacceptable failure mode in a regulatory context, and we see no systematic fix in public cases yet.
Impact on regular people
For enterprise IT: The center of gravity in bank IT is shifting from "maintaining documents and systems" to "designing agent workflows and audit oversight." Traditional ops roles are contracting; AI workflow orchestration and RegTech roles are expanding.
For individual careers: Within compliance, risk, and internal audit, "information organizer" work — collecting logs, aggregating events, drafting reports — gets automated first. Judgment work (deciding risk levels, designing drill scenarios) is safe for now but requires learning new tools.
For consumer markets: You won't notice a change in the short term. Over time, higher operational resilience means shorter impact windows when bank systems fail. Whether lower compliance costs translate into lower financial-service pricing, however, we see no mechanism yet.