There is a room in every bank that customers never see and founders rarely fight over. It is where suspicious transactions get flagged, where a human reads through account histories to decide whether a wire looks like money laundering, and where a loan file sits in a queue for weeks. It is slow, heavily regulated, and deeply unglamorous. It is exactly the room Fenrock AI wants.
Fenrock AI is a San Francisco company in Y Combinator's Winter 2026 batch, and its pitch is narrow on purpose: AI agents for the banking back office, starting with financial crime compliance. Not a chatbot for consumers. Not a coding copilot. Software that sits behind the counter and does the work compliance analysts have historically done by hand - reading alerts, gathering context, drafting the case, and logging every step so a regulator can later trace how a decision was made.
What it doesAn analyst's co-pilot, not a replacement
The core product is what the company calls an AI workspace for the banking back office. In practice, that means a compliance analyst opens a suspicious-activity alert and, instead of manually pulling account records, transaction histories, and prior cases, an agent assembles the context and drafts an analysis. The human still makes the call. Fenrock says this lets a single analyst work through roughly 10 to 20 times more alerts a day.
Beyond fraud and anti-money-laundering (AML) investigations, the company describes agents aimed at other back-office chores: processing loans in minutes rather than months, and resolving customer complaints in seconds. The through-line is volume - taking work that scales linearly with headcount and letting a small team handle far more of it.
It helps to picture the job as it exists today. A mid-sized bank might generate thousands of transaction-monitoring alerts a week, the large majority of which turn out to be nothing. An analyst still has to open each one, reconstruct the story - who sent money to whom, whether it fits the customer's history, whether it echoes a known laundering pattern - and write it up. Most of that time is spent assembling context, not exercising judgment. Fenrock's argument is that the assembly is exactly what an agent can do, leaving the judgment where it belongs.
The compliance bottleneck, illustrated
Relative alerts reviewed per analyst per day, per Fenrock's stated target. Approximate; a company claim, not an independent benchmark.
The problemWhy now, and why compliance
Fenrock's founders frame the timing bluntly. The same generative AI that drafts emails can also generate convincing phishing scripts, forged documents, and synthetic identities at scale. As those tools get cheaper, the volume of attempted fraud rises - and the compliance teams meant to catch it are still largely staffed and paced for a pre-AI world.
CEO Charu Sharma describes it as a race against time to secure financial infrastructure. That framing matters for the product, because it puts Fenrock on the defensive side of the AI arms race - building for the people whose job is to stop bad transactions rather than to move fast and break things.
The differenceShow your work, or it doesn't count
In most software categories, an AI that is right most of the time is good enough. In bank compliance, it is not. A regulator can ask, months later, exactly why an account was cleared or a report was filed - and "the model decided" is not an acceptable answer. This is the constraint that kills a lot of black-box AI in finance.
Fenrock's answer is auditability as a built-in feature. Its agents automatically log all decisions, the steps taken, and the rationale behind them. Two other design choices follow the same logic: humans stay in the loop for final decisions, and the software overlays on a bank's existing stack - integrating internal policies and standard operating procedures without forcing a data migration or a system switch.
How an alert moves through Fenrock
A simplified view of the investigation loop Fenrock describes. The human decision point in step 3 is the part the company insists on keeping.
The peopleA bravery award and Apple's privacy ML
The founding story is unusual. Charu Sharma is a repeat founder; Fenrock is her third company. She previously co-founded and led the healthcare API company Osana, which she scaled to more than six million patients and over a hundred employees, raising from top-tier investors including General Catalyst's Hemant Taneja. Before that, she spent time as an investor. Earlier still, as a teenager in India, she received the country's National Bravery Award - presented by the Prime Minister and President - after confronting robbers during a train robbery in Mumbai.
Her cofounder, Michael M, comes from the other side of the problem - the machine learning. He spent roughly a decade at Google and Apple and helped build Apple's first privacy-preserving ML at scale, the kind used across billions of devices. For a product that will live inside banks and handle sensitive customer data, a cofounder whose specialty is learning from data without exposing it is not an accident.
The pairing is a neat fit for the problem. Compliance is a domain where the two hardest things are trust and data handling, and each founder owns one of them. Sharma has spent two prior companies learning how to sell into cautious, regulated buyers and keep them for years. Michael has spent a career making models useful without turning private records into a liability. Neither skill alone builds a compliance company; together they map cleanly onto what a bank's risk officer will ask about in the first meeting.
The marketThe moat is the red tape
Fenrock is deliberately aiming at small and mid-sized banks, private lenders, and fintechs rather than the largest institutions. Sharma has been open about the strategy behind that: regulated markets are harder to enter, which means less competition and more defensibility for whoever does the work of getting in. The friction that makes banking software painful to sell is the same friction that keeps rivals out once you are inside.
That patience shows up in how she talks about customers - not as accounts to churn through, but as relationships to hold for 20-plus years. In a category crowded with compliance and fraud vendors - names like Hummingbird, Unit21, Sardine, ComplyAdvantage, and newer AI-native entrants - Fenrock's wager is that the winner will be the one banks trust to sit inside their most sensitive workflows and still be there decades later.
The businessSmall team, long game
The company is early. It is a two-to-three-person team backed by Y Combinator, with Jon Xu as its primary YC partner, and it was named among Forbes' most promising startups from YC's latest batch in March 2026. The model is straightforward B2B software sold to financial institutions, integrating with what they already run. Revenue, valuation, and customer counts are not public - which is normal for a company this new, and worth remembering before reading too much into any single claim.
There is also a practical reason to court smaller institutions first. Regional banks and private lenders feel the compliance squeeze acutely - they carry the same regulatory obligations as the giants but without armies of analysts to absorb the workload. For them, software that multiplies a small team is not a nice-to-have; it is the difference between keeping up and falling behind. That makes them a more motivated buyer than a global bank with a thousand-person compliance floor, and a friendlier place to prove the product before moving upmarket.
What Fenrock is really selling is a bet about where AI agents will matter first. Not in the flashy consumer app, but in the back office of a regional bank, quietly reading the ten-thousandth alert of the week and writing down exactly why it flagged the one that mattered. If that bet is right, the boring room turns out to be the valuable one.
Follow Fenrock AI
- Webfenrock.ai
- YCycombinator.com/companies/fenrock-ai
- LinkedInFenrock AI
- X@FenrockAI
- FounderCharu Sharma (LinkedIn)
- Founder X@charu1603
- Emailcharu@fenrock.ai
- Read"A race against time" interview