Share with your CISO
Daniel Kjellén and Fredrik Hedberg, who built Tink into a roughly €1.8 billion open banking exit to Visa, have launched Freda, an agentic compliance platform targeting the European regulatory stack. The pitch is that AI can do what generic checklists never could: map obligations to a specific company’s structure and then execute the follow-through across vendors, contracts, systems, and people. The company emerged from stealth in September 2026, is self-funded, and is running lean at around 20 people.
What this means for your business
The story that triggered Freda’s creation is recognizable to any security or compliance leader who has watched a product launch stall because legal needed months to interpret a regulation that, in principle, should have taken weeks. If your compliance function still runs on static frameworks and specialist-dependent workflows, Freda’s architecture, a regulatory engine paired with a knowledge graph of your own operations, describes the gap you already feel. If you’ve already invested in a GRC platform (governance, risk, and compliance tooling that tracks obligations and audit evidence), the more pointed question is whether that investment is doing the execution work or just the cataloguing.
The architectural distinction Hedberg draws is the one worth stress-testing. Most AI tools bolted onto compliance today behave like well-read assistants: they can explain a regulation, summarize a gap, draft a policy. Freda is claiming the agentic step, where software actually updates the risk register, routes vendor reviews, and attaches evidence without a human triggering each action. That claim carries real audit liability, because regulators don’t accept “the agent did it” as a defense when something goes wrong. The credibility test for any CISO evaluating this category isn’t whether the AI understands DORA or the EU AI Act; it’s whether the audit trail the system produces would survive a regulator’s inspection.
The founders’ fintech pedigree cuts both ways here. Tink succeeded precisely because it abstracted away the complexity of connecting to thousands of bank APIs, which is an infrastructure problem with relatively clean success criteria. Compliance interpretation is fuzzier, jurisdiction-specific, and changes mid-cycle. The vendors who will lose ground if Freda’s model proves out aren’t just legacy GRC platforms; they’re the law firms and boutique consultancies whose billable hours live in exactly the “weeks that became months” gap the founders described. Watch whether Freda’s first enterprise references come from regulated fintechs already comfortable delegating operational decisions to software, because that adoption pattern would be the leading indicator that the liability question has been answered well enough for the market to move.
Based on reporting from Tink Founders Return With Freda, An AI Compliance Platform, originally published 2026-09-24 17:41:00.

