AML, KYC & Financial Crime
B

Bretton AI

Bretton AI, which operated as Greenlite until its 2026 rebrand, supplies agents that carry out financial crime compliance work rather than tooling for humans to do it faster. The agents clear first line sanctions, politically exposed person, adverse media and transaction monitoring alerts, run customer and enhanced due diligence including financial statement and web presence analysis, and hand enriched cases with drafted narratives to human analysts for the judgement calls. Its distinguishing layer is a trust framework built around named United States banking supervisory guidance on model risk and transaction monitoring.

Last VerifiedAugust 8, 2026
Compare Bretton AI with other vendors
Founded
2023
Headquarters
San Francisco, California, United States
Website
greenlite.ai
Categories
aml-kyc-financial-crime, compliance-and-surveillance
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 11 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The agents are the product, not an assistant layered over one. What the company sells is the completion of compliance work that was previously done by outsourced analyst teams, clearing first line alerts, running due diligence on customer documentation, financial statements and web presence, and drafting the narrative record.

Apply the removal test and nothing is left except the outsourced human workforce this explicitly replaces, which the founding thesis names directly as the problem: months of training, difficult quality assurance and low productivity from offshore review teams.

Autonomy and Oversight Model
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a person checks it are all published: modes, thresholds, sampling or audit controls, and the route a case takes to human review.
Vendor Published

The division of labour is stated in the industry's own vocabulary, which makes it unusually legible. Agents fully remediate first line alerts, clearing false positives across sanctions, politically exposed person, adverse media and transaction monitoring queues, while second line analysts receive enriched data, pre analysis and drafted narratives and retain the risk based decisions that require judgement.

That is an explicit map of which determinations are automated and which escalate, drawn along a boundary compliance functions and their examiners already recognise, and human in the loop testing is described as part of how agents are validated before they run.

Model Risk Management and Transparency
AA on Model Risk Management and TransparencyExplainability and validation are built into the product and mapped to the supervisory instrument they serve: per alert attribution, backtesting or test before deploy, with a stated alignment to a framework like SR 11-7, OCC 2011-12 or NYDFS Part 504.
Vendor Published

The first top grade on this axis anywhere in this index, and it is earned by naming the instruments every other vendor avoids. Bretton AI builds its agents on a trust framework that embeds federal supervisory guidance on model risk management and the New York transaction monitoring regulation into their foundation, and states that this exists to meet requirements for validation, testing and accuracy with transparent model governance and auditability.

The state instrument is Part 504 of the Superintendent's Regulations (3 NYCRR Part 504), Banking Division Transaction Monitoring and Filtering Program Requirements and Certifications, effective 1 January 2017, which requires a covered institution to certify annually by 15 April, signed by its board or a senior officer, that its transaction monitoring and OFAC filtering programs meet the prescribed attributes.

Every other vendor assessed here leaves the buyer to work out unaided how a machine learning component will survive model validation. The grade is held, and one material qualification is now on the record, decided 23 August 2026.

The federal half of that mapping points at instruments that no longer exist: on 17 April 2026 the Federal Reserve, OCC and FDIC issued SR 26-2, superseding SR 11-7 and OCC Bulletin 2011-12 and the 2021 interagency statement on model risk for BSA and AML systems (SR 21-8, OCC Bulletin 2021-19, FDIC FIL-27-2021), and SR 26-2 expressly excludes generative and agentic AI from its scope while disclaiming its own enforceability. This vendor's product is generative and agentic.

The grade is held because this axis measures what a vendor has published about how its models are governed, and mapping an architecture to a named instrument remains a materially stronger disclosure than naming none; downgrading the only vendor in the lane that named anything would penalise the disclosure rather than assess it, and supersession four months ago is a market wide condition rather than this company's failure. The New York certification is untouched by any of it.

One falsification condition is pre registered against the grade: if the vendor's own material still presents SR 11-7 as current at the next re verification, with no acknowledgement of SR 26-2, that becomes a currency problem in the disclosure rather than a supersession problem in the guidance, and the grade moves. Two questions belong in diligence.

The framework is described rather than published, so ask to see the validation and testing artifacts it produces rather than accept the architecture claim on its own, and ask what the mapping points at now.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Outcomes are attributed to named customers rather than aggregated, which is what this grade requires. A payments customer reports a 90 percent reduction in alert processing time and 95 percent fewer false positives; a corporate card platform, a digital bank and a wealth manager are cited returning three to four times investment within twelve weeks.

The named roster spans fintech, banking and professional services, and includes a chartered bank scaling due diligence on small business and startup clients, which is the hardest version of that problem. The company states plainly that it serves banks and broker dealers under federal and securities supervision, a claim those regulators' examinations would test.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

Agents are configured against the institution's own risk policies, standard operating procedures and compliance guidelines rather than generic templates, which scopes their behaviour to the customer and implies learning that does not pool across the base, and human in the loop testing is named as part of the deployment method. The completed security attestation supports the operational side.

Two gaps remain: the claim that agents achieve lower error rates than human analysts is offered without any published measurement, and nothing identifies which model providers sit behind the agents or how customer documentation is handled when it reaches them.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

The company holds a service organisation control type two attestation and describes it as covering security, availability, processing integrity, confidentiality and privacy, which is a completed multi month audit rather than a policy statement and is more privacy assurance than most vendors in this index offer. That matters given what the agents read: customer identity documentation, financial statements, adverse media and web presence for individuals and businesses under review.

What is not published is the framework beneath the attestation, with no privacy policy detail on agent data handling, no retention schedule and no subprocessor list identifying which model providers process customer material.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

A service organisation control type two attestation is publicly announced and named specifically, with the trust criteria it covers identified, and the company frames it as the signal regulated institutions require before allowing generative systems near their data. That is a completed independent audit rather than an unreadable badge or an unnamed claim of maintaining certifications, which puts it ahead of most of this index. What is missing is the surrounding surface: no trust centre, no report request path, no stated audit period and no further framework coverage such as an international information security standard.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

Bretton AI supplies software and holds no licence, the expected posture, and its regulatory grounding is the most specific in this index. Rather than referring to anti money laundering obligations generally, the company names the two supervisory instruments its architecture is built against: the federal banking guidance on model risk management, and the New York state transaction monitoring regulation that requires an annual certification by a senior officer that the monitoring system is compliant. Building to that second instrument means the vendor is addressing an obligation a named executive signs personally, which is a materially different design constraint from generic compliance.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

Governance is genuinely well handled and fairness is not addressed, and the two should not be confused. Adverse media screening and name based sanctions and politically exposed person matching carry a structural error asymmetry: matching accuracy varies by naming convention, transliteration and script, and adverse media corpora are dominated by English language sources, so customers with non Western names or from less covered media markets attract different false positive rates as a property of the method. An agent clearing first line alerts at scale inherits that asymmetry. No demographic or per population error analysis, no fairness testing and no correction route were located.

AI Liability and Recourse
BB on AI Liability and RecourseA published falsifiable commitment such as an accuracy figure with its method, or a real correction route for the affected person, such as step up verification instead of silent denial.
Vendor Published

Bretton AI comes closer to structural accountability than any peer without a contractual guarantee. Its agents are built on a framework that embeds the federal model risk guidance and the state transaction monitoring rule, the latter requiring a senior officer to certify annually that the monitoring system is compliant, so the vendor is designing to support an obligation a named executive signs personally. A completed independent security audit backs the operational side. Still missing: no accuracy guarantee, no published error rate, and no correction route for a customer whose alert an agent cleared or escalated wrongly.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

Agents are configured against the institution's own policies, procedures and guidelines rather than generic templates, which scopes behaviour to the customer and implies the chain does not run through other customers' data. The integration posture is additive, connecting to existing case management, screening and core banking rather than displacing them, so the institution keeps its own data suppliers. What is absent is the model layer itself: no provider named, and no statement on where customer due diligence documentation is processed.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

The integration posture is deliberately additive and is a stated differentiator against the incumbent platforms: agents connect to the case management, screening and core banking systems an institution already runs, so a compliance team keeps its existing queues and adds automation inside them rather than replacing a monitoring platform. For a regulated buyer that avoids revalidating a system of record, which is the real cost of switching in this category. What was not located is the outward facing surface the strongest integrators publish, with no named connector directory, no public developer documentation, no status page and no changelog.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Delivery is cloud hosted software as a service. The customer base is largely domestic but includes at least one United Kingdom professional services firm, which brings European data protection expectations into scope for that engagement.

No public material identifies hosting regions, residency options, transfer mechanisms, tenancy separation or the subprocessor chain, and the last of those matters more than usual here because agent processing of customer documentation implies material passing to third party model providers wherever they operate.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

No rates, tiers, billing unit or minimum are published. The pricing question is more interesting than usual for this product because the value proposition is replacing outsourced analyst headcount, which has a known and comparable unit cost, so a published per review or per agent price would let a buyer run the comparison directly. Instead the return figures are offered without the denominator that would make them checkable.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Coverage spans fintechs, federally supervised banks, securities regulated broker dealers, large corporates and at least one professional services firm, with work covering customer due diligence, enhanced due diligence, sanctions and politically exposed person screening, adverse media and transaction monitoring alerts, and business onboarding.

The breadth of institution type is real but narrower than the widest vendors in this lane, with no dedicated treatment of credit unions, insurers, sponsor bank partner oversight or capital markets, and the geographic centre of gravity is domestic with limited non United States material.

Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to Bretton AI

The closest documented capability profiles to Bretton AI in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents Model Supply Chain Disclosure where Bretton AI does not

Documents Model Supply Chain Disclosure where Bretton AI does not

Documents Model Supply Chain Disclosure where Bretton AI does not

Documents Model Supply Chain Disclosure where Bretton AI does not

Stronger documented coverage on Institution and Segment Coverage

Documents AI Governance and Bias Disclosure and Model Supply Chain Disclosure where Bretton AI does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 550 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 23, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746