AI Agents in GRC Tools: Which Vendor Leads in 2026?

No clear leader has emerged among AI agents in GRC tools in 2026. NIS2Compass compares KaitoSec, Kertos, Athereon, Drata, and Vanta on features, NIS2 coverage, and price.
Written by the NIS2Compass editorial team | Last updated: September 2026
There's no clear market leader for AI agents in GRC tools in 2026: KaitoSec, Kertos, Athereon, Drata, and Vanta take five different approaches, ranging from controlled assistance to autonomous action. NIS2Compass compares all five AI agents across feature scope, NIS2 coverage, target audience, maturity, and price, not as a ranking, but as a trade-off between degree of autonomy and control risk.
This article doesn't crown a best AI system; it categorizes the five approaches objectively. The order presented is neutral, not sorted by quality. NIS2Compass compared five vendors systematically: five individual profiles follow, then a cross-comparison across five topic areas.
What Can KaitoSec's AI Assistant Do?
KaitoSec's AI assistant drafts policies, risk assessments, and questionnaire responses, but never touches the workspace without human approval. The vendor confirms this directly: no permission tier allows an autopilot mode. The underlying data model covers 12+ frameworks uniformly, from ISO 27001 to NIS2.
Even though KaitoSec markets its platform as an "Agentic Cyber Security Workspace," the AI assistant is not a fully autonomous actor. According to the vendor, human approval is built into the design and can't be switched off by any role or pricing tier: "No change is made to the workspace without human approval," the vendor states in its product documentation. This restraint reduces control risk but slows the pace of automation compared to more autonomous vendors.
Specifically, the assistant handles policy drafts, control recommendations, risk assessments, asset classification, questionnaire responses, gap analyses, evidence collection, and contextual summaries. Results land as drafts in the workspace, and approval stays with the user.
Behind this sits, according to the vendor, a unified data model spanning 12+ frameworks: ISO 27001, ISO 22301, ISO 42001, BSI IT-Grundschutz(++), NIST CSF, SOC 2, TISAX, NIS2, DORA, KRITIS-DG, GDPR, and the EU AI Act. Captured content can therefore be gathered once and reused across multiple frameworks.
The AI assistant is excluded from the Free tier and only available, quota-limited, from Standard onward. Pricing details follow in a later section. KaitoSec is a Berlin-based GmbH and, by its own account, "made & hosted in Germany," relevant when assessing data protection and residency.
More on KaitoSec as an overall tool in the ISMS Tool Comparison 2026.
What Does KAIA, Kertos's AI Assistant, Do?
According to the vendor, KAIA answers over 90 percent of questions on ISO 27001, GDPR, and the EU AI Act directly within the platform, and automatically fills in vendor and system data. The focus is on data-entry automation and platform guidance, not on autonomous action toward the outside world. KAIA has been live since September 22, 2025.
An intelligent autofill function independently completes supplier and internal system data, alongside context-aware guidance that walks users step by step through the certification process. Compared to the other vendors here, KAIA stays closer to the role of an assistant than an independently acting system.
With KAIA, Kertos covers a broad range of frameworks: GDPR including DPIA, records of processing, and TOMs, plus ISO 27001, ISO 27701, and ISO 42001 via a dedicated AIMS module. NIS2, SOC 2, TISAX®, and C5 round out the list. In September 2025, Kertos secured a Series A funding round of 14 million euros, led by Portage and Sagard.
On its own product page, Kertos cites figures such as "100% audit success," "98% customer satisfaction," and "around 80% faster to audit," all according to the vendor, without independent confirmation. Kertos lists reference customers including Personio, Grohe, Blacklane, Enpal, Flink, and AskUI. This customer list signals trust but doesn't substitute for verified case studies with documented outcomes.
Source: kertos.io
How Does LAiKA, Athereon's Multi-Agent System, Work?
Athereon's LAiKA isn't a single bot but four specialized agents: Assist, Infrastructure Mapper, Compliance Assistant, and Questionnaire Assistant. All four work explicitly human-in-the-loop: nothing happens without approval. LAiKA is developed and hosted entirely in Saarbrücken at Deutsche Telekom.
LAiKA Assist takes requests in natural language, prioritizes them, assigns tasks, and sends reminders for open items. The Infrastructure Mapper captures the IT landscape and automatically researches the web for EOL dates and known vulnerabilities. The Compliance Assistant compares actual and target states across various frameworks, identifies gaps, and prioritizes measures. The Questionnaire Assistant handles sending, follow-up, completion, and evaluation of security questionnaires.
According to the vendor, responsibility stays with humans throughout: the agents deliver suggestions and analyses, but the company makes the decisions. This principle runs through all four agents and sets LAiKA apart from fully automated approaches.
LAiKA covers seven frameworks: ISO 27001, NIS2, DORA, TISAX®, BSI IT-Grundschutz, the EU AI Act, and the Cyber Resilience Act.
Its German roots stand out in particular. LAiKA is developed, operated, and hosted in Deutsche Telekom AG data centers in Saarbrücken. The underlying language model can be chosen flexibly, for example Mistral AI, OpenLLaMA, or Claude, with separate training instances per customer.
User reviews on Capterra suggest, however, that many features still feel unfinished. Athereon publishes no public price or launch date for LAiKA; this information is missing from Athereon's AI product page.
What Can Drata AI Do Compared to a Classic Chatbot?
Drata AI goes beyond simple question-and-answer interaction: the agent independently retrieves vendor documents and SOC 2 reports, communicates directly with suppliers, and enforces security policies automatically. A dedicated governance feature even detects foreign AI agents within the customer's system. Over 8,500 customers worldwide use Drata, according to Drata, and G2 users rate the tool 4.7 out of 5 stars.
Three agentic building blocks form the core of Drata AI. AI Agent Governance automatically detects all AI agents in the customer environment, enforces policies before any action is executed, and continuously monitors for deviations. This addresses a problem that only emerges as companies deploy their own AI agents more widely.
Agentic TPRM Assessment independently handles vendor risk assessment: it retrieves vendor documents and SOC 2 reports, automatically generates follow-up questions when gaps appear, and communicates directly with suppliers. The result is a finished risk assessment. AI Questionnaire Assistance, in turn, automatically answers security questionnaires using data from the Trust Center and learns from human approvals along the way.
These three building blocks demonstrate a genuinely high degree of autonomy: autonomous vendor communication, autonomous policy enforcement, autonomous detection of foreign agents. This goes well beyond simple chat interaction.
Drata also has a dedicated NIS2 product page. NIS2Compass has already assessed how Drata performs as an overall ISMS tool in NIS2 Compliance: Vanta, Drata, and ISMS Tools Compared. Drata's G2 rating of 4.7 to 4.8 out of 5 stars across more than 1,300 reviews confirms broad market acceptance.
What Tasks Do the Vanta AI Agents Handle?
In 2026, Vanta split its originally singular "Vanta AI Agent" into four sub-agents: Compliance Agent, Third-Party Risk Agent, Customer Trust Agent, and Agent for Risk. Unlike KAIA or LAiKA, none of them carries a proper name. According to the vendor, automated questionnaire responses achieve an acceptance rate of 95 percent, though they remain subject to human approval.
Specifically, the sub-agents handle policy drafts, answering compliance questions with cited sources, and reviewing existing evidence. The Third-Party Risk Agent also monitors third-party risk and flags inconsistencies between documented policy and actual practice. For identified gaps, the agents provide remediation snippets as concrete suggested fixes.
Execution is semi-automated, not autonomous. Humans grant approvals, while the agents independently handle the preparatory research and drafting work. This sets the sub-agents apart from a pure chatbot that only responds on request.
The so-called Agentic Trust Platform officially launched on November 19, 2025, at VantaCon. The four sub-agents were added gradually between March and June 2026, and development has continued on a quarterly basis since. On G2, Vanta sits at around 4.5 to 4.6 out of 5 points across roughly 2,700 reviews, depending on when the data was pulled.
With these five profiles covered, we now turn to the cross-comparison: feature scope and autonomy, NIS2 coverage, target audience, maturity, and price.
Degree of Autonomy vs. Control Risk: How Much Decision-Making Freedom Should an AI Agent in a GRC Tool Have?
More autonomy isn't a pure advantage for AI agents in GRC tools: it widens the surface for misclassifications or unwanted policy changes before a human ever sees them. That's why NIS2Compass doesn't rank the five vendors by "who is the most agentic," but along the trade-off axis of degree of autonomy versus control risk.
The controlled end: KaitoSec and Athereon/LAiKA treat human-in-the-loop as a fixed, non-negotiable design principle: the agent prepares the work, the human decides. KaitoSec has the broadest integration scope of the two, with over 12 frameworks in a shared data model, but operates deliberately more slowly and at lower risk as a result.
In between: Kertos/KAIA sits in the middle of the spectrum with autofill and Q&A. Unlike Drata, the agent doesn't act independently toward third parties, for example in supplier communication.
The more autonomous end: Drata can, according to its own claims, communicate independently with suppliers and enforce policies without every individual step requiring separate approval. Vanta moves similarly far along this axis and has split its agent into four independent sub-agents for this purpose: Compliance, TPRM, Customer Trust, and Risk.
With autonomy, the attack surface grows too. An agent that independently communicates with suppliers or enforces policies can make wrong decisions through manipulated inputs or faulty automation before a human intervenes. Drata addresses this risk head-on with its own AI Agent Governance feature, which also monitors for foreign AI agents in the customer's system, a sign that the vendor itself considers this risk real.
Neither end of this axis is "better"; both carry a clear trade-off. In NIS2Compass's assessment, more autonomous action isn't an automatic advantage: it shifts responsibility from execution to the oversight before and after it. Organizations with limited capacity for that oversight are often better served by a more conservative agent than by the most autonomous one on the market.
How Well Do the Five AI Agents Cover NIS2 and the German NIS2UmsuCG?
All five vendors explicitly list NIS2 as a covered framework. None of them publicly and verifiably map the German NIS2 Implementation Act (NIS2UmsuCG) or §30 BSIG at a granular level, coverage consistently stays at the level of the EU Directive, such as Article 21. Drata gets the most concrete with a dedicated NIS2 product page on reporting deadlines, while the NIS2Compass Guide remains the most granular resource for the German law itself.
The vendors differ considerably in sheer framework breadth:
- KaitoSec: over 12 frameworks in a shared data model, with NIS2 as one of them.
- Kertos (KAIA): covers, among others, GDPR, ISO 27001, ISO 27701, ISO 42001, NIS2, SOC 2, TISAX, and C5.
- Athereon (LAiKA): 7 frameworks, a narrower but more focused portfolio.
- Drata and Vanta: each with a dedicated NIS2 and EU AI Act focus, supplemented by classic US frameworks such as SOC 2, HIPAA, and FedRAMP, plus CMMC at Drata.
Drata has the most concrete NIS2-specific AI functionality of all five vendors with its NIS2 product page: support for incident reporting and general NIS2 notification obligations. This still stays at the EU level, not the §30 BSIG level. An external assessment confirms this: NIS2 functionality at Drata is "fine if NIS2 is a secondary obligation". In other words, it's not a core strength.
Vanta takes a different approach: existing ISO 27001 controls are mapped to NIS2 requirements, and evidence is centralized. Here too, coverage stays at the EU Directive and ISO-mapping level.
Companies that need the German legal framework mapped in detail won't find that with any of the five AI agents. The NIS2Compass Guide walks through all 12 measures under §30(2) BSIG across 8 chapters and around 124 steps, with explicit mapping to German law rather than just the EU Directive.
Which Company Size and Market Does Each AI Agent Fit?
KaitoSec, Kertos, and Athereon are DACH-focused with German or European hosting. Drata and Vanta are US companies with an enterprise focus, without a recognizable EU hosting guarantee or German-language interface. For a typical German mid-market company with 30 to 250 employees, the three DACH vendors tend to fit better than the two US platforms.
KaitoSec: Targets startups, SMEs/mid-market, and the public sector, such as municipalities and districts. Consulting firms also use the platform via white-label. Headquartered in Berlin, and by its own account "made & hosted in Germany".
Kertos: Addresses startups, scale-ups, and mid-market companies, with an industry focus on SaaS, healthtech, fintech, and automotive. Founded in Munich, and positions itself, by its own account, as a European compliance partner with agentic automation.
Athereon: Targets compliance officers, CISOs, and BCM managers, and by its own account serves everyone "from startups to enterprise" without an explicit SME focus. Headquartered in Saarbrücken, hosted in Deutsche Telekom data centers.
Drata: Enterprise and mid-market focus, a US company without recognizable EU hosting and without a dedicated German-language interface.
Vanta: Covers startups through enterprise, with a focus on healthcare, government, and fintech, tending toward larger organizations rather than the classic 30-to-250-employee mid-market.
3 of the 5 vendors compared were founded in the DACH region and host in Germany or the EU: only KaitoSec, Kertos, and Athereon.
One knowledge gap persists across all but one vendor: only Athereon publicly discloses concrete details about how its AI agent processes data, such as its flexible choice of LLM and separate training instances per customer. For KaitoSec, Kertos, Drata, and Vanta, there is no public information on how the respective agent is classified for data-processing purposes, or whether customer data is used for training. Companies should clarify this question directly with the vendor before making a decision.
How Mature and Well-Documented Are the Five AI Features?
Drata and Vanta have the largest public review base, with over 1,300 and roughly 2,700 G2 reviews respectively. KaitoSec is the biggest black box: no findable reviews on G2, Capterra, or Trustpilot, and even its founding year and funding remain unclear. Athereon continues to carry unchanged criticism about some features feeling unfinished, while Kertos, launched in September 2025, is the youngest of the five.
KaitoSec remains a knowledge gap rather than a rating. Neither its founding year nor any funding rounds are publicly verifiable, and as of September 2026 there are no user reviews on common platforms. This gap should be treated as an open question, not as a signal of quality in either direction.
Kertos/KAIA is the youngest agent in this comparison, having launched on September 22, 2025. That same month, it secured a Series A funding round of 14 million euros. Figures on customer satisfaction or audit success, however, come exclusively from the vendor itself.
Athereon/LAiKA has no public launch date. ProvenExpert shows a rating of 5.00 out of 5, though based on very few votes, a weak signal rather than a reliable metric. On Capterra (DE), users praise support and pricing but criticize that many features still feel unfinished.
Drata has had its agentic vendor-risk feature live since August 2025; the newer "AI Agent Governance" has no fixed launch date. Across more than 1,300 G2 reviews, Drata scores 4.7 to 4.8 out of 5. Users praise the dashboard and auditor collaboration, while criticizing price increases at contract renewal and automation gaps in non-standard and on-premise environments.
Vanta has run its agent since mid-2025, with the official launch of the "Agentic Trust Platform" following on November 19, 2025, and sub-agents added between March and June 2026. With roughly 2,700 G2 reviews, Vanta scores 4.5 to 4.6 out of 5 depending on when the data was pulled. Reviews describe quarterly improvement, with criticism tending to focus on price transparency and support.
Companies looking for AI-supported answers with a reliable last-updated date instead of unverified vendor claims will find over 40 professionally reviewed articles with update dates in the NIS2Compass Knowledge Hub.
What Do AI Agents in GRC Tools Cost in 2026?
Only KaitoSec publishes a price list: Standard starts at €240 per month with 100 AI calls included, Professional starts at €575 per month with 500 AI calls included. Kertos, Athereon, Drata, and Vanta only share pricing on request. For Drata and Vanta, third-party estimates often sit well above a typical SME budget.
KaitoSec fully discloses its pricing tiers:
- Free: no access to the AI assistant.
- Standard: from €240 per month with annual billing (€290 with monthly billing), 100 AI calls included.
- Professional (marked by KaitoSec as "Recommended"): from €575 per month with annual billing (€690 monthly), 500 AI calls, access to all four systems.
- Enterprise: price on request, 2,000 AI calls, with an on-premise option.
Details are available on KaitoSec's pricing page.
The other four vendors, by contrast, don't publish their pricing:
- Kertos: only "request a quote," no figures available. The vendor advertises being "over 60 percent cheaper," though the basis for that comparison remains unclear.
- Athereon: no prices on its AI product page. Capterra mentions "fair pricing with various subscription cycles," without naming specific amounts.
- Drata: only a quote after a needs assessment. Third-party sources report annual costs between $9,649 and $60,000, with the Advanced plan typically falling between $15,000 and $25,000 per year.
- Vanta: also only a sales conversation instead of a price list. Estimates range from $10,000 to $20,000 per year for the Essentials tier up to $50,000 to over $100,000 for the Enterprise tier, with AI agent features tiered by plan.
Among the five vendors, KaitoSec is the exception: it's the only one where you can calculate your budget in advance, with no sales conversation required.
Frequently Asked Questions
Which AI agent in a GRC tool is the most advanced in 2026?
No vendor is objectively the most advanced. The five AI agents compared here set different priorities. Drata and Vanta act more autonomously and have gathered the most user reviews, which speeds up processes but also widens the surface for unwanted changes. KaitoSec and Athereon deliberately favor human approval over autonomy, a lower-risk but slower approach.
Does an AI agent in a GRC tool also cover the German NIS2 Implementation Act?
No. Neither KaitoSec, Kertos, Athereon, Drata, nor Vanta map the NIS2UmsuCG at a granular level; all five stay at the level of the EU NIS2 Directive. None of them publicly demonstrates concrete coverage of individual obligations under §30 BSIG. National implementation requires additional, specific expertise.
Is an AI agent in a GRC tool a substitute for NIS2 consulting?
No. The AI agents compared here automate sub-tasks within an existing GRC tool, such as evidence collection or policy suggestions. They don't replace legal classification, a scope assessment, or initial consultation by qualified professionals. Sound expertise remains essential for understanding your own NIS2 obligations, regardless of which tool you use.
What does a GRC tool with an AI agent cost for a small or mid-sized company?
Only KaitoSec publishes prices: €240 to €690 per month, depending on tier and billing method. The other four vendors negotiate individually after a needs assessment. For Drata and Vanta, third-party estimates frequently exceed $10,000 per year, which tends to put them outside a typical budget for small and mid-sized companies.
Can AI agents in GRC tools independently change policies or communicate with suppliers?
At Drata and Vanta, according to the vendors, this is possible: automated policy enforcement and independent communication with suppliers. KaitoSec and Athereon deliberately avoid this: every change there requires human approval. Kertos/KAIA sits in between: the agent fills out forms automatically but doesn't independently communicate with external parties.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.
Get startedRelated Articles
Ransomware Attack on a Hospital: Which NIS2 Duties Apply?
A ransomware attack on Nipigon Hospital (Canada) knocked out lab and diagnostics. Which NIS2 duties (§§30, 32, 65 BSIG) apply to German hospitals.
5 min read
NIS2 Crisis Communication: What Role Does Telfo Play?
NIS2 requires crisis management and secure emergency communication under §30 BSIG: escalation matrix, redundant channels, crisis communication plan — plus where Telfo fits in.
10 min read
Rhysida Berlin Leak: Is Redistributing the Data a Crime?
Rhysida published Berlin government data after the city refused a ransom. Redistributing it is a crime under §202d StGB and §42 BDSG — the legal analysis, plus NIS2 lessons.
4 min read