The alarm went off in compliance departments sometime in late 2025: AI agents were getting write access to enterprise resource planning systems. Not read-only browsing or data retrieval—actual permission to modify financial records, update customer files, initiate supply chain transactions. The kind of access that, if mishandled, doesn't just create headaches. It creates regulatory nightmares.
For months, the answer from governance vendors was scattered at best. Runtime guardrails here, logging tools there, but nothing purpose-built for the sprawling mess that is an ERP system at scale.
Enter TrustAI, a San Francisco startup that emerged from Y Combinator's Summer 2026 batch with an argument: if you're going to let agents touch SAP, Oracle, or NetSuite, you need more than good intentions. You need proof they'll behave—before they go live, and continuously after.
The company announced its product this week with a compliance platform built exclusively for that use case. Announced on July 22, the product targets what TrustAI's founders call the highest-stakes corner of enterprise AI: systems where a rogue agent doesn't just hallucinate an email. It approves an invoice. Or exposes payroll data. Or violates segregation-of-duties controls that auditors have spent years locking down.
Fifty-One Ways to Fail
At the core is a framework TrustAI has organized into six risk domains—Data Privacy, Hallucinations, Permission Compliance, Robustness at Scale, Accountability, and Security. Within those, the company has cataloged 51 distinct tests.
Some are table stakes: PII leakage checks, token efficiency under load. Others get specific. Can the agent handle a prompt injection attack designed to escalate privileges? Does it respect cross-customer boundaries in a multi-tenant setup? If an agent is supposed to honor segregation-of-duties rules in financial workflows, will it actually flag a transaction that violates them?
Each test runs on a cadence—some continuously, others triggered by configuration changes—and produces pass/fail metrics with confidence intervals. The platform uses those intervals to set gates. A sample report on the company's site shows an agent with a 14.2% upper-bound attack success rate measured against a 5.0% threshold. Verdict: no-go, fix the holes first.
But the verdicts do more than block deployments. TrustAI maps each assessment to specific policy anchors—SOX IT general controls, EU AI Act Article 26 record-keeping, SOC 2, ISO 42001—so compliance officers get audit trails that speak the language regulators already understand. It's less "our agent is probably fine" and more "here's documentation tied to the frameworks your auditor will ask about."
ERPs First, Everything Else Later

TrustAI isn't chasing the broader enterprise AI governance market—at least not yet. The company is starting with ERPs, where the stakes are unambiguous. A chatbot that gives bad advice is a PR problem. An agent that corrupts financial data or leaks customer records is a compliance crisis, potentially an existential one.
The platform connects to SAP S/4HANA, SAP ECC, Oracle, and NetSuite environments. It discovers agents through Model Context Protocol hubs, or through a TrustAI-provided MCP Gateway if the ERP vendor hasn't exposed a native hub. Once connected, the system reconstructs each agent's configuration—prompts, tool access, authorization scope—without requiring code changes to the agents themselves.
Then it runs the battery of controls, maps what data and transactions the agent can reach, and scores the risk. Go/no-go decisions flow into IT change management tools like Jira and ServiceNow, embedding compliance checks directly into deployment pipelines.
The approach reflects something the founders clearly understand: most enterprises aren't building agents from scratch. They're adopting what SAP ships (Joule Agents rolled out through 2026), what Oracle bundles, or what third-party vendors sell them. The need isn't for developer tooling. It's for verification that those pre-built agents won't blow up in production.
MIT Pedigree, ERP Focus

Hannah Chung and Medha Venkatapathy, the co-founders, both come from MIT with backgrounds spanning quantitative finance and enterprise systems research. According to the company's about page, they were driven by a frustration: agents were gaining write access to sensitive systems "without proof of staying in-bounds."
That phrase—proof, not promises—runs through the product's design. Pre-registered controls. Exportable audit trails. Evidence you can hand to a regulator without needing a translator.
The timing puts TrustAI in the middle of what's become a minor land rush. The first half of 2026 saw a cluster of enterprise AI governance launches: Trust3 AI (formerly Privacera) introduced agent-focused governance tools in April and May, Arthur AI made its Agent Discovery & Governance platform available on Google Cloud Marketplace in January, and even CrowdStrike announced "Continuous Identity for AI Agents" in June.
The company's strength may lie in the depth of its ERP focus and the granularity of its test catalog. Fifty-one controls isn't a round number pulled from a slide deck; it's specific scenarios—deployment hardening, IP protection in shared environments, token management under stress—that suggest the founders have spent time in the weeds of how ERPs actually operate.
Early, Unproven, But Timely

As of this week, TrustAI lists no public customers and hasn't disclosed funding beyond its Y Combinator participation. The team is still just three people, according to YC's directory. That suggests early pilots, maybe a handful of design partnerships, but not yet a broad commercial rollout.
Still, the market they're targeting is undeniable. Enterprises are deploying agentic AI faster than they're building the governance infrastructure to support it—and in an ERP context, the consequences of getting it wrong aren't theoretical. A hallucinating agent that approves fraudulent invoices, a permission bug that exposes employee compensation data: these are the scenarios that get CFOs and CISOs fired, and sometimes get companies fined.
TrustAI's bet is that compliance teams will pay for continuous verification that goes beyond runtime guardrails. That they want a layer that understands ERP-specific risks, integrates with audit frameworks they already maintain, and produces evidence clean enough to hand over in a regulatory review.
Whether that's a sustainable wedge in an increasingly crowded governance market depends on execution—and on whether the startup can scale beyond three employees and a handful of tests before larger players absorb the functionality into their own stacks. But the gap they're targeting is real, and the thesis is grounded in a problem enterprises are facing right now, not in some distant future.
For compliance officers watching agents creep closer to production systems with write access, that might be enough.
