Dili Raises $21.7 Million Series A Led by Khosla Ventures for AI Compliance in Infrastructure

Dili is betting that the next phase of the AI boom won’t be defined by model capability alone, but by whether organizations can prove—internally and externally—that their AI systems are safe, compliant, and operationally trustworthy. On July 30, the company announced a $21.7 million Series A round to build out its approach to AI compliance for the infrastructure layer of modern enterprises. The round was led by Khosla Ventures, with participation from Allianz, Rebel Fund, Brick and Mortar Ventures’ Darren Bechtel, and Y Combinator’s Garry Tan.

At first glance, “AI compliance” can sound like a catch-all term—something that belongs in policy decks rather than production environments. But Dili’s positioning reflects a more practical reality: as AI moves from experimentation into critical workflows, compliance stops being a periodic checklist and becomes a continuous engineering discipline. That shift is especially pronounced when AI is embedded into infrastructure—systems that manage identity, access, data flows, monitoring, incident response, and the governance controls that determine what an organization can safely do at scale.

The funding arrives as companies race to deploy AI across customer support, internal operations, security tooling, analytics, and automation. Many of these deployments are happening faster than the organizations’ ability to document how models behave, how data is handled, and how risk is managed. Meanwhile, regulators, enterprise buyers, and enterprise risk teams are increasingly demanding evidence: not just assurances that “we follow best practices,” but concrete artifacts that show what was evaluated, what was tested, what changed, and what safeguards exist.

Dili’s thesis is that compliance needs to be engineered into the same systems that make AI reliable—rather than bolted on after the fact. In other words, compliance should be treated like observability and security: something you can measure, audit, and improve over time.

Why infrastructure is the new compliance battleground

The infrastructure boom has been driven by a simple pattern: organizations adopt new capabilities by plugging them into existing platforms. AI is no different. But unlike earlier software categories, AI introduces uncertainty. Even when a model is deterministic in the narrow sense, its outputs can vary based on prompts, context, retrieval results, tool calls, and the evolving state of the underlying data. That variability complicates traditional compliance approaches that assume stable behavior.

Infrastructure teams are therefore forced into a new role. They’re not only deploying AI; they’re also responsible for the guardrails around it. That includes:

1) Data governance: ensuring sensitive information is handled appropriately, including where it comes from and where it goes.
2) Access control: making sure only authorized users and services can trigger certain AI behaviors.
3) Auditability: capturing enough detail to reconstruct what happened during an incident or a dispute.
4) Monitoring and evaluation: tracking performance and safety signals over time, not just at launch.
5) Change management: documenting updates to models, prompts, retrieval pipelines, and policies.

When these elements are missing or fragmented, compliance becomes expensive and slow. Teams end up producing documents that don’t map cleanly to what’s actually running. Or they rely on manual processes that break under scale. Or they discover too late that the evidence required by auditors doesn’t exist in a form that can be produced quickly.

Dili’s focus on AI compliance for infrastructure suggests it wants to close that gap by turning compliance into a system property—something that can be generated, verified, and maintained as part of the deployment lifecycle.

A compliance stack built for the real world

The most interesting part of Dili’s announcement isn’t just the amount of money—though $21.7 million is meaningful for a Series A—but the implied direction: compliance as a product category that sits alongside the tools teams already use to ship software.

In practice, AI compliance requires more than policy statements. It requires traceability. If an organization claims that it has evaluated a model for certain risks, it needs to know which version was evaluated, what test suite was used, what data was included, what thresholds were applied, and what the results were. If it claims that sensitive data is protected, it needs to demonstrate how data is classified, filtered, logged, and retained. If it claims that unsafe outputs are mitigated, it needs to show what safety mechanisms exist and how they behave under realistic conditions.

That’s where many compliance efforts stall: they depend on teams manually collecting evidence from notebooks, spreadsheets, internal tickets, and ad hoc logs. Manual evidence collection doesn’t scale, and it’s hard to keep consistent across teams and vendors.

Dili’s approach—based on how the company frames its mission—appears designed to make compliance artifacts part of the operational workflow. Instead of treating compliance as a separate deliverable, it treats it as a set of requirements that can be continuously satisfied by the system itself.

This is also why the infrastructure angle matters. Infrastructure is where the “source of truth” lives: configuration, permissions, telemetry, and the runtime environment. If compliance evidence can be derived from those sources, it becomes easier to keep it current. And if compliance checks can run automatically as part of deployment, it becomes harder for risky changes to slip through.

The investors signal enterprise seriousness

The investor lineup provides additional context for what Dili is likely building. Khosla Ventures leading the round suggests confidence in a platform approach—something that could become foundational rather than a narrow point solution. Allianz’s participation is notable because large insurers and financial institutions tend to be early adopters of risk frameworks and audit-friendly systems. Their involvement often indicates that the product is expected to meet high standards for governance and documentation.

Rebel Fund and Brick and Mortar Ventures’ Darren Bechtel add further credibility, particularly given the emphasis on infrastructure and operational rigor. Y Combinator’s Garry Tan’s participation also fits a pattern: when compliance becomes a bottleneck for adoption, startups that reduce friction can capture outsized value.

While investors don’t determine product details, their backgrounds often correlate with what they want to see: clear differentiation, strong execution, and a path to adoption in environments where trust and auditability matter.

Compliance pressure is rising, but the shape of the pressure is changing

It’s tempting to think of compliance as a response to regulation alone. Regulation matters, but the pressure is broader than that. Enterprises are increasingly asked to justify AI decisions to multiple stakeholders: internal governance boards, customers with contractual requirements, partners who need assurance about data handling, and auditors who want repeatable evidence.

At the same time, AI deployments are becoming more complex. Many organizations aren’t using a single model in isolation. They’re using pipelines: retrieval-augmented generation, tool calling, multi-agent workflows, and integrations with internal systems. Each integration adds new risk surfaces. For example, a tool-calling agent might access internal databases; a retrieval system might pull documents containing sensitive information; a workflow might trigger actions that have real-world consequences.

As complexity increases, compliance can’t remain a one-time assessment. It has to adapt to changes in the pipeline. That means compliance needs to understand not only the model, but the surrounding system: prompts, policies, data sources, runtime behavior, and monitoring.

Dili’s timing suggests it’s entering the market at the moment when this shift is becoming unavoidable. Companies can still move fast without compliance—until they hit procurement, legal review, or an incident that forces them to explain what happened. Then compliance becomes urgent, and the cost of retrofitting evidence becomes obvious.

A unique take: compliance as a living system, not a report

Many compliance products focus on generating reports or managing documentation. Those tools can be useful, but they often treat compliance as a static artifact. Dili’s framing—bringing AI compliance to the infrastructure boom—implies a different philosophy: compliance should be continuously enforced and continuously verifiable.

That’s a subtle but important distinction. A living compliance system would ideally do at least three things:

First, it would define compliance requirements in a way that maps to technical controls. For example, instead of saying “protect sensitive data,” it would connect that requirement to specific mechanisms: classification rules, redaction behavior, logging policies, retention schedules, and access controls.

Second, it would produce evidence automatically from runtime signals and configuration. If a system is configured to block certain categories of data, the evidence should be generated from actual enforcement events, not just from a policy document.

Third, it would support change management. When models or prompts change, compliance evidence should update accordingly. Otherwise, organizations end up with stale documentation that no longer matches what’s deployed.

If Dili can deliver on these principles, it would help organizations avoid a common failure mode: compliance theater. That’s when teams create documentation that looks good but doesn’t reflect operational reality. In AI, where behavior can shift with context and pipeline changes, theater is especially risky.

What “AI compliance” might mean in practice

Because the announcement is focused on the funding and the general mission, it’s worth translating what “AI compliance” could look like when applied to infrastructure deployments.

In a typical enterprise AI setup, there are several layers where compliance can be implemented:

1) Input layer controls: filtering prompts, detecting sensitive content, and applying policy constraints before the model sees data.
2) Model and generation controls: configuring safety settings, limiting output types, and applying post-generation checks.
3) Retrieval and grounding controls: ensuring that retrieved documents meet data governance requirements and that citations or references are handled correctly.
4) Tool and action controls: restricting what tools an AI agent can call, validating parameters, and requiring approvals for high-risk actions.
5) Logging and audit trails: capturing enough detail to reconstruct decisions while respecting privacy and retention requirements.
6) Monitoring and evaluation: tracking safety and quality metrics, detecting drift, and triggering re-evaluations when behavior changes.

A compliance system that integrates with infrastructure would likely need to coordinate across these layers. It would also need to support different compliance regimes depending on industry and geography. Even within the same country, requirements can differ between sectors—healthcare, finance, education, and public sector each