for regulated teams

By industry

Agent governance obligations read differently under each regulator: a bank examiner asks who approved the action, while a hospital's privacy officer asks what was disclosed. These guides map runtime controls to the frameworks five industries already report against.

No. 01 · By industryfor regulated teams

Why the same control lands differently

Regulators reached AI at different speeds and from different worries. Insurance commissioners already expect governance over any system that influences underwriting or claims. HIPAA's minimum-necessary standard binds what an agent may read. SR 11-7 was written for models that predict, and has no box for a model that acts.

So the compliance question is never abstract. Each regime names the decision it cares about, the evidence it accepts, and the person it expects to have been in the loop, and those answers differ by industry.

No. 02 · By industryfor regulated teams

What stays constant underneath

Under every regime the operational questions converge: who authorized this action, under what policy, and where is the record. A pre-execution policy check, a human approval where the action warrants one, and a per-decision receipt answer all three, whatever the framework's vocabulary.

That is how these guides are built: each takes the frameworks an industry already reports against and shows which runtime record answers which obligation. No guide claims a product makes you compliant.

No. 03 · By industryfor regulated teams

Financial services and insurance

Financial services: SR 11-7, DORA, and the examiner's actual question, which is an authorization and audit question rather than an accuracy question. The guide maps the runtime record onto the three-lines-of-defense documentation your model-risk team already maintains.

Insurance: the NAIC model bulletin treats an agent that adjusts a reserve or fast-tracks a claim as a regulated decision-maker. The guide translates the bulletin's governance expectations into runtime controls and a deployment sequence built to survive market-conduct review.

No. 04 · By industryfor regulated teams

Healthcare and legal

Healthcare: every retrieval from an EHR is a disclosure in HIPAA's terms, so the distinctive problem is what the agent reads, and only then what it does. The guide covers minimum-necessary scoping, bias-risk accounting under Section 1557, and the record that turns an OCR inquiry into a report you print.

Legal: matter A's strategy surfacing in matter B's draft is a disqualification motion. The guide covers ethical walls enforced as retrieval policy, client-consent boundaries under evolving bar guidance, and a per-engagement record of exactly what was accessed.

No. 05 · By industryfor regulated teams

Government

Public-sector adoption turns on one question before capability matters: where does the decision happen? If every agent action requires a round trip to a vendor's cloud, an airgapped network cannot use it, and a FedRAMP boundary has to swallow the whole vendor.

The government guide covers deployment shapes that keep authorization inside your boundary, NIST AI RMF alignment for agentic systems, and the procurement questions that establish whether a vendor's on-prem offering actually keeps authorization inside your network.