“Which version is the right one?”
Somewhere there's a hygiene procedure, an accreditation file, an insurer contract. Which folder, which version, nobody's quite sure. So people search for an hour, or use the copy from two years ago.
Industries
Compliance-heavy sectors all have the same three problems: the knowledge is in documents, the documents are in the wrong places, and the tools that could help are banned for good reason. You do not need an exception to the policy. You need an architecture that never triggers it.
Clinics, hospitals, dental networks, labs, medical devices, pharma, elder and home care. Health data is special-category data under GDPR, which is exactly why staff end up using public tools on their phones.
Healthcare
Firms and in-house teams. Privilege rules out public AI, and the memo that answers the question was written by someone who has since left.
Legal
Banking, insurance, investment and payments. Policy is current at head office and two revisions behind everywhere else.
Finance
Utilities, grid, renewables and engineering contractors. Critical-infrastructure data that must not be uploaded anywhere. Where policy demands it, it runs fully on-premise.
Energy
Contractors, engineering, infrastructure and developers. The claim is in the drawings, the RFIs and six months of correspondence.
Construction
Device manufacturers, diagnostics and clinical software, where technical files, regulatory submissions and clinical evidence all have to be traceable to a source. Our published reference runs here.
Read the case studyConsultancies, accountancy, architecture and the public sector, where the work product is documents and clients have opinions about where their data goes.
Tell us about your sectorWatch one problem at a time, across every sector at once. The vocabulary changes from industry to industry, but the underlying failure does not, which is why the fix is not sector software.
Why the ban is not holding
of employees now use AI regularly on work devices
Two in three of them go through accounts their employer does not control. In a compliance-heavy sector that is not a productivity story, it is an unlogged export of whatever they pasted in.
Source: Verizon 2026 Data Breach Investigations Report, pp. 12 & 60.
What replaces it
01 · Healthcare · published references
Your staff stop hunting through protocols, procedures and paperwork and start asking for the answer, with the page attached. It helps people find things. It doesn't make medical decisions, and it isn't a medical device.
Somewhere there's a hygiene procedure, an accreditation file, an insurer contract. Which folder, which version, nobody's quite sure. So people search for an hour, or use the copy from two years ago.
Most clinics have one person who knows how everything really works. Then they retire or leave for a competitor, and the new hire spends six months asking questions nobody can answer.
Health data is special-category data under GDPR, so public AI tools are banned. Except staff use them anyway, on their phones, and you'll find out the day it becomes a reportable incident.
The same document, the same question, the same day. What differs is which passages each person is entitled to, and the restricted ones are never retrieved at all. Swap the audit report for a matter file, a credit policy, a switching procedure or a variation order and nothing else changes.
What the searching costs you · illustrative
A 50-person clinic where each person loses just 15 minutes a day looking for a document, a version, a contract. At €12 an hour, that's over €3,000 of salary every month, spent on searching. Substitute your own headcount and the arithmetic works the same way.
What you get back
02 · Legal · illustrative scenario
Precedents, matter files, engagement letters and past advice, answerable in plain language, and every answer quotes the paragraph it came from, so nothing goes out the door unverified.
Somewhere there is a memo that answers this exact question, written by someone who has since left. Nobody can find it, so it gets researched again from scratch and billed as if it were new.
Six versions of a clause bank, four of them superseded. The one that gets pasted into a draft is whichever the associate found first.
Client confidentiality and professional privilege rule out public AI outright. Staff use it anyway, on personal accounts, and you learn about it at the worst possible moment.
What you get back · illustrative
Matter-level permissions work exactly like the ward-level ones above: the matter team sees the cap figure, the wider firm sees its shape, support staff retrieve nothing.
03 · Finance · illustrative scenario
Product terms, credit policy, AML procedures and regulatory correspondence, answerable in seconds, with the clause attached, which is exactly what an examiner will ask for. Customer and position data stays in your own infrastructure.
Credit policy has been revised three times this year. Branch staff are working from a PDF someone emailed in March, and nobody can say which decisions were made against it.
One team is the bottleneck for every interpretation question in the business. Their queue is the reason a deal slips a week.
Customer data, positions and pricing are exactly what public AI tools must never see, and the regulator increasingly expects you to document how AI is used internally.
What you get back · illustrative
Compliance sees the full due-diligence standard, relationship managers see enough to act on, the front office retrieves nothing, and the examiner can see exactly which role saw what.
04 · Energy · illustrative scenario
Operating procedures, HSE documentation, asset manuals, permits and inspection reports, answerable from the field instead of by phoning the office. Critical-infrastructure data never reaches a third-party AI, and where policy demands it, an on-premise deployment runs with no egress at all.
The procedure was revised after the last incident. The copy in the control room binder was not. Nobody notices until an audit or an incident review.
Plant knowledge sits with a handful of people who have been there thirty years. The handover plan is a shared drive nobody has opened.
Operational data, network topology and asset conditions are precisely what must not be uploaded anywhere, under regulation and under common sense.
What you get back · illustrative
Operations gets the full procedure from the revision in force, field crews get the steps that apply to them, and no network detail reaches a contractor account.
05 · Construction · illustrative scenario
Contracts, specifications, RFIs, variation orders, method statements and site reports, answerable in seconds, and every answer points at the document and page, which is exactly what a claim needs. Commercially sensitive project material never reaches a third-party AI.
A variation was agreed in an email, referenced in an RFI, and priced in a revision nobody filed. Assembling the trail takes a quantity surveyor a fortnight.
Rev C is on site, Rev E was issued last month, and the work in progress was priced against Rev B. Somebody is going to pay for that gap.
Tender pricing, subcontractor rates and claim positions are exactly what must not be pasted into a public tool, and exactly what people paste in when they are under deadline.
What you get back · illustrative
Commercial sees the full position including cost, project management sees the programme consequence, and no pricing or claim position reaches a site account.
The two customer stories we can tell are a regulated European medtech company and a children's therapy network, both anonymised. The legal, finance, energy and construction scenarios above are illustrative, and the platform is the same one in every section. We would rather point you at a reference we can stand behind than invent one for your sector.
The platform helps people find and verify information in your own documents. It does not make medical decisions and it is not a medical device.
30-minute demo, on your files, no commitment.