Skip to content

Industries

The sectors that cannot use public AI are the ones that need this most

Compliance-heavy sectors all have the same three problems: the knowledge is in documents, the documents are in the wrong places, and the tools that could help are banned for good reason. You do not need an exception to the policy. You need an architecture that never triggers it.

Every sector calls it something different. It is the same three problems.

Watch one problem at a time, across every sector at once. The vocabulary changes from industry to industry, but the underlying failure does not, which is why the fix is not sector software.

Why the ban is not holding

45%

of employees now use AI regularly on work devices

Two in three of them go through accounts their employer does not control. In a compliance-heavy sector that is not a productivity story, it is an unlogged export of whatever they pasted in.

Source: Verizon 2026 Data Breach Investigations Report, pp. 12 & 60.

What replaces it

  • A sanctioned tool that is better at the job than the one they were using unofficially.
  • Permissions that apply inside each document, rather than only to the files a person can open.
  • An audit log, so you can answer what was asked and by whom.
  • Single sign-on, so there is no second directory and no orphan accounts.
How the boundary is enforced

01 · Healthcare · published references

Your protocols, answerable in seconds. Patient data never reaches a third-party AI.

Your staff stop hunting through protocols, procedures and paperwork and start asking for the answer, with the page attached. It helps people find things. It doesn't make medical decisions, and it isn't a medical device.

Clinics & clinic networks Hospitals Dental networks Labs & diagnostics Medical devices Pharma Elder & home care

“Which version is the right one?”

Somewhere there's a hygiene procedure, an accreditation file, an insurer contract. Which folder, which version, nobody's quite sure. So people search for an hour, or use the copy from two years ago.

“Ask the head nurse.”

Most clinics have one person who knows how everything really works. Then they retire or leave for a competitor, and the new hire spends six months asking questions nobody can answer.

“We can't put that into ChatGPT.”

Health data is special-category data under GDPR, so public AI tools are banned. Except staff use them anyway, on their phones, and you'll find out the day it becomes a reportable incident.

One question. Three answers. Nobody sees a line they should not.

The same document, the same question, the same day. What differs is which passages each person is entitled to, and the restricted ones are never retrieved at all. Swap the audit report for a matter file, a credit policy, a switching procedure or a variation order and nothing else changes.

What the searching costs you · illustrative

260 hours a month.

A 50-person clinic where each person loses just 15 minutes a day looking for a document, a version, a contract. At €12 an hour, that's over €3,000 of salary every month, spent on searching. Substitute your own headcount and the arithmetic works the same way.

What you get back

  • The searching takes seconds, and the answer shows its source.
  • Audit prep starts from a report generated out of the files you already have, not from an empty page.
  • New hires stop waiting for the one colleague who knows.
  • The GDPR incident from someone's phone doesn't happen.

03 · Finance · illustrative scenario

The policy answer, from the version that is actually in force.

Product terms, credit policy, AML procedures and regulatory correspondence, answerable in seconds, with the clause attached, which is exactly what an examiner will ask for. Customer and position data stays in your own infrastructure.

Banks Insurers Asset management Payments Brokers & intermediaries

“Which policy version applies?”

Credit policy has been revised three times this year. Branch staff are working from a PDF someone emailed in March, and nobody can say which decisions were made against it.

“Ask compliance.”

One team is the bottleneck for every interpretation question in the business. Their queue is the reason a deal slips a week.

“That data can't go into AI.”

Customer data, positions and pricing are exactly what public AI tools must never see, and the regulator increasingly expects you to document how AI is used internally.

What you get back · illustrative

Compliance sees the full due-diligence standard, relationship managers see enough to act on, the front office retrieves nothing, and the examiner can see exactly which role saw what.

  • Policy questions get answered in seconds, from the version currently in force.
  • Compliance is no longer the queue everything waits behind.
  • Examination prep starts from a sourced report rather than a document hunt.
  • Customer data never reaches a public AI tool, because there is no path to one.

04 · Energy · illustrative scenario

Your crews get the procedure on site, from the revision currently in force.

Operating procedures, HSE documentation, asset manuals, permits and inspection reports, answerable from the field instead of by phoning the office. Critical-infrastructure data never reaches a third-party AI, and where policy demands it, an on-premise deployment runs with no egress at all.

Utilities Grid operators Renewables Oil & gas Engineering contractors

“Which revision is on site?”

The procedure was revised after the last incident. The copy in the control room binder was not. Nobody notices until an audit or an incident review.

“That knowledge retires next year.”

Plant knowledge sits with a handful of people who have been there thirty years. The handover plan is a shared drive nobody has opened.

“Critical infrastructure. No external AI.”

Operational data, network topology and asset conditions are precisely what must not be uploaded anywhere, under regulation and under common sense.

What you get back · illustrative

Operations gets the full procedure from the revision in force, field crews get the steps that apply to them, and no network detail reaches a contractor account.

  • Field staff get the current revision, not the one printed in the binder.
  • Incident reviews start from every related report already gathered and cited.
  • Thirty years of plant knowledge stops walking out with the person who has it.
  • No third-party AI ever sees operational data. Where the site must stay offline, the model runs on your own servers, served by Ollama or another self-hosted runtime.

05 · Construction · illustrative scenario

The answer is in the drawings, the RFIs and six months of correspondence.

Contracts, specifications, RFIs, variation orders, method statements and site reports, answerable in seconds, and every answer points at the document and page, which is exactly what a claim needs. Commercially sensitive project material never reaches a third-party AI.

Main contractors Engineering consultancies Infrastructure Developers Facilities management

“Where did we agree that?”

A variation was agreed in an email, referenced in an RFI, and priced in a revision nobody filed. Assembling the trail takes a quantity surveyor a fortnight.

“Which spec revision?”

Rev C is on site, Rev E was issued last month, and the work in progress was priced against Rev B. Somebody is going to pay for that gap.

“Project data can't go into AI.”

Tender pricing, subcontractor rates and claim positions are exactly what must not be pasted into a public tool, and exactly what people paste in when they are under deadline.

What you get back · illustrative

Commercial sees the full position including cost, project management sees the programme consequence, and no pricing or claim position reaches a site account.

  • Claim preparation starts from an assembled, cited trail instead of a fortnight of searching.
  • Site teams work from the current revision, because superseded revisions drop out of answers.
  • Commercial data stays inside, separate from what site accounts can reach.
  • Handover packs get generated from the files you already have.

Our named references are in healthcare. Here is why that is not a problem.

The two customer stories we can tell are a regulated European medtech company and a children's therapy network, both anonymised. The legal, finance, energy and construction scenarios above are illustrative, and the platform is the same one in every section. We would rather point you at a reference we can stand behind than invent one for your sector.

The platform helps people find and verify information in your own documents. It does not make medical decisions and it is not a medical device.

Read the case studies

See it running on your own documents

Book a demo

30-minute demo, on your files, no commitment.