← All posts

Industry Verticals

227 posts on industry verticals.

Shadow AI for the CISO: The Three Boards a Detection Program Has to Cover

Cloud Radix data shows 90% of CISOs rank shadow AI as their top security concern for the year. The detection program has to cover three boards a typical detection stack does not look at: browser extensions, IDE plug-ins, and chat-platform apps. This piece walks through the three populations, the detection signal for each, the regulatory exposure under EU AI Act Article 26 and HIPAA, and the policy enforcement layer that closes the loop after detection.

shadow-aicisodetectionenforcementai-security
Read post →

AI Security for Prior Authorization: HIPAA, State Laws, and the Identity-Bound Decision Record

Prior authorization is the highest-volume AI use case inside payer organizations and a growing one inside health systems. The compliance stack covers HIPAA, the new state utilization-review laws (California SB-1120, Texas SB-815, Colorado SB 26-189), and the ongoing CMS scrutiny of AI denial patterns. This article walks through the identity, classification, and audit requirements specific to prior authorization, the failure modes documented in recent enforcement actions, and the gateway-layer controls that produce decision records the regulators have started asking for.

ai-securityhealthcareprior-authorizationhipaacomplianceaudit
Read post →

AI Security for KYC Onboarding: BSA, FINRA, and the Per-Decision Record Regulators Inspect

KYC onboarding is one of the highest-volume AI use cases inside banks, broker-dealers, payments firms, and crypto exchanges. The regulatory stack covers the Bank Secrecy Act customer-identification rules, FINRA know-your-customer obligations, FinCEN beneficial-ownership reporting, and (in EU operations) the EBA AML package. This article walks through the AI integration points inside a KYC pipeline, the per-decision audit fields the relevant regulators inspect, and the gateway-layer controls that produce records sufficient for an enforcement inquiry.

ai-securityfinancial-serviceskycamlcomplianceaudit
Read post →

The FCA Mills Review Puts Agentic Finance on the Record: Who Is Accountable When an AI Agent Moves the Money

The FCA published the Mills Review on July 6, 2026, the first review of its kind by a financial regulator. It names four shifts AI is driving in retail financial services and makes seven recommendations, including enabling the foundations for agentic finance. This article stays on the accountability gap the Review opens: once an agent acts within a customer pre-set goal, a firm has to prove per action which identity authorized it and what the agent asked the model to do.

ai-governanceai-complianceagentic-airegulationforensic-auditai-security
Read post →

AI and HIPAA Compliance: What the Security Rule Requires of Any System Touching PHI

HIPAA does not have an AI section, and the Security Rule and Privacy Rule already govern any AI system that touches protected health information. This article walks the three obligations that bind an LLM deployment: access control and audit controls under 45 CFR 164.312, the minimum necessary standard, and the business associate agreement a third-party model provider triggers. It then marks where most deployments leave those obligations unmet at the request layer.

hipaahealthcareai-compliancephiaudit-trailidentity-and-authorization
Read post →

DORA AI Inference Controls: ICT Risk Requirements at the AI Request Layer

DORA is read as a third-party register exercise, and its ICT risk management and testing chapters also reach the runtime AI request path. This article walks the DORA obligations that land on inference itself, protection and detection under Articles 9 and 10, incident reconstruction under Article 17, and threat-led testing under Articles 24 to 27, and shows what a financial entity has to enforce and record on its live AI traffic to meet them.

financedoraict-riskai-complianceoperational-resilienceaudit-trail
Read post →

Fintech AI Fraud Model Governance: Controlling Adaptive Detection Models in Production

A fintech fraud model makes a real-time decision on every transaction, and when it declines a legitimate customer it creates an adverse-action obligation and a fair-lending exposure. This article walks the governance a fraud model needs in production: version control on the live decision, drift monitoring as fraud patterns shift, and a per-decision record that reconstructs why a specific transaction was blocked, so a dispute or a regulator can be answered.

fintechfinancefraud-detectionmodel-governanceai-complianceaudit-trail
Read post →

Government FedRAMP and AI Compliance: Authorizing LLM Services for Federal Use

A federal agency that wants to use an LLM inherits FedRAMP, and the question that decides compliance is where the agency data goes when a prompt leaves the authorized boundary. This article walks the authorization boundary problem, the NIST SP 800-53 audit and access-control families that AI traffic has to satisfy, and why keeping agency prompts inside the authorized estate is an enforcement problem on the request path, not a policy statement.

governmentfedrampai-compliancenist-800-53public-sectoraudit-trail
Read post →

Healthcare AI Agents and HIPAA: Attribution and Minimum Necessary for Autonomous Actions

A healthcare AI agent chains several PHI accesses to complete one task, and HIPAA still asks who accessed what and whether the access was the minimum necessary. This article walks the two obligations agents strain hardest, attribution under the audit-control standard and minimum necessary applied per action rather than per session, and shows why a shared agent credential and session-level logging leave both unmet at the request layer.

healthcarehipaaai-agentsphiaudit-trailidentity-and-authorization
Read post →

AI Medical Scribes and HIPAA: The PHI Leaves With the Prompt

An AI medical scribe listens to a patient encounter and drafts the clinical note, which means protected health information flows into an LLM on every visit. HIPAA compliance for that workflow turns on three things a policy gateway can enforce on the AI request path: a Business Associate Agreement covering the model endpoint, minimum-necessary control over what PHI is sent, and an audit record of every call.

healthcare-aihipaaphiai-audit-trailai-egress
Read post →

Illinois AI Employment Law: The Notice and Non-Discrimination Duties Need a Record

Illinois House Bill 3773 amended the Illinois Human Rights Act, effective January 1, 2026, to make it a civil-rights violation for an employer to use AI that discriminates in employment decisions, and to require notice when AI is used. Both duties turn on evidence: proving what the AI was asked and what it returned. This article shows where that record gets written.

illinois-ai-lawai-employmentai-audit-trailcompliancestate-ai-law
Read post →

HR Hiring AI Under the EU AI Act: The Bias Question Becomes a Logging Question

The EU AI Act classifies AI used to screen and evaluate job candidates as high-risk under Annex III, which brings record-keeping, logging, and human-oversight duties. Bias mitigation is model and data work, but proving a hiring decision was accountable is a logging problem. This article separates the two and shows which obligations a policy gateway produces evidence for on the AI request path.

eu-ai-acthr-aihigh-risk-aiai-audit-trailcompliance
Read post →