← All posts

Industry Verticals

227 posts on industry verticals.

Clinical Research AI Audit Trails Must Reconstruct the Trial Record

FDA guidance says inspectors may request the records needed to reconstruct a clinical investigation, including metadata and audit trails. ICH E6(R3) adds traceability, attributable access and review of relevant metadata. This article maps those duties to AI request records while keeping the clinical record and the AI gateway record separate.

ai-governanceai-complianceauditcompliancepolicy-enforcement
Read post →

Capital Markets AI Audit Trails Must Join Supervision to Books and Records

Broker-dealers already make current transaction records, preserve business communications and evidence principal review under SEC and FINRA rules. An LLM used to draft research, summarize customer correspondence or assist an order workflow can sit between those records. This article defines the request-level evidence needed to connect AI use to the supervised activity without claiming that an AI gateway log is itself a complete books-and-records system.

ai-governanceai-complianceauditcompliancepolicy-enforcement
Read post →

Accounting Firm AI Audit Trails Must Preserve the Work Behind the Workpaper

An accounting firm that uses an LLM to analyze a ledger, summarize a contract or draft an audit memo creates an evidence problem alongside the productivity gain. The engagement file may show the final workpaper while omitting the model, source data, policy and reviewer action that produced it. This article maps request-level AI records to PCAOB evidence expectations and the NIST AI Risk Management Framework without treating an AI log as audit evidence by itself.

ai-governanceai-complianceauditforensic-auditpolicy-enforcement
Read post →

Behavioral Health AI Audit Trails Must Separate Access, Disclosure and Model Use

Behavioral health AI can place HIPAA-protected data and 42 CFR Part 2 records into the same model request, but the legal questions remain distinct. HIPAA requires mechanisms that record and examine activity in systems containing or using electronic protected health information. Part 2 adds restrictions and patient rights for substance use disorder records. This article maps those duties to identity-bound request records without treating a gateway log as a complete disclosure accounting.

ai-governanceai-compliancehipaaauditdata-loss-prevention
Read post →

Does Utah Require AI Disclosure? Yes, Since May 2024

Yes. Utah's AI Policy Act has required disclosing generative AI to consumers since May 1, 2024, with a stricter upfront duty for licensed professionals. Here is exactly what the Act requires and the record that proves you met it.

regulationcomplianceai-complianceai-governanceauditai-security
Read post →

Pharmaceutical AI Audit Trails Follow the Predicate Rule, Not the Tool

FDA guidance states that the agency intends to interpret the scope of 21 CFR Part 11 narrowly, applying it to records maintained electronically in place of paper and relied on to perform regulated activities. That scoping test decides whether an AI interaction needs a Part 11 audit trail. This article works through the test, the enforcement discretion positions FDA has stated and the request-level evidence a sponsor needs regardless of how Part 11 lands.

ai-governanceai-compliancepharmaceuticalsauditdata-protection
Read post →

Public Sector AI Audit Trails Answer the High-Impact Determination

OMB Memorandum M-25-21, issued April 3, 2025, directs federal agencies to implement minimum risk management practices for high-impact AI, to establish a process for determining and documenting high-impact use cases, to measure and monitor ongoing performance and to centrally track those determinations. An audit trail is what makes those processes examinable. This article maps the memorandum duties to the per-request records an agency has to hold.

ai-governanceai-compliancegovernmentauditnist-ai-rmf
Read post →

AI Data Protection in Payments Inherits the Safeguards Rule Monitoring Duty

The FTC Safeguards Rule requires covered financial institutions to implement and periodically review access controls, and to establish procedures and controls to monitor when authorized users are accessing customer information and to detect unauthorized access. An AI assistant reading transaction records is an authorized user accessing customer information. This article maps the nine program elements onto the AI request path and names the evidence each one needs.

ai-governanceai-compliancepaymentsdata-protectionaudit
Read post →

AI Data Protection for Law Firms Now Turns on Agent Access Scope

The State Bar of California issued a 2026 revision of its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, replacing the 2023 version and addressing agentic AI at the request of the California Supreme Court. It warns that agentic systems with access to email, document management and client files raise acute confidentiality concerns, and that a lawyer must not permit autonomous external transmission of client information without safeguards and human review.

ai-governanceai-compliancelegaldata-protectionagentic-ai
Read post →

AI Data Protection for Insurers Is Examined Against Your AIS Program

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 4, 2023, expects a written AIS Program covering governance, risk management controls and internal audit, and it lists the documentation a Department may request during an investigation or examination. This article maps those documentation items to the data protection controls an insurer has to evidence on its AI request path.

ai-governanceai-complianceinsurancedata-protectionaudit
Read post →

AI Vendor Risk in Hospitality Follows the Guest Data Route

Hotels move guest information through reservation systems, loyalty platforms, franchise operations, payment services, and model endpoints. GDPR Article 28 sets processor and subprocessor conditions where it applies, while FTC action against Marriott shows the cost of weak data governance. This article ties vendor review to authenticated AI requests.

ai-securityai-governanceai-compliancegdprauditpolicy-enforcement
Read post →

AI Vendor Risk in Higher Education Starts with the Student Record Route

FERPA permits a contractor to receive education-record information under the school official exception only under defined conditions, including direct institutional control over record use and maintenance. AI services add a live disclosure route that procurement files alone cannot describe. This article maps FERPA duties onto authenticated model requests.

ai-securityai-governanceai-complianceauditpolicy-enforcementidentity-and-authorization
Read post →