I keep hearing the same question from executives: "How do we use AI without ending up in front of a regulator?" It's the right question, but most organizations are answering it the wrong way. They're treating AI adoption in regulated industries as a compliance review checklist when what they actually need is a strategic framework that makes speed and safety compatible.

The problem isn't that regulations prohibit AI. The problem is that most organizations wait until they're already deploying AI to ask what the rules require. By then, they're making compliance decisions under pressure, with limited options, and they're often forced to choose between innovation and safety. That's not a choice you should have to make.

I've worked with healthcare organizations, defense contractors, and financial services firms navigating this exact tension. The ones who get it right don't move slowly. They move deliberately. There's a difference.

The Real Barrier Isn't Regulation—It's Readiness

When organizations tell me they can't adopt AI because of HIPAA, or CMMC, or their prudential regulator, I ask them to show me the specific prohibition. Nine times out of ten, they can't. What they're really saying is that they don't have the infrastructure to adopt AI in a way that satisfies their existing obligations.

That's a data governance problem, not a regulatory problem. If you can't tell me where your sensitive data lives, how it's classified, who has access to it, and how it moves through your systems, you're not ready to deploy AI in a regulated environment. Not because the law says you can't, but because you lack the baseline visibility required to manage risk.

The pattern I see repeatedly: organizations that struggle with AI adoption in regulated industries are the same ones who struggled with cloud adoption five years ago, with mobile device management before that, and with remote access before that. The common thread isn't the technology. It's the absence of foundational controls and governance structures that make any new capability manageable.

The Three Prerequisites

Before you talk about AI policy or risk frameworks, you need three things in place:

These aren't AI-specific requirements. They're table stakes for any regulated organization. But AI makes their absence catastrophic.

Sector-Specific Realities: What Actually Applies

Regulatory frameworks don't address "AI" as a monolith. They address specific risks: unauthorized access, inappropriate disclosure, lack of accountability, automated decision-making without human oversight, bias and fairness, and data retention. Your sector determines which of those risks regulators care most about.

Healthcare and HIPAA

HIPAA doesn't mention AI. It doesn't need to. The Security Rule already requires you to implement technical safeguards to protect electronic PHI from unauthorized access and disclosure. The Privacy Rule already limits how you can use and share that data. If your AI tool processes PHI, those rules apply.

The specific questions healthcare organizations need to answer:

I worked with a health system that wanted to deploy an AI-powered clinical documentation tool. The vendor's sales team assured them it was "HIPAA compliant." When we looked at the contract, there was no BAA. When we asked about data retention, the vendor couldn't tell us where the data was stored or how long it was kept. When we asked about access logging, they said it was "available on request."

That's not HIPAA compliance. That's marketing.

The health system didn't abandon the project. They required the vendor to sign a BAA, provide specific contractual commitments about data handling, and integrate access logs into the health system's SIEM. It took three months longer than the original timeline. But when OCR comes asking questions—and they will—that organization will have answers.

Defense Contractors and CMMC

If you're a defense contractor handling Controlled Unclassified Information (CUI), your AI adoption decisions are constrained by NIST 800-171 and CMMC. The question isn't whether you can use AI. The question is whether your AI deployment creates new CUI flows that aren't protected by your existing security controls.

The specific issues that trip up defense contractors:

The defense contractors who navigate this well treat AI vendors the same way they treat any other subcontractor: with a clear scope, defined data handling requirements, and contractual flow-down of DFARS and NIST 800-171 obligations. The ones who struggle treat AI tools as "just software" and wake up six months later realizing they've created a compliance gap they can't close without ripping the tool out.

Financial Services and Prudential Regulators

Banks, credit unions, and other financial institutions face a different set of constraints. Prudential regulators—OCC, FDIC, NCUA, the Fed—care about operational risk, third-party risk management, and model risk management. If your AI tool makes or influences decisions about credit, fraud detection, or risk assessment, you're operating in an environment with decades of regulatory precedent about models and accountability.

The specific concerns regulators raise:

Financial institutions that get this right build AI adoption into their existing model risk management frameworks. They don't treat AI as a separate category. They treat it as a new type of model that requires the same governance, validation, and oversight as any other decision-making tool.

Need a Framework for AI Adoption in Your Regulated Environment?

Carl speaks to healthcare, defense, and financial services organizations about building AI governance frameworks that satisfy regulators without stalling innovation. His keynotes are built on real implementation experience, not vendor talking points.

Book Carl to Speak
Inline article illustration

Building a Framework That Works: Strategy Over Prohibition

Most AI policies I see are lists of things employees can't do. Don't upload customer data. Don't use unapproved tools. Don't share proprietary information. That's not a strategy. That's risk avoidance masquerading as governance.

A real framework does three things: it defines what "approved use" looks like, it creates a process for evaluating new AI tools and use cases, and it establishes accountability for decisions. Here's how that breaks down in practice.

Define Approved Use Cases and Risk Tiers

Not all AI use carries the same risk. Using AI to summarize internal meeting notes is not the same as using AI to draft patient care plans or make credit decisions. Your framework should distinguish between risk tiers and apply proportional controls.

In my experience, a three-tier model works well:

The point isn't to create bureaucracy. The point is to make risk-based decisions transparent and repeatable. When someone in your organization wants to adopt a new AI tool, they should know immediately which tier it falls into and what the approval process looks like.

Create a Cross-Functional Review Process

AI adoption decisions shouldn't live in IT alone. They require input from legal, compliance, risk management, the business unit that will use the tool, and IT security. The organizations that move fastest are the ones who assemble this group once and give them a clear mandate: evaluate AI proposals against defined criteria and make go/no-go decisions within a set timeframe.

The criteria should be specific:

These aren't hypothetical questions. They're the questions auditors and regulators will ask after an incident. Answering them before deployment is the difference between controlled adoption and crisis management.

Establish Clear Accountability

Every AI deployment needs an owner. Not an IT owner. A business owner who is accountable for how the tool is used, who has access, and whether it's delivering value without creating unacceptable risk. That person should be identified during the approval process and should be responsible for periodic review.

In practice, this looks like a quarterly or semi-annual check-in: Is the tool still being used as intended? Have there been any incidents or near-misses? Has the vendor's risk profile changed? Are we still meeting our compliance obligations?

This isn't heavy process. It's basic operational hygiene. But most organizations skip it because nobody's job description says "AI tool owner." Make it someone's job.

The Vendor Conversation You're Probably Not Having

AI vendors are very good at selling capability. They're less good at transparency. When you ask a vendor whether their tool is HIPAA-compliant or meets NIST 800-171, the answer is almost always yes. When you ask for evidence, things get interesting.

The questions I ask every AI vendor, regardless of sector:

If a vendor can't or won't answer these questions, that's a signal. You're not being difficult. You're doing due diligence.

One healthcare organization I worked with was evaluating an AI scribe tool. The vendor's contract included a clause saying they could use de-identified data for research and product improvement. When we asked how they de-identified the data, they said it was "automated." When we asked what de-identification standard they used, they said it met "industry best practices." When we asked for a technical specification, they stopped responding.

That organization walked away. Not because the tool wasn't useful, but because the vendor couldn't demonstrate that they understood the regulatory obligations involved. Six months later, that same vendor had a data breach. The healthcare organization had made the right call.

Inline article illustration

When "Compliant AI" Is Really Just Theatre

There's a growing market for AI tools marketed specifically to regulated industries: "HIPAA-compliant AI," "secure AI for defense contractors," "regulatory-ready AI." Some of these tools are legitimate. Many are not.

The warning signs I look for:

I'm not anti-vendor. I'm anti-vendor-theatre. The AI vendors who earn trust in regulated industries are the ones who understand that compliance is an ongoing operational commitment, not a marketing claim. They provide detailed documentation, they're transparent about limitations, and they're willing to put commitments in writing.

Looking for Practical Guidance on AI Governance?

Carl delivers keynotes on AI risk, governance, and regulatory strategy for organizations that need frameworks, not fear. See all keynote speaking topics or reach out about your event.

Book Carl for Your Event

What Regulators Are Actually Watching

Regulators aren't waiting for comprehensive AI legislation to start scrutinizing how organizations use these tools. They're applying existing frameworks and making clear that "we didn't know AI was covered" isn't a defense.

OCR has already issued guidance making clear that HIPAA applies to AI tools that process PHI. The FTC has brought enforcement actions against companies whose AI systems caused consumer harm or violated fairness standards. The EU AI Act is creating compliance obligations for U.S. companies operating in Europe, and states are beginning to pass their own AI-related requirements.

What regulators are looking for isn't perfect AI. They're looking for evidence that you took reasonable steps to understand and manage risk. That means:

The organizations that will face enforcement actions aren't the ones using AI. They're the ones using AI carelessly, without governance, without accountability, and without documentation. Don't be that organization.

Moving Forward: What This Looks Like in Practice

AI adoption in regulated industries doesn't require a two-year planning process. It requires a framework, a decision-making process, and a commitment to doing it right. Here's what that looks like for most organizations:

Start with inventory. You can't govern what you don't know about. Identify where AI is already being used in your organization—sanctioned and unsanctioned. Most organizations are surprised by what they find. That inventory becomes the foundation for your risk assessment and policy development.

Define your risk appetite and approval process. Decide what AI use cases are acceptable, which require review, and which are prohibited. Document the approval criteria and the people responsible for making decisions. Make the process transparent so employees know how to get AI tools approved instead of working around the rules.

Build vendor evaluation into procurement. AI vendors should go through the same due diligence process as any other critical vendor. Security assessment, contract review, compliance validation. If your procurement team doesn't know how to evaluate AI vendors, train them or bring in expertise.

Establish monitoring and review cadences. AI tools and use cases aren't static. The vendor's risk profile changes. Your regulatory obligations evolve. New use cases emerge. Set up a process to review AI deployments on a regular basis and adjust controls as needed.

Prepare for incidents. At some point, something will go wrong. An employee will use an unapproved tool. A vendor will have a breach. A model will produce an output that creates a compliance issue. Your incident response plan should account for AI-related scenarios and specify who's responsible for containment, investigation, and regulatory notification.

These steps aren't revolutionary. They're the same risk management practices that regulated organizations have been using for decades, applied to a new category of technology. The organizations that treat AI as fundamentally different from every other operational risk are the ones who get stuck. The ones who treat it as a manageable risk within existing frameworks are the ones who move forward.

The Strategic Advantage of Getting This Right

Organizations that build real AI governance frameworks don't just reduce compliance risk. They create a competitive advantage. When your competitors are paralyzed by uncertainty or forced to pull back AI deployments after an incident, you're operating with confidence because you've done the work up front.

Customers and partners notice. In healthcare, patients are asking which organizations are using AI and how they're protecting privacy. In defense contracting, primes are asking subs about their AI security posture. In financial services, regulators are making AI risk management part of their examination process. The organizations that can demonstrate mature AI governance aren't just checking a box—they're signaling operational competence.

The executive conversation should shift from "Can we use AI?" to "How do we use AI in a way that strengthens trust and manages risk?" That's a conversation worth having. And it's one that requires leadership, not just technical implementation. If your AI strategy is being driven entirely by IT or a single business unit, you're missing the bigger picture. This is a business strategy question that happens to involve technology and regulation.

The organizations that will lead in AI adoption in regulated industries aren't the ones with the most resources or the most sophisticated technology. They're the ones with the clearest frameworks, the most disciplined processes, and the strongest alignment between business objectives and risk management. Build that foundation, and speed becomes possible. Skip it, and you'll spend the next three years reacting to problems you could have prevented.

📖
10 Questions Every Executive Should Ask Before Deploying AI → The Human Side of AI Adoption →