Rainkernel

Industries

Every domain. The same engineering underneath.

Evaluation, cost, attestation and records are the same problem in a bank and in a warehouse. What changes is the regulator, the data, the peak and the person who has to sign — so we have written those down for each sector, in the order the rules push, with the Lab's evidence pack for each. If yours is not listed, the engineering still applies: tell us the use case.

Insurance and health insurance

Rules push hardest

Claims triage, prior authorisation, underwriting support and policy servicing — agents acting on decisions regulators now ask to see.

Agents being deployed

  • Claims triage and first-notice-of-loss agents
  • Prior-authorisation and utilisation-review agents
  • Underwriting and broker-submission copilots
  • Policy-servicing and renewal agents

Where they stall

  • Decision records and explanations the regulator can ask for do not exist
  • Bias and unfair-discrimination probes have never been run
  • Peak claim volumes (storms, outages) break the pilot

What meets the stall

Regulatory context. State AI bulletins adopted across most US states and Colorado's unfair-discrimination rules; CMS-0057-F prior-authorisation APIs for US payers from January 2027; IRDAI governance and outsourcing expectations in India; EU AI Act high-risk pricing and claims categories.

The Lab's evidence pack for this domain →

Banking and fintech

Rules push hard

KYC, dispute handling, collections and credit copilots — agents inside model-risk and consumer-protection regimes.

Agents being deployed

  • KYC and onboarding document agents
  • Dispute and chargeback handling
  • Collections and payment-plan agents
  • Credit and lending copilots
  • Wealth and compliance assistants

Where they stall

  • Model risk teams have nothing to sign off
  • Per-case cost unknown at production volume
  • Agents over-permissioned on core systems

What meets the stall

  • Agent Readiness Gate — The pre-deployment gate
  • Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.
  • Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.

Regulatory context. Model-risk management expectations (SR 11-7 in the US, RBI's FREE-AI framework in India); EU AI Act high-risk credit scoring; AML and KYC record-keeping; consumer-protection rules on automated decisions.

The Lab's evidence pack for this domain →

Healthcare, pharma and life sciences

Rules push hard

Prior authorisation, revenue-cycle, pharmacovigilance and medical-information agents — where a wrong answer is a safety event.

Agents being deployed

  • Prior-authorisation and revenue-cycle agents
  • Medical-information and literature agents
  • Pharmacovigilance case intake
  • Clinical-operations scheduling and documentation copilots

Where they stall

  • Hallucinated deliverables with real consequences
  • PHI reaching tools and models it should not
  • No evaluation set that a clinical reviewer trusts

What meets the stall

  • Agent Readiness Gate — The pre-deployment gate
  • MCPSentry — Continuous attestation of MCP servers and agent skills
  • Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.

Regulatory context. HIPAA in the US (delivered with a US partner holding the BAA), DPDP Act in India, EU MDR and AI Act where software is a medical device. We assess and harden; we do not operate PHI workloads ourselves.

The Lab's evidence pack for this domain →

Supply chain, manufacturing and logistics

Rules push hard

Document exceptions, procurement, customs, planning and maintenance agents on ERP data.

Agents being deployed

  • Procurement and invoice-exception agents
  • Customs and trade-compliance document agents
  • Demand planning and replenishment copilots
  • Maintenance and quality-report agents on SAP and Oracle data

Where they stall

  • Cost per document unknown; ROI case cannot be made
  • Agents over-permissioned on the ERP
  • Peak-season volumes break the pilot

What meets the stall

  • Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
  • Agent Readiness Gate — The pre-deployment gate
  • Support-Surge Reliability — Independent reliability engineering for the support agents you have already bought

Regulatory context. Customs and trade documentation rules; SOX controls around purchase-to-pay; ISO 9001 and 27001 audit expectations extended to AI changes.

The Lab's evidence pack for this domain →

HR, hiring and workforce

Rules push hard

Screening, ranking, interview and HR help-desk agents — the most regulated agent decisions outside finance and health.

Agents being deployed

  • Candidate screening and ranking agents
  • Interview and assessment agents
  • HR help-desk and policy agents
  • Workforce scheduling and performance copilots

Where they stall

  • Bias audits required by law have never been run
  • Candidates are not told an automated tool was used
  • Policy answers drift with no evaluation set

What meets the stall

  • Agent Readiness Gate — The pre-deployment gate
  • Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.
  • Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.

Regulatory context. New York City Local Law 144 bias audits; Illinois's AI-in-employment amendment from 1 January 2026; Colorado SB 26-189 from 1 January 2027; the EU AI Act's employment high-risk category (December 2027).

The Lab's evidence pack for this domain →

Public sector, education and non-profits

Rules push hard

Citizen-service, admissions and grants agents, where explainability and records are the first requirement.

Agents being deployed

  • Citizen-service and benefits-query agents
  • Admissions and student-service copilots
  • Grant and case-management assistants

Where they stall

  • Decisions must be explainable on request
  • Procurement demands an inventory and security evidence
  • Budgets are fixed; cost overruns are not an option

What meets the stall

  • Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.
  • Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
  • Agent Readiness Gate — The pre-deployment gate

Regulatory context. Public-procurement and records laws; the EU AI Act's public-service high-risk categories; India's DPDP Act and sector guidance.

The Lab's evidence pack for this domain →

SaaS and technology

Rules push moderately

Support agents, coding agents, in-product copilots and the MCP servers that power them.

Agents being deployed

  • In-product copilots and AI features
  • Support agents on Intercom, Zendesk or custom stacks
  • Internal coding and DevOps agents
  • MCP servers published for customers

Where they stall

  • Inference cost grows faster than revenue
  • Enterprise buyers ask for an agent inventory and a security review
  • Coding agents with production credentials

What meets the stall

  • Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
  • MCPSentry — Continuous attestation of MCP servers and agent skills
  • Agent Readiness Gate — The pre-deployment gate

Regulatory context. SOC 2 and ISO 27001 questionnaires now carrying AI sections; EU AI Act GPAI and transparency duties; customers' procurement asking for an Agent BOM.

The Lab's evidence pack for this domain →

Shared services, BPO and global capability centres

Rules push moderately

Finance, HR and IT service-desk agents at scale, often in Hyderabad, Bengaluru, Manila or Kraków.

Agents being deployed

  • IT and HR service-desk agents
  • Accounts-payable and expense agents
  • Employee-query copilots on policy documents
  • Ticket triage and routing agents

Where they stall

  • Volume makes small per-ticket costs large
  • Policy documents poisoned or stale
  • No independent QA of resolution quality

What meets the stall

  • Support-Surge Reliability — Independent reliability engineering for the support agents you have already bought
  • Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
  • Agent Readiness Gate — The pre-deployment gate

Regulatory context. Client contracts' data-residency and audit clauses; SOC 1 and 2 for service organisations; DPDP Act for employee data in India.

The Lab's evidence pack for this domain →

Consultancies, integrators and auditors

Rules push moderately

Firms that sold agent programmes and need an independent gate, a toolkit and evidence their clients can produce.

Agents being deployed

  • Agent programmes delivered for clients
  • Internal knowledge and proposal agents
  • Audit and assurance workflows touching AI systems

Where they stall

  • No independent readiness report to put in front of the client's risk function
  • Benches without the production toolkit
  • Audit evidence for AI improvised per engagement

What meets the stall

  • Agent Readiness Gate — The pre-deployment gate
  • MCPSentry — Continuous attestation of MCP servers and agent skills
  • Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.

Regulatory context. Professional-standards and independence rules; ISO/IEC 42001 certification practices; the frameworks your clients are audited against.

The Lab's evidence pack for this domain →

Retail and e-commerce

Rules push least

Customer-service, returns, catalogue and merchandising agents that live or die on launch day.

Agents being deployed

  • Customer-service and order-status agents
  • Returns and refund agents with payment actions
  • Catalogue enrichment and search copilots
  • Merchandising and pricing assistants

Where they stall

  • Sale-day traffic hits rate limits and the agent goes quiet
  • Refund actions need guardrails that have never been tested
  • Containment numbers come from the vendor

What meets the stall

  • Support-Surge Reliability — Independent reliability engineering for the support agents you have already bought
  • Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
  • Agent Readiness Gate — The pre-deployment gate

Regulatory context. Consumer-protection and payment rules (PCI DSS scope when agents touch payment actions); DPDP and GDPR for customer data.

The Lab's evidence pack for this domain →

Your sector is not the obstacle. The missing evidence is.

Tell us the agent, the data and the person who has to sign. We will tell you which of the five would stall first — in a 30-minute call, no deck, no charge.