Insurance and health insurance
Rules push hardestClaims triage, prior authorisation, underwriting support and policy servicing — agents acting on decisions regulators now ask to see.
Agents being deployed
- Claims triage and first-notice-of-loss agents
- Prior-authorisation and utilisation-review agents
- Underwriting and broker-submission copilots
- Policy-servicing and renewal agents
Where they stall
- Decision records and explanations the regulator can ask for do not exist
- Bias and unfair-discrimination probes have never been run
- Peak claim volumes (storms, outages) break the pilot
Regulatory context. State AI bulletins adopted across most US states and Colorado's unfair-discrimination rules; CMS-0057-F prior-authorisation APIs for US payers from January 2027; IRDAI governance and outsourcing expectations in India; EU AI Act high-risk pricing and claims categories.
The Lab's evidence pack for this domain →
Banking and fintech
Rules push hardKYC, dispute handling, collections and credit copilots — agents inside model-risk and consumer-protection regimes.
Agents being deployed
- KYC and onboarding document agents
- Dispute and chargeback handling
- Collections and payment-plan agents
- Credit and lending copilots
- Wealth and compliance assistants
Where they stall
- Model risk teams have nothing to sign off
- Per-case cost unknown at production volume
- Agents over-permissioned on core systems
What meets the stall
- Agent Readiness Gate — The pre-deployment gate
- Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.
- Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
Regulatory context. Model-risk management expectations (SR 11-7 in the US, RBI's FREE-AI framework in India); EU AI Act high-risk credit scoring; AML and KYC record-keeping; consumer-protection rules on automated decisions.
The Lab's evidence pack for this domain →
Healthcare, pharma and life sciences
Rules push hardPrior authorisation, revenue-cycle, pharmacovigilance and medical-information agents — where a wrong answer is a safety event.
Agents being deployed
- Prior-authorisation and revenue-cycle agents
- Medical-information and literature agents
- Pharmacovigilance case intake
- Clinical-operations scheduling and documentation copilots
Where they stall
- Hallucinated deliverables with real consequences
- PHI reaching tools and models it should not
- No evaluation set that a clinical reviewer trusts
What meets the stall
- Agent Readiness Gate — The pre-deployment gate
- MCPSentry — Continuous attestation of MCP servers and agent skills
- Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.
Regulatory context. HIPAA in the US (delivered with a US partner holding the BAA), DPDP Act in India, EU MDR and AI Act where software is a medical device. We assess and harden; we do not operate PHI workloads ourselves.
The Lab's evidence pack for this domain →
Supply chain, manufacturing and logistics
Rules push hardDocument exceptions, procurement, customs, planning and maintenance agents on ERP data.
Agents being deployed
- Procurement and invoice-exception agents
- Customs and trade-compliance document agents
- Demand planning and replenishment copilots
- Maintenance and quality-report agents on SAP and Oracle data
Where they stall
- Cost per document unknown; ROI case cannot be made
- Agents over-permissioned on the ERP
- Peak-season volumes break the pilot
What meets the stall
- Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
- Agent Readiness Gate — The pre-deployment gate
- Support-Surge Reliability — Independent reliability engineering for the support agents you have already bought
Regulatory context. Customs and trade documentation rules; SOX controls around purchase-to-pay; ISO 9001 and 27001 audit expectations extended to AI changes.
The Lab's evidence pack for this domain →
HR, hiring and workforce
Rules push hardScreening, ranking, interview and HR help-desk agents — the most regulated agent decisions outside finance and health.
Agents being deployed
- Candidate screening and ranking agents
- Interview and assessment agents
- HR help-desk and policy agents
- Workforce scheduling and performance copilots
Where they stall
- Bias audits required by law have never been run
- Candidates are not told an automated tool was used
- Policy answers drift with no evaluation set
What meets the stall
- Agent Readiness Gate — The pre-deployment gate
- Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.
- Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
Regulatory context. New York City Local Law 144 bias audits; Illinois's AI-in-employment amendment from 1 January 2026; Colorado SB 26-189 from 1 January 2027; the EU AI Act's employment high-risk category (December 2027).
The Lab's evidence pack for this domain →
Public sector, education and non-profits
Rules push hardCitizen-service, admissions and grants agents, where explainability and records are the first requirement.
Agents being deployed
- Citizen-service and benefits-query agents
- Admissions and student-service copilots
- Grant and case-management assistants
Where they stall
- Decisions must be explainable on request
- Procurement demands an inventory and security evidence
- Budgets are fixed; cost overruns are not an option
What meets the stall
- Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.
- Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
- Agent Readiness Gate — The pre-deployment gate
Regulatory context. Public-procurement and records laws; the EU AI Act's public-service high-risk categories; India's DPDP Act and sector guidance.
The Lab's evidence pack for this domain →
SaaS and technology
Rules push moderatelySupport agents, coding agents, in-product copilots and the MCP servers that power them.
Agents being deployed
- In-product copilots and AI features
- Support agents on Intercom, Zendesk or custom stacks
- Internal coding and DevOps agents
- MCP servers published for customers
Where they stall
- Inference cost grows faster than revenue
- Enterprise buyers ask for an agent inventory and a security review
- Coding agents with production credentials
What meets the stall
- Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
- MCPSentry — Continuous attestation of MCP servers and agent skills
- Agent Readiness Gate — The pre-deployment gate
Regulatory context. SOC 2 and ISO 27001 questionnaires now carrying AI sections; EU AI Act GPAI and transparency duties; customers' procurement asking for an Agent BOM.
The Lab's evidence pack for this domain →
Shared services, BPO and global capability centres
Rules push moderatelyFinance, HR and IT service-desk agents at scale, often in Hyderabad, Bengaluru, Manila or Kraków.
Agents being deployed
- IT and HR service-desk agents
- Accounts-payable and expense agents
- Employee-query copilots on policy documents
- Ticket triage and routing agents
Where they stall
- Volume makes small per-ticket costs large
- Policy documents poisoned or stale
- No independent QA of resolution quality
What meets the stall
- Support-Surge Reliability — Independent reliability engineering for the support agents you have already bought
- Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
- Agent Readiness Gate — The pre-deployment gate
Regulatory context. Client contracts' data-residency and audit clauses; SOC 1 and 2 for service organisations; DPDP Act for employee data in India.
The Lab's evidence pack for this domain →
Consultancies, integrators and auditors
Rules push moderatelyFirms that sold agent programmes and need an independent gate, a toolkit and evidence their clients can produce.
Agents being deployed
- Agent programmes delivered for clients
- Internal knowledge and proposal agents
- Audit and assurance workflows touching AI systems
Where they stall
- No independent readiness report to put in front of the client's risk function
- Benches without the production toolkit
- Audit evidence for AI improvised per engagement
What meets the stall
- Agent Readiness Gate — The pre-deployment gate
- MCPSentry — Continuous attestation of MCP servers and agent skills
- Compliance Evidence Pack — Tamper-evident records from running agents, mapped to ISO/IEC 42001, the EU AI Act, Colorado SB 26-189 and your auditor's request list.
Regulatory context. Professional-standards and independence rules; ISO/IEC 42001 certification practices; the frameworks your clients are audited against.
The Lab's evidence pack for this domain →
Retail and e-commerce
Rules push leastCustomer-service, returns, catalogue and merchandising agents that live or die on launch day.
Agents being deployed
- Customer-service and order-status agents
- Returns and refund agents with payment actions
- Catalogue enrichment and search copilots
- Merchandising and pricing assistants
Where they stall
- Sale-day traffic hits rate limits and the agent goes quiet
- Refund actions need guardrails that have never been tested
- Containment numbers come from the vendor
What meets the stall
- Support-Surge Reliability — Independent reliability engineering for the support agents you have already bought
- Agent Cost Governor — Per-task cost ceilings enforced inside the agent loop, with a server-side circuit breaker and nightly reconciliation against the provider bill.
- Agent Readiness Gate — The pre-deployment gate
Regulatory context. Consumer-protection and payment rules (PCI DSS scope when agents touch payment actions); DPDP and GDPR for customer data.
The Lab's evidence pack for this domain →