The engine — attack pack, harness, cost meter, permission audit, BOM, recorder — is the same everywhere. What changes is the regulator's question, the attack cases that matter and the record that has to exist. Each pack is published after the first Gate in that domain.
Rules push hardest
Insurance and health insurance
What makes buyers prove it. State AI bulletins adopted across most US states; Colorado's rules on unfair discrimination in insurance; CMS-0057-F prior-authorisation APIs for US payers from January 2027; IRDAI outsourcing and governance expectations in India; EU AI Act high-risk pricing and claims categories.
- Claims-triage and FNOL agents: decision records, adverse-action explanations
- Prior-authorisation agents: human review trail, turnaround evidence
- Underwriting copilots: disparate-impact probes on protected classes
Pack output. Decision record with explanation and human-review trail; bias-probe results; model and prompt version inventory
Rules push hard
Banking and fintech
What makes buyers prove it. Model-risk management expectations (SR 11-7 in the US, RBI's FREE-AI framework in India); EU AI Act high-risk credit scoring; AML and KYC record-keeping; consumer-protection rules on automated decisions.
- KYC and onboarding document agents: injection through uploaded documents
- Dispute and collections agents: policy adherence, escalation
- Credit copilots: explanation quality, drift
Pack output. Model-risk validation pack: evaluation set, challenger results, monitoring plan, change records
Rules push hard
HR, hiring and workforce
What makes buyers prove it. New York City Local Law 144 bias audits; Illinois's AI-in-employment amendment from 1 January 2026; Colorado SB 26-189 from 1 January 2027; the EU AI Act's employment high-risk category (December 2027).
- Screening and ranking agents: bias audit by protected class
- Interview and assessment agents: explanation, candidate notice
- HR help-desk agents: policy accuracy, PII handling
Pack output. Bias-audit report in the published format; notice and explanation records; evaluation set and results
Rules push hard
Manufacturing and industrial
What makes buyers prove it. The EU Machinery Regulation from January 2027 (AI in safety functions); the Cyber Resilience Act for products with digital elements (reporting from September 2026); ISO 9001 change control; functional-safety standards.
- Maintenance and quality-report agents: action safety, authority limits
- Supplier and procurement agents: document exceptions, cost per document
- Product-embedded agents: BOM, vulnerability handling
Pack output. Agent BOM; change and incident records; authority-limit test results
Rules push hard
Pharma and life sciences
What makes buyers prove it. GxP computerised-system validation (EU Annex 11, 21 CFR Part 11); FDA and EMA guidance on AI in regulatory decision-making; pharmacovigilance reporting timelines.
- Batch-record and deviation agents: validation evidence, audit trail
- Pharmacovigilance intake agents: case completeness, timeliness
- Medical-information agents: source grounding, off-label guardrails
Pack output. Validation pack (IQ/OQ/PQ-style evidence for the agent), tamper-evident audit trail, periodic review records
Rules push hard
Public sector and education
What makes buyers prove it. Public-procurement rules asking for inventories and impact assessments; records and freedom-of-information laws; the EU AI Act's public-service high-risk category; US federal and state AI-use policies.
- Citizen-service agents: explainability on request, accessibility
- Benefits and case agents: decision records, appeal trail
- Admissions and grants assistants: bias probes
Pack output. AI inventory entry, impact-assessment inputs, decision records, accessibility results
Rules push hard
Healthcare providers
What makes buyers prove it. ONC HTI-1 transparency for decision-support software; state laws on generative AI in patient communications; HIPAA; EU MDR where software is a medical device.
- Scheduling and intake agents: PHI boundaries, consent
- Documentation and coding agents: accuracy on held-out charts
- Patient-facing agents: disclosure, escalation to clinicians
Pack output. PHI data-flow map, evaluation results a clinical reviewer signs, disclosure records
Rules push moderately
Customer service, BPO and GCCs
What makes buyers prove it. EU AI Act transparency duties (Article 50, from August 2026); the FCC's ruling that AI voices in calls fall under the TCPA; client contracts' data-residency and audit clauses; SOC 1 and 2 for service organisations.
- Support agents at peak: surge, rate limits, fallback
- Voice agents: disclosure, consent, containment
- Shared-mailbox triage: routing accuracy, PII
Pack output. Containment and resolution QA score, surge test report, cost per resolution
Rules push moderately
Legal and professional services
What makes buyers prove it. Professional-conduct and confidentiality rules; court orders on AI-assisted filings; client audit clauses; ISO/IEC 42001 adoption among firms.
- Research and drafting agents: citation grounding, hallucination rate
- Contract-review agents: clause recall on held-out sets
- Client-facing agents: confidentiality boundaries
Pack output. Grounding and citation audit; confidentiality test results; usage records
Rules push moderately
Software and SaaS
What makes buyers prove it. SOC 2 and ISO 27001 questionnaires with AI sections; the Cyber Resilience Act for products sold in the EU; EU AI Act GPAI and transparency duties; customers' procurement asking for an agent inventory.
- In-product copilots: injection via user content, data boundaries
- Coding and DevOps agents: credential scope, change control
- Published MCP servers: description integrity, permissions
Pack output. Agent BOM for the security questionnaire; attack-pack results; cost per task
Rules push least
Supply chain and logistics
What makes buyers prove it. Customs and trade documentation rules; SOX controls around purchase-to-pay; contractual SLAs with carriers and customers — little AI-specific regulation.
- Document-exception agents: accuracy and cost per document
- Carrier-communication agents: commitment limits
- Planning copilots: forecast evaluation
Pack output. Cost-per-document baseline, exception-handling evaluation, change records
Rules push least
Retail and e-commerce
What makes buyers prove it. Consumer-protection and advertising rules; PCI DSS where agents touch payments; DPDP and GDPR for customer data — little AI-specific regulation.
- Returns and refund agents: action limits, fraud probes
- Catalogue and search copilots: accuracy, brand-safety
- Sale-day support agents: surge and fallback
Pack output. Action-limit test results, surge report, cost per resolution
Languages: every pack runs in English and in the languages the agent serves customers in; the multilingual test set is on the Readiness Kit roadmap for Q1 2027. Sector detail on the industries page; the evidence exports on the Compliance Evidence Pack page.