Episode 391 How Regulated Industries Can Adopt AI Without Losing Control

Explore more in the episode archive.

Summary

Regulated industries are under pressure to adopt AI without compromising security, compliance, or critical thinking. In this episode, Aaron Bach and Dr. Darren Pulsipher discuss why blanket AI bans fail, how shadow AI increases organizational risk, and what leaders can do to adopt AI responsibly. Th

AI in Regulated Industries: How to Move Fast Without Losing Control

Artificial intelligence is moving quickly into the places where caution matters most: healthcare, banking, insurance, education, and other regulated industries where people, data, and compliance all carry real risk. That creates a difficult tension for leaders. Move too slowly, and the business falls behind. Move too fast, and the organization can expose itself to security failures, policy violations, and regulatory trouble.

What makes this moment so important is that AI is no longer just a lab experiment or a back-office curiosity. Employees are already using it, often outside of formal policy. The question for executives is no longer whether AI will enter the enterprise, but how to manage it in a way that preserves speed, trust, and sound judgment.

Why Regulated Industries Are Cautious

The instinct to slow down is understandable. In healthcare, finance, and insurance, the cost of a mistake can be measured in fines, lost trust, or even harm to people. Many leaders initially assumed generative AI would never be usable in their environment. That reaction made sense in 2023, when tools like ChatGPT were still new and the landscape was changing almost weekly.

But the pace of change has not given organizations the luxury of waiting for perfect rules. Policies are being rewritten, sometimes repeatedly, as leaders try to balance innovation with control. At the same time, employees are often already experimenting with AI on their own, which creates a familiar but intensified version of shadow IT — the use of unauthorized technology inside an organization.

That is why the modern CIO and CISO are under pressure. Their job is still to protect the organization from risk, but now they must do it while a rapidly evolving toolset is pushing from below and from outside the company.

The Real Risk Is Not Just the Model

One of the strongest themes in the conversation was that the biggest risk is not simply the technology itself. It is what happens when organizations lose the human ability to question it. AI can accelerate work, summarize information, and generate outputs quickly, but it can also be confidently wrong. In high-stakes settings, that matters.

There is also a strategic risk. Large organizations know that if they wait too long, they may face their own “Kodak moment” — a reference to a company that failed to adapt to a major technological shift and lost its relevance. That fear is driving some regulated industries to explore AI in limited, controlled ways, even while they remain cautious about broad deployment.

A useful way to think about it is sovereignty. It is not enough to ask where the data lives. Leaders also need to ask whether they can move between AI providers without giving up governance, visibility, or control. In practice, that means avoiding dependence on a single model or vendor and building an architecture that can adapt as the market changes.

Augment People, Don’t Replace Judgment

The strongest case for AI in regulated industries is not automation for its own sake. It is augmentation — using AI to help people work better without removing their expertise from the process. That distinction matters. A lawyer, clinician, architect, or analyst should still be the validator. AI can assist, but it should not become the final authority.

That is also why basic human skills are becoming more important, not less. Critical thinking, communication, creativity, and judgment are becoming the differentiators. Technical skills still matter, but leaders should not confuse faster code generation with better architecture. Understanding trade-offs, system design, and long-term consequences is more important than ever.

Aaron Bach’s company, Liminal, was built around this idea. The platform is designed to let organizations use multiple AI models while keeping control over sensitive information and visibility into how employees are using the tools. The goal is not to block AI or unleash it unchecked. It is to create a structured boundary — enough freedom to innovate, enough governance to stay safe.

For many organizations, that balance is already paying off in practical ways. Legal teams are using AI to reduce document review time. Frontline employees are finding small but meaningful ways to remove friction from daily work. These are not flashy headlines, but they are exactly the kind of improvements that make AI valuable in the real world.

The full conversation goes deeper into what safe, practical AI adoption looks like in regulated industries, and it is well worth a listen.