THE INDEPENDENT RECORD · AGENTIC AI AS A SERVICE AboutStandardsContact
GAASAGENTIC AI · AS A SERVICE
INDEPENDENT · SINCE 2026
UPDATED DAILY
NO HYPE · NO PAY-TO-PLAY
PER-TASK PRICING NOW STANDARD ● NEW BENCHMARK: 71% TASK COMPLETION ● ENTERPRISE PILOTS UP 4X ● RUNTIME FUNDING ACCELERATES ● "AGENTS ARE THE NEW SEATS" ● MARGINS UNDER PRESSURE ● THE INDEPENDENT RECORD ON GAAS
Verticals

How Vertical Agents Win Regulated Industries

Regulated industries are the hardest place to sell software and the most lucrative place to win. Horizontal AI platforms stall at the compliance wall; vertical agents clear it because they bake regulation into the workflow itself, audit trails, human-in-the-loop checkpoints, and domain-specific guardrails are features, not afterthoughts. The winners aren't the smartest models. They're the agents that make a compliance officer comfortable signing off. This article maps how that actually happens in healthcare, finance, and law, and where the strategy breaks.

By T. Brennan · Mar 13, 2026 · 13 min read

Table of Contents

The compliance wall that stops horizontal platforms

Every horizontal AI platform pitch sounds the same in a regulated boardroom: "Our agent can do anything." And every general counsel in the room hears the same thing back: "So it can do anything wrong, and I can't predict what."

That's the wall. It's not about model quality. The frontier models from the major providers are more than capable of reading a clinical note, reconciling a ledger, or summarizing a contract. The wall is that a regulated buyer cannot deploy a system whose behavior they can't bound, document, and defend after the fact. A hospital that gets audited by CMS, a bank examined by the OCC, a firm facing a malpractice claim, none of them can stand in front of a regulator and say "the AI decided." They need to show the decision, the inputs, who reviewed it, and why it was reasonable.

Horizontal platforms treat compliance as configuration. You buy the general agent, then you bolt on your policies, your retention rules, your sign-off flows. In practice that bolt-on never fully sets. The platform doesn't know what a HIPAA minimum-necessary determination is, or why a SAR filing has a 30-day clock, or that a privileged document can't be processed on the same infrastructure as discovery material. Someone on the customer side has to teach it all that, hold the risk, and own the gaps. Most don't have the appetite.

Vertical agents win here for an unglamorous reason: they show up already knowing the rules, and they're built so that following the rules is the path of least resistance, not an obstacle the user routes around.

Why regulation is a moat, not a tax

Founders new to regulated markets tend to treat compliance as a cost center, a tax you pay to enter. The ones who win flip it. Regulation is the moat.

Here's the logic. In an unregulated market, a better model is a thin advantage; anyone can swap in the next frontier release and catch up in a weekend. In a regulated market, the differentiation isn't the model at all. It's the accumulated, validated, audited apparatus around the model: the controls that have survived an examiner's questions, the workflows a risk committee already approved, the integration into the system of record that took eighteen months and three security reviews to land. None of that transfers to a competitor by swapping the underlying LLM.

a16z has argued that vertical AI's defensibility comes from owning the workflow and the proprietary data exhaust it generates, and regulated industries amplify that effect, see their framing on why AI is eating the services economy. Every compliance interaction your agent logs becomes training signal a generalist can't replicate, because the generalist was never trusted with the regulated workflow in the first place. The moat compounds: trust earns access, access earns data, data earns better outcomes, better outcomes earn more trust.

There's a second-order effect too. Regulators move slowly, which is usually a complaint but here is a gift. Once your agent's controls are accepted as the de facto standard in a vertical, once examiners recognize your audit format, once buyers' own auditors are comfortable with your evidence package, that acceptance is sticky in a way no feature is. You become the safe choice. In risk-averse markets, "safe" beats "best" almost every time.

What a "regulation-native" agent actually looks like

The phrase "compliance-ready" gets thrown around loosely. Let's be concrete about what separates an agent built for a regulated vertical from a general one with a privacy policy.

The audit trail is the product

In an unregulated workflow, the output is the product, the drafted email, the generated code, the answer. In a regulated workflow, the output is half of it. The other half is the record of how the output was produced: every source document retrieved, every tool called, every model version used, the prompt and the response, the confidence signal, and the human who reviewed it. That record has to be immutable, time-stamped, and exportable in a format an auditor accepts.

This sounds like plumbing. It is the plumbing, and it's also the entire value proposition. A bank doesn't buy a compliance-monitoring agent because it flags suspicious transactions faster, plenty of tools do that. It buys the one that produces a defensible, examiner-ready trail for every flag and every dismissal, because the dismissals are what get the bank fined. The agent that can prove why it ignored 9,000 alerts is worth more than the one that caught the 10th. (The compliance-monitoring agent category for banks is a whole node in this cluster for exactly this reason.)

A general-purpose agent platform almost never logs at this granularity by default, because for most customers it's overhead. For regulated customers it's the spine of the entire purchase.

Human-in-the-loop as a pricing tier, not a fallback

Horizontal platforms treat human review as a sign of failure, the thing you do until the model gets good enough to remove it. Vertical agents in regulated fields treat the human checkpoint as a deliberate, permanent, and monetizable part of the design.

This is where per-outcome and per-task pricing gets interesting in regulated verticals. You can sell three tiers of the same agent: fully autonomous for low-risk tasks, human-confirmed for medium-risk, and human-authored-with-agent-assist for the cases where a licensed professional must own the decision by law. A radiology agent can pre-read and draft, but a board-certified radiologist signs. A tax agent can prepare, but a CPA attests. The agent does 80% of the labor and the human supplies the 20% that is legally load-bearing, and crucially, the credential. Pricing follows the liability: the more risk the agent absorbs, the more it can charge, but the law caps how much it's allowed to absorb. Smart vertical companies price right up against that ceiling.

Three industries, three different games

"Regulated" isn't one market. The shape of the win differs sharply by vertical, and conflating them is how generalists lose.

Healthcare: the liability wall

Healthcare's defining constraint isn't HIPAA, privacy is solvable with engineering. It's malpractice liability and the scope-of-practice laws that say only a licensed clinician can diagnose or prescribe. That hard legal line is why clinical-documentation agents have taken off while autonomous-diagnosis agents have not. Documentation is the sweet spot: it's enormous, soul-crushing labor (clinicians spend a punishing share of their day on notes), and it sits just below the liability wall. An ambient agent that listens to a visit and drafts the note doesn't diagnose; the physician reviews and signs, owning the medical judgment.

The winning healthcare agents are obsessive about staying on the safe side of that wall while creeping right up to it. They draft, suggest, surface, and flag, they never decide. And they integrate into the EHR as the system of record, because a note that lives outside the chart is worthless. This is also why prior-authorization and medical-coding agents are such fertile ground: high-volume, rules-dense, financially painful work that's adjacent to clinical judgment without being clinical judgment itself.

Financial services: explainability or nothing

Finance's constraint is explainability and fair-lending law. A model that denies a loan has to produce an adverse-action reason that holds up under the Equal Credit Opportunity Act. A trading-research agent's output feeds decisions that can trigger market-abuse scrutiny. "The neural net said no" is not a defense, regulators have been explicit that complexity is no excuse for opacity, a theme running through the Consumer Financial Protection Bureau's guidance on AI and adverse-action notices.

So the winning financial-services agents are built around reason codes and deterministic guardrails. They lean on retrieval and explicit rules for the parts that must be explainable, and use the generative model for drafting and synthesis where a human still reviews. Underwriting agents, anti-fraud agents, and compliance-monitoring agents all live or die on whether their decisions can be reconstructed and justified line by line. The model is the assistant; the auditable rule engine is the boss.

Law's constraint is the duty of competence and the brutal cost of being wrong. The infamous cases of lawyers sanctioned for citing AI-hallucinated precedents made the risk vivid for the entire profession. The result is a "verification tax": any legal agent's output must be checkable against primary sources, fast.

This reshapes what a good legal agent does. The best contract-review and legal-research agents don't just answer, they cite, link to the source clause or case, and quantify their own uncertainty so a lawyer knows where to look hard. They're built for a workflow where a licensed attorney verifies and bears responsibility. The agent's job is to make verification ten times faster, not to replace it. E-discovery and contract-review agents win precisely because review-and-verify is a workflow they accelerate rather than a wall they pretend doesn't exist.

The go-to-market that regulated buyers reward

You can build the most compliant agent in the world and still lose if you sell it like consumer software. Regulated buyers buy differently, and the vertical companies that win adapt their motion to it.

They lead with the security and compliance package, not the demo. Before a regulated buyer evaluates the agent, their risk, security, and legal teams evaluate the vendor: SOC 2, the data-processing agreement, the model-governance documentation, the incident-response plan. Vertical winners arrive with all of it pre-built and a named compliance contact, because they know the procurement gauntlet is the real product evaluation.

They price for the system of record, not the seat. And they sell to the risk owner, the compliance officer, the chief medical information officer, the general counsel, as much as to the end user, because in regulated industries the person who can veto the purchase is rarely the person who'll use the tool. McKinsey's research on enterprise AI adoption repeatedly finds that governance and risk management are the gating factors for scaling, not technical capability. The vertical agent that makes the risk owner's job easier, that hands them a ready-made control narrative, gets through the gate.

Where the vertical-agent thesis breaks

It's not a guaranteed win, and the honest version of this argument has to say where it fails.

The thesis breaks when the regulation is shallow. If a "regulated" workflow is really just a checkbox, a light disclosure requirement, no examiner, no liability with teeth, then there's no wall for the horizontal platform to crash into, and the vertical agent's compliance apparatus is overhead the generalist undercuts on price.

It breaks when the horizontal platform decides to go vertical itself. A foundation-model provider or a major cloud can stand up a regulated-industry offering with a compliance team you can't match, and the system-of-record incumbents (Epic in health records, the core-banking vendors) can bolt an agent onto the platform that already holds the data and the trust. That competitive squeeze, when a horizontal platform eats your vertical agent, is a real and recurring risk in this cluster.

And it breaks when regulation changes faster than your moat compounds. A new rule can obsolete your carefully validated control set overnight, or a regulator can bless a standard that commoditizes the very thing you sell. The moat is real, but it's made of rules, and rules are written in pencil.

The durable winners treat all three as live threats: they go where regulation is deep, they integrate so far into the system of record that displacing them means ripping out plumbing, and they stay close enough to regulators to see rule changes coming rather than getting blindsided.

Insights Most People Overlook

References

#ai agent audit trail

More in Verticals