What Blocks AI Projects in Regulated Industries
33 firms in healthcare, medical devices, fintech, and nearby regulated sectors named rules that stopped their AI project. For 19 of them, the blocker was producing evidence of how a decision was made, compared with 2 for model validation.
Study methodology: An open-response survey administered via Connectively, with direct outreach, between June and August 2026. We received 67 submissions from 65 respondents, and included 33 after screening. Each respondent got one primary barrier code.
What blocks AI projects in regulated industries, survey statistics
| Audit trail and decision reconstruction | 12 |
| Confidential data boundary | 7 |
| Data lineage, consent and provenance | 4 |
| Change control and revalidation | 2 |
| Explainability of individual decisions | 2 |
| Model validation and generalization | 2 |
| Professional accountability and licensure | 2 |
| No barrier encountered | 2 |
Essential statistics
- Audit trail and decision reconstruction blocked 12 of 33 AI projects, the largest single category.
- The confidential-data boundary blocked 7, covering health records and privileged client files.
- Training-data provenance blocked 4, including lineage and consent records.
- Change control and revalidation, explainability of individual decisions, model validation and generalization, and professional accountability each drew 2 responses.
- 2 firms hit no barrier at all.
- 19 of the 33 primary barriers concerned evidence production rather than model behavior.
- The top 3 categories cover 23 of the 33 responses.
Key takeaways
- An AI system can hit its accuracy target and still fail review. 12 of the 33 blockers came down to rebuilding a decision.
- Evidence barriers beat model barriers by about 10 to 1 here, with 19 responses on one side against 2 on the other.
- Data boundaries block differently from audit trails, since 7 firms could not move the data at all and better logging does not help.
- The long tail is thin and flat, with 4 separate categories drawing 2 responses each. No other barrier stands out once you set aside the top 3.
- 2 of 33 firms reported no barrier, and 1 of those had ruled AI out of regulated decisions before the project started.
Actionable insights
- Budget the audit trail as a build item, since 12 of 33 firms were blocked there, more than at any other point.
- Check whether the best use case falls inside a data boundary before design starts, since 7 firms found the data could not move at all.
- Capture lineage and consent records in the training pipeline from the first build, since 4 firms were blocked on provenance, which is set at collection time.
- Keep accuracy metrics in the model report and build compliance evidence on its own track, because only 2 of 33 barriers concerned model validation.
- Set the boundary before the build. MedicalCert UK reported no blocked projects after ruling AI out of certificate approval and clinical work.
“Security reviewers and auditors at regulated buyers do not ask ‘is your AI good’; they ask ‘show me the artifact and prove you can produce it again.’ An AI agent is non-deterministic by nature, so two runs against the same target do not look identical. That collides directly with how audit evidence works.” — Viktor Bulanek, Founder and Chief Technology Officer, Penetrify





