What Blocks AI Projects in Regulated Industries

What Blocks AI Projects in Regulated Industries

33 firms in healthcare, medical devices, fintech, and nearby regulated sectors named rules that stopped their AI project. For 19 of them, the blocker was producing evidence of how a decision was made, compared with 2 for model validation.

Study methodology: An open-response survey administered via Connectively, with direct outreach, between June and August 2026. We received 67 submissions from 65 respondents, and included 33 after screening. Each respondent got one primary barrier code.

What blocks AI projects in regulated industries, survey statistics

Audit trail and decision reconstruction12
Confidential data boundary7
Data lineage, consent and provenance4
Change control and revalidation2
Explainability of individual decisions2
Model validation and generalization2
Professional accountability and licensure2
No barrier encountered2

Essential statistics

  • Audit trail and decision reconstruction blocked 12 of 33 AI projects, the largest single category.
  • The confidential-data boundary blocked 7, covering health records and privileged client files.
  • Training-data provenance blocked 4, including lineage and consent records.
  • Change control and revalidation, explainability of individual decisions, model validation and generalization, and professional accountability each drew 2 responses.
  • 2 firms hit no barrier at all.
  • 19 of the 33 primary barriers concerned evidence production rather than model behavior.
  • The top 3 categories cover 23 of the 33 responses.

Key takeaways

  • An AI system can hit its accuracy target and still fail review. 12 of the 33 blockers came down to rebuilding a decision.
  • Evidence barriers beat model barriers by about 10 to 1 here, with 19 responses on one side against 2 on the other.
  • Data boundaries block differently from audit trails, since 7 firms could not move the data at all and better logging does not help.
  • The long tail is thin and flat, with 4 separate categories drawing 2 responses each. No other barrier stands out once you set aside the top 3.
  • 2 of 33 firms reported no barrier, and 1 of those had ruled AI out of regulated decisions before the project started.

Actionable insights

  • Budget the audit trail as a build item, since 12 of 33 firms were blocked there, more than at any other point.
  • Check whether the best use case falls inside a data boundary before design starts, since 7 firms found the data could not move at all.
  • Capture lineage and consent records in the training pipeline from the first build, since 4 firms were blocked on provenance, which is set at collection time.
  • Keep accuracy metrics in the model report and build compliance evidence on its own track, because only 2 of 33 barriers concerned model validation.
  • Set the boundary before the build. MedicalCert UK reported no blocked projects after ruling AI out of certificate approval and clinical work.

“Security reviewers and auditors at regulated buyers do not ask ‘is your AI good’; they ask ‘show me the artifact and prove you can produce it again.’ An AI agent is non-deterministic by nature, so two runs against the same target do not look identical. That collides directly with how audit evidence works.” — Viktor Bulanek, Founder and Chief Technology Officer, Penetrify

Research Compliance Barriers to AI Adoption in Regulated Industries
Compliance and Audit Barriers to AI Adoption in Regulated Industries
View research
SumatoSoft logo
If you have any questions, email us info@sumatosoft.com

    Please be informed that when you click the Send button Sumatosoft will process your personal data in accordance with our Privacy notice for the purpose of providing you with appropriate information.

    Vlad Fedortsov (Account Manager)
    Vlad Fedortsov
    Account Manager
    Book an intro call
    Thank you!
    We've received your message and will get back to you within 24 hours.
    Do you want to book a call? Book now
    SumatoSoft clients logo