
How to think about AI risk in a regulated industry
Most organisations in regulated industries approach AI risk backwards. They wait for the regulator to publish guidance, then retrofit compliance onto systems that were already built. By the time the policy lands, the architecture is set, the vendor is contracted and the risk is already embedded.



