Use-case guides

Industry-specific guides to AI regulation — which laws apply, what they require, and the practical dos and don'ts.

AI in Agriculture & AgTech

For: Precision-ag platform developers, agricultural drone operators, livestock-AI vendors, agronomic-data brokers, agri-business compliance

Agricultural AI doesn't have a single AI regulation aimed at it — but it has more sectoral overlays than most industries: USDA + FDA in the US, the EU's CAP (Common Agricultural Policy) data-sharing rules, FAA Part 107 for drones, EU Drone Regulation 2019/947, state right-to-repair laws affecting John Deere-style AI lockout, and a growing patchwork of livestock-welfare AI rules. The high-leverage AI uses — yield prediction, precision irrigation, pest detection, livestock health monitoring, autonomous tractors — each triggers different overlays. The pattern: agricultural AI is regulated where it touches sensors, drones, livestock, or worker-safety; everywhere else it's mostly an antitrust + data-broker question.

Read guide →

AI in Autonomous Vehicles & Transportation

For: AV developers (L3-L5), OEMs adding driver-assist, fleet operators, federal/state transport regulators, AV insurance counsel

Autonomous-vehicle AI is the most regulated AI domain on earth — and the rules come from three layers simultaneously. International: UNECE WP.29 framework (UN R155 cybersecurity, UN R156 software updates, UN R157 ALKS). EU: type-approval regulation 2018/858 plus the AI Act treating AVs as Annex I products. US: federal NHTSA framework plus a state-by-state patchwork (California DMV Autonomous Vehicle Tester Program, Arizona, Texas, Nevada, all with different rules). Add ISO/SAE 21434 cybersecurity, ISO 26262 functional safety, and SAE J3016 levels — and you have a compliance map most teams take a year to build.

Read guide →

AI in Children's Products & Family-Facing AI

For: Toy makers, EdTech vendors selling to families, children's app developers, family-streaming platforms, child-safety compliance officers

AI for children is governed by the strictest privacy and safety regimes anywhere — separate from the Education guide because this covers consumer-product use, not curricular use. The core hooks: COPPA (US), GDPR-K (EU), the UK Age-Appropriate Design Code, California's Age-Appropriate Design Code (AB 2273), and a wave of state laws (NY SAFE for Kids Act, Maryland AADC, Connecticut). Plus FTC enforcement that's intensified since 2023 — Epic Games' $520M COPPA settlement set a new ceiling. AI features layered on top: chatbots aimed at kids, recommendation algorithms, biometric data collection from age verification. The compliance design choice — gate or strip — drives the entire product.

Read guide →

AI in Content Moderation & Online Platforms

For: Trust-and-safety teams, platform policy leads, generative-AI product teams, marketplaces with user-generated content

Anyone running a platform with user-generated content, or shipping a generative-AI product the public uses, sits at the intersection of three accelerating regimes: the EU AI Act's transparency rules for generative AI (Article 50), the EU Digital Services Act's content-moderation obligations, and a wave of national rules on AI-generated political content, intimate-image deepfakes, and child sexual abuse material. China's Generative AI Measures add a fourth regime if your service reaches mainland users. The compliance asks aren't just 'don't generate bad stuff' — they're about labelling, audit logs, takedown SLAs, and risk assessments.

Read guide →

AI in Cybersecurity

For: CISOs, SOC managers, AI-security vendors, EDR product teams, threat-intel platforms, security counsel

AI in cybersecurity has two faces: AI as defender (SOC automation, EDR, fraud detection, vulnerability AI) and AI as attacker (LLM-driven phishing, deepfake voice attacks, exploit generation). The regulatory load comes from both sides and from a third, less visible angle: the AI tooling itself is now part of the regulated cybersecurity supply chain. NIS2, the EU Cyber Resilience Act, the US Cybersecurity Maturity Model Certification (CMMC), and SEC cyber-disclosure rules all interact. Add CISA's Secure-by-Design + Secure-AI initiatives and you have an emerging compliance pattern: 'AI is now a covered IT asset by default'.

Read guide →

AI in Defense & National Security

For: Defense primes, government acquisition, intelligence community contractors, dual-use AI startups, export-control counsel

Defense AI lives in its own regulatory universe — partly governed by the same AI laws that cover everyone else, partly by export controls (EAR/ITAR, EU dual-use regulation), and partly by national-security carve-outs that exempt some uses but expose others. The EU AI Act includes a national-security carve-out (Article 2(3)) but it's narrower than industry expected. The US, UK, and allies have all issued separate frameworks (NDAA-driven RAI guidance, MOD JSP 936, NATO AI strategy) that operate parallel to civilian AI law. The combination produces tight margins for error: get the export classification wrong, and a software update becomes a criminal act.

Read guide →

AI in Education

For: K-12 districts, university administrators, edtech founders, AI tutoring product teams

Education is where 'AI for kids' meets the most protective legal regimes on earth. AI tutors, automated grading, proctoring, admissions algorithms, and chatbots aimed at minors all simultaneously trigger (1) the EU AI Act's high-risk classification for education, (2) FERPA + state student-data-privacy laws in the US, (3) child-data rules (COPPA, GDPR-K, Article 14 UK age-appropriate design code), and (4) sector-specific equality law. Regulators are also moving fast on AI-generated academic misconduct, deepfake nude images of students, and emotion-recognition in classrooms.

Read guide →

AI in Finance & Banking

For: Banks, insurers, asset managers, fintech founders, compliance and model-risk officers

Financial services has the longest history of model-risk regulation of any industry — and AI is the next chapter, not a new beginning. Credit decisions, fraud scoring, anti-money-laundering surveillance, and algorithmic trading were all already under regulator scrutiny before generative AI arrived. What changed in 2024-2026 is that AI-specific laws are now stacking on top of the existing model-risk rules: the EU AI Act treats credit and insurance pricing as high-risk by default, Colorado classifies consumer finance as a consequential-decision domain, and bank supervisors (Fed/OCC/FCA/ECB) have all issued AI-specific guidance that pulls model-risk principles into the AI era.

Read guide →

AI in Gaming & Esports

For: Game studio CTOs, online-platform leads, generative-AI tooling for game content, esports league operators, gaming-platform compliance

Gaming AI is regulated through three distinct lenses: (1) generative AI in game content (UGC moderation, AI-generated NPCs, voice cloning), (2) AI-driven monetisation (loot boxes, dynamic pricing, in-game economy), and (3) AI anti-cheat + player safety (anti-toxicity, age-verification). The EU AI Act Article 50 plus the DSA cover the first two. Belgium and the Netherlands have already classified loot-box mechanics with AI-driven probability as gambling under specific conditions; the UK Gambling Commission, Australian ACMA, and German GlüStV regulators have followed. Plus child-product overlays (COPPA, AADC) for any game with under-18 players — which is most games.

Read guide →

AI in Healthcare

For: Clinicians, hospital systems, healthtech founders, payers, and regulators

AI in healthcare touches the most sensitive personal data there is — and the wrong decision can kill someone. Regulators have responded with two layers of rules: data-protection laws that govern how you process health data, and AI-specific laws that treat clinical decision support, triage, and medical-device AI as high-risk by default. If your AI is used in diagnosis, triage, drug discovery, claims adjudication, or patient-facing chatbots, almost every major regulator currently has you in scope.

Read guide →

AI in HR & Hiring

For: Talent acquisition, HRIS owners, people-ops leaders, HRTech founders, employment counsel

Hiring AI was one of the first areas regulators targeted, and it remains one of the most scrutinised. AI resume screeners, video-interview analysers, and skills-assessment tools are presumed to be high-risk in the EU and a 'consequential decision' system in Colorado. Layered on top of the AI rules, you have decades of anti-discrimination law (Title VII, the EEOC, Equality Act, AGG) that already applied to the human version of these decisions — and applies just as forcefully to the automated version.

Read guide →

AI in Insurance

For: P&C and life-and-health insurers, reinsurers, insurtech founders, actuarial leads, insurance regulators, broker compliance

Insurance is one of the few sectors where the EU AI Act explicitly names you as high-risk by default. Life and health pricing using AI sits in Annex III §5(c); credit/property-side coverage often falls in §5(b). Layered on top: US state insurance regulators are issuing AI bulletins (NAIC Model Bulletin on AI 2023; Colorado Reg 10-1-1; NYDFS Circular Letter 7), state UDAP rules on discriminatory pricing, and Solvency II model-risk overlays in the EU. Algorithmic bias in underwriting has been the most-litigated area of insurance discrimination since 2022.

Read guide →

AI in Insurance Claims & Adjudication

For: Claims VPs, SIU teams, healthtech claims platforms, Medicare-Advantage operators, AI claims-adjudication vendors

AI in claims adjudication is the live wire of insurance regulation right now — distinct from underwriting AI. Three things changed in 2023-2025: (1) CMS issued binding rules requiring human review for Medicare-Advantage AI denials, (2) class actions against UnitedHealthcare and Cigna over algorithmic denials moved through US federal court, (3) state insurance commissioners started subpoenaing claim-AI documentation in market-conduct exams. The risk profile is acute because every wrongful denial is a discrete plaintiff with a discrete cause of action.

Read guide →

AI in Journalism & News Media

For: Editors-in-chief, news platform tech leads, journalism standards officers, syndicators, fact-check organisations, media defense counsel

News organisations face AI-driven exposure on three fronts at once: as content producers (AI-drafted articles, AI-generated images), as platforms (recommendation algorithms, comment moderation), and as litigation defendants (the NYT/OpenAI case is the most visible, but others are pending). The regulatory load is lighter than in heavily-regulated sectors but the reputational and defamation exposure is unusually high — a hallucinated fact in a CNN/Reuters/AP byline is a Section 230 / European Convention Article 10 catastrophe in a way it isn't on a personal blog.

Read guide →

AI in Legal Services

For: Law firm partners, in-house GCs, legal-tech founders, bar-association compliance officers, courts and judicial admin

Lawyers and AI are a high-friction combination — the profession is regulated, the use cases (research, drafting, e-discovery, due diligence) are all data-sensitive, and the malpractice consequences of getting it wrong are paid in disbarment proceedings rather than dollars. Multiple US courts have sanctioned counsel for filing briefs with AI-hallucinated case law. State bars (California, Florida, New York, DC) have issued formal opinions on AI use. The EU AI Act treats AI used in administration of justice as high-risk. And the underlying data — client confidences, settlement terms, IP — is among the most jealously guarded in any industry.

Read guide →

AI in Manufacturing & Industrial IoT

For: OT engineers, plant managers, industrial AI vendors, robotics teams, product-safety counsel

AI in factories and connected industrial devices sits at the intersection of product-safety law (centuries old, ferocious enforcement) and the new AI rules (still being written). The EU AI Act treats AI used as a safety component of a regulated machine or device as high-risk by default, plugging directly into the existing Machinery Regulation, Medical Devices Regulation, and Radio Equipment Directive. In the US, OSHA, the CPSC, and sector regulators (FDA, FAA, NHTSA) are scrutinising AI components inside their existing safety frameworks. The compliance burden often comes from those existing regimes, not new AI law.

Read guide →

AI in Marketing & Advertising

For: CMOs, performance marketers, creative directors, brand teams, ad-tech founders, advertising counsel

AI has rewired the advertising stack — from algorithmic targeting and creative generation to dynamic optimisation and influencer-style synthetic personalities. Regulators have been catching up, fast. The biggest exposure today is in three buckets: (1) AI-generated content that's not labelled, (2) automated decisioning that determines who sees what (and at what price), and (3) the political-advertising and election-integrity overlay where the rules are tightest and the penalties are highest. None of this is hypothetical — the Italian Garante, FTC, and ASA have all opened cases against advertisers using generative AI without disclosure.

Read guide →

AI in Media & Entertainment

For: Studio executives, streaming platforms, music labels, generative-AI tool vendors for content, talent agencies, performer-rights counsel

Generative AI hit media and entertainment first and hardest. The legal landscape consolidated rapidly: SAG-AFTRA + WGA 2023 strikes resulted in landmark AI clauses, the New York Times v. OpenAI litigation is testing training-data fair use, voice-cloning bans rolled out across states, and the EU AI Act layered Article 50 transparency on all generative content. The compliance pattern is now clear: consent + disclosure + provenance + payment. Every generative-AI feature in production now navigates this four-way intersection — and the platforms (Netflix, Disney, Spotify) have started requiring contractual flow-down of all four to vendor partners.

Read guide →

AI in Pharmaceuticals & Drug Discovery

For: Pharma R&D leaders, clinical-ops VPs, biotech founders using AI for discovery, regulatory affairs (FDA/EMA), AI-drug-discovery vendors

Pharma AI splits into three regulatory tracks: (1) AI for early-stage drug discovery (relatively light-touch — IP and trade-secret framing dominates), (2) AI in clinical trial design and patient stratification (FDA/EMA guidance is becoming binding fast), and (3) AI in pharmacovigilance and adverse-event reporting (where the rules are oldest and strictest). The big shift in 2024-2025 is that FDA's CDER and CBER both issued draft guidance treating AI used in drug-submission components as a regulated activity — meaning the model itself becomes part of the submission package.

Read guide →

AI in Public Sector & Government

For: Federal/state/local government technology teams, public-service AI buyers, government CTOs, GovTech vendors

Governments are simultaneously the biggest deployers and the strictest regulators of AI. The same agency that writes the AI rules for the rest of the economy buys AI tools to deliver benefits, identify fraud, sentence offenders, and process visa applications — and these uses are increasingly subject to special rules. The EU AI Act treats most public-sector AI as high-risk. The US has executive orders and OMB guidance for federal AI use. Canada's Directive on Automated Decision-Making predates almost all of this. And several jurisdictions now have AI procurement standards that vendors must meet to sell to government.

Read guide →

AI in Real Estate & Tenant Screening

For: Landlords, REITs, proptech founders, tenant-screening platforms, AI valuation vendors, fair-housing compliance counsel

AI in real estate is most regulated at the point where it touches a person — tenant screening, mortgage underwriting, and algorithmic rent-setting. Three forces converged in 2023-2025: HUD's renewed Fair Housing Act enforcement scrutiny (the 2024 SafeRent Solutions consent decree set the template), state attorneys general going after algorithmic rent-setting (DOJ + 9 states v. RealPage YieldStar), and a wave of state AI tenant-screening laws (NYC LL 28, California AB 1418, Illinois, Minnesota). On the property-side: AI for valuation (AVMs) is now part of CFPB + OCC + FDIC quality-control rule for federally-related transactions.

Read guide →

AI in Retail & E-commerce

For: E-commerce platform owners, marketplace operators, pricing/recommendation engineers, consumer-protection counsel, DTC brand technology leads

Retail AI is becoming a regulated practice in three areas: dynamic pricing (algorithmic price discrimination), recommendation algorithms (DSA scrutiny + dark-pattern enforcement), and AI-driven customer service (Article 50 disclosure + state chatbot laws). The shift since 2023: regulators stopped treating algorithmic pricing as a competition-only question and started treating it as a consumer-protection question. The FTC's 'surveillance pricing' inquiry (2024) and the EU's DSA-driven dark-pattern enforcement set the new baseline. Add California SB 243 chatbot disclosure, Connecticut AB 6691, and similar — retail is suddenly multi-jurisdictionally regulated for the first time.

Read guide →

AI in Smart Cities & Urban Tech

For: City CTOs, urban-tech vendors, transit authorities, public-procurement officers, civic-tech compliance leads, municipal-data privacy officers

Smart-city AI is where public-procurement-procedure meets the strictest AI rules. The EU AI Act treats public-space biometric ID, law-enforcement AI, and access-to-public-services AI as high-risk or prohibited. New York Local Law 35, San Francisco's Stop-Secret-Surveillance, and Portland's Surveillance-AI Ordinance build city-level controls. The US AI Executive Order 14110 (rescinded 2025, replaced by EO 14179 + OMB M-25-21) and OMB Memo M-25-21 establish federal-procurement-driven baselines. Cross-cutting: NIST AI RMF, the IEEE Standard for Algorithmic Bias Considerations, and growing state procurement rules.

Read guide →

AI in Telecommunications

For: Telco network engineers, regulatory affairs, MVNOs, satellite/5G product leads, NIS2 compliance officers, telecom-tech vendors

Telecom AI sits in the most heavily regulated and most slowly-moving regulatory space. The EU NIS2 Directive treats telco operators as essential entities with the strictest cybersecurity duties. FCC, BNetzA, Ofcom, and national equivalents have spectrum + network-availability rules that AI in network management must not violate. Plus: AI in voice/SMS interactions touches CCPA + TCPA in the US, EU ePrivacy Directive in the EU. The high-leverage AI use cases — predictive maintenance, fraud detection, traffic-shaping — each implicate a different regulator. Most telcos have built parallel compliance programmes; the consolidation in 2024-2026 is moving toward integrated AI-governance.

Read guide →

AI in Travel & Hospitality

For: Hotel chain CTOs, airline operations, OTA platforms, biometric border-tech vendors, travel-tech founders, hospitality compliance

Travel AI lives at the awkward intersection of border control, dynamic pricing, and biometric ID. The EU AI Act treats AI used in migration, asylum, and border control as high-risk (Annex III §7) — the 'human face' a passenger sees at automated border control falls in scope. EU PNR Directive, TSA Biometric Implementation Plan, Schengen Entry/Exit System rollout (2025-2026), and CBP's evolving facial-recognition deployment all overlay AI-specific regimes onto an industry that already had heavy regulatory load. Pricing AI plus accessibility AI complete the picture.

Read guide →

25 industries covered. Hand-curated; not legal advice.