This week I sat down to write sales collateral for three regulated industries: legal, financial services, and insurance. The instinct, and the industry norm, is to write one document and change the logo and the industry buzzwords per vertical. I got about a paragraph into that before it fell apart, because the three buyers are not defending against the same thing. They just look similar from the outside, because all three involve sensitive data and a regulator who can ask hard questions later.
Look closer and the failure each one is actually afraid of is different.
Three different things go wrong, not the same thing three times
A law firm's exposure is privilege. Privilege is not just confidentiality with better branding; it is a legal protection that can be waived by disclosure to a third party, and a model provider is a third party. An associate who pastes matter details into a general-purpose chat tool has not just been careless. Depending on how a court reads it, they may have handed opposing counsel an argument that the protection no longer applies. The failure mode is a single act of disclosure, and the damage is often irreversible the moment it happens.
A bank or insurer's exposure to a regulator is different in kind. APRA, the FCA, and SEC/FINRA are not primarily worried about a single leaked email. They are worried about whether the institution can reconstruct, after the fact, what an AI system was told, what it decided, and why - across thousands of interactions, on demand, months later. "The model did it" has not held up as a defence anywhere it has been tested. The failure mode here is not one bad disclosure; it is an evidentiary gap that only becomes visible during an exam, when it is too late to close it.
An insurer carrying out claims and underwriting has a third, separate exposure again: fair-claims-handling and anti-discrimination obligations that apply to the decision itself, not just the data behind it. If an AI-assisted claim denial or underwriting outcome cannot be explained and defended on its own terms, the exposure is not that data leaked. It is that the decision itself cannot survive scrutiny - a different failure, attached to the output rather than the input.
Same pipeline, different job
Privilege waiver, recordkeeping gaps, and undefendable decisions are not variations on one theme. They fail at different moments, for different reasons, and a control that closes one of them does not automatically close the other two.
The same three primitives, pointed differently
OBEL runs the same underlying governance pipeline for all three: Stateful Tokenization, an immutable audit trail, and Multi-Model Response for high-stakes analysis. What changes by vertical is which one is doing the load-bearing work, and what it is actually defending against.
For the law firm, Stateful Tokenization is the front line. Client names and matter details are replaced with stable tokens - [CLIENT_001], [MATTER_001] - before any external model call, which means the model never receives the real names in the first place. There is no disclosure event to waive privilege over, because privileged information never left the firm's boundary in an identifiable form. The audit trail matters here too, but mainly as a defence exhibit: proof of the controls that were in place, produced if the question is ever asked.
For the bank, the audit trail is the front line and tokenization is the supporting control. The regulator's question is retrospective - show me what happened - so the thing that has to exist is a complete, queryable, immutable record of every prompt, response, and governance decision, built at the time of the interaction rather than reconstructed afterward from whatever logs happened to survive. Tokenization reduces what is in that record that could itself become a new point of exposure, but it is not the thing standing between the institution and an adverse finding. The record is.
For the insurer, Multi-Model Response is doing work the other two verticals do not need in the same way. A claims or underwriting decision that affects a real person's coverage or payout benefits from a second opinion before it goes out - comparing a primary model's output against independent review models, with an agreement rating attached, gives the insurer something to point to beyond "the model said so" when a decision is challenged. Tokenization and the audit trail are both present and both doing real work, but the thing that specifically answers "can you defend this decision" is the comparison step, not the data protection underneath it.
Three verticals, one governance pipeline, three different primitives carrying the actual weight. That is not a coincidence and it is not a marketing framing exercise. It is what happens when you take the threat model seriously enough to ask what specifically goes wrong, instead of stopping at "this industry handles sensitive data too."
“Every regulated industry handles sensitive data. That observation is true and almost useless. The question that actually matters is what happens the moment something goes wrong - and it is never the same answer twice.”
- Denis Bouton
Denis Bouton is the founding Chief Architect of OBEL™ and Managing Partner at ninthLABS Ventures, where he advises Post-Sales Services and Customer Success organisations on scaling onboarding, adoption, and retention. He leads OBEL's product and platform strategy.
More in Perspective