INDUSTRIES
The attack is the same. The consequence is not.
Prompt injection works the same way in a hospital and a hedge fund. What changes is what happens next, who has to explain it, and which regulator asks first. Sector rule modules ship pre-configured so that part is hours of work rather than months.
Financial services
PCI DSS, NYDFS Part 500, SOX
Customer-facing assistants with account context, agents touching payment and trading systems, and internal copilots sitting on top of material non-public information.
What we look for first
- An assistant that can be talked into disclosing another customer's position
- Agents with write access to systems where an unauthorized action is a reportable event
- Model-inversion attempts against systems trained on customer data, averaging $6.07 million per breach
- Cross-border inference exposing regulated data to a jurisdiction you did not choose
Worth knowing. NYDFS issued guidance in October 2024 explaining how existing 23 NYCRR Part 500 obligations apply to AI risk, covering AI-enabled social engineering, AI-enhanced attacks and third-party AI exposure. It is guidance, not a new rule, which means your existing obligations already cover this and an examiner can already ask.
Healthcare
HIPAA, ONC HTI-1, state AI laws
Clinical documentation assistants, patient-facing triage, prior-authorization automation and any model with a path to the record.
- Protected health information in a prompt heading to a third-party model
- Output that reproduces another patient's information from context
- Prior-authorization or triage agents acting on a manipulated instruction
- Shadow AI in clinical teams, which showed up in 43% of breached organizations overall
Worth knowing. The ONC HTI-1 final rule sets certification criteria for decision support interventions, including predictive ones, requiring certified health IT developers to disclose 31 categories of source attribute information and to run risk management practices. States continue to add their own requirements on top.
Government and defense
FIPS, sovereignty, air-gapped operation
Analyst copilots, document processing at classification boundaries, and any system where the question of whose infrastructure the inference ran on is the first question asked.
- Inference traffic leaving operator control, at all, ever
- Prompt injection planted in an ingested document from an untrusted source
- Model or system-prompt extraction revealing operational detail
- Supply-chain exposure through a security vendor owned outside the United States
Worth knowing. AI-Sentinel is engineered and operated in the United States with no foreign cloud dependency. The default posture is that zero data leaves operator control. The frontier-model tier that would transmit anything is opt-in, redacts before transmission, and can be switched off entirely with the enforcement engine remaining provably byte-identical.
Legal
Privilege, confidentiality, court AI rules
Research and drafting assistants, discovery review, and client-matter systems where a single cross-contamination is a professional conduct problem rather than an IT ticket.
- Privileged material crossing matter boundaries through shared context
- Client confidential information reaching a third-party model without consent
- Hallucinated citations reaching a filing, which courts now sanction for
- Agents with document-management write access acting on injected instructions
Worth knowing. Air Canada tried to argue in 2024 that its chatbot was a separate legal entity responsible for its own statements. The tribunal rejected it. You own what your AI says, and the legal sector is the one that understands soonest what that means.
SaaS and software vendors
SOC 2, customer security review
AI features shipped inside your product to your customers, which makes their prompt injection your incident and their security questionnaire your problem.
- Multi-tenant context bleed between customers
- Your customers' end users injecting through your product into your model
- Unbounded consumption attacks against your token budget rather than theirs
- Every enterprise customer asking how you secure the AI, in every renewal, forever
Worth knowing. The sidecar co-locates with your application so the added latency does not show up in your product. This is the tier where the $100 per user entry pricing exists, and where partners most often want the OEM terms.
Education, K-12
FERPA, COPPA, child safety
Tutoring assistants, administrative automation and anything a minor can type into.
- Student data in prompts to third-party models
- Jailbreaks producing age-inappropriate output through a school-sanctioned tool
- Cost-amplification attacks against a district budget that has no slack in it
- Shadow AI adopted by teachers faster than any district can assess it
Worth knowing. The sector module ships with tighter output constraints and stricter default spend ceilings, because the failure modes here are reputational and safeguarding before they are financial.
COMPLIANCE, STATED ACCURATELY
What we are, what we are working toward, and what we are not.
| Framework | Our position | What that actually means |
|---|---|---|
| MITRE ATLAS | 100% of applicable techniques | Measured against release 2026.07. Techniques that occur on the attacker's own infrastructure, before any traffic reaches you, are outside what any runtime pipeline can address and are excluded. We publish the exclusion list. |
| OWASP LLM Top 10 | 100%, 2026 edition | Re-mapped against the edition released 3 August 2026, in which Excessive Agency moved to third and LLM08 became Hidden Context Exposure. |
| HIPAA | Technically compliant | Controls, logging and PHI handling meet the technical safeguards. Your covered-entity obligations remain yours. |
| FIPS | Technically compliant | Cryptographic handling meets the standard. |
| EU AI Act | Compliance-ready | Logging under Article 12 and human oversight under Article 14 are supported, with 8 documents in the bundled suite. Article 50 transparency obligations applied from 2 August 2026. Stand-alone high-risk obligations were deferred to 2 December 2027 by the Digital Omnibus. |
| GDPR | Supported | For clients with EU exposure. |
| ISO/IEC 42001 | In progress, not certified | Documentation is complete. Organizational process is underway. We will say so plainly until the certificate exists. |
| SOC 2 | No AI-specific criteria exist | There is no AI-specific Trust Services Criteria. Anyone selling you a SOC 2 for AI is mapping AI onto the 2017 criteria, which is legitimate, but it is not a separate certification. |
Regulatory positions verified August 2026. The EU AI Act timeline changed when the Digital Omnibus on AI entered into force on 27 July 2026, and the Colorado AI Act was repealed and replaced in May 2026. If a vendor's compliance page still cites the old dates, it has not been read since last year.
Do not take our word for it. Run it against your own traffic.
Monitor mode goes in non-blocking, in minutes, with zero risk to live workflows. Within days you get a written audit of the prompt injections, extraction attempts and data leaks your current stack is not catching. Then you decide.
The audit is free. The blind spot is not.