{
  "version": "2026-05-14",
  "updated_at": "2026-05-14",
  "canonical_url": "https://g14.ai/regulated-industries",
  "page": "/regulated-industries",
  "title": "G‑14 Regulated AI Action Review Console",
  "publicScope": "Capability, evidence, and integration framing for regulated AI action control. Private scoring logic, exact enforcement implementation, customer-specific topology, and protected IP are controlled during access review.",
  "jobs": [
    "Identify the action boundary for one regulated AI workflow.",
    "Map the evidence a buyer, architect, consultant, or auditor needs before live enforcement.",
    "Inspect proof receipt fields and API/Test Lab request shapes.",
    "Route qualified buyers into SDK access or regulated deployment review."
  ],
  "deploymentModes": [
    {
      "title": "Replay",
      "body": "Run G‑14 against historical or synthetic action records to expose authority gaps, missing evidence, and proof requirements."
    },
    {
      "title": "Shadow",
      "body": "Evaluate live proposals without intervening, producing a side-by-side record for governance, security, and operations."
    },
    {
      "title": "Assist",
      "body": "Recommend hold, correction, block, or release decisions to a human or host workflow with evidence attached."
    },
    {
      "title": "Control",
      "body": "Enforce the release decision before action reaches the tool, robot, workflow, or downstream system."
    }
  ],
  "industries": [
    {
      "id": "pharma",
      "label": "Pharmaceuticals & Life Sciences",
      "primaryBuyer": "Quality, validation, lab automation, manufacturing, and regulated-document owners",
      "outcome": "Govern AI-assisted lab, quality, manufacturing, and regulated-document actions before they become record, release, or patient-impacting consequence.",
      "workflows": [
        "Batch-record update or review step",
        "SOP authoring or controlled-procedure change",
        "Training material generation",
        "CAPA effectiveness review",
        "Validation protocol drafting",
        "Change-control documentation",
        "Deviation or quality-event triage",
        "Lab automation and sample-handling action",
        "Pharmacovigilance case routing"
      ],
      "apiStart": "POST /v1/regulated/actions/evaluate",
      "proofReceipt": {
        "id": "G14-PHARMA-REVIEW-042",
        "proposal": "AI agent proposed a controlled batch-record update.",
        "boundary": "GxP record-affecting workflow.",
        "authority": "Quality owner review required before release.",
        "decision": "Held for authorized review.",
        "evidence": "Batch record, SOP version, user role, workflow state.",
        "timing": "Policy-only local gate: sub-ms to low-ms target. Evidence-bound review: 6 configured checks.",
        "risk": "Record mutation without authorized admission.",
        "outcome": "Action not released; review packet exported.",
        "verifier": "Receipt hash-bound where configured."
      },
      "evidenceMatrix": [
        {
          "anchor": "21 CFR Part 211 / CGMP procedural evidence",
          "buyerQuestion": "Can we show who admitted AI-assisted SOP, training, CAPA, validation, or change-control evidence before it became part of the quality record?",
          "g14Evidence": "Procedural action receipt with proposal, boundary, authority route, evidence references, decision, and final outcome."
        },
        {
          "anchor": "21 CFR Part 11 / EU Annex 11",
          "buyerQuestion": "Can we prove who admitted a record-affecting action, when, and from what evidence?",
          "g14Evidence": "Proof receipt with proposal, authority, timestamp, decision, evidence references, and audit binding where configured."
        },
        {
          "anchor": "GAMP 5 / CSV",
          "buyerQuestion": "Can validation teams review one workflow before live enforcement?",
          "g14Evidence": "Replay or shadow packet showing expected action path, hold behavior, release rules, and verifier output."
        },
        {
          "anchor": "Quality system review",
          "buyerQuestion": "Can a held or blocked AI action be routed to the right quality owner?",
          "g14Evidence": "Authority context, reviewer custody, hold resolution, risk event, and final outcome."
        },
        {
          "anchor": "FDA AI/drug development review support",
          "buyerQuestion": "Can the organization explain how AI-assisted actions were controlled in a regulated process?",
          "g14Evidence": "Boundary map, evidence matrix, proof packet exports, and deployment-mode history."
        }
      ],
      "publicBoundary": "G‑14 does not replace a QMS, CSV program, validation owner, clinical judgment, regulatory submission duty, or required human release authority."
    },
    {
      "id": "healthcare",
      "label": "Healthcare",
      "primaryBuyer": "Clinical governance, compliance, security, revenue cycle, and care operations",
      "outcome": "Control AI action paths touching patients, records, claims, care operations, and administrative decisions.",
      "workflows": [
        "Patient-record update or summary writeback",
        "Claim action or payment hold recommendation",
        "Care-management task routing",
        "Clinical workflow handoff",
        "Patient communication or scheduling escalation"
      ],
      "apiStart": "POST /v1/healthcare/actions/evaluate",
      "proofReceipt": {
        "id": "G14-HEALTH-REVIEW-018",
        "proposal": "AI system proposed a patient-record writeback.",
        "boundary": "PHI and clinical documentation workflow.",
        "authority": "Licensed or delegated reviewer required.",
        "decision": "Held before writeback.",
        "evidence": "Role context, encounter state, policy reference.",
        "timing": "Policy-only local gate: sub-ms to low-ms target. Evidence-bound review: 5 configured checks.",
        "risk": "Unauthorized clinical record change.",
        "outcome": "No writeback released; review packet retained.",
        "verifier": "Verifier receipt available where configured."
      },
      "evidenceMatrix": [
        {
          "anchor": "HIPAA Security Rule",
          "buyerQuestion": "Can we show access, audit, and risk handling for AI-assisted actions involving PHI?",
          "g14Evidence": "Action packet with role context, evidence references, decision state, and audit export."
        },
        {
          "anchor": "Clinical governance",
          "buyerQuestion": "Which actions require licensed or policy review before they affect care operations?",
          "g14Evidence": "Boundary classification, hold route, reviewer custody, and final release outcome."
        },
        {
          "anchor": "NIST AI RMF",
          "buyerQuestion": "Can AI actions be governed, measured, and reviewed after execution?",
          "g14Evidence": "Runtime decision record, risk event, evidence used, and proof receipt."
        },
        {
          "anchor": "Vendor risk review",
          "buyerQuestion": "Can a buyer inspect what the AI was allowed to touch?",
          "g14Evidence": "Workflow map, proof-packet fields, deployment mode, and export path."
        }
      ],
      "publicBoundary": "G‑14 does not replace clinical judgment, medical-device regulatory analysis, HIPAA compliance programs, EHR controls, or required licensed review."
    },
    {
      "id": "finance",
      "label": "Financial Services & Insurance",
      "primaryBuyer": "Model risk, operations risk, claims, payments, trading support, and compliance",
      "outcome": "Govern AI actions before they touch money movement, customer commitments, trading systems, claims, credit, fraud, or model-risk workflows.",
      "workflows": [
        "Claims decision or payment hold",
        "Fraud queue action",
        "Customer commitment or refund path",
        "Credit workflow step",
        "Trading support or production operations action"
      ],
      "apiStart": "POST /v1/financial/actions/evaluate",
      "proofReceipt": {
        "id": "G14-FIN-REVIEW-091",
        "proposal": "AI system proposed a claims payment hold.",
        "boundary": "Customer-impacting financial decision.",
        "authority": "Supervisor or policy owner required.",
        "decision": "Held pending review.",
        "evidence": "Claim record, fraud indicator, notice policy.",
        "timing": "Policy-only local gate: sub-ms to low-ms target. Evidence-bound review: 7 configured checks.",
        "risk": "Unreviewed customer-impacting hold.",
        "outcome": "Action not released until authority resolves hold.",
        "verifier": "Verifier bundle available where configured."
      },
      "evidenceMatrix": [
        {
          "anchor": "SR 11-7 model risk",
          "buyerQuestion": "Can model-driven actions be reconstructed and challenged?",
          "g14Evidence": "Proposal, evidence, authority context, decision reason, and verifier receipt."
        },
        {
          "anchor": "Operational risk",
          "buyerQuestion": "Can controls fail closed when evidence or authority is missing?",
          "g14Evidence": "Hold/block event, reason code, custody record, and final outcome."
        },
        {
          "anchor": "SEC Regulation SCI where applicable",
          "buyerQuestion": "Can covered technology actions support incident and control review?",
          "g14Evidence": "Action packet, release state, timing, risk event, and export bundle."
        },
        {
          "anchor": "Customer dispute review",
          "buyerQuestion": "Can the institution prove what was proposed and what was authorized?",
          "g14Evidence": "Proof receipt with proposal, decision, evidence, reviewer custody, and outcome."
        }
      ],
      "publicBoundary": "G‑14 does not replace regulated supervisory duties, BSA/AML programs, model validation, trading controls, core banking controls, or legal review."
    },
    {
      "id": "industrial",
      "label": "Manufacturing, Robotics & OT",
      "primaryBuyer": "Robotics, OT, plant operations, safety, quality, and industrial engineering",
      "outcome": "Gate robot, AMR, manufacturing, inspection, and industrial workflow actions before commands reach the execution channel.",
      "workflows": [
        "Robot manipulation or assembly step",
        "AMR route or zone authorization",
        "Quality inspection disposition",
        "Industrial task permit",
        "Operator instruction or maintenance action"
      ],
      "apiStart": "POST /v1/industrial/permits/evaluate",
      "proofReceipt": {
        "id": "G14-OT-REVIEW-147",
        "proposal": "AMR route entered a temporary human-work zone.",
        "boundary": "Physical execution channel.",
        "authority": "Operator rule permits route correction.",
        "decision": "Corrected and released.",
        "evidence": "Zone state, mission packet, robot status.",
        "timing": "Policy-only local gate: sub-ms to low-ms target. Evidence-bound review: 8 configured checks.",
        "risk": "Robot route through constrained work zone.",
        "outcome": "Alternate route released; original command suppressed.",
        "verifier": "Hash-bound receipt where configured."
      },
      "evidenceMatrix": [
        {
          "anchor": "ISA/IEC 62443-aligned review",
          "buyerQuestion": "Can the control boundary be scoped around OT connectivity and downstream egress?",
          "g14Evidence": "Deployment boundary, connector review, command custody, and evidence export."
        },
        {
          "anchor": "Safety case support",
          "buyerQuestion": "Can unsafe or unauthorized robot commands be stopped before execution?",
          "g14Evidence": "Blocked/corrected command path, runtime evidence, risk event, and outcome."
        },
        {
          "anchor": "NIST CSF / AI RMF",
          "buyerQuestion": "Can physical AI actions be governed and reviewed after the fact?",
          "g14Evidence": "Proposal, zone state, decision, release path, and proof receipt."
        },
        {
          "anchor": "Private deployment review",
          "buyerQuestion": "Can the deployment avoid public-cloud dependency where required?",
          "g14Evidence": "Infrastructure boundary, private networking plan, and evidence-retention design."
        }
      ],
      "publicBoundary": "G‑14 does not replace certified safety systems, PLCs, interlocks, low-level motion controllers, risk assessments, or required plant safety approvals."
    },
    {
      "id": "energy",
      "label": "Energy, Utilities & Infrastructure",
      "primaryBuyer": "Critical operations, infrastructure security, field operations, and resilience teams",
      "outcome": "Control AI-assisted operational actions where availability, safety, cyber posture, and public trust matter.",
      "workflows": [
        "Maintenance dispatch or field-work action",
        "Anomaly response escalation",
        "Operator note or control-room support action",
        "Asset inspection workflow",
        "Public-service commitment or outage communication"
      ],
      "apiStart": "POST /v1/infrastructure/actions/evaluate",
      "proofReceipt": {
        "id": "G14-INFRA-REVIEW-063",
        "proposal": "AI agent proposed field dispatch for anomaly response.",
        "boundary": "Critical operations workflow.",
        "authority": "Operations center review required.",
        "decision": "Held before dispatch.",
        "evidence": "Asset state, incident ticket, crew state.",
        "timing": "Policy-only local gate: sub-ms to low-ms target. Evidence-bound review: 6 configured checks.",
        "risk": "Operational commitment without admission.",
        "outcome": "Dispatch held; review packet exported.",
        "verifier": "Verifier record available where configured."
      },
      "evidenceMatrix": [
        {
          "anchor": "NIST CSF 2.0",
          "buyerQuestion": "Can AI-assisted operational actions be governed and reviewed inside the cyber boundary?",
          "g14Evidence": "Action packet, boundary context, decision, custody, and audit export."
        },
        {
          "anchor": "NIST AI RMF",
          "buyerQuestion": "Can the organization measure and review AI action risk over time?",
          "g14Evidence": "Risk events, deployment mode, proof receipts, and final outcomes."
        },
        {
          "anchor": "Critical infrastructure review",
          "buyerQuestion": "Can evidence survive incident, regulator, or board review?",
          "g14Evidence": "Verifier-ready packet with timing, authority, evidence, and outcome."
        },
        {
          "anchor": "Private infrastructure",
          "buyerQuestion": "Can the path be scoped around residency, network, and operational requirements?",
          "g14Evidence": "Deployment boundary review, private path, and evidence-retention plan."
        }
      ],
      "publicBoundary": "G‑14 does not replace utility compliance programs, grid-control systems, certified safety controls, NERC obligations, or operator authority."
    },
    {
      "id": "government",
      "label": "Government, Defense & Public Sector",
      "primaryBuyer": "Mission owners, public-sector CIOs, oversight, procurement, security, and program leaders",
      "outcome": "Create a governed action boundary for AI systems that touch mission workflows, public services, records, benefits, procurement, or operational commitments.",
      "workflows": [
        "Case action or benefits workflow step",
        "Public-record update",
        "Procurement or contract workflow action",
        "Mission support recommendation",
        "Citizen-facing decision support output"
      ],
      "apiStart": "POST /v1/public-sector/actions/evaluate",
      "proofReceipt": {
        "id": "G14-PUBLIC-REVIEW-025",
        "proposal": "AI agent proposed a case-record status update.",
        "boundary": "Public authority and records workflow.",
        "authority": "Authorized official required.",
        "decision": "Held before record update.",
        "evidence": "Case state, policy rule, user role.",
        "timing": "Policy-only local gate: sub-ms to low-ms target. Evidence-bound review: 5 configured checks.",
        "risk": "Public-record change without admission.",
        "outcome": "Action held; oversight packet retained.",
        "verifier": "Tamper-evident packet where configured."
      },
      "evidenceMatrix": [
        {
          "anchor": "NIST SP 800-171 / CMMC paths",
          "buyerQuestion": "Can controlled information and action evidence stay inside the scoped boundary?",
          "g14Evidence": "Deployment boundary, evidence-retention plan, access context, and verifier output."
        },
        {
          "anchor": "FedRAMP path where scoped",
          "buyerQuestion": "Can cloud or private deployment review receive proof of action control?",
          "g14Evidence": "Control mapping, packet export, audit binding, and access separation."
        },
        {
          "anchor": "EU AI Act / public-sector oversight analogs",
          "buyerQuestion": "Can high-impact decisions be traced from proposal through authority and proof?",
          "g14Evidence": "Proposal, authority context, evidence used, decision, custody, and outcome."
        },
        {
          "anchor": "Procurement and mission assurance",
          "buyerQuestion": "Can evaluators inspect the action boundary without receiving protected implementation?",
          "g14Evidence": "Controlled route pack, redacted proof receipt, and governed evaluation path."
        }
      ],
      "publicBoundary": "G‑14 does not replace agency authority, legal determinations, accreditation packages, classified-system controls, human rights review, or procurement obligations."
    }
  ],
  "related_surfaces": {
    "sdk": "https://g14.ai/sdk",
    "gxp_brief": "https://externalcontrollayer.ai/gxp",
    "route_pack_json": "https://g14.ai/regulated-industries.json",
    "route_pack_markdown": "https://g14.ai/regulated-industries.md"
  }
}
