top of page

Nine Industries. No New AI Law Needed. One Rule That Was Already There.

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
Aug 31
7 min read

Two weeks ago we started asking one question of nine different industries: what rule actually governs the AI tools your staff already use? We expected to find gaps. Instead we found the same thing nine times. The rule was already there, written years before anyone pasted a client file into a chatbot, and in every case the only thing missing was an inventory of the tools it now reaches.

This page is the whole series in one place. Find your industry, read the paragraph, and follow the link to the full piece. If you run a business in a sector we did not cover, read the last two sections anyway, because the pattern is not really about industries.

The pattern, in one paragraph

Adoption came first and fast. Verizon's 2026 Data Breach Investigations Report found 45 percent of employees are now regular users of AI tools at work, up from 15 percent a year earlier, and 67 percent of the people using AI on corporate devices were signed in with non-corporate accounts. IBM's 2026 Cost of a Data Breach study found shadow AI involved in 43 percent of the security incidents it examined, up from 20 percent. Those are cross-industry numbers. What differs by industry is not whether the tools arrived but which existing rule they walked into. Here are the nine.

1. Medical practices: HIPAA reached the tools first

HIPAA's business associate rules date to the Privacy Rule, in force since 2003, with direct liability for business associates arriving in the 2013 HITECH Omnibus Rule. HHS's own business associate guidance, last reviewed July 30, 2026, lists a third-party AI chatbot on a patient portal, handling patient information, as an example of a business associate. The consumer and self-serve team tiers of the standalone AI assistants we compared do not come with a Business Associate Agreement, which means a staff member summarizing a patient note in one of them has handed protected health information to a vendor with no BAA. A December 2025 survey of 518 healthcare professionals found 40 percent had encountered unauthorized AI tools in the workplace. Read the healthcare piece.

2. Financial firms: the SEC withdrew its AI rule, and did not need it

In July 2023 the SEC proposed a rule on predictive data analytics, written broadly enough to cover AI. In June 2025 the Commission formally withdrew it. There is no SEC rule specifically about artificial intelligence today. There did not need to be: the amended Regulation S-P requires written policies for oversight of service providers, including due diligence and monitoring, and its compliance dates, December 3, 2025 for larger firms and June 3, 2026 for smaller ones, have both passed. The rule does not mention AI; it reaches any service provider that receives customer information, and a firm's own policies are expected to say how that provider is overseen. A Schwab study of 533 advisors found 63 percent using AI, and 82 percent of those users relying on generative AI tools, most often through individual experimentation rather than firm-wide systems. Read the financial services piece.

3. Law firms: Virginia's AI opinion is about fees, not secrets

The Supreme Court of Virginia approved Legal Ethics Opinion 1901 on November 24, 2025. It addresses how the time savings from generative AI bear on the reasonableness of fees. It does not address confidentiality; Rule 1.6 already covers that, and the ABA's Formal Opinion 512 of July 29, 2024 walked through how the existing duties of competence, confidentiality, and supervision apply to generative AI tools. Meanwhile an industry survey found 69 percent of legal professionals using AI tools while 54 percent of respondents said their firm provides no AI training and has no plans to. Read the law firm piece.

4. Accounting and tax firms: the IRS restated what already applied

On June 24, 2026 the IRS Office of Professional Responsibility issued its Introductory Guidelines for Responsible AI Use in Federal Tax Practice. Rather than creating AI-specific rules, the guidance applies existing Circular 230 obligations, competence, due diligence, supervision, and confidentiality among them, to AI. Beneath it sit older rules: IRC section 7216, which makes knowing or reckless disclosure or use of tax return information beyond preparing the return a misdemeanor, with any consent to broader use required, under its regulations, in writing and in advance, and the FTC Safeguards Rule, under which tax professionals are, in the IRS's own phrasing, considered financial institutions. A 2026 survey of more than 1,000 tax professionals found 60 percent of respondents using AI for tax research at least weekly, up from 33 percent the year before, while a separate global survey found about one in five firms with an AI policy or strategy. Read the accounting piece.

5. Government contractors: the audits paused, the CUI rules did not

On July 13, 2026 the Pentagon suspended Phase 2 of CMMC while a Reform Task Force reviews the program, with the Task Force's recommendations reported to be expected in mid-September. What did not pause: DFARS 252.204-7012, NIST SP 800-171 Revision 2 and its 110 controls, and the SPRS score with its annual affirmation. Nor did the guidance on where CUI may go: ISOO Notice 2026-01 of March 30, 2026 told agencies that CUI is not to be entered into internet-enabled or external AI systems. And the enforcement route that has actually cost contractors money is the False Claims Act, where firms have paid millions to resolve allegations that their self-attested security posture did not match reality. A pasted CUI paragraph is an affirmation problem long before it is an AI problem. Read the government contractor piece.

6. Manufacturers: trade secret law protects only what you guard

Manufacturing has no confidentiality regulator. It has something more fragile. Under the Defend Trade Secrets Act, information is a trade secret only if, in the statute's words, "the owner thereof has taken reasonable measures to keep such information secret." A drawing or process sheet pasted into a personal AI account is evidence about those measures, and once secrecy is actually lost, there is nothing left to enforce. The stakes are not abstract: IBM's X-Force 2026 report found manufacturing the most attacked industry for the fifth consecutive year, with data theft the most common outcome. Read the manufacturing piece.

7. Real estate: the duty is written into the license

Virginia's real estate license law requires a licensee engaged by a seller to "maintain confidentiality of all personal and financial information received from the client during the brokerage relationship," and the buyer-side statute says the same. That duty predates AI and reaches it. A February 2026 industry survey of 225 agents found 82 percent already using AI, mostly for writing. The federal layer is split: the FTC Safeguards Rule reaches the settlement and mortgage side of a closing, while agents and brokerages sit outside it and title insurers answer to state insurance regulators. Read the real estate piece.

8. Nonprofits: the exemption is quietly expiring

Nonprofits adopted AI as fast as any sector in this series: a December 2025 survey of 346 organizations found 92 percent using it and 47 percent with no AI governance policy. The rules are newer than most boards think. Colorado's and New Jersey's comprehensive privacy laws contain no nonprofit exemption, Delaware and Oregon carve out only narrow categories, chiefly nonprofits focused on insurance fraud, and state breach notification laws generally apply regardless of tax status. Virginia still exempts nonprofits, but donors do not live in one state, and where another state's law applies and its size thresholds are met, the exemption a board assumed is simply gone. The sector's own defining breach came through its donor CRM vendor and led to a $49.5 million settlement with 49 states and the District of Columbia. Read the nonprofit piece.

9. Professional services: the rules were signed, not passed

Consultants, agencies, engineering firms, and IT shops are the vendor every other industry was told to scrutinize, and their rulebook is contractual. Nearly every engagement sits under an NDA or master services agreement with a confidentiality clause broad enough to cover a consumer AI tool on a personal account. Newer AI clauses are now appearing in real services agreements, prohibiting AI use in the performance of services or the input of client confidential information into AI tools without prior written consent. Between contracts sit the security questionnaires, and a 2025 survey of 3,500 business and IT leaders found 61 percent spending more time proving security than improving it. Read the professional services piece.

What nine industries actually taught us

Three things held every single time.

First, no industry was waiting for a rule. Every regulator, statute, ethics body, and contract we examined had already reached the AI tools, often years before those tools existed, because the rules were written about information, not about technology.

Second, the honest caveat was the same everywhere. Public enforcement actions against small firms specifically for staff AI misuse were hard to find, and we said so plainly rather than pretend otherwise. The exposure arrives sideways: a breach notification, a failed audit affirmation, a renewal questionnaire, a lost trade secret, a client who quietly moves on.

Third, and this is the part that matters, every industry shared one starting point. You cannot honor a confidentiality duty, sign an affirmation, answer a questionnaire, or take "reasonable measures" around tools you have not found. So the first move was never a policy memo. It was an inventory: every AI tool, browser extension, and AI agent on the machines that touch sensitive work, and which account each one is signed into, work or personal. Then one clear rule about what data stays out of unapproved tools. Then an approved path, because staff adopted these tools to get work done and that pressure is not going away.

Where we fit, and where we do not

We are not lawyers, auditors, or compliance consultants, and nothing on this page is legal advice. What your regulator, bar, or contract requires is a question for counsel.

What we run is the inventory and the enforcement behind it. Our Managed AI Security service starts with a free AI Discovery: a light install, about a week of quiet observation, then a report of the AI tools, extensions, and agents found in use across your machines, including which are running on personal accounts, risk ranked in plain English. Nothing changes for your staff while it runs, and the report is yours whatever you do next. From there we enforce the tool list you approve and keep watching as new AI shows up. It supports the duties described above; it does not satisfy them on its own, and no honest vendor would claim otherwise.

The question worth asking this week

Pick your industry above and read its rule again. Then ask the question all nine pieces ended with, in one form or another: if that rule reaches the AI your staff already use, and it does, do you know today which tools those are?

We work with regulated and trust-bound businesses nationwide from our home base in McLean, Virginia. If you run a practice, firm, contractor, plant, brokerage, nonprofit, or agency in Washington DC, Northern Virginia, Maryland, or anywhere in the country, book a free 15-minute call. The discovery is free, and the answer is yours either way.

Comments


bottom of page