While AI is being sold on its ability to transform the enterprise, a different question is starting to surface within regulated industries: can it be trusted?
Trust has been a recurring theme during recent discussions with digital leaders across healthcare, government, higher education, and critical infrastructure. While the sectors and use cases are different, organizations spanning regulated industries are considering whether they can rely on AI in environments where mistakes can carry huge operational, regulatory, and reputational consequences.
“In a regulated industry, trust isn’t a ‘nice to have’. It’s the currency,” said Alan Rosa, CISO and SVP of infrastructure and operations at CVS Health, speaking at the recent launch of ServiceNow’s latest AI features.
The topic raised its head again at the ServiceNow AI Summit London last week. There,ServiceNow’s VP of public sector UK, Aaron Neil, said: “The sticking point is really confidence and decision making.”
He pointed to organizations’ ambition around AI, but slower progress in real deployment. According to ServiceNow research cited during the event, only 25% of AI investments had created more human experiences or improved productivity across government.
Governance Moving to the Centre
Rather than viewing trust as a separate issue, many in regulated sectors are now discussing it operationally, describing things like guardrails, visibility, policy frameworks, review processes, auditability, and clearly defined escalation paths.
At Oxford University Hospitals NHS Foundation Trust, that meant putting governance in place early. “We needed our structural governance in place to support the adoption and the understanding,” said head of IT, Lee Massie.
The University of London described a similar approach. Richard Michel, the institution’s chief information and digital officer, said the university had developed an AI policy framework to help define where AI could appropriately be used and where it could not.
“Here’s where you can and should use AI, and here are the guardrails and the considerations,” he said.
Both suggest that in regulated sectors, serious AI work is beginning with the question, ‘under what conditions would we be prepared to trust this?’
“Boring Is Beautiful”
Rosa’s take is that “Boring is beautiful… It’s predictable, it’s stable,” pointing to a predictability in systems, which can be understood, tested, monitored, and governed.
The same preference has emerged in critical infrastructure. Jody Elliott, head of IT risk and sustainability at National Grid, described how easy it can be for AI to produce output that appears compelling while lacking the context needed for sound decision-making.
He explained: “It had no visibility of our data integrations, our build patterns, our security requirements, our contractual obligations with vendors, our price controls. It had none of that information, so it filled in the blanks.”
That means human oversight remains central to the trust conversation. All the leaders described AI as a way of reducing repetitive burden while preserving human judgment when it matters most.
“AI isn’t replacing human connection. It’s creating space for it,” said Rosa.
In healthcare, that translates to more time for clinicians to focus on patients rather than admin work. In higher education, Michel pointed to areas such as wellbeing services, where, he said, “you really do need to pass straight through to a human.”
At National Grid, Elliott made a similar point from a risk and controls perspective, saying AI agents “need to be sat underneath those SMEs [subject matter experts].”
The idea that AI should sit under expert oversight rather than outside of it may turn out to be a defining principle of enterprise AI in regulated sectors.
At the same time, workflow is becoming a prominent part of the AI discussion – after all, “AI without workflow is just an expensive advice tool,” according to Neil.
Along the same lines, ServiceNow’s SVP product management, John Aisien, recently differentiated between AI that produces insight and AI that can actually help complete work, noting “answers are not business outcomes.”
A system that can generate suggestions but not operate inside governed workflows may still leave organizations carrying the same execution risk.
Trust Is Not a One-Time Decision
Another takeaway is that AI adoption involves a continuous learning curve. “You can’t just train and deploy and expect it to work,” said Massie.
Elliott echoed the point: “It’s not a one-and-done. We need to reinforce that, and continually reinforce that.”
“You have to start with responsible, explainable AI… guardrails. You treat it as an evolving set of capabilities that needs to be governed, tested, and continuously validated,” said Rosa.
Final Thoughts
This year, 50% of governments worldwide are expected to enforce the use of responsible AI through strict policies and data privacy requirements, according to Gartner.
Regulated industries are often assumed to be behind the curve on emerging technology. But unlike many of their enterprise counterparts, regulated organizations are not just asking whether AI can generate an answer faster. They are asking whether it can operate within policy, stand up to scrutiny, and support decisions and workflows without introducing unacceptable risk.