Business Functions · Cross-industry comparison
AI Across Regulated Industries: Adoption Benchmarks and Cross-Sector Lessons
The assumption that regulated industries trail on AI does not survive contact with the adoption data. Finance and insurance adopt at well above the national rate, and large professional-services firms sit near the top of the distribution. This comparison benchmarks adoption across finance, healthcare, and professional services, maps what actually gates deployment in each sector, and extracts the governance lessons that transfer.
Regulated industries are not AI laggards. As of May 3, 2026, 33.9% of U.S. finance and insurance firms reported using AI, against a national rate of 19.8%[1]. The real question for a CIO is no longer whether regulated sectors adopt — they demonstrably do — but how each sector's gatekeeper reshapes what adoption looks like, and which governance lessons transfer across sector lines.
of U.S. businesses reported using AI as of May 3, 2026[^census-btos-ai-2026] — up from 3.8% in fall 2023[^census-btos-ai-2023].
U.S. Census Bureau, BTOS
AI use rate in finance and insurance as of May 3, 2026 — second only to the information sector's 39.7%[^census-btos-ai-2026].
U.S. Census Bureau, BTOS
of firms use AI on an employment-weighted basis, versus 18% counting each firm equally — adoption concentrates in large employers[^census-ces-wp-26-25].
Census CES Working Paper 26-25
The benchmark: what the federal data actually show
Most sector-by-sector AI numbers in circulation come from vendor surveys with unstated samples and self-selected respondents. The exception is the Census Bureau's Business Trends and Outlook Survey (BTOS), which asks a large probability sample of U.S. businesses directly whether they use AI in producing goods and services. The Bureau's May 2026 analysis, covering responses collected from December 14, 2025 through May 3, 2026, found overall AI use hovering between 17% and 20% across the period, with between 20% and 23% of businesses expecting to be using AI within the next six months[1]. Those are the numbers to benchmark against — not a vendor's claim about its own customer base.
The trajectory matters as much as the level. In fall 2023, only 3.8% of U.S. businesses reported using AI to produce goods and services, with the information sector leading at 13.8% and professional, scientific, and technical services at 9.1%[2]. National adoption has therefore roughly quintupled in two and a half years — but the sector ordering has barely moved. The sectors that led in 2023 lead in 2026. For a strategy team, that is the important read: sector position is path-dependent, and no regulated industry has been frozen out of the curve by its regulator.
Size is the second axis, and it is steeper than sector. As of May 3, 2026, 37% of firms with at least 250 employees reported using AI in their business operations, 32% of firms with 100 to 249 employees did, and firms with fewer than 20 employees stayed below 20% — with the growth over the winter and spring concentrated among firms with at least 20 employees[1]. A companion Census working paper makes the same point another way: during its November 2025 to January 2026 reference period, 18% of firms used AI in a business function, but the employment-weighted rate was 32%[3]. If you are an enterprise leader, the firms you actually compete with are adopting at roughly double the headline national rate.
AI use rate as of May 3, 2026 (% of firms)
Same technology, three different gatekeepers
The interesting comparison across regulated industries is not the adoption rate — it is the shape of the gate. Finance, healthcare, and legal services all deploy the same underlying model families, often from the same handful of vendors, yet the mechanism that decides whether a given system reaches production is structurally different in each. That mechanism, more than any technology choice, determines deployment speed, evidence burden, and where in the organization AI lands first. The full regulatory map — SR 11-7, the FDA's software framework, HIPAA, SEC and FINRA obligations — is covered in depth in /guides/sectoral-ai-regulation-regtech; the table below compresses it to the decision-relevant contrast.
| Sector | Adoption signal (2026 federal data) | Who gates deployment | What the gate demands | Portable lesson |
|---|---|---|---|---|
| Finance and insurance | 33.9% of firms using AI as of May 3, 2026[^census-btos-ai-2026] | Prudential supervisors, via model risk management guidance (SR 11-7, issued April 4, 2011)[^frb-sr-11-7] | Model inventory, independent validation, effective challenge, documented governance | Extend the model-risk machinery you already have; do not build a parallel AI bureaucracy |
| Healthcare | No sector rate in the May 2026 BTOS story; clinical AI is gated per product, not per firm | FDA for clinical systems that qualify as devices; privacy rules for the data layer | Marketing authorization for AI-enabled devices, tracked on a public FDA list that is updated periodically[^fda-ai-devices] | Validate continuously after deployment, not once before it |
| Legal and professional services | Very large firms in information, professional services, and finance reach 50–60% use, 60–70% employment-weighted[^census-ces-wp-26-25] | Professional-responsibility duties attached to practitioners, not a product regulator | Confidentiality and privilege protection, competence in supervising output, defensible process | Duty-based controls scale where no regulator writes the checklist — but only with training and audit trails |
| Information (the unregulated benchmark) | 39.7% of firms using AI as of May 3, 2026[^census-btos-ai-2026] | Sector-neutral law only | Market pressure: product cycles and talent | The gap to the leader (~6 points for finance)[^census-btos-ai-2026] approximates the cost of sector gatekeeping — smaller than most boards assume |
Finance: governance muscle that predates the technology
Finance's position near the top of the adoption table is often read as appetite for risk. It is closer to the opposite. U.S. banking supervisors issued comprehensive model risk management guidance — SR 11-7 — on April 4, 2011, more than a decade before generative AI reached the enterprise, establishing expectations for validation, governance, and effective challenge of any model a bank relies on[4]. That means a bank adopting a fraud model or an underwriting assistant in 2026 is not inventing governance from scratch; it is registering one more entry in an inventory process that already has owners, validators, and board reporting. The marginal compliance cost of each new AI system is low precisely because the fixed cost was paid years ago.
That pre-existing machinery also explains where AI lands first in financial institutions: fraud and financial-crime detection, where the model-risk framework already governed statistical scoring and the business case is a straight loss-reduction line. The pattern, and how to run it, is the subject of /use-cases/ai-fraud-financial-crime. The tradeoff finance accepts is pace: every model class must be made explainable enough to survive effective challenge, which slows frontier techniques into production.
Healthcare: product-level gates and split-speed adoption
Healthcare's gate sits somewhere structurally different: on the product, not the firm. A clinical AI system that meets the definition of a medical device must be authorized before marketing, and the FDA maintains a public, periodically updated list of AI-enabled medical devices that have cleared that bar[5]. The consequence is a split-speed sector. Clinical AI — imaging triage, diagnostic support — moves at the pace of authorization evidence and post-deployment monitoring. Administrative AI — clinical documentation, coding, scheduling, prior-authorization drafting — sits outside device regulation and moves at the pace of ordinary enterprise software. Health systems that look slow on AI are usually slow on the first track and fast on the second.
The exportable discipline is lifecycle validation. Because clinical models degrade against drifting populations and practice patterns, healthcare governance treats validation as a continuing obligation rather than a launch gate — a stance the FDA's device-list model reinforces by tying each authorization to a defined intended use[5]. Financial institutions accustomed to periodic model reviews, and professional-services firms with no review cadence at all, both have something to copy here. How to select and govern the clinical track specifically is covered in /use-cases/clinical-ai-guide.
Legal and professional services: duties instead of regulators
Legal services have no FDA and no SR 11-7. The gate is the practitioner's own professional duties — confidentiality, competence, candor to tribunals — enforced through liability and discipline rather than pre-approval. In principle that should make adoption frictionless; in practice it shifts the entire control burden onto firm-level process: privilege screens around what data reaches a model, verification obligations on generated output, and audit trails that make an AI-assisted work product defensible after the fact. The federal data suggest large firms are managing that shift: very large firms in the information, professional services, and finance sectors reach use rates of 50–60%, and 60–70% on an employment-weighted basis[3].
The portable lesson runs in both directions. Sectors with heavy gatekeepers can learn from professional services that duty-based controls — named humans accountable for output, not just approved artifacts — cover the gap that product-level review leaves open once a system is live. And professional-services firms can borrow the artifact discipline they lack: a model inventory and a validation habit, even without a supervisor demanding one.
Where AI actually lands inside the firm
Sector rates hide the more actionable pattern: which business functions adopt first. The Census working paper's function-level data are unambiguous. Among firms using AI, sales and marketing leads at 52%, followed by strategy and business development at 45% and IT at 41% — and 57% of users deploy AI in three or fewer business functions[3]. At the worker-task level, 23% of firms (41% employment-weighted) report AI in use for tasks such as writing, document analysis, and information search, with 65% of firms limiting use to three or fewer tasks[3].
Top business functions using AI, among adopting firms (%)
Read that against the gatekeeper table and a strategy falls out. Even inside heavily regulated firms, the first functions to adopt are the least regulated ones — marketing content before underwriting models, internal strategy analysis before claims decisions, IT operations before clinical workflows. Regulated industries are not adopting despite their regulators; they are adopting around them first, building organizational fluency in low-stakes functions while the regulated core moves on a deliberate track. That sequencing is the honest explanation for how finance and insurance posts a 33.9% adoption rate[1] under some of the strictest model governance in the economy.
The augmentation-heavy posture is not an accident of immaturity — in regulated sectors it is the design. Every gate examined here ultimately demands an accountable human: the validator who challenges the model, the clinician responsible for the diagnosis, the lawyer who signs the filing. Firms that architect for augmentation from the start — explicit human review points, override paths, logged rationale — find their edge-function deployments already shaped correctly by the time AI reaches the regulated core. Firms that chase full automation at the edge end up retrofitting accountability later, which is the more expensive order of operations.
What this means for vendor selection
The gatekeeper map should also restructure how regulated buyers evaluate AI vendors, because a generic enterprise checklist — security posture, uptime, price per seat — misses the sector-specific artifact each gate demands. A financial-services buyer needs vendors that can produce validation-ready evidence: documentation of training data lineage, performance characteristics, and known failure modes, in a form that survives independent review — since under the model-risk regime the vendor's model becomes, for supervisory purposes, the buyer's model[4]. A healthcare buyer purchasing anything near a clinical claim needs to establish whether the product's regulatory status matches the intended use — an authorized device on the FDA's list, or a product deliberately scoped outside device regulation[5] — and whether the vendor supports the post-deployment performance monitoring the buyer will remain accountable for. A legal buyer's first questions are data questions: where privileged material flows, whether it is retained or trained on, and what audit trail survives a challenge to the work product.
Two practical consequences follow. First, weight artifacts over attestations: formal certification schemes do not yet exist for most AI-specific obligations, so a vendor's willingness to hand over model documentation, evaluation results, and monitoring hooks is a stronger signal than any compliance badge on a website. Second, budget for the governance you are buying into, not just the license. In every sector here, the recurring cost of validation, monitoring, and audit sits with the buyer, and for systems touching the regulated core it can exceed the software cost itself. A vendor that reduces that ongoing burden — through transparency, tooling, and monitoring support — is frequently the cheaper option at a higher sticker price.
Honest objections
The strongest objection to this comparison is that the headline adoption rates measure breadth, not depth. A firm counts as an AI user in BTOS if it uses AI anywhere in producing goods and services — one marketing team drafting copy with a chatbot clears the bar. The function-level data confirm the shallowness: 57% of adopting firms use AI in three or fewer business functions, and 65% limit task-level use to three or fewer tasks[3]. A 33.9% finance adoption rate is therefore not evidence that a third of financial institutions have AI in their regulated core. It is evidence that a third have AI somewhere — often precisely in the functions their regulators do not touch.
Second, the data are self-reported, and the definitional boundary is soft. As AI features arrive embedded in office suites, CRMs, and EHRs, some respondents will report use they barely control, and others will run embedded AI without reporting it at all. Treat the levels as noisy and the trend and cross-sector ordering — which are consistent across the 2023 and 2026 surveys[2][1] — as the reliable signal.
Third, cross-sector transfer has real limits. Healthcare-style continuous validation assumes a defined intended use to validate against; a bank's trading model has no equivalent of a stable clinical indication. Finance-style effective challenge assumes an independent review function that a 200-lawyer firm cannot staff. The lessons in this piece transfer as governance postures — validate over the lifecycle, keep an inventory, name accountable humans — not as procedures to photocopy. Adapting them to your sector's failure modes and regulatory cadence is the actual work, and it is where cross-industry playbooks most often break.
The read
For an enterprise leader, these benchmarks support three concrete decisions. First, the budget conversation changes: with finance and insurance at 33.9% and large firms at 37%[1], "our regulated peers are waiting" is no longer a defensible board position — and expectation data pointing to 20% to 23% national use within six months[1] says the gap will widen for those who wait. Second, sequencing: the revealed strategy of adopting firms is edge-functions-first, regulated-core-deliberately. Plan both tracks explicitly instead of letting the edge track happen as shadow IT; a structured way to run that progression is in /guides/ai-pilots-and-maturity-guide. Third, governance reuse: every sector examined here got faster by extending an existing control framework — model risk in finance, quality and post-market systems in healthcare, professional duty in legal — rather than inventing a freestanding AI bureaucracy. If your organization straddles jurisdictions as well as sectors, the same reuse logic applies to the international layer mapped in /guides/global-ai-regulation-guide.
Benchmark against your weight class, not the national rate
The 19.8% national rate is dominated by small firms and is the wrong yardstick for an enterprise[1]. A large regulated firm should benchmark against 37% for firms with 250 or more employees, 33.9% for finance and insurance[1], and the 50–60% band that very large information, professional-services, and finance firms already occupy[3]. If you are below your weight class and your sector, the constraint is organizational, not regulatory.
How to apply these benchmarks
- Benchmark against the right cell: your sector's rate and your size band from the Census BTOS data, not the national average.
- Map your gatekeeper's shape — firm-level supervision, product-level authorization, or practitioner duties — before copying any other sector's playbook.
- Inventory where AI already runs by business function; expect it in sales, marketing, strategy, and IT before anywhere regulated.
- Run two explicit tracks: fast adoption in unregulated edge functions, a deliberate evidence-driven track for the regulated core.
- Adopt lifecycle validation from healthcare: schedule post-deployment model reviews, not just launch approvals.
- Adopt inventory and effective challenge from finance: one register of AI systems, each with an owner and an independent reviewer.
- Adopt duty-based accountability from professional services: a named human answerable for every AI-assisted output that leaves the firm.
- Revisit the numbers quarterly — the BTOS series updates continuously, and six-month expectation data signal where your sector's bar moves next.
Sources
Every quantitative or attributed claim above is linked to a primary source. Last verified at publication.
- [1]Large Firms With at Least 20 Employees Biggest AI UsersU.S. Census Bureau · · accessed
- [2]How Many U.S. Businesses Use Artificial Intelligence?U.S. Census Bureau · · accessed
- [3]The Microstructure of AI Diffusion: Evidence from Firms, Business Functions, and Worker Tasks (CES Working Paper 26-25)U.S. Census Bureau, Center for Economic Studies · · accessed
- [4]SR 11-7: Guidance on Model Risk ManagementBoard of Governors of the Federal Reserve System · · accessed
- [5]Artificial Intelligence-Enabled Medical DevicesU.S. Food and Drug Administration · accessed