The same prompt injection attack has fundamentally different consequences depending on what data it reaches. In healthcare it exposes PHI. In financial services it triggers regulatory investigation. In legal it compromises attorney-client privilege. This pillar maps how every major regulated industry approaches AI security — and why one-size-fits-all doesn't work.
General AI security guidance tells you to use least privilege, monitor runtime behaviour, and test for prompt injection. That advice is correct and necessary. It is also insufficient for regulated environments, because it doesn't account for the specific legal consequences of specific data types being exposed through specific attack vectors.
A SaaS company that has a prompt injection incident recovers with a patch and a customer communication. A hospital that has the same incident with PHI has a mandatory HIPAA breach notification within 60 days, potential OCR investigation, and patient trust damage that affects care relationships. The technical controls are similar; the governance, legal, and compliance context is entirely different.
HIPAA · PHI · Clinical AI · CDS
DORA · MiFID II · SR 11-7 · PCI DSS
Privilege · Confidentiality · ABA Ethics
SOC 2 · Multi-Tenant · ISO 27001
Despite their differences, regulated industries share a common threat landscape. These six categories affect every vertical — the regulatory consequences differ, but the attacks and defences are structurally similar.
| Threat | Severity | Healthcare Impact | Financial Impact | Legal Impact |
|---|---|---|---|---|
| Prompt Injection | Critical | PHI disclosure, HIPAA breach notification | Regulatory investigation, customer data exposure | Privilege waiver, client confidentiality breach |
| RAG Access Control Failure | Critical | Cross-patient PHI access, minimum necessary violation | Cross-account data exposure, DORA reportable event | Cross-client contamination, privilege waiver risk |
| AI Agent Tool Abuse | Critical | Unauthorised record modification, care workflow disruption | Unauthorised transactions, financial fraud | Unauthorised document access, client actions without approval |
| Third-Party AI Risk | High | PHI to non-BAA vendor, HIPAA liability transfer | DORA supply chain obligations, vendor concentration risk | Privilege waiver, ABA Rule 5.3 supervision obligation |
| AI Supply Chain Attack | High | Compromised clinical AI affecting patient care | Compromised fraud detection, regulatory model risk | Compromised legal research outputs |
| Governance Failures | High | OCR investigation, corrective action plan | Regulatory examination findings, model risk citations | Bar ethics complaint, malpractice exposure |
HexTyx evaluates your AI security posture with industry context — healthcare, financial services, legal, and SaaS profiles. Identify your highest-risk gaps before auditors or regulators do. Free, 10 minutes.