AI adoption in a regulated company: rules before tools

AI adoption. Written in October 2026.

In my current role I lead AI adoption and administer the tools. The order matters: tasks first, then tools, then rules and access rights, then a pilot. What follows are the steps in order, with the control each step needs. In this article an agent is an assistant set up for one task, with its own instructions and its own access group.

Start with tasks

Ask each department which tasks take the most time and what data they touch. For each task note how often it happens, what data it needs, who checks the result and what happens if the result is wrong. This list decides where AI is worth trying.

Choose few tools

Judge tools against two lists: what the business needs and what data protection requires. Test them on the same real tasks. Every extra tool brings another set of rules, users and access rights to manage, so a small set is easier to govern.

Write the usage rules

One page is enough if it answers these questions.

  • What data may be entered, and what may never be entered?
  • Who must review the output before it is used?
  • How is AI-assisted content marked?
  • What is logged, and who can see the log?
  • Who decides on exceptions?

In healthcare, the answer to the first question includes patient data and unpublished claims. A short excerpt, as an example:

  • Do not enter patient data or unpublished claims.
  • Check every figure and every claim against its source.
  • Mark AI-assisted content internally before it goes to review.
  • Use only tools from the approved list, with your own access.
  • Report anything unexpected to the administrator.

Set access rights

Create access groups by role and by data sensitivity. Not everyone needs every tool or agent. A named administrator manages the users and groups and reviews the rules when the tools change.

Who owns what

  • Management sponsors the programme and decides how much risk is acceptable.
  • The administrator runs the tools, the users, the groups and the log.
  • Each department names one person who knows its tasks and answers colleagues’ questions.
  • Data protection and legal review the rules before the pilot starts.

Run a pilot with success criteria

Agree the criteria before the pilot starts, and agree the date on which you will decide to extend, change or stop. Typical criteria are the time a task takes, the amount of rework after review, how many people in the team use the tool, and incidents or near misses. My pilot covers 12 AI agents for 8 departments, with the success criteria agreed in advance.

Risks and the control for each

Risk Control
Confidential or patient data entered into a tool Usage rules, access groups, approved tools only
Wrong or unapproved claims in content Human review, assistants limited to approved terminology and claims rules
Staff using unapproved tools on their own Approved tools that do the job
Rules out of date The administrator reviews the rules when tools or tasks change

After the pilot

Review the results against the criteria and update the rules with what the pilot showed. Extend to the next teams in steps. Keep the log.

In pharma terms, where AI touches regulated documents, expect further requirements such as validation and audit trails. Check them with your quality and compliance teams.

AI adoption for your team is one of the four ways I work with companies. See Working together on the home page.