AI across industries: the sector decides where risk comes from
Six sectors, six different breaking points. Credit in banking, third-party models in insurance, athletes in sport, shifts in retail, the product in manufacturing, commercial systems in telecom.
In short. The question of what the AI Act means for a company has no single answer, because the sector decides where high risk comes from and which gate blocks the rating. In banking it comes from credit, in insurance from suppliers' models, in sport from athletes as workers, in retail from the systems managing shifts, in manufacturing from the product sold, in telecom from commercial systems. The rest of the method stays the same everywhere.
We have worked across six sectors with the same sequence, system inventory, classification, measurement of the four dimensions, and each time the point blocking the organisation came from a direction management didn't expect. Below is the map, with pointers to the detailed pieces.
The sector decides where risk comes from
| Sector | Where high risk comes from | The recurring gate |
|---|---|---|
| Finance | Creditworthiness assessment, Annex III | No inventory covering systems already in production |
| Insurance | Pricing and risk selection on third-party models | Perimeter: the insurance company deploys models it didn't build |
| Telecom | Commercial systems, starting with customer credit assessment | Classification never done on systems born as administrative tools |
| Sport | Athletes as workers, biometrics in stadiums, training of coaches and match officials | Data ownership, almost always with suppliers |
| Manufacturing | Products with embedded AI, Annex I | Missing separation between plant systems and systems bound for the product |
| Retail | Shift planning and staff evaluation, Annex III | Predictive modules inside workforce management software |
In finance and insurance the perimeter matters more than the machinery
These two sectors arrive best prepared, because independent model validation predates the AI Act and documentation is an established habit. What is missing is the boundary: which systems are in scope, who built them, which obligations stay with whoever uses them.
In banking, training grafts onto paths that are already mandatory and the critical roles are three, as AI literacy in banking explains. The first use case is almost always chosen the wrong way round, and the reason is in AI adoption in banking. How the rating weighs the four dimensions is in AI Rating in banking.
On the insurance side a modelling culture helps and the forgotten perimeter is the agency network, as AI literacy in insurance sets out. The most valuable use case is also the one falling under Annex III, and the reasoning is in AI adoption in insurance. The gate that sets the class is described in AI Rating in insurance.
Telecom and manufacturing: where technology isn't the problem
Here companies own their data, run solid infrastructure and have mature release cycles, and precisely for that reason they arrive at the measurement convinced they are ahead. The score falls elsewhere.
For telecom operators the training difficulty is scale, with thousands of people who are not on the operator's payroll, and the answer is in AI literacy in telecom. The area with most value is also the one with least friction, a rare case explained in AI adoption in telecom, while the gate sits on commercial systems, as AI Rating in telecom shows.
In manufacturing everything turns on a separation that precedes every other assessment, between a system that stays in the plant and one that ends up inside a product sold to customers. Training grafts onto workplace safety, with the risk described in AI literacy in manufacturing. The choice of the first case is in AI adoption in manufacturing, and the data weakness that surprises technologically advanced companies is in AI Rating in manufacturing.
Which framework does your company actually need?
AI Rating measures maturity across the four areas of the model and shows where to start, with priorities and estimated effort.
Start your AI RatingRetail and sport, risk where nobody looks
These two sectors share a trait: management attention sits on the customer and the supporter, while the real exposure concerns the people who work.
In retail, turnover makes the annual training plan useless, and the alternative is in AI literacy in retail. The use case that pays and the one that exposes are separated in AI adoption in retail, while the gate on predictive modules inside workforce software is in AI Rating in retail.
In sport the populations to train are two in clubs and three in federations, as AI literacy in sport explains. The starting point differs between clubs and federations, and the difference is in AI adoption in sport. The gate on data ownership, which in clubs almost always sits with suppliers, is in AI Rating in sport.
The constants that cut across sectors
Three things recur everywhere, whatever the sector. The first is that the most exposed systems arrive inside software bought for something else, predictive modules switched on within tools nobody reassessed after purchase. The second is that role-based training already exists on other fronts, from workplace safety to anti-money laundering, and grafting onto those paths costs far less than building new ones. The third concerns data, which in almost every sector belongs contractually to a supplier, and a company unable to export what it works on doesn't control its own systems.
How these three weigh on the score is described in the four dimensions of AI maturity and in the critical gates.
Where to start
The prerequisite is the same in every sector, and it doesn't depend on company size: the AI system inventory, built by looking inside software already in use as well.
From there comes risk classification and the measurement described on the AI Rating page. The full sector map is on the Sectors page.
To understand where the exposure sits in your organisation you can book an assessment session or start the self-assessment.