Ask a bank and a hospital the same question, 'can your AI agent do that in production,' and you'll learn less about their ambition than about which regulator they answer to.
In Today’s Email:
Roughly 31% of enterprises now have at least one AI agent in production, according to S&P Global Market Intelligence and McKinsey, but that average hides a split that's widening rather than closing: banking and insurance lead at 47% production adoption, while healthcare sits at 18% and government trails at 14%. The year-over-year numbers make the trend unmistakable, banking and insurance gained 23 percentage points while healthcare gained 7 and government gained 5. This issue builds on "The Move to Vertical Agentic AI Solutions" (Feb 5) and "The Compliance Countdown" (Apr 23) to explain why this gap exists, why it's structural rather than a maturity problem healthcare and government will simply grow out of, and what actually closes it.
News
1. California Passes Landmark Ban on AI Emotion Surveillance
On September 1, 2026, the California legislature passed a major employment bill (AB 1883) that explicitly prohibits employers from using AI-powered workplace surveillance tools to infer workers' emotional states or collect their neural data. This aggressive move is part of a broader wave of California AI employment legislation advanced this session. Alongside the surveillance ban, the legislature advanced bills that would require employers to notify workers of mass layoffs caused directly by AI, and bar companies from relying solely on automated systems for disciplinary or termination decisions. This legislative push sets hard, legally binding boundaries on how artificial intelligence can be used to monitor and manage human capital.
Key Takeaway: The "wild west" of AI-driven employee management is closing rapidly. HR, Legal, and IT teams must immediately audit any AI productivity, surveillance, or automated HR systems currently deployed to ensure they don't violate these emerging privacy and "human-in-the-loop" mandates, as California’s regulations frequently set the national standard for corporate compliance.
2. AI Surges to the Second-Biggest Human Risk in the Workplace
According to the SANS Institute’s newly released 2026 Security Awareness & Culture Report (published August 27), artificial intelligence has officially become the second-biggest human risk tracked by security professionals, trailing only social engineering. Just two years ago, AI ranked fourth on this list. The report identifies three massive new behavioral vulnerabilities for the digital workforce that practitioners must now manage: the unauthorized use of generative AI tools, risky "vibe coding" by employees with zero software development background, and the deployment of autonomous AI agents operating without proper human review.
Key Takeaway: Equipping your workforce with AI tools is no longer just a productivity play; it is an active security liability. Leaders must pivot their training programs immediately to address AI-specific risks—particularly the dangers of non-technical staff deploying unsupervised AI agents and generating unvetted code directly into enterprise environments.
3. The Industrial Sector Pivots to "Agentic Digital Workers"
New research released this past week by The Futurum Group and industrial AI provider IFS reveals that industrial and frontline workers are still losing roughly 41% of their time to manual, repetitive tasks. To close this severe capacity gap, which is being exacerbated by a retiring workforce, companies are aggressively accelerating their investments in "agentic digital workers". These specialized AI agents autonomously monitor systems, make operational decisions, and execute tasks, only escalating to a human when complex judgment is required. However, the data highlights a massive trust deficit: while 66% of businesses plan to invest in digital workers this year, a mere 5.7% of decision-makers actually trust AI to act fully autonomously.
Key Takeaway: The transition to an autonomous digital workforce requires a "human-in-the-loop" bridge. Rather than deploying AI to operate entirely in the dark, organizations must design AI workflows that hand off critical judgment calls to human operators, building the internal trust and auditability required before scaling to full automation.
The Gap That's Widening, Not Closing
It's tempting to read a 47% versus 18% versus 14% split as a snapshot of who's ahead today and assume the laggards catch up over time, the way most technology adoption curves eventually flatten out. The year-over-year data says otherwise. Banking and insurance added 23 percentage points of production adoption in a single year. Healthcare added 7; Government added 5. The leaders aren't just ahead, they're pulling away nearly three times faster than the industries behind them are closing distance. Left unaddressed, this isn't a gap that narrows on its own. It's a gap that compounds.
That distinction matters for how enterprise leaders in every industry should think about this data. If the gap were simply about organizational readiness, more budget, more executive attention, more pilots, you'd expect healthcare and government to be catching up as agentic AI matures and gets easier to deploy. Instead, the industries furthest behind are falling further behind in relative terms even as the technology itself gets more capable. That points to something structural sitting underneath the adoption numbers, not a temporary lag that better tooling eventually erases.
Why Banking and Insurance Were Built for This
Banking and insurance didn't get to 47% production adoption because their technology teams are better than everyone else's. They got there because decades of prior automation left them with something most industries don't have: business processes already broken down into discrete, rules-governed steps that map cleanly onto what an agent can execute. Fraud detection, claims triage, underwriting decisions, and straight-through loan processing were built for structured decisioning long before agentic AI existed. Layering an agent on top of a process that's already codified into explicit rules and thresholds is a categorically easier problem than asking an agent to operate inside a process that still depends on tacit judgment.
The results show up in production numbers that are hard to argue with. JPMorgan alone runs more than 500 AI use cases in production today, with a stated goal of reaching 1,000 by year-end, and that scale isn't experimental, it's operational. Fraud detection systems across the sector report reductions in false positives as high as 80%, translating directly into lower investigator workload and quantifiable cost savings. Early adopters report an average 2.3x return on investment within just 13 months of deployment, the kind of number that makes the next budget approval an easy conversation rather than a hard one. This is exactly the dynamic "The Move to Vertical Agentic AI Solutions" (Feb 5) described: industries where domain expertise was already encoded into rules and models are the ones where agentic AI plugs in fastest, because the hard work of formalizing the domain happened years before any agent showed up to execute it.
The Governance Gap Hiding Inside the Leaders
It would be a mistake to read banking and insurance's production numbers as evidence they've solved agentic AI governance, and KPMG's Q2 2026 AI Pulse survey makes that clear. Even inside banking and capital markets, only 31% of institutions report full visibility into what their AI agents actually cost to run, a startling gap for an industry this far ahead on deployment. Sixty-three percent cite data readiness as a top barrier, 49% cite the sheer complexity of coordinating multiple agents, and 36% report meaningful workforce resistance still slowing rollout. Employee adoption inside banks jumped from 23% to 56% in a single quarter, evidence of real momentum, but also evidence of how recent and unsettled this shift still is even at the industry that's supposedly furthest along.
The honest read is that banking and insurance are ahead on deployment while still catching up on the governance maturity that deployment at scale actually requires. They got the green light to move fast because their processes were structurally ready, not because their oversight infrastructure was. That distinction matters, because it means the 47% figure describes velocity, not necessarily durability, and the industries watching from behind shouldn't assume matching that velocity is the goal worth chasing on its own.
Healthcare's Regulatory Ceiling
Healthcare's 18% production rate looks like a capability gap until you look at what's actually gating deployment, and it isn't capability. Any AI system that diagnoses, treats, prevents, or drives clinical decision-making requires FDA clearance, a process measured in months even under the best circumstances, and as of March 2026 only 1,524 AI-enabled medical devices had cleared the FDA at all, with 76% of those concentrated in radiology alone. Everywhere else in clinical care, the regulatory infrastructure for approving an autonomous agent barely exists yet.
The deeper problem is that FDA approval assumes a static product, and agentic AI is built to keep learning. The agency's Predetermined Change Control Plan process was designed to let approved systems update without restarting the entire clearance process, but only 26 devices, under 2% of everything cleared, currently have an authorized PCCP. That means the overwhelming majority of approved healthcare AI is frozen at the moment of approval, unable to improve the way agentic systems are supposed to. Layer HIPAA on top of that: any cloud AI service touching patient health information needs a business associate agreement most vendors won't sign, forcing healthcare organizations into self-hosted models or heavily restricted compliant infrastructure before they can even start building. And liability remains entirely unresolved. Courts still apply a reasonable-physician standard that keeps clinicians on the hook regardless of what an AI recommends, which is exactly why fully autonomous clinical AI, without a clinician in the loop, is what one industry analysis called the frontier almost nobody ships. The EU AI Act adds its own timeline on top of all this, with general high-risk obligations beginning August 2, 2026 and medical device AI specifically given until August 2, 2028 to comply. None of this is a story about healthcare lacking the technical talent or ambition to build agents. It's a story about an approval architecture built for static devices trying to accommodate systems that were never meant to sit still.
Government's Procurement Ceiling
Government's 14% figure has a similarly structural explanation, and it starts with FedRAMP. The standard federal cloud authorization process takes 12 to 18 months on average, and organizations without strong existing security maturity can see that stretch past two years. For a technology category evolving as fast as agentic AI, an 18-month authorization clock means agencies are often evaluating capability that's already a generation behind what's commercially available by the time approval lands. The GSA's FedRAMP 20x initiative is a direct acknowledgment of the problem: it's designed to compress authorization to roughly two months for AI tools that meet a narrow set of eligibility criteria, a meaningful fix, but one that only reaches a fraction of what agencies actually need to evaluate.
The adoption data inside government tells a consistent story once you separate federal from state and local. Sixty-four percent of federal employees report using AI tools daily, compared to 48% at the state and local level, a gap that maps closely onto which layer of government has more mature procurement and governance infrastructure already in place. Sixty percent of public sector professionals across both levels cite the AI skills gap as their single biggest obstacle, and state and local agencies are more than three times as likely as federal agencies to have no AI-use policy at all. Just as "The Compliance Countdown" (Apr 23) mapped the 100-day sprint enterprises faced ahead of EU AI Act enforcement, government agencies are now running their own version of that sprint against a procurement clock that was never designed to move at the speed agentic AI requires.
Compliance Overhead Isn't the Same as Capability Gap
Put the healthcare and government stories side by side and the pattern is identical even though the mechanisms differ. Healthcare is gated by an approval process built for static medical devices. Government is gated by a procurement process built for static software purchases. Neither industry is behind because its people can't build good agents. Both are behind because the regulatory and procurement infrastructure surrounding them was designed for a technology category, software that doesn't change once it's approved, that agentic AI simply isn't.
This reframe matters because it changes what "catching up" should actually mean for leaders in these industries. If the gap were a maturity problem, the fix would be more pilots, more training, more executive sponsorship, the standard playbook. If the gap is a structural mismatch between approval architecture and how agentic systems actually work, then the fix has to happen at the level of the approval architecture itself: PCCP-style frameworks that let approved systems update without restarting clearance, FedRAMP-style fast tracks that reach more than a narrow eligibility slice, liability frameworks that finally settle who's accountable when an autonomous system, not a static tool, makes the call. Banking and insurance didn't need those fixes because their regulatory environment was already built around structured, auditable decisioning. Healthcare and government need those fixes before their adoption curves can behave anything like banking's.
What Catching Up Actually Requires
Enterprises in healthcare and government reading the 47% versus 18% versus 14% gap as a call to move faster are aiming at the wrong target. Moving as fast as a bank isn't available to them yet, not because their technology strategy is weaker, but because the compliance and procurement infrastructure surrounding them hasn't caught up to what agentic AI needs. The organizations actually gaining ground inside these industries are the ones treating regulatory readiness itself as the competitive investment, building toward PCCP eligibility before a product needs it, designing infrastructure around HIPAA-compliant hosting from day one instead of retrofitting it later, positioning early for FedRAMP 20x eligibility rather than waiting to see whether the standard timeline eventually improves.
That's a different kind of readiness than the operational readiness banking and insurance needed, and it takes longer to build precisely because it depends on external regulatory processes moving in parallel, not just internal engineering effort. But it's the actual lever available. An enterprise that spends the next year building the compliance and documentation infrastructure its regulator will eventually require is positioned to move the moment that regulator's process catches up. An enterprise that waits for the process to catch up before starting is guaranteed to be exactly where it is today when that moment arrives.
The Bottom Line
The industry adoption gap isn't a story about who's more serious about agentic AI. It's a story about which industries had their operational and regulatory infrastructure already built for the kind of structured, auditable, machine-executable decisioning agents require, and which industries are still waiting on infrastructure, FDA change-control pathways, FedRAMP authorization speed, settled liability doctrine, that hasn't been built yet. Banking and insurance got a head start measured in decades, not months, and the widening year-over-year gap shows that head start compounding rather than eroding.
None of that means healthcare and government are stuck. It means the work required to close the gap looks different than the work banking and insurance already did, and enterprises in those industries need to stop benchmarking their pace against banking's production numbers and start benchmarking their regulatory readiness against what their own approval pathway will eventually demand. The gap will close eventually, as PCCP authorizations grow past 26 devices and FedRAMP 20x reaches beyond its current narrow slice. The enterprises that spend this year building toward that moment, rather than waiting for it, are the ones that turn a structural disadvantage into a much shorter one.
Closing the gap between where your industry sits today and where regulated deployment actually requires you to be starts with an honest assessment of what's gating you: capability, or compliance infrastructure. The Complete Agentic AI Readiness Assessment includes frameworks for evaluating regulatory readiness alongside technical maturity, mapping your path through approval processes built for static systems, and prioritizing the infrastructure investments that shorten your own adoption curve. Get your copy on Amazon or learn more at yourdigitalworkforce.com. For organizations in healthcare, government, or other regulated industries working to close this gap, our AI Blueprint consulting helps build compliance-ready agent architectures, navigate approval and authorization pathways, and design the governance infrastructure that turns regulatory readiness into competitive advantage.

